Trojan Detection Based on Network Flow Clustering
Xiaochen Zhang, Shengli Liu, Lei Meng, Yunfang Shi · 2012
Trojan is a threat to network security which poses a serious threat to national security. Through research on Trojan communication process, this paper proposes a data stream clustering method based on packet timestamp. This method uses cluster to compress Trojan communication data stream information, extracts cluster characteristics and then detects Trojans according to the cluster characteristics and correlation between the clusters. The experimental results showed that this method achieved good detection results.