arrow
返回

ShellBreaker: Automatically detecting PHP-based malicious web shells

delete2019-11-01
delete16
delete
OA
AI
Y
Yu Li
J
Jin Huang
A
Ademola Ikusan
M
Milliken Mitchell
J
Junjie Zhang *
R
Rui Dai
DOI:10.1016/j.cose.2019.101595delete
delete原文链接
delete分享
delete收藏
查看原文
摘要

摘要

En 中文
A web shell is a server-side script uploaded by an attacker to enable persistent access on a compromised machine. Detecting web shells is therefore of significant importance. In this paper, we present a novel system named ShellBreaker to detect web shells written in PHP, one of the leading languages used for server-side script development. ShellBreaker performs detection by correlating syntactical and semantic features that systematically characterize web shells through three aspects including (i) their communication with external users/attackers, (ii) their adaption to the run-time environment, and (iii) their usage of sensitive operations. We have evaluated ShellBreaker using real-world, PHP-based web shells and benign PHP scripts. Experimental results have demonstrated that ShellBreaker can achieve a high detection rate of 91.7% at a low false positive rate of 1%. (C) 2019 Elsevier Ltd. All rights reserved.
Keyword:
Intrusion detection
Web security
Web shells
Data flows
Taint analysis
AI总结

AI总结

对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。

期刊

C
Computers and Security
IF:
5.4
论文数:
4.6K
被引数:
1.4W

机构

U
University System of Ohio
学者数:
15.4W
论文数: 13.0W
被引数: 200
W
wright state university dayton
学者数:
1.8K
论文数: 1.5K
被引数: 0