信息安全研究 ›› 2018, Vol. 4 ›› Issue (3): 251-255.

• 学术论文 • 上一篇    下一篇

基于关联分析的Webshell检测方法研究

周颖,胡勇   

  1. 四川大学
  • 收稿日期:2018-03-21 出版日期:2018-03-15 发布日期:2018-03-21
  • 通讯作者: 周颖
  • 作者简介:周颖 1992年,硕士研究生,主要研究方向为Web安全 胡勇 1973年,副教授,硕士生导师,主要研究方向为信息系统安全

Webshell Detection Method Based on Correlation Analysis

  • Received:2018-03-21 Online:2018-03-15 Published:2018-03-21

摘要: 目前Webshell检测工具大多基于特征库匹配实现检测,而对混淆加密后的Webshell检测准确率低。本文针对Webshell的混淆性选取统计特征,提出一种基于关联分析的Webshell检测方法。该方法应用关联分析算法得出特征参数潜在的隐含关系,通过支持度和置信度阈值调整,建立同时满足最小支持度和置信度的特征关联规则,再通过交叉验证对检测效果。结果表明,该方法实现对混淆Webshell的检测,并将两种关联分析方法和检测工具进行比较,证明该方法提高了检测效率和准确率。

关键词: Webshell检测, 关联分析, 混淆特征

Abstract: Webshell current detection tools are mostly based on feature library matching detection, while the accuracy of confusion encryption webshell is low. In this paper, a webshell detection method based on correlation analysis is proposed according to the obfuscation statistical characteristics of webshells. The method uses correlation analysis algorithm to derive the potential implicit relationship of feature parameters, through the adjustment of support and confidence thresholds, and setting up a feature correlationrule that satisfies minimum support and confidence, then using the cross-validation to test the effect. The results show that this method can achieve the detection of obfuscated Webshell. It proves that this method improves the detection efficiency and accuracy compared with the two correlation analysis methods and detection tools.

Key words: Webshell detection, correlation analysis, confusing characteristics