Invention Grant
- Patent Title: Trojan detection method and device
- Patent Title (中): 木马检测方法和设备
-
Application No.: US14366665Application Date: 2012-12-18
-
Publication No.: US09596248B2Publication Date: 2017-03-14
- Inventor: Yuxuan Duan , Lijun Cheng , Peng Han
- Applicant: NSFOCUS INFORMATION TECHNOLOGY CO., LTD.
- Applicant Address: CN Beijing
- Assignee: NSFOCUS INFORMATION TECHNOLOGY CO., LTD.
- Current Assignee: NSFOCUS INFORMATION TECHNOLOGY CO., LTD.
- Current Assignee Address: CN Beijing
- Agency: TIPS Group
- Priority: CN201110430821 20111220
- International Application: PCT/CN2012/086871 WO 20121218
- International Announcement: WO2013/091534 WO 20130627
- Main IPC: H04L29/06
- IPC: H04L29/06

Abstract:
A trojan detection method and device, used to solve the problem in the prior art of being unable to effectively detect a trojan in a network, the method comprising: when a trojan heartbeat is detected in a session, according to whether the trojan heartbeat detection frequency is fixed, increasing the recorded session weight by a corresponding weight and recording the increased weight, and checking whether each packet transmitted from a controlling end to a controlled end complies with the characteristics of a trojan control command packet; if yes, then increasing by a third weight onto the recorded session weight and recording the same, and when the session weight reaches an alarm threshold, generating an alarm to notify that the session is initiated by a trojan. An embodiment of the present invention achieves trojan detection by detecting the packet in the session, thereby the trojan in a network can be detected. The detection to the packet in the session is not simply string matching, thus reducing false alarm rate and effectively detecting the trojan in the network.
Public/Granted literature
- US20140344935A1 TROJAN DETECTION METHOD AND DEVICE Public/Granted day:2014-11-20
Information query