摘要
目前用Win32汇编生成的木马核心程序或木马服务端可以通过二进制资源的形式导入PE文件,针对该种特征木马,提出利用分析程序通信特征及资源特征相结合的方法,快速定位含有非标准资源的可疑程序,并对其进行检测,实现基于资源分析对该种特征木马的检测系统.
Trojan horse core program and server program generated by Win32 assembly can be injected into PE files as binary resource form.Aiming at this certain horse,this paper puts forward Analysis of program's Communication characteristics and resource characteristics to quickly locate suspicious programs with non-standard resources,conduct its detection and realize the detection system of this trojan based on resource analysis.
出处
《安徽工程大学学报》
CAS
2012年第1期71-73,94,共4页
Journal of Anhui Polytechnic University
基金
安徽省自然科学基金资助项目(kj2007a046)
关键词
木马检测
PE文件
资源
trojan horse detection
PE files
resource