论文部分内容阅读
传统计算机隐蔽通信方式采用的HOOK技术,不能从根本上解决通信数据包被防火墙截获丢弃的问题。NDIS中间层驱动技术常用于防火墙和抓包软件,通过分析NDIS中间层驱动技术原理,提出一种新的可应用于Windows防火墙穿透的隐蔽通信方法,并详细介绍了隐蔽通信方式的设计思路和实现方式,最后,在安装有常见Windows防火墙的主机上进行测试,测试结果表明,该隐蔽通信方式能成功穿透大多数防火墙。
HOOK technology used in the traditional computer covert communication mode can not solve the problem that communication data packets are intercepted and discarded by the firewall fundamentally. NDIS middle layer driver technology is often used in firewall and packet capture software. Based on the analysis of the principle of NDIS middle driver technology, a new covert communication method that can be applied to Windows firewall penetration is proposed. The design concept of covert communication method is introduced in detail. Finally, the test is performed on a host computer with a common Windows firewall. The test results show that the covert communication method can successfully penetrate most firewalls.