Paper
2 November 2022 A high-performance Webshell detection model
Wenhao Yuan, Shanfeng Wang, Yixuan Feng, Shujie Li, Songhua Li, Ruyin Sun
Author Affiliations +
Proceedings Volume 12455, International Conference on Signal Processing and Communication Security (ICSPCS 2022); 124550G (2022) https://doi.org/10.1117/12.2655320
Event: International Conference on Signal Processing and Communication Security (ICSPCS 2022), 2022, Dalian, China
Abstract
Webshell exists as a command execution environment in the form of a web page file, which is often referred to as a backdoor. After hacking a website, hackers usually upload it to the web directory of the web server and mix it with the normal web files, and then access the backdoor program through the browser, which can achieve the purpose of controlling the browser. Since there are many kinds of web backdoors in the form of asp, php, jsp or cgi files, here we choose the more popular php file as the research object. In this paper, the Webshell dataset comes from common Webshell samples on the Internet, and the white samples mainly use common open source software developed based on PHP. We use bag-of-words and TF-IDF models for feature extraction, and construct Webshell detection models based on the LightGBM algorithm. The results show that our model is more than 98% accurate and has higher performance in space and time compared to the current popular classification models.
© (2022) COPYRIGHT Society of Photo-Optical Instrumentation Engineers (SPIE). Downloading of the abstract is permitted for personal use only.
Wenhao Yuan, Shanfeng Wang, Yixuan Feng, Shujie Li, Songhua Li, and Ruyin Sun "A high-performance Webshell detection model", Proc. SPIE 12455, International Conference on Signal Processing and Communication Security (ICSPCS 2022), 124550G (2 November 2022); https://doi.org/10.1117/12.2655320
Advertisement
Advertisement
RIGHTS & PERMISSIONS
Get copyright permission  Get copyright permission on Copyright Marketplace
KEYWORDS
Data modeling

Detection and tracking algorithms

Statistical modeling

Feature extraction

Internet

Open source software

Performance modeling

Back to Top