期刊文献+
共找到1篇文章
< 1 >
每页显示 20 50 100
Evil-hunter: a novel web shell detection system based on scoring scheme 被引量:1
1
作者 张庭秀 程光 +1 位作者 郭晓军 潘吴斌 《Journal of Southeast University(English Edition)》 EI CAS 2014年第3期278-284,共7页
In order to detect web shells that hackers inject into web servers by exploiting system vulnerabilities or web page open sources, a novel web shell detection system based on the scoring scheme is proposed, named Evil-... In order to detect web shells that hackers inject into web servers by exploiting system vulnerabilities or web page open sources, a novel web shell detection system based on the scoring scheme is proposed, named Evil-hunter. First, a large set of malicious function samples normally used in web shells are collected from various sources on the Internet and security forums. Secondly, according to the danger level and the frequency of using these malicious functions in the web shells as well as in legal web applications, an assigning score strategy for each malicious sample is devised. Then, the appropriate score threshold value for each sample is obtained from the results of a statistical analysis. Finally, based on the threshold value, a simple algorithm is presented to identify files that contain web shells in web applications. The experimental results show that compared with other approaches, Evil-hunter can identify web shells more efficiently and accurately. 展开更多
关键词 web shell detection scoring scheme malicious code identification
下载PDF
上一页 1 下一页 到第
使用帮助 返回顶部