A model generation method and device for detecting a WebShell attack
Patent Information
- Application Number
- CN202211712066.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-29
- Publication Date
- 2026-09-25
- Estimated Expiration
- 2042-12-29
AI Technical Summary
该种方法对于黑客定制的免杀WebShell及未知新型WebShell检测能力较弱,因此不可避免的会出现漏报率较高的问题
Smart Images

Figure CN116015910B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network security technology, and more specifically, to a model generation method and apparatus for detecting WebShell attacks. Background Technology
[0002] With the rapid development of Web technology, Internet applications based on the Web environment are widely used. While Internet applications offer a wealth of functionality, they also expand the attack surface, exposing sensitive personal and business information to risks.
[0003] As is well known, a WebShell is a code execution environment that exists in the form of web page files such as ASP (Active Server Pages), PHP (PHP: Hypertext Preprocessor), and JSP (Java Server Pages). Hackers typically use tools or directly access the corresponding WebShell web page backdoor to communicate with the web server and carry out network intrusion to control and operate the victim's host. These operations include, but are not limited to, reading sensitive files, reverse shells, adding users, clearing traces, internal network probing, and lateral movement.
[0004] Currently, WebShell detection methods primarily rely on static detection based on known WebShell sample characteristics and communication features. This approach is relatively weak against custom-designed, undetectable WebShells and unknown, novel WebShells, inevitably leading to a high false negative rate. Summary of the Invention
[0005] The purpose of this application is to provide a model generation method and apparatus for detecting WebShell attacks, which can improve the effectiveness of WebShell attack analysis and judgment and the efficiency of response and handling.
[0006] The first aspect of this application provides a model generation method for detecting WebShell attacks, including:
[0007] Based on the characteristics of WebShell attack traffic, a first detection model for detecting WebShell attacks is established.
[0008] Artificial intelligence was trained based on the features of black and white samples of WebShell to obtain a second detection model for detecting WebShell attacks;
[0009] The WebShell test features are input into the first detection model and the second detection model respectively to obtain the first detection result and the second detection result.
[0010] Based on the first and second detection results, a detection confidence level corresponding to the WebShell test features is generated;
[0011] Based on the first detection model, the second detection model, the WebShell test features, and the detection confidence, a comprehensive detection model for detecting WebShell attacks is obtained through correlation modeling.
[0012] In the above implementation process, this method can prioritize establishing a first detection model for detecting WebShell attacks based on the characteristics of WebShell attack traffic. It is evident that this method can extract strong features of WebShell attacks based on the characteristics and methods of different types of WebShell attacks, and write a detection model (or bidirectional detection rules) based on these strong features. Simultaneously, an artificial intelligence training process is performed based on the features of black and white samples of WebShell attacks to obtain a second detection model for detecting WebShell attacks. This method can train and validate an artificial intelligence model based on collected black and white sample files using machine learning algorithms. Then, this method can determine some WebShell test features and input these features into the first and second detection models respectively to obtain the first and second detection results. This method can determine the output values based on the same input values, facilitating subsequent steps to make corresponding judgments based on the two output values. Specifically, this method can generate detection confidence levels corresponding to the WebShell test features based on the first and second detection results. It is easy to see that this method jointly determines the detection confidence levels of the WebShell test features based on the first and second detection models, thereby achieving the effect of joint detection. Furthermore, this method performs correlation modeling based on the first detection model, the second detection model, WebShell test features, and detection confidence to obtain a comprehensive detection model for detecting WebShell attacks. It can be seen that this method can correlate the first detection model and the second detection model based on the jointly detected detection confidence to form an independent and complete WebShell detection model, thereby improving the detection effect and efficiency of WebShell.
[0013] Furthermore, the method also includes:
[0014] Collect traffic data;
[0015] By employing both real and simulated WebShell attacks, WebShell attack traffic characteristics are extracted from the traffic data. The feature extraction dimensions of the WebShell attack traffic characteristics include at least one of the following: dynamic variables, callback functions, control characters, class methods, special functions, and pseudo-protocols.
[0016] In the above implementation process, this method can prioritize the collection of traffic data; and through real WebShell attacks and simulated WebShell attacks, it extracts WebShell attack traffic features corresponding to multiple preset dimensions from the traffic data. Therefore, this method can determine more comprehensive WebShell attack traffic features based on multiple dimensions, thereby improving the comprehensiveness of WebShell detection.
[0017] Furthermore, after the step of performing correlation modeling based on the first detection model, the second detection model, the WebShell test features, and the detection confidence to obtain a comprehensive detection model for detecting WebShell attacks, the method further includes:
[0018] Obtain the WebShell features to be detected;
[0019] The WebShell features to be detected are input into the comprehensive detection model to obtain the comprehensive detection results;
[0020] When the comprehensive detection result indicates that the WebShell detection feature is a WebShell attack feature, threat intelligence corresponding to the WebShell detection feature is obtained;
[0021] Output the threat intelligence.
[0022] In the above implementation process, after obtaining the comprehensive detection model, this method can further acquire the WebShell detection features, enabling it to further detect the actual target based on the comprehensive detection model. Specifically, the method can input the WebShell detection features into the comprehensive detection model to obtain the comprehensive detection result; when the comprehensive detection result indicates that the WebShell detection features are WebShell attack features, it acquires the threat intelligence corresponding to the WebShell detection features; finally, it outputs the threat intelligence. Therefore, this method can automatically complete the WebShell detection process, thereby ensuring the detection effect and efficiency.
[0023] Furthermore, after the step of obtaining threat intelligence corresponding to the WebShell's detectable features, the method further includes:
[0024] The threat intelligence is sent to a third-party device so that the third-party device can automatically perform security processing based on the threat intelligence.
[0025] In the above implementation process, after acquiring threat intelligence, this method can automatically send the threat intelligence to third-party devices, enabling these devices to automatically perform security actions based on the threat intelligence. Therefore, this method can automatically link with security devices such as firewalls, enabling them to automatically perform corresponding security actions, thereby ensuring the security of their respective application systems.
[0026] Furthermore, after the step of obtaining threat intelligence corresponding to the WebShell's detectable features, the method further includes:
[0027] Detect whether there are security events in the database that match the threat intelligence;
[0028] When the security event exists in the database, obtain the handling method for the security event;
[0029] Based on the processing method and the WebShell characteristics to be detected, security processing is performed automatically.
[0030] In the above implementation process, after obtaining threat intelligence, this method can detect whether there are security events in the database that match the threat intelligence; if a security event exists in the database, it obtains the handling method for the security event; and then automatically performs security processing based on the handling method and the characteristics of the WebShell to be detected. It is evident that this method can determine the corresponding handling method based on the database, thereby automatically processing the issue according to the appropriate method, thus achieving the effect of automated processing.
[0031] Furthermore, the method also includes:
[0032] The processing device that sends the threat intelligence to staff when the security event is not found in the database.
[0033] In the above implementation process, when there are no security events in the database, Gaifangfa can send threat intelligence to staff so that staff can make manual judgments and handle the situation, thereby avoiding mishandling caused by automatic processing and ensuring the effectiveness of handling WebShell attacks.
[0034] Furthermore, the security process includes at least blocking attack addresses.
[0035] In the above implementation process, this method can automatically block the source address of security events associated with threat intelligence, thereby blocking attacks in a timely and effective manner.
[0036] A second aspect of this application provides a model generation apparatus for detecting WebShell attacks, the model generation apparatus for detecting WebShell attacks comprising:
[0037] The modeling unit is used to establish a first detection model for detecting WebShell attacks based on the characteristics of WebShell attack traffic.
[0038] The training unit is used to train artificial intelligence based on the features of WebShell black and white samples to obtain a second detection model for detecting WebShell attacks;
[0039] The first input unit is used to input WebShell test features into the first detection model and the second detection model respectively to obtain the first detection result and the second detection result;
[0040] A confidence detection unit is used to generate a detection confidence level corresponding to the WebShell test feature based on the first detection result and the second detection result.
[0041] The generation unit is used to perform correlation modeling based on the first detection model, the second detection model, the WebShell test features, and the detection confidence level to obtain a comprehensive detection model for detecting WebShell attacks.
[0042] In the above implementation process, the device can establish a first detection model for detecting WebShell attacks based on WebShell attack traffic characteristics through a modeling unit; obtain a second detection model for detecting WebShell attacks through artificial intelligence training based on WebShell black-and-white sample characteristics through a training unit; input WebShell test features into the first and second detection models respectively through a first input unit to obtain a first detection result and a second detection result; generate a detection confidence level corresponding to the WebShell test features based on the first and second detection results through a confidence level detection unit; and then perform correlation modeling based on the first detection model, the second detection model, the WebShell test features, and the detection confidence level through a generation unit to obtain a comprehensive detection model for detecting WebShell attacks. Therefore, this device can improve the effectiveness of WebShell attack analysis and judgment and the efficiency of response and handling.
[0043] Furthermore, the model generation device for detecting WebShell attacks also includes:
[0044] The data acquisition unit is used to collect traffic data.
[0045] The extraction unit is used to extract WebShell attack traffic features from the traffic data through real WebShell attacks and simulated WebShell attacks; wherein the feature extraction dimensions of the WebShell attack traffic features include at least one of dynamic variables, callback functions, control characters, class methods, special functions, and pseudo-protocols.
[0046] Furthermore, the model generation device for detecting WebShell attacks also includes:
[0047] The first acquisition unit is used to acquire the WebShell features to be detected.
[0048] The second input unit is used to input the WebShell features to be detected into the comprehensive detection model to obtain the comprehensive detection result;
[0049] The first acquisition unit is further configured to acquire threat intelligence corresponding to the WebShell detection feature when the comprehensive detection result indicates that the WebShell detection feature is a WebShell attack feature;
[0050] The output unit is used to output the threat intelligence.
[0051] Furthermore, the model generation device for detecting WebShell attacks also includes:
[0052] A sending unit is used to send the threat intelligence to a third-party device so that the third-party device can automatically perform security processing based on the threat intelligence.
[0053] Furthermore, the model generation device for detecting WebShell attacks also includes:
[0054] The database detection unit is used to detect whether there are security events in the database that match the threat intelligence.
[0055] The second acquisition unit is used to acquire the handling method of the security event when the security event exists in the database;
[0056] The security processing unit is used to automatically perform security processing based on the processing method and the WebShell detection features.
[0057] Furthermore, the sending unit is also used to send the threat intelligence to the staff's processing device when the security event does not exist in the database.
[0058] Furthermore, the security process includes at least blocking attack addresses.
[0059] A third aspect of this application provides an electronic device, including a memory and a processor. The memory stores a computer program, and the processor runs the computer program to cause the electronic device to perform the model generation method for detecting WebShell attacks as described in any one of the first aspects of this application.
[0060] A fourth aspect of this application provides a computer-readable storage medium storing computer program instructions, which, when read and executed by a processor, perform the model generation method for detecting WebShell attacks as described in any one of the first aspects of this application. Attached Figure Description
[0061] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings used in the embodiments of this application will be briefly introduced below. It should be understood that the following drawings only show some embodiments of this application and should not be regarded as a limitation of the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.
[0062] Figure 1 A flowchart illustrating a model generation method for detecting WebShell attacks provided in an embodiment of this application;
[0063] Figure 2 A flowchart illustrating another model generation method for detecting WebShell attacks provided in this application embodiment;
[0064] Figure 3 A schematic diagram of a model generation device for detecting WebShell attacks provided in an embodiment of this application;
[0065] Figure 4 A schematic diagram of another model generation device for detecting WebShell attacks provided in an embodiment of this application;
[0066] Figure 5 This application provides a schematic diagram of data acquisition relationships for a graph dataset.
[0067] Figure 6 A schematic diagram illustrating an example of a first detection model establishment process provided in an embodiment of this application;
[0068] Figure 7 This application provides a schematic diagram of a black and white sample file partitioning process.
[0069] Figure 8 This is a schematic diagram illustrating the correlation analysis between a first detection model and a second detection model, provided as an embodiment of this application. Detailed Implementation
[0070] The technical solutions in the embodiments of this application will now be described with reference to the accompanying drawings.
[0071] It should be noted that similar reference numerals and letters in the following figures indicate similar items; therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures. Furthermore, in the description of this application, terms such as "first," "second," etc., are used only to distinguish descriptions and should not be construed as indicating or implying relative importance.
[0072] Example 1
[0073] Please refer to Figure 1 , Figure 1 This embodiment provides a flowchart illustrating a model generation method for detecting WebShell attacks. The model generation method for detecting WebShell attacks includes:
[0074] S101. Based on the characteristics of WebShell attack traffic, establish a first detection model for detecting WebShell attacks.
[0075] In this embodiment, the method can prioritize the collection of traffic data, extract WebShell attack traffic characteristics from the traffic data, and simultaneously standardize the logs.
[0076] In this embodiment, the method can extract WebShell attack features from traffic data through real WebShell attacks and simulated WebShell attacks, and accumulate and refine feature sets; at the same time, the method can also collect known WebShell feature sets through Internet resources.
[0077] S102. Based on the characteristics of WebShell attack traffic, artificial intelligence training is performed to obtain a second detection model for detecting WebShell attacks.
[0078] In this embodiment, the method can prioritize collecting black and white samples and establish a black and white sample library based on the collected black and white samples.
[0079] In this embodiment, the method can extract features from black and white samples, and train and perform training prediction and verification using different machine learning algorithms.
[0080] In this embodiment, the second detection model can refer to the model used to validate black and white samples. Black and white samples validated using this model can be fed into the first detection model for joint validation to determine the detection confidence level. Therefore, when black and white samples are jointly validated with the first detection model, the participation of the second detection model is not required. However, since the black and white samples have been validated by the second detection model, they can be used as inputs and outputs of the second detection model to link the first and second detection models. In other words, the combination of the first and second detection models can be direct or indirect, based on the validation relationship between black and white samples.
[0081] S103. Input the WebShell test features into the first detection model and the second detection model respectively to obtain the first detection result and the second detection result.
[0082] In this embodiment, the WebShell test characteristics can be either WebShell attack traffic characteristics or WebShell attack traffic characteristics.
[0083] S104. Generate detection confidence scores corresponding to the WebShell test features based on the first and second detection results.
[0084] In this embodiment, the method can perform correlation analysis and iterative optimization by linking WebShell attack feature alert content with the training results of different machine learning algorithms, and add confidence labels to security events.
[0085] S105. Based on the first detection model, the second detection model, WebShell test features, and detection confidence, a correlation model is performed to obtain a comprehensive detection model for detecting WebShell attacks.
[0086] In this embodiment, the method can also use an intelligence database to identify detected attack assets. If the attack assets belong to known black and gray market assets in the intelligence, an attack IP set is generated. The attack IP set is then sent to a third-party response and handling device (firewall) for linkage, and security events unrelated to the threat intelligence are transferred to manual handling. Specific processing methods may include blocking the attack IPs or IP sets; automating this process can also effectively and promptly block attacks.
[0087] In this embodiment, the method can analyze and detect WebShell attacks from multiple dimensions by extracting WebShell attack features and analyzing the correlation between them and training various machine learning algorithms, and by combining threat intelligence. This improves the efficiency and accuracy of WebShell attack detection, as well as the efficiency of responding to and handling hacker attacks.
[0088] In this embodiment, the subject executing the method can be a computing device such as a computer or server, and no limitation is made in this embodiment.
[0089] In this embodiment, the subject executing the method can also be a smart device such as a smartphone or tablet, and no limitation is made in this embodiment.
[0090] As can be seen, the model generation method for detecting WebShell attacks described in this embodiment can build an automated response and handling system based on the combination of WebShell attack detection and threat intelligence, thereby constructing a linkage system based on traffic data collection, attack feature extraction, feature correlation analysis, threat intelligence matching, and automatic attack blocking, further improving the efficiency of WebShell attack analysis, judgment, and response.
[0091] Example 2
[0092] Please refer to Figure 2 , Figure 2 This embodiment provides a flowchart illustrating a model generation method for detecting WebShell attacks. The model generation method for detecting WebShell attacks includes:
[0093] S201, Collect traffic data.
[0094] S202. Extract WebShell attack traffic characteristics from traffic data through real WebShell attacks and simulated WebShell attacks.
[0095] In this embodiment, the feature extraction dimensions of WebShell attack traffic characteristics include at least one of the following: dynamic variables, callback functions, control characters, class methods, special functions, and pseudo-protocols.
[0096] In this embodiment, the method can extract strong features of WebShell attacks (i.e., WebShell attack traffic features) based on the collected traffic data and according to the characteristics and methods of different types of WebShell attacks. The extracted dimensions include, but are not limited to, dynamic variables, callback functions, control characters, class methods, special functions, pseudo-protocols, etc., and bidirectional detection rules or detection models are written based on the strong features, which are then loaded and run by the device engine.
[0097] In this embodiment, the method can prioritize acquiring two types of data: one is traffic data, i.e., traffic data acquired through a simulation device; the other is establishing a black and white sample database. Among these,
[0098] Traffic data is acquired by monitoring internet nodes connected to a simulated device to obtain traffic from real hacker attacks. A WebShell attack environment is set up in a test range, and internal network attack traffic is obtained through self-testing or attack-defense drills. Then, traffic data corresponding to ASP, JSP, and PHP source files related to WebShell attacks is extracted, including but not limited to WebShell file upload traffic, WebShell management tool connection communication traffic, and WebShell command execution traffic. The acquired traffic data is then standardized, including but not limited to HTTP protocol fields such as http.uri, http.method, http.header, http.request_body, http.stat_code, http.response_body, and file_data. Finally, the standardized traffic logs are stored and retained.
[0099] As for the black and white sample libraries, black samples can be ASP, PHP, and JSP type WebShell samples obtained through internal self-testing or by collecting resources from the internet, including large backdoors, small backdoors, and one-line backdoors. Internal self-testing can utilize different WebShell management tools (e.g., IceScorpion, Godzilla, etc.) to generate samples and modified samples, while WebShell samples can also be obtained from the internet through open-source projects such as GitHub. White samples are common open-source software, such as phpMyAdmin and WordPress.
[0100] Please refer to Figure 5 , Figure 5 The diagram illustrates the data acquisition relationships of the dataset obtained in the early stages using this method.
[0101] S203. Based on the characteristics of WebShell attack traffic, establish a first detection model for detecting WebShell attacks.
[0102] In this embodiment, the process of establishing the first monitoring model is illustrated as follows:
[0103] (1) Build test environments for various open-source platforms with file upload and file write functions, such as DVWA (Damn Vulnerable Web Application, a PHP / MySQL web application used for security vulnerability identification), Tomcat simulation business environment, etc.
[0104] (2) Use mainstream WebShell management tools, such as IceScorpion and Godzilla, to generate WebShell5 samples.
[0105] (3) Use the file upload or file write function of the test environment to upload the WebShell sample first. After the upload is successful, perform connection / execution operations on the WebShell.
[0106] (4) Capture network traffic during the WebShell sample operation process, further analyze and judge the data packets, and extract the attack characteristics of the WebShell operation. For example, the characteristics extracted from the upload operation of the PHP type WebShell sample are shown in the table below.
[0107]
[0108] (5) Based on the attack features extracted in the previous step, use the syntax of the detection rules supported by the device engine to write WebShell detection rules.
[0109] (6) Load the detection rule file and related configuration files through the device engine to detect WebShell attack behavior in real time.
[0110] Please refer to Figure 6 , Figure 6 The diagram illustrates an example of the process for establishing the first detection model.
[0111] S204. Based on the features of black and white samples of WebShell, artificial intelligence training is performed to obtain a second detection model for detecting WebShell attacks.
[0112] In this embodiment, the following is an example of how the method trains and validates the collected black and white sample files using a machine learning algorithm model to obtain the second detection model:
[0113] (1) The black and white sample files are classified according to the web page language type, namely ASP sample, JSP sample, PHP sample, etc. The WebShell sample and web page sample file of each dynamic web page language are treated as strings respectively. During the processing, the sample file content is filtered, screened, and statistically analyzed.
[0114] (2) Feature extraction is performed based on different language types such as ASP, JSP, and PHP. For example, ASP files are compiled into CIL (Common Intermeditate Language) using .NET language and then assembled into bytecode. JSP files are converted into Java files and then the bytecode in the class files is extracted. PHP files are processed by compilation to obtain the corresponding opcode sequence.
[0115] (3) Use the statistical language model N-gram (n-gram model) to extract instruction sequences by grouping.
[0116] (4) The instruction sequence is randomly divided into three sets: a training set, a test set, and a validation set. The training set is used to build a prediction model and make predictions using different machine learning algorithms, including but not limited to convolutional neural networks, naive Bayesian algorithms, and multilayer perceptrons.
[0117] (5) By using the "two synchronizations" principle, namely synchronous training and synchronous verification, the model effect is tested using the validation set, and the model is iteratively tuned.
[0118] Please refer to Figure 7 , Figure 7 The diagram illustrates the process of dividing black and white sample files before the second detection model is established.
[0119] S205. Input the WebShell test features into the first detection model and the second detection model respectively to obtain the first detection result and the second detection result.
[0120] S206. Generate detection confidence scores corresponding to the WebShell test features based on the first and second detection results.
[0121] In this embodiment, the method can utilize the efficiency and accuracy of the first detection model, and the high detection rate of the second detection model, to perform correlation analysis between the WebShell alert content and the results of the training and validation sets mentioned above. It can also assign confidence labels based on the WebShell detection rules / model and the results trained and validated by the machine learning algorithm, and then iterate and optimize the detection model according to the confidence level, thereby continuously improving the effectiveness of WebShell attack detection.
[0122] In this embodiment, the method for verifying confidence level is explained as follows: If the attack detection rule generates an alarm, but the machine learning algorithm does not generate an alarm, the security event data information is automatically added to the machine learning training sample; if the attack detection rule does not generate an alarm, but the machine learning algorithm generates an alarm, the security event data information is transferred to manual processing, and features are extracted and optimized for detection after analysis and judgment; confidence level labels are added to the security event according to the alarm situation, as shown in the table below.
[0123] The first detection model generates an alarm, and the second detection model generates an alarm. high The first detection model generated an alarm, but the second detection model did not. middle The first detection model did not generate an alarm, but the second detection model did. Low
[0124] S207. Based on the first detection model, the second detection model, WebShell test features, and detection confidence, a correlation model is performed to obtain a comprehensive detection model for detecting WebShell attacks.
[0125] Please refer to Figure 8 , Figure 8 A schematic diagram illustrating the correlation analysis between the first and second detection models is shown. The result of iterative optimization of the detection models is the aforementioned integrated detection model.
[0126] S208. Obtain the WebShell features to be detected.
[0127] S209. Input the WebShell features to be detected into the comprehensive detection model to obtain the comprehensive detection results.
[0128] S210. When the comprehensive detection results indicate that the WebShell to be detected features are WebShell attack features, obtain threat intelligence corresponding to the WebShell to be detected features.
[0129] S211. Output threat intelligence or send threat intelligence to a third-party device so that the third-party device can automatically perform security processing based on the threat intelligence.
[0130] In this embodiment, it is used to coordinate with a third-party firewall to send the obtained attacking IPs to the firewall for blocking. For example, based on the "Open Command and Control (OpenC2) Profile for Stateless Packet Filtering Version 1.0", the coordination protocol supports the standard OpenC2 SLPF protocol, which can allow or block communication based on static data such as address and port. The protocol format is described in the table below.
[0131]
[0132] In this embodiment, the security processing includes at least blocking the attacking address.
[0133] In this embodiment, the method can block attacks by linking with a third-party firewall based on the attacking IP address, thereby effectively and promptly blocking hacker attacks.
[0134] S212. Check if there are any security events in the database that match the threat intelligence. If yes, proceed to steps S213-S214; otherwise, proceed to step S215.
[0135] S213. Obtain the handling method for security incidents.
[0136] S214. Based on the processing method and the characteristics of the WebShell to be detected, perform automatic security processing and end this process.
[0137] S215. A processing device for sending threat intelligence to staff.
[0138] In this embodiment, the method extracts attack information from WebShell attack alerts and performs correlation analysis with threat intelligence to identify information such as the source address and port, geographical location, latest activity time, earliest activity time, attack category, protocol, and affected assets of the hacker attack. Then, the attack source addresses of security events correlated with the threat intelligence are automatically blocked, while security events not correlated with the threat intelligence are transferred to manual handling. This method can improve the accuracy of automatically blocking hacker attacks and lays the foundation for hacker attack analysis, judgment, and forensic tracing.
[0139] In this embodiment, the subject executing the method can be a computing device such as a computer or server, and no limitation is made in this embodiment.
[0140] In this embodiment, the subject executing the method can also be a smart device such as a smartphone or tablet, and no limitation is made in this embodiment.
[0141] As can be seen, the model generation method for detecting WebShell attacks described in this embodiment can build an automated response and handling system based on the combination of WebShell attack detection and threat intelligence, thereby constructing a linkage system based on traffic data collection, attack feature extraction, feature correlation analysis, threat intelligence matching, and automatic attack blocking, further improving the efficiency of WebShell attack analysis, judgment, and response.
[0142] Example 3
[0143] Please refer to Figure 3 , Figure 3 This is a schematic diagram of a model generation device for detecting WebShell attacks provided in this embodiment. Figure 3 As shown, the model generation device for detecting WebShell attacks includes:
[0144] Modeling unit 310 is used to establish a first detection model for detecting WebShell attacks based on WebShell attack traffic characteristics;
[0145] Training unit 320 is used for artificial intelligence training based on WebShell black and white sample features to obtain a second detection model for detecting WebShell attacks;
[0146] The first input unit 330 is used to input WebShell test features into the first detection model and the second detection model respectively to obtain the first detection result and the second detection result;
[0147] The confidence detection unit 340 is used to generate a detection confidence level corresponding to the WebShell test features based on the first detection result and the second detection result.
[0148] The generation unit 350 is used to perform correlation modeling based on the first detection model, the second detection model, WebShell test features, and detection confidence to obtain a comprehensive detection model for detecting WebShell attacks.
[0149] In this embodiment, the explanation of the model generation device used to detect WebShell attacks can be found in the description in Embodiment 1 or Embodiment 2, and will not be repeated here.
[0150] As can be seen, the model generation device for detecting WebShell attacks described in this embodiment can automatically respond to and handle WebShell attacks by combining WebShell attack detection with threat intelligence, thereby constructing a linkage system based on traffic data collection, attack feature extraction, feature correlation analysis, threat intelligence matching, and automatic attack blocking, which further improves the efficiency of WebShell attack analysis, judgment, and response.
[0151] Example 4
[0152] Please refer to Figure 4 , Figure 4 This is a schematic diagram of a model generation device for detecting WebShell attacks provided in this embodiment. Figure 4 As shown, the model generation device for detecting WebShell attacks includes:
[0153] Modeling unit 310 is used to establish a first detection model for detecting WebShell attacks based on WebShell attack traffic characteristics;
[0154] Training unit 320 is used for artificial intelligence training based on WebShell black and white sample features to obtain a second detection model for detecting WebShell attacks;
[0155] The first input unit 330 is used to input WebShell test features into the first detection model and the second detection model respectively to obtain the first detection result and the second detection result;
[0156] The confidence detection unit 340 is used to generate a detection confidence level corresponding to the WebShell test features based on the first detection result and the second detection result.
[0157] The generation unit 350 is used to perform correlation modeling based on the first detection model, the second detection model, WebShell test features, and detection confidence to obtain a comprehensive detection model for detecting WebShell attacks.
[0158] As an optional implementation, the model generation apparatus for detecting WebShell attacks further includes:
[0159] The 360-degree acquisition unit is used to collect traffic data.
[0160] Extraction unit 370 is used to extract WebShell attack traffic features from traffic data through real WebShell attacks and simulated WebShell attacks; wherein, the feature extraction dimensions of WebShell attack traffic features include at least one of dynamic variables, callback functions, control characters, class methods, special functions, and pseudo-protocols.
[0161] As an optional implementation, the model generation apparatus for detecting WebShell attacks further includes:
[0162] The first acquisition unit 380 is used to acquire the WebShell features to be detected.
[0163] The second input unit 390 is used to input the WebShell features to be detected into the comprehensive detection model to obtain the comprehensive detection result;
[0164] The first acquisition unit 380 is also used to acquire threat intelligence corresponding to the WebShell detection feature when the comprehensive detection result indicates that the WebShell detection feature is a WebShell attack feature;
[0165] Output unit 400 is used to output threat intelligence.
[0166] As an optional implementation, the model generation apparatus for detecting WebShell attacks further includes:
[0167] The sending unit 410 is used to send threat intelligence to a third-party device so that the third-party device can automatically perform security processing based on the threat intelligence.
[0168] As an optional implementation, the model generation apparatus for detecting WebShell attacks further includes:
[0169] Database detection unit 420 is used to detect whether there are security events in the database that match threat intelligence;
[0170] The second acquisition unit 430 is used to acquire the handling method of a security event when a security event exists in the database;
[0171] The security processing unit 440 is used to automatically perform security processing based on the processing method and the characteristics of the WebShell to be detected.
[0172] 0 In this embodiment, the security processing includes at least the blocking of attack addresses.
[0173] As an optional implementation, the sending unit 410 is also used to send threat intelligence to the staff processing device when no security event exists in the database.
[0174] In this embodiment, the explanation of the model generation device for detecting WebShell attacks can be found in Embodiment 1 or Embodiment 2, and will not be repeated here. 5. It can be seen that implementing the model generation device for detecting WebShell attacks described in this embodiment...
[0175] It can automate response and handling based on the combination of WebShell attack detection and threat intelligence, thereby building a linkage system based on traffic data collection, attack feature extraction, feature correlation analysis, threat intelligence matching, and automatic attack blocking, which further improves the efficiency of WebShell attack analysis, judgment, and response.
[0176] This application provides an electronic device, including a memory and a processor. The memory stores a computer program, and the processor runs the computer program to cause the electronic device to execute the model generation method for detecting WebShell attacks in Embodiment 1 or Embodiment 2 of this application.
[0177] This application provides a computer-readable storage medium storing computer program instructions. When these computer program instructions are read and executed by a processor, they perform the model generation method for detecting WebShell attacks as described in embodiment 1 or embodiment 2 of this application.
[0178] In the several embodiments provided in this application, it should be understood that the disclosed apparatus and methods can also be implemented in other ways. The apparatus embodiments described above are merely illustrative. For example, the flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of apparatus, methods, and computer program products according to various embodiments of this application. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than those marked in the drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram and / or flowchart, and combinations of blocks in block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or action, or using a combination of dedicated hardware and computer instructions.
[0179] In addition, the functional modules in the various embodiments of this application can be integrated together to form an independent part, or each module can exist independently, or two or more modules can be integrated to form an independent part.
[0180] If the aforementioned functions are implemented as software functional modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0181] The above description is merely an embodiment of this application and is not intended to limit the scope of protection of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of protection of this application. It should be noted that similar reference numerals and letters in the following figures indicate similar items; therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures.
[0182] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
[0183] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.
Claims
1. A model generation method for detecting WebShell attacks, characterized in that, include: Based on the characteristics of WebShell attack traffic, a first detection model for detecting WebShell attacks is established. Artificial intelligence was trained based on the features of black and white samples of WebShell to obtain a second detection model for detecting WebShell attacks; The WebShell test features are input into the first detection model and the second detection model respectively to obtain the first detection result and the second detection result. Based on the first and second detection results, a detection confidence level corresponding to the WebShell test features is generated; Based on the first detection model, the second detection model, the WebShell test features, and the detection confidence, a comprehensive detection model for detecting WebShell attacks is obtained through correlation modeling. The step of performing correlation modeling based on the first detection model, the second detection model, the WebShell test features, and the detection confidence to obtain a comprehensive detection model for detecting WebShell attacks includes: Establish logical association rules between the first detection model and the second detection model; and iteratively optimize the first detection model and / or the second detection model based on the WebShell test features and the detection confidence level to obtain the optimized first detection model and / or the optimized second detection model. Based on the aforementioned logical association rules, the optimized first detection model and the optimized second detection model are associated and modeled to obtain a comprehensive detection model for detecting WebShell attacks.
2. The model generation method for detecting WebShell attacks according to claim 1, characterized in that, The method further includes: Collect traffic data; By employing both real and simulated WebShell attacks, WebShell attack traffic characteristics are extracted from the traffic data. The feature extraction dimensions of the WebShell attack traffic characteristics include at least one of the following: dynamic variables, callback functions, control characters, class methods, special functions, and pseudo-protocols.
3. The model generation method for detecting WebShell attacks according to claim 1, characterized in that, After the step of performing correlation modeling based on the first detection model, the second detection model, the WebShell test features, and the detection confidence to obtain a comprehensive detection model for detecting WebShell attacks, the method further includes: Obtain the WebShell features to be detected; The WebShell features to be detected are input into the comprehensive detection model to obtain the comprehensive detection results; When the comprehensive detection result indicates that the WebShell detection feature is a WebShell attack feature, threat intelligence corresponding to the WebShell detection feature is obtained; Output the threat intelligence.
4. The model generation method for detecting WebShell attacks according to claim 3, characterized in that, After the step of obtaining threat intelligence corresponding to the WebShell's detectable features, the method further includes: The threat intelligence is sent to a third-party device so that the third-party device can automatically perform security processing based on the threat intelligence.
5. The model generation method for detecting WebShell attacks according to claim 3, characterized in that, After the step of obtaining threat intelligence corresponding to the WebShell's detectable features, the method further includes: Detect whether there are security events in the database that match the threat intelligence; When the security event exists in the database, obtain the handling method for the security event; Based on the processing method and the WebShell characteristics to be detected, security processing is performed automatically.
6. The model generation method for detecting WebShell attacks according to claim 5, characterized in that, The method further includes: The processing device that sends the threat intelligence to staff when the security event is not found in the database.
7. The model generation method for detecting WebShell attacks according to claim 5, characterized in that, The security measures include at least blocking attack addresses.
8. A model generation device for detecting WebShell attacks, characterized in that, The model generation device for detecting WebShell attacks includes: The modeling unit is used to establish a first detection model for detecting WebShell attacks based on the characteristics of WebShell attack traffic. The training unit is used to train artificial intelligence based on the features of WebShell black and white samples to obtain a second detection model for detecting WebShell attacks; The first input unit is used to input WebShell test features into the first detection model and the second detection model respectively to obtain the first detection result and the second detection result; A confidence detection unit is used to generate a detection confidence level corresponding to the WebShell test feature based on the first detection result and the second detection result. The generation unit is used to perform correlation modeling based on the first detection model, the second detection model, the WebShell test features, and the detection confidence to obtain a comprehensive detection model for detecting WebShell attacks; Specifically, the generation unit is used to establish logical association rules between the first detection model and the second detection model; and based on the WebShell test features and the detection confidence, to iteratively optimize the first detection model and / or the second detection model to obtain the optimized first detection model and / or the optimized second detection model. Based on the aforementioned logical association rules, the optimized first detection model and the optimized second detection model are associated and modeled to obtain a comprehensive detection model for detecting WebShell attacks.
9. An electronic device, characterized in that, The electronic device includes a memory and a processor, the memory being used to store a computer program, and the processor running the computer program to cause the electronic device to perform the model generation method for detecting WebShell attacks as described in any one of claims 1 to 7.
10. A readable storage medium, characterized in that, The readable storage medium stores computer program instructions, which, when read and executed by a processor, perform the model generation method for detecting WebShell attacks as described in any one of claims 1 to 7.
Citation Information
Patent Citations
A webshell detection method based on model fusion
CN108985061A
Intranet security threat multi-model collaborative defense method based on credibility
CN111565192A