›› 2013, Vol. 26 ›› Issue (5): 156-.

• Articles • Previous Articles     Next Articles

Research on and Implementation of Protective Mechanism of Trojan Based on NDIS Intermediate Layer

HONG Shuangxi,LEI Tao   

  1. (School of Information Engineering,North China University of Water Conservancy and Electric Power,Zhengzhou 450011,China)
  • Online:2013-05-15 Published:2013-06-20

Abstract:

Through analyzing the characteristics,types and communication mode of the Trojan program,a protection mechanism in kernel level based on NDIS intermediate driver technique on the windows platform is put forward.IP address and port number and the process of captured data packet are analyzed and judged to realize interception of Trojan virus communications and the identification of Trojan process.With the same interception rate of Trojan communications,it is obviously superior to the similar functional anti-Trojan software in the data packet processing speed.

Key words: trojan virus,NDIS driver,ip information,network security,legal process table

CLC Number: 

  • TP311.563+.2