Skip to main navigation Skip to search Skip to main content

WADS: A Webshell Attack Defender Assisted by Software-Defined Networks

  • Beiyuan Yu
  • , Jian Wei Liu*
  • , Ziyu Zhou
  • *Corresponding author for this work
  • Beihang University

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Webshell is a code execution environment with extensions like php, asp, and jsp, which essence is to help managers of the system manage the web application effortlessly. Therefore, an attacker can use weshell as a backdoor program to control the webserver similarly. Traditional webshell detection mechanisms like rule matching and feature code detection usually suffer from poor generalization capabilities, leading to a higher rate of false negatives. Based on the Machine Learning model N-Gram, TF-IDF to extract the webshell sample features, three Machine Learning algorithms Multilayer Perceptron, XGBoost, and Naive Bayesian, to train the model. Analysis through training and testing, detection accuracy is more than 99% under the experimental environment, which detectable scope includes php, jsp, asp, and others. By combing the Machine Learning webshell detection model with the Software-Defined Networks using the flow table operate method, we implement a dynamic defense solution against webshell attackers, leading attackers to disconnect with the target network.

Original languageEnglish
Title of host publicationInformation Security Practice and Experience - 16th International Conference, ISPEC 2021, Proceedings
EditorsRobert Deng, Feng Bao, Guilin Wang, Jian Shen, Mark Ryan, Weizhi Meng, Ding Wang
PublisherSpringer Science and Business Media Deutschland GmbH
Pages209-222
Number of pages14
ISBN (Print)9783030932053
DOIs
StatePublished - 2021
Event16th International Conference on Information Security Practice and Experience, ISPEC 2021 - Nanjing, China
Duration: 17 Dec 202119 Dec 2021

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume13107 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference16th International Conference on Information Security Practice and Experience, ISPEC 2021
Country/TerritoryChina
CityNanjing
Period17/12/2119/12/21

Keywords

  • Machine learning
  • SDN
  • Webshell detection

Fingerprint

Dive into the research topics of 'WADS: A Webshell Attack Defender Assisted by Software-Defined Networks'. Together they form a unique fingerprint.

Cite this