Method and system for Trojan network communication detecting and evidence obtaining
A technology of network communication and network link information, which is applied in the field of computer network communication forensics, can solve problems such as inability to associate, inability to present Trojan horse incoming or outgoing data packets in complete file form, and non-repudiation of criminal behavior, so as to enhance correlation Effect
- Summary
- Abstract
- Description
- Claims
- Application Information
AI Technical Summary
Problems solved by technology
Method used
Image
Examples
Embodiment Construction
[0031] In order to make the object, technical solution and advantages of the present invention clearer, the present invention will be further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described here are only used to explain the present invention, not to limit the present invention. In addition, the technical features involved in the various embodiments of the present invention described below can be combined with each other as long as they do not constitute a conflict with each other.
[0032] The overall thought of the present invention is, through the network communication link information (IP address, port number, connection time) of the computer Trojan horse's network communication link information (IP address, port number, connection time) captured at the transmission-network layer place and the data packet file that obtains at the network card layer association comparison ...
PUM
Login to View More Abstract
Description
Claims
Application Information
Login to View More 