Dissertation > Excellent graduate degree dissertation topics show

Research on Trojan Horse Detection under Windows Platform

Author: WuYuFeng
Tutor: DangQun
School: Northeastern University
Course: Applied Computer Technology
Keywords: TrojWare Buffer overflow RootKit DKOM SSDT
CLC: TP309.5
Type: Master's thesis
Year: 2008
Downloads: 99
Quote: 0
Read: Download Dissertation

Abstract


With the wide spread of Internet, Mailware became more and more rampancy. The number of law case that uses TrojWare is increasing. Criminal plant TrojWare into the couputer of user’s to steal more valuable information, for example, Security Accounty, password, etc. All above has bring a large scale of loss to many net citizens, and threaten the security of internet.Further more,the techinology that the TrojWare used has become deeply imerse into operating system’s internal. So they were very difficult to find them.This article first analysis the common skill of TrojWare used to plant,for example,file bind,buffer flow,and web TrojHorse,etc.Second,it uncover the techonology that TrojWare used to hide themselves after they invade the user’s computer successfully.This technology involved many data struct in the windows operating system. That is common undocumented, so many conclusions is conclused by disassembling the code of operate systems and the symbol file by Microsoft provided.At last, the auther of this article develop a utility to detect the existing of Trojware. We use this software’analysis for the key palace in operating system, can decide whether the TrojWare has been planted into our computer, and restore the data struct that be modified by TrojWare.

Related Dissertations

  1. Malicious code detection technology,TP393.08
  2. An Improved Kernel Trojan Horse Architecture Model and Realization,TP393.08
  3. The Testing and Analysis of Live Computer Forensics Tool,TP399-C2
  4. The Design and Implementation of a buffer overflow attack detection tools,TP309
  5. Rootkit detection system based on the Windows operating system,TP316.7
  6. Based on Win32 Rootkit hidden platform design and implementation,TP311.52
  7. Dynamic taint based on information flow analysis technique,TP393.08
  8. Design and Implementation of the malicious code situational awareness system,TP393.08
  9. Security Detection of An Object-based Storage System Environment,TP333
  10. Research of the Rootkit Based on Linux Kernel,TP316.81
  11. Kernel-mode driver -level anti- virus technology research and strategic analysis,TP309.5
  12. Memory-based data mining fuzzing mechanisms of vulnerability,TP393.08
  13. Buffer overflow vulnerability digging and exploit Methods,TP393.08
  14. Detection and Elimination of "Buffer-Overflow" Based on GECISM,TP393.08
  15. Research on Attack and Defense of Trojan Horse,TP393.08
  16. Technology of Buffer Overflow Detection,TP393.08
  17. Analysis and Demo of Network Attack,TP393.08
  18. Anti - Trojan technology research based on identity checks,TP393.08
  19. An Effective Way to Prevent Heap-Based Buffer Overflow,TP393.08
  20. Research on Rootkit Detection Technology Based on Hardware Virtualization Technology,TP393.08

CLC: > Industrial Technology > Automation technology,computer technology > Computing technology,computer technology > General issues > Security and confidentiality > Computer viruses and prevention
© 2012 www.DissertationTopic.Net  Mobile