论文部分内容阅读
木马是以获取主机控制权和窃取信息为主要目的恶意程序,对网络安全和信息安全造成极大危害。首先介绍了木马的工作原理,针对传统木马检测技术比较被动这一缺陷,研究了木马检测新技术—行为分析,进而分析了朴素贝叶斯算法在木马检测中的应用,并在此基础上结合监控技术提出了基于行为分析的木马检测模型,采用朴素贝叶斯算法对可疑行为进行分析与判定,可有效检测已知木马的变种及新型木马,提高木马检测的精准度。
Trojan horse is a malicious program whose main purpose is to gain control of the host computer and steal information, which causes great harm to network security and information security. Firstly, the working principle of Trojan is introduced. In view of the defect that the traditional Trojan detection technology is passive, the new technology of Trojan detection, behavior analysis, and the application of Naive Bayesian algorithm in Trojan detection are analyzed. On the basis of this, Monitoring technology puts forward a Trojan detection model based on behavior analysis. By using naive Bayesian algorithm to analyze and determine suspicious behavior, it can effectively detect Trojan variants and new Trojans and improve the precision of Trojan detection.