Trojan Detection Using Its Auto-startup Characteristic

LI Xiao-dong,LUO Ping,ZENG Zhi-feng
DOI: https://doi.org/10.3969/j.issn.1001-3695.2007.05.044
2007-01-01
Abstract:Trojan horse is a new kind computer virus,which makes much damage to computer information resources in a local network.This paper represented a new method to detect Trojans using its auto-startup characteristic.This method uses hooking system services dispatch table,so as to monitor file system and registry table.Compared with traditional detective methods,it can detect not only known Trojans but unknown ones.It is difficult for Trojans to escape detection because it is implemented in the kernel.
What problem does this paper attempt to address?