arrow
Return

ShellBreaker: Automatically detecting PHP-based malicious web shells

delete2019-11-01
delete16
delete
OA
AI
Y
Yu Li
J
Jin Huang
A
Ademola Ikusan
M
Milliken Mitchell
J
Junjie Zhang *
R
Rui Dai
DOI:10.1016/j.cose.2019.101595delete
deleteOriginal
deleteShare
deleteSave
View PDF
Abstract

Abstract

En 中文
A web shell is a server-side script uploaded by an attacker to enable persistent access on a compromised machine. Detecting web shells is therefore of significant importance. In this paper, we present a novel system named ShellBreaker to detect web shells written in PHP, one of the leading languages used for server-side script development. ShellBreaker performs detection by correlating syntactical and semantic features that systematically characterize web shells through three aspects including (i) their communication with external users/attackers, (ii) their adaption to the run-time environment, and (iii) their usage of sensitive operations. We have evaluated ShellBreaker using real-world, PHP-based web shells and benign PHP scripts. Experimental results have demonstrated that ShellBreaker can achieve a high detection rate of 91.7% at a low false positive rate of 1%. (C) 2019 Elsevier Ltd. All rights reserved.
Keywords:
Intrusion detection
Web security
Web shells
Data flows
Taint analysis
AI Summary

AI Summary

Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.

Journal

C
Computers and Security
IF:
5.4
Papers:
4.6K
Citations:
1.4W

Organization

U
University System of Ohio
Scholars:
15.4W
Papers: 13.0W
Citations: 200
W
wright state university dayton
Scholars:
1.8K
Papers: 1.5K
Citations: 0