信息网络安全 ›› 2017, Vol. 17 ›› Issue (12): 47-53.doi: 10.3969/j.issn.1671-1122.2017.12.009

• • 上一篇    下一篇


周振飞1,2, 方滨兴1,4, 崔翔2,3, 刘奇旭2,3()   

  1. 1.北京邮电大学网络空间安全学院,北京 100049
    2.中国科学院信息工程研究所,北京 100093
    3.中国科学院大学网络空间安全学院,北京 100049
    4.电子科技大学广东电子信息工程研究院,广东东莞 523808
  • 收稿日期:2017-08-15 出版日期:2017-12-20 发布日期:2020-05-12
  • 作者简介:


  • 基金资助:

A Method of Malicious Code Detection in WordPress Theme Based on Similarity Analysis

Zhenfei ZHOU1,2, Binxing FANG1,4, Xiang CUI2,3, Qixu LIU2,3()   

  1. 1.School of Cyberspace Security, Beijing University of Posts and Telecommunications, Beijing 100049, China
    2. Institute of Information Engineering, Chinese Academy of Sciences, Beijing 100093, China
    3. School of Cyber Security, University of Chinese Academy of Sciences, Beijing 100049, China
    4.Institute of Electronic and Information Engineering of UESTC in Guangdong, Dongguan Guangdong 523808, China
  • Received:2017-08-15 Online:2017-12-20 Published:2020-05-12



关键词: WordPress主题, 恶意代码, 相似性, 同源关系


Existing detection methods mainly rely on characteristic of known malicious code. This paper concludes repackaging and reusing phenomena and propose a detection method based on similarity analysis. Firstly, it analyzes homologous relationship of themes based on page style similarity. Secondly, it finds different code in same-origin themes and similar code in different-origin themes. Finally, it filters code by threshold and white list, the remaining are considered as highly suspicious malicious code. This paper analyzes 252 non-official themes and finds 17 themes containing malicious code. Result shows that this method can find malicious code without knowledge of their characteristic, which is better than existing methods in some extent.

Key words: WordPress theme, malicious code, similarity, homologous relationship
