Defense model against cheating backdoors in applications
Guixiong Liu · Jisuanji gongcheng yu sheji · 2010
Aiming at the problem that traditional approaches that detect and remove backdoor code by means of code pattern recognition tend to leave over undetected backdoors,on the basis of analysis of the structure of programs with embedded backdoor code and its activation mechanism,the minimum condition for establishing covert channel in existing legal message channel to transmit backdoor control information is acquired.An application model that prevents against undetected cheating backdoors by inhibiting their activation condition is proposed.Legal messages that are transmitted in legal channel are examined,buffered and transformed,so that those that carry covert information are intercepted and encoding of backdoor control message hidden in them is broken.Illegal operation and backdoor behavior that escape from interception of the pump are reexamined by audit of their event logs.Experimental results from a PC-based weighing instrument verified the validity of the model for protecting applications against cheating backdoors.