Previous Articles     Next Articles

Research of Linux WebShell Detection based on SVM Classiifer

MENG Zheng%MEI Rui%ZHANG Tao%WEN Wei-ping   

  • About author:北京大学软件与微电子学院,北京,100871

Abstract: WebShell is a common webpage back door, which can be used by attackers to obtain Web server permissions. The realization mechanism of Linux WebShell is analyzed, the common characteristics and the characteristic mixed method are described in this paper. On this basis, a detection method based on SVM classiifer is put forward and realized. From three aspects of accuracy, speciifcity and sensitivity, the WebShell detection methods individually based on SVM classiifer, characteristic matching and decision tree are compared. The experimental result shows that the method proposed in this paper can detect WebShell accurately and efifciently.