返回
Handling webshell attacks: A systematic mapping and survey
DOI:10.1016/j.cose.2021.102366.png)
摘要
En 中文
In recent years, there has been a significant increase in research interest in webshell attacks. Webshells are pieces of code that can be written in different scripting languages. They are uploaded to web servers after creating a breach making use of injection vulnerabilities. Webshells provide hackers a web interface to remotely execute commands, manipulate confidential data and invade web servers. The aim of this study is to provide researchers and practitioners with a holistic view of existing studies, approaches, techniques and tools for the detection of webshells and highlight potential gaps. To achieve this goal, a systematic mapping study is conducted. Forty-four primary studies are identified, surveyed and categorized following their scope of interest. Collections of malicious and benign webshells useful for validation and testing are identified. We also provide an overview of existing tools used for webshell detection with their limitations. Our findings revealed biases toward PHP web shells and machine learning technology as detection method. The study also revealed the need for more comprehensive studies and benchmark datasets for proper validation. (c) 2021 Elsevier Ltd. All rights reserved.
Keyword:
Cybersecurity
Webshell attack
Systematic mapping
Survey
AI总结
对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。
期刊
C
IF:
5.4
论文数:
4.6K
被引数:
1.4W
机构
引用论文
WS-LSMR: Malicious WebShell Detection Algorithm Based on Ensemble LearningWs-lsmr: 基于集成学习的恶意WebShell检测算法
IEEE ACCESS
IF3.6

