Detection of Trojan Covert Communication Based on Client Honeypot

ZHANG Chen,WANG Yi-jun,XUE Zhi
DOI: https://doi.org/10.3969/j.issn.1009-8054.2011.02.023
2011-01-01
Abstract:Today's popular Trojans begin to use covert communication technology and bypass the detection of honeypot system.This paper first describes the common Trojan covert communication technologies and the growing popular kernel layer Rootkit covert communication technology,then discusses the current client honeypot detecting methods for malware.Aiming at the deficiency of Honeypot detection mechanisms for network communication,an effective improvement scheme is proposed,By using network traffic detection technology based on the NDIS intermediate driver,the Trojans date packets are acquired.This scheme could effectively detect Rootkit covert communication based on network driver and extract the key communication information for Trojan track and analysis.
What problem does this paper attempt to address?