Detecting Http-Tunnel with Process Monitoring

Kang Le,Han Junjie,Liu Shengli
DOI: https://doi.org/10.3321/j.issn:1002-8331.2006.07.034
2006-01-01
Abstract:Http-Tunnel is a new Trojan communication technology.Due to its efficient disguise,it is difficult for the conventional Intrusion Detection Systems(IDS) and the firewalls to perform effective inspection.This paper explains how to trace the source of unauthorized process with process monitoring to defend Http-Tunnel.It is a new method of detecting abnormalities in the network flow,and has achieved a good result in the laboratory.
What problem does this paper attempt to address?