Abstract
Webshell is a code execution environment with extensions like php, asp, and jsp, which essence is to help managers of the system manage the web application effortlessly. Therefore, an attacker can use weshell as a backdoor program to control the webserver similarly. Traditional webshell detection mechanisms like rule matching and feature code detection usually suffer from poor generalization capabilities, leading to a higher rate of false negatives. Based on the Machine Learning model N-Gram, TF-IDF to extract the webshell sample features, three Machine Learning algorithms Multilayer Perceptron, XGBoost, and Naive Bayesian, to train the model. Analysis through training and testing, detection accuracy is more than 99% under the experimental environment, which detectable scope includes php, jsp, asp, and others. By combing the Machine Learning webshell detection model with the Software-Defined Networks using the flow table operate method, we implement a dynamic defense solution against webshell attackers, leading attackers to disconnect with the target network.
Author supplied keywords
Cite
CITATION STYLE
Yu, B., Liu, J. W., & Zhou, Z. (2021). WADS: A Webshell Attack Defender Assisted by Software-Defined Networks. In Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics) (Vol. 13107 LNCS, pp. 209–222). Springer Science and Business Media Deutschland GmbH. https://doi.org/10.1007/978-3-030-93206-0_13
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.