• DocumentCode
    2103189
  • Title

    A novel approach of detecting Trojan based on network behavior analysis

  • Author

    Shicong Li ; Xiaochun Yun ; Yongzheng Zhang ; Yi Pang ; Tao Yin

  • Author_Institution
    Inst. of Comput. Technol., Beijing, China
  • fYear
    2012
  • fDate
    9-11 Nov. 2012
  • Firstpage
    513
  • Lastpage
    518
  • Abstract
    Most existing approaches for detecting Trojan are limited for obfuscation and encryption techniques. In this paper, we present a network behavior analysis designed to address the limitations of previously-proposed approaches. Our solution considered not only transport layer characteristics but also network layer characteristics. The approach in this paper exhibits two major advantages: (1) can better represent Trojan network behavior, and (2) performed at very low computational cost. Based on clustering technique, we proposed a detection model that detects Trojan communication with high accuracy. We implement the model on real-world traces. The experiments show that our model is suitable for detecting Trojan communication amongst the vast amount of network traffic, with over 90% accuracy and less than 3.5% false positive rate. We confidently consider that our detection approach is complementary to the existing techniques.
  • Keywords
    invasive software; pattern clustering; Trojan communication; clustering technique; detection model; network behavior analysis; network layer characteristics; transport layer characteristics; network behavior analysis; network security; trojan detection;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Communication Technology (ICCT), 2012 IEEE 14th International Conference on
  • Conference_Location
    Chengdu
  • Print_ISBN
    978-1-4673-2100-6
  • Type

    conf

  • DOI
    10.1109/ICCT.2012.6511272
  • Filename
    6511272