Computer Science ›› 2016, Vol. 43 ›› Issue (4): 150-154.doi: 10.11896/j.issn.1002-137X.2016.04.030

Trojans Keep-alive Behavior Detection Approach Based on Wavelet Transform

BAI Hong, PANG Jian-min, DAI Chao and YUE Feng   

  • Online:2018-12-01 Published:2018-12-01

Abstract: Trojans keep-alive behavior detection algorithms generally are based on the method of clustering,which can hardly avoid the interference of other packets in the network,leading to false positive results.Therefore,this paper proposed a Trojans keep-alive behavior detection approach based on wavelet transform.In this approach,firstly,TCP packetsstream is described by packet length signal,then the signal is processed by compelling threshold denoising method based on Mallat theory,and finally detection results can be acquired through detail information decision algorithm based on packet rate.Experiments show that this approach can detect Trojan keep-alive behavior effectively and has better anti-interference.

Key words: Trojans keep-alive behavior,Packet length signal,Mallat theory,Wavelet transform

