Netinfo Security ›› 2021, Vol. 21 ›› Issue (1): 65-71.doi: 10.3969/j.issn.1671-1122.2021.01.008

Previous Articles     Next Articles

Research and Implementation on WebShell Comprehensive Detection and Traceability Technology Based on High-speed Network

WANG Yueda1(), HUANG Pan2, JING Tao3, SONG Yaxi1   

  1. 1. Computer Network Information Center, Chinese Academy of Sciences, Beijing 100190, China
    2. Beilong Zedata (Beijing) Data Technology Co., Ltd., Beijing 100190, China
    3. Office of General Affairs,Chinese Academy of Sciences, Beijing 100864, China
  • Received:2020-11-07 Online:2021-01-10 Published:2021-02-23
  • Contact: WANG Yueda E-mail:anquanip@cnic.cn

Abstract:

WebShell is a common Web script intrusion attack tool. By implanting WebShell into the Website server, the Website server can be controlled and the server operating program permissions can be obtained. WebShell is usually nested in normal Webpage scripts, which has strong concealment and brings great harm to the Website itself and visitors. In response to the above problems, this paper proposes a high-speed network traffic analysis and detection technology based on DPDK, which captures and analyzes network traffic in a high-speed network environment, and realizes efficient detection of WebShell in traffic data packets through feature code matching. At the same time, the WebShell file and the attacker are traced and analyzed.

Key words: WebShell, DPDK, traffic analysis, traceability analysis

CLC Number: