首先介绍了特洛伊木马的基本概念及常用的木马检测方法,然后在分析传统的基于静态特征的木马检测技术缺点的基础上,结合基于动态行为监测的木马检测思想,研究以木马植入、隐蔽和恶意操作所需资源的控制和动态可疑行为监测相结合的隐藏木马检测技术,并提出了基于动态行为监测的木马检测系统的基本框架,给出了动态行为监测的相关策略和可疑行为的分析与判定的方法。
This paper first introduced the basic conceptions about Trojan Horse and the common methods most in use in detecting it. Then, on the basis of analyzing the weakness of traditional detection system of Trojan Horse based on static features, in the light of the idea of Trojan Horse based on monitoring dynamic behavior ,it researched the detection techniques of concealed Trojan Horse combining the Trojan Horse implantation,comcealment and resources control needed by malicious operations with the monitoring of questionable behavior, and put forward the basic frame about detection system of Trojan Horse based monitoring dynamic behavior, and the strategy of monitoring dynamic behavior.