DocumentCode
2103189
Title
A novel approach of detecting Trojan based on network behavior analysis
Author
Shicong Li ; Xiaochun Yun ; Yongzheng Zhang ; Yi Pang ; Tao Yin
Author_Institution
Inst. of Comput. Technol., Beijing, China
fYear
2012
fDate
9-11 Nov. 2012
Firstpage
513
Lastpage
518
Abstract
Most existing approaches for detecting Trojan are limited for obfuscation and encryption techniques. In this paper, we present a network behavior analysis designed to address the limitations of previously-proposed approaches. Our solution considered not only transport layer characteristics but also network layer characteristics. The approach in this paper exhibits two major advantages: (1) can better represent Trojan network behavior, and (2) performed at very low computational cost. Based on clustering technique, we proposed a detection model that detects Trojan communication with high accuracy. We implement the model on real-world traces. The experiments show that our model is suitable for detecting Trojan communication amongst the vast amount of network traffic, with over 90% accuracy and less than 3.5% false positive rate. We confidently consider that our detection approach is complementary to the existing techniques.
Keywords
invasive software; pattern clustering; Trojan communication; clustering technique; detection model; network behavior analysis; network layer characteristics; transport layer characteristics; network behavior analysis; network security; trojan detection;
fLanguage
English
Publisher
ieee
Conference_Titel
Communication Technology (ICCT), 2012 IEEE 14th International Conference on
Conference_Location
Chengdu
Print_ISBN
978-1-4673-2100-6
Type
conf
DOI
10.1109/ICCT.2012.6511272
Filename
6511272
Link To Document