Telecommunications Science ›› 2014, Vol. 30 ›› Issue (11): 105-109.doi: 10.3969/j.issn.1000-0801.2014.11.018

• research and development • Previous Articles     Next Articles

Research on Anti-Trojan Malware Mechanism Based on Characteristic Behavior

Weifu Zou1,Yiying Zhang2,Suxiang Zhang2,Chengyue Yang3   

  1. 1 State Grid Quanzhou Electric Power Supply Company, Quanzhou 362000, China
    2 State Grid Information & Telecommunication Co., Ltd., Beijing 100761, China
    3 NARI Group Corporation Xiamen Great Power Gio Information Technology Co., Ltd., Xiamen 361009, China
  • Online:2014-11-20 Published:2017-07-15

Abstract:

Trojans inject systems and launch various attacks, such as eavesdropping secret information, tampering with system configuration etc., which threats to system security seriously. A novel anti-Trojan malware mechanism based on characteristic behavior and cosine similarity was proposed. Firstly, according to the initial rules base and application behavior, the mechanism regularized the operations of application, and then, the mechanism invoked rules to judges suspicious behaviors based on current rules base and operational impact. Once the application was considered as Trojan malware, the system would dispatch the appropriate algorithm for processing. The mechanism triggered by sensitive behaviors, and had the active prevention function and self-learning function. The analysis and experiment show the solution can detect Trojan malware effectively.

Key words: Trojan malware, behavior detection, regularization, security

No Suggested Reading articles found!