| The rapid development of Internet leads to many criminal means for cybercriminals. Information security problems become increasingly prominent. As an evaluation approach of network security, network penetration can also be applied to reconnoitre criminal activities and collect criminal evidences. Trojan, a common virus, is able to control hosts and steal privacy. Therefore, the improvement of Trojan detection technology has practical significance for protecting the user’s property and privacy. In this paper, HTTP communication of network penetration is analyzed. And the concerned study is shown as follows.Firstly, HTTP communication approach of network penetration is researched. Research the HTTP-based firewall penetration technology by analyzing the principles of firewall and other network security devices. The approaches of hiding network activity are researched through the analysis of three kinds of network security software. The HTTP communication rules of network penetration are constructed by the study of HTTP data transmission mechanism. A HTTP-based network penetration system is built with the above approaches. Secondly, a network communication analysis and detection model of HTTP-based Trojan is proposed. According to the analysis of the HTTP network traffic of HTTP-based Trojan and normal programs, six network communication behavior characteristics of HTTP-based Trojans are sought out. The HTTP-based Trojan detection model which utilizes hierarchical clustering, Davies-Bouldin index and k-means algorithm is constructed. The model is only used to detect the HTTP-based Trojan.Finally, the feasibility of this HTTP communication approach and HTTP-based Trojan detection model is verified by experiments. Experimental results show that this HTTP communication approach is able to penetrate the protection of network firewall, hide its own network activity, and provide reliable data transmission. The HTTP-based Trojan detection model can efficiently detect the HTTP-based Trojan with good accuracy and low false positive ratios.To improve the penetration and concealment of communication, the HTTP communication approach of network penetration is proposed by studying common HTTP communication. Meanwhile, a HTTP-based Trojan detection model which has good detection accuracy against typical HTTP-based Trojan is constructed, and it can be used as a complement to existent Trojan detection approaches. |