信息网络安全 ›› 2017, Vol. 17 ›› Issue (12): 47-53.doi: 10.3969/j.issn.1671-1122.2017.12.009

• • 上一篇    下一篇

基于相似性分析的WordPress主题恶意代码检测

周振飞1,2, 方滨兴1,4, 崔翔2,3, 刘奇旭2,3()   

  1. 1.北京邮电大学网络空间安全学院,北京 100049
    2.中国科学院信息工程研究所,北京 100093
    3.中国科学院大学网络空间安全学院,北京 100049
    4.电子科技大学广东电子信息工程研究院,广东东莞 523808
  • 收稿日期:2017-08-15 出版日期:2017-12-20 发布日期:2020-05-12
  • 作者简介:

    作者简介:周振飞(1992—),男,广东,硕士研究生,主要研究方向为网络安全;方滨兴(1960—),男,黑龙江,教授,博士,主要研究方向为网络安全、信息内容安全;崔翔(1978—),男,黑龙江,研究员,博士,主要研究方向为网络安全、僵尸网络;刘奇旭(1984—),男,江苏,副研究员,博士,主要研究方向为Web安全、恶意代码分析。

  • 基金资助:
    国家重点研发计划[2016YFB0801604];东莞市引进创新科研团队计划[201636000100038]

A Method of Malicious Code Detection in WordPress Theme Based on Similarity Analysis

Zhenfei ZHOU1,2, Binxing FANG1,4, Xiang CUI2,3, Qixu LIU2,3()   

  1. 1.School of Cyberspace Security, Beijing University of Posts and Telecommunications, Beijing 100049, China
    2. Institute of Information Engineering, Chinese Academy of Sciences, Beijing 100093, China
    3. School of Cyber Security, University of Chinese Academy of Sciences, Beijing 100049, China
    4.Institute of Electronic and Information Engineering of UESTC in Guangdong, Dongguan Guangdong 523808, China
  • Received:2017-08-15 Online:2017-12-20 Published:2020-05-12

摘要:

已有的主题安全检测方法主要依赖于已知恶意代码特征,无法应对未知恶意代码。文章总结出恶意代码植入主题存在的主题重打包与恶意代码复用两个现象并提出基于相似性分析的恶意代码检测方法。该方法通过对多个主题同时进行分析,根据页面样式相似性得出主题间的同源关系,进而检测出同源主题相异代码与非同源主题相似代码,最后通过阈值与白名单过滤出高度可疑的恶意代码。文章针对252个非官方主题进行实验,检测出17个含有恶意代码的主题。实验证明,该检测方法能够在不依赖特征的情况下检测出未知的恶意代码,一定程度上优于现有的方法。

关键词: WordPress主题, 恶意代码, 相似性, 同源关系

Abstract:

Existing detection methods mainly rely on characteristic of known malicious code. This paper concludes repackaging and reusing phenomena and propose a detection method based on similarity analysis. Firstly, it analyzes homologous relationship of themes based on page style similarity. Secondly, it finds different code in same-origin themes and similar code in different-origin themes. Finally, it filters code by threshold and white list, the remaining are considered as highly suspicious malicious code. This paper analyzes 252 non-official themes and finds 17 themes containing malicious code. Result shows that this method can find malicious code without knowledge of their characteristic, which is better than existing methods in some extent.

Key words: WordPress theme, malicious code, similarity, homologous relationship

中图分类号: