Webshell file detection method, device and electronic equipment

By acquiring and analyzing the operational behavior characteristics of webshell files, combined with upload behavior characteristics, the problem of low detection accuracy of webshell files in existing technologies has been solved, and efficient identification of obfuscated files has been achieved.

CN116436690BActive Publication Date: 2026-03-24BEIJING TOPSEC NETWORK SECURITY TECH +2
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-05-05
Publication Date
2026-03-24

AI Technical Summary

Technical Problem

Existing technologies have low accuracy in detecting webshell files, especially in detecting obfuscated webshell files.

Method used

By acquiring the operational behavior characteristics of the initial file, the user's operational behavior is analyzed to determine whether the file is a webshell file, and the detection accuracy is further improved by combining the upload behavior characteristics.

Benefits of technology

It improves the detection accuracy of obfuscated webshell files, enabling more accurate identification of webshell files.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116436690B_ABST
    Figure CN116436690B_ABST
Patent Text Reader

Abstract

The application provides a webshell file detection method and device and electronic equipment, and relates to the technical field of security. The method obtains operation behavior characteristics of an initial file, and then determines whether the initial file is a webshell file according to the operation behavior characteristics. The operation behavior characteristics can reflect some operation behaviors of an attacker, so the webshell file can be accurately detected by analyzing the operation behavior characteristics. Compared with a feature matching detection method, the scheme has better detection effect on obfuscated webshell files and higher detection precision.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of security, in particular to a webshell file detection method and device and electronic equipment. BACKGROUND

[0002] A webshell is a code execution environment in the form of an asp, php, jsp or cgi web page file, and is mainly used for website management, server management, permission management and the like. The method of use is simple, and only a code file needs to be uploaded, and a lot of daily operations can be performed by accessing the website, greatly facilitating the management of the website and server by the user. As such, a small number of people modify the code and use it as a backdoor program to achieve the purpose of controlling the website server.

[0003] With the development of webshell detection technology, bypassing and anti-virus methods for webshell are emerging in an endless stream. Traditional intrusion detection systems mainly match some webshell traffic characteristics according to specific network characteristic rules, but this method is usually unable to detect some obfuscated webshells, that is, the detection accuracy is low. SUMMARY

[0004] The purpose of the embodiments of the present application is to provide a webshell file detection method, device and electronic equipment to improve the low detection accuracy of webshell files in the prior art.

[0005] In a first aspect, the embodiments of the present application provide a webshell file detection method, which comprises:

[0006] obtaining an initial file uploaded;

[0007] obtaining an operation behavior characteristic of the initial file;

[0008] determining whether the initial file is a webshell file according to the operation behavior characteristic.

[0009] In the above implementation process, the operation behavior characteristic of the initial file is obtained, and then it is determined whether the initial file is a webshell file according to the operation behavior characteristic. The operation behavior characteristic can reflect some operation behaviors of an attacker, so the webshell file can be accurately detected by analyzing the operation behavior characteristic. Compared with the detection method of characteristic matching, the detection effect of the present application on obfuscated webshell files is better, and the detection accuracy is higher.

[0010] Optionally, before the operation behavior characteristic of the initial file is obtained, the method further comprises:

[0011] Obtain the upload behavior characteristics during the initial file upload;

[0012] The step of determining whether the initial file is a webshell file based on the operational behavior characteristics includes:

[0013] Based on the upload behavior characteristics and the operation behavior characteristics, determine whether the initial file is a webshell file.

[0014] In the above implementation process, combining upload behavior characteristics and operation behavior characteristics to comprehensively detect webshell files can further improve detection accuracy.

[0015] Optionally, the upload behavior characteristics include at least one of the following: the name of the initial file, the time the initial file was uploaded, the path to the initial file, and the IP address of the initial file. By detecting these upload behavior characteristics, it can be preliminarily determined whether the initial file is a suspicious webshell file.

[0016] Optionally, before obtaining the upload behavior characteristics during the initial file upload, the method further includes:

[0017] Detect whether the initial file is a suspicious webshell file;

[0018] If so, proceed with the following step: Obtain the upload behavior characteristics during the initial file upload.

[0019] In the above implementation process, the initial file is first checked to see if it is a suspicious webshell file. This initial file is then checked, and then the upload behavior characteristics and operation behavior characteristics are combined to increase the accuracy of subsequent detection.

[0020] Optionally, detecting whether the initial file is a suspicious webshell file includes:

[0021] Obtain the network traffic characteristics during the upload of the initial file;

[0022] The initial file is detected as a suspicious webshell file based on the traffic characteristics.

[0023] In the above implementation process, traffic characteristics are used to initially detect whether the initial file is a suspicious webshell file, thereby enabling preliminary screening of the initial file and improving detection efficiency.

[0024] Optionally, the traffic characteristics include at least one of the following: key fields, request characteristics, file extensions, and server response characteristics.

[0025] Optionally, the operation behavior feature comprises at least one of the following: a session feature, an operation instruction, a database operation behavior feature, a file operation behavior feature, and an access behavior feature.

[0026] In a second aspect, an embodiment of the present application provides a webshell file detection device, the device comprising:

[0027] a file acquisition module configured to acquire an initial file uploaded;

[0028] a feature acquisition module configured to acquire an operation behavior feature of the initial file;

[0029] a file detection module configured to determine whether the initial file is a webshell file according to the operation behavior feature.

[0030] In a third aspect, an embodiment of the present application provides an electronic device comprising a processor and a memory, wherein the memory stores computer readable instructions, and when the computer readable instructions are executed by the processor, the steps in the method provided in the first aspect are executed.

[0031] In a fourth aspect, an embodiment of the present application provides a computer readable storage medium, which stores a computer program, and when the computer program is executed by a processor, the steps in the method provided in the first aspect are executed.

[0032] Other features and advantages of the present application will be described in the following description and will be apparent from the description, or will be learned from the practice of the application. The purposes and other advantages of the application will be realized and attained by the structure particularly pointed out in the written description and claims. BRIEF DESCRIPTION OF DRAWINGS

[0033] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following will briefly introduce the drawings needed to be used in the embodiments of the present application. It should be understood that the following drawings only show some embodiments of the present application, and therefore should not be considered as limiting the scope. For those skilled in the art, other related drawings can also be obtained from these drawings without creative labor.

[0034] Figure 1 A flow chart of a webshell file detection method provided by an embodiment of the present application;

[0035] Figure 2 A structural block diagram of a webshell file detection device provided by an embodiment of the present application;

[0036] Figure 3A structural schematic diagram of an electronic device for performing a webshell file detection method is provided in the embodiments of the present application. DETAILED DESCRIPTION

[0037] The technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application.

[0038] It should be noted that the terms “system” and “network” in the embodiments of the present application can be used interchangeably. “Multiple” means two or more, and therefore, “multiple” can also be understood as “at least two” in the embodiments of the present application. “And / or” describes the association relationship of the associated objects, which means that there can be three kinds of relationships, for example, A and / or B can represent the following three cases: A exists alone, A and B exist together, and B exists alone. In addition, the character “ / ”, if not specially stated, generally represents an “or” relationship between the associated objects before and after it.

[0039] The embodiments of the present application provide a webshell file detection method, which obtains the operation behavior characteristics of an initial file, and then judges whether the initial file is a webshell file according to the operation behavior characteristics. Since the operation behavior characteristics can reflect the operation of the user on the initial file, if it is an attacker, it can reflect some operation behaviors of the attacker, so by analyzing the operation behavior characteristics, the webshell file can be accurately detected. Compared with the recognition mode of feature matching, the detection effect of the present scheme on the obfuscated webshell file is better, and the detection precision is higher.

[0040] Please refer to Figure 1 , Figure 1 A flowchart of a webshell file detection method is provided in the embodiments of the present application, and the method comprises the following steps:

[0041] Step S110: Obtain an uploaded initial file.

[0042] When an attacker wants to attack a server, the attacker can upload a webshell file to the server through various methods. Therefore, in order to ensure the security of the server, the server can detect the webshell file for each uploaded file, so if the server detects that a file is uploaded, the uploaded file is obtained, which can be referred to as an initial file.

[0043] Step S120: Obtain the operation behavior characteristics of the initial file.

[0044] In order to bypass the security detection of the server, the attacker generally modifies the webshell file before uploading, that is, the webshell file is not a standard webshell file, but a confused webshell file. If the server detects by feature matching, the confused webshell file may not be detected, so that the attacker can easily escape the security detection of the server. Therefore, in order to avoid the attacker bypassing the detection of the server, the operation of the user on the initial file can be tracked and detected in the scheme to obtain the operation behavior feature of the initial file.

[0045] The operation behavior feature can reflect the real intention of the user uploading the initial file. For example, if it is a webshell file, the attacker will try to connect the file and control the server, such as remotely accessing the file to execute the file.

[0046] Step S130: judging whether the initial file is a webshell file according to the operation behavior feature.

[0047] By analyzing the operation behavior feature, the intention of the user operating the initial file can be identified to detect whether the initial file is a webshell file.

[0048] In the above implementation process, the operation behavior feature of the initial file is obtained, and then whether the initial file is a webshell file is judged according to the operation behavior feature. The operation behavior feature can reflect some operation behaviors of the attacker, so the webshell file can be accurately detected by analyzing the operation behavior feature. Compared with the feature matching detection method, the detection effect of the confused webshell file is better, and the detection precision is higher.

[0049] On the basis of the above embodiment, the operation behavior feature can include at least one of the following: session feature, operation instruction, database operation behavior feature, file operation behavior feature and access behavior feature.

[0050] For example, after the initial file is uploaded to the server, if the attacker remotely connects, there will be a remote IP accessing the initial file. If the access is successful, the server will store a complete response success session. Therefore, the session feature can be obtained by analyzing the session, such as a suspicious IP (such as a strange IP, which has not connected the server before, or an IP in the internal stored IP black list), or the response feature of the server is 200OK. If the session feature is detected, the initial file is considered to be a webshell file.

[0051] The attacker sends some operation instructions in the process of executing the webshell file, such as executing a system command. If the webshell file executes a system command, there is a related process, such as IIS User starting a cmd command under Windows. If the operation instruction is detected, it can be considered that the initial file is a webshell file.

[0052] For the database operation behavior feature, the corresponding operation record can be viewed in combination with the database log, such as a suspicious access statement, a modification operation on the database, access by a non-administrator, and the like. If these database operation behavior features are detected, it can be considered that the initial file is a webshell file.

[0053] The file operation behavior feature, such as a newly created file, a deleted file, and a file modification time in non-working hours, if these file operation behavior features are detected, it can be considered that the initial file is a webshell file.

[0054] The attacker can also detect the access behavior feature of the file when performing these operations, such as finding an access request from a certain IP address, uploading a suspicious file, and then accessing the file and initiating some operation requests and the server giving a response. The access time has a certain regularity, and the file is relatively independent and has no association with other pages. The IP address initiating the access to the file is less, and the overall access times are also less. If these access behavior features are detected, it can be considered that the initial file is a webshell file.

[0055] On the basis of the above embodiments, in order to improve the accuracy of webshell file detection, the uploading behavior feature of the initial file when uploading can also be obtained, and then the uploading behavior feature and the operation behavior feature are combined to comprehensively judge whether the initial file is a webshell file.

[0056] The uploading behavior feature here can include at least one of the following: the name of the initial file, the time of uploading the initial file, the path of uploading the initial file, and the IP address of the initial file.

[0057] For example, it can be seen whether the name of the initial file is an abnormal file name, such as carrying special characters or characteristic fields in the name. If it is considered to be an abnormal file name, the operation behavior feature can be combined to judge whether the initial file is a webshell file. If the above-mentioned operation behavior features are detected, it can be determined that the initial file is a webshell file.

[0058] For example, if the time of uploading the initial file is during non-working hours, the initial file can be determined to be a webshell file in combination with the operation behavior features. If the above-mentioned operation behavior features are also detected, it can be determined that the initial file is a webshell file.

[0059] For example, if the path of uploading the initial file is an abnormal file path, the initial file can be determined to be a webshell file in combination with the operation behavior features. If the above-mentioned operation behavior features are also detected, it can be determined that the initial file is a webshell file.

[0060] For example, if the IP address of the initial file is an IP address in the preset blacklist, the initial file can be determined to be a webshell file in combination with the operation behavior features. If the above-mentioned operation behavior features are also detected, it can be determined that the initial file is a webshell file.

[0061] It can be understood that when the initial file is determined to be a webshell file in combination with the operation behavior features, at least one of the above-mentioned upload behavior features can also be selected to determine the initial file in combination with the operation behavior features. For example, when at least one of the upload behavior features meets the set condition (for example, the name of the initial file is an abnormal file name and the time of uploading the initial file is during non-working hours), the initial file can be determined to be a webshell file in combination with the operation behavior features.

[0062] That is, when at least one of the upload behavior features meets the set condition and at least one of the operation behavior features meets the set condition (for example, the above-mentioned database operation behavior features are detected), the initial file can be determined to be a webshell file. This can further identify the real webshell file and improve the accuracy of webshell file identification.

[0063] For at least one of the upload behavior features not meeting the set condition and at least one of the operation behavior features meeting the set condition, the initial file can be considered to be a webshell file. Of course, other information can also be combined for judgment, such as the malicious feature matching mode. If the initial file matches the set malicious feature and at least one of the operation behavior features meets the set condition, the initial file can be determined to be a webshell file.

[0064] In some embodiments, when detecting the initial file by combining the upload behavior features and the operation behavior features, the initial file can also be detected based on the upload behavior features to obtain a first detection weight value, and the initial file can also be detected based on the operation behavior features to obtain a second detection weight value, and then whether the initial file is a webshell file is determined according to the first detection weight value and the second detection weight value.

[0065] Specifically, for example, for each of the upload behavior features mentioned above, the first detection weight value is determined according to the number of upload behavior features of the initial file that meet the conditions, for example, if three upload behavior features meet the corresponding conditions, the first detection weight value accounts for 3 / 4, where 4 is the total number of upload behavior features, and similarly, the calculation method of the second detection weight value is similar. Finally, the first detection weight value and the second detection weight value are normalized and averaged, and if the average value is greater than a set value, the initial file can be determined as a webshell file.

[0066] It can be understood that in actual application, the calculation method of the first detection weight value and the second detection weight value can also have other methods, for example, a neural network model can also be used for prediction, such as inputting the upload behavior features into a first neural network model, and taking the confidence output by the first neural network model as the first detection weight value, and inputting the operation behavior features into a second neural network model, and taking the confidence output by the second neural network model as the second detection weight value. The first neural network model and the second neural network model here can be the same model, or different models, and the two models can be obtained by training different label data respectively.

[0067] In the above implementation process, the upload behavior features and the operation behavior features are combined to comprehensively detect the webshell file, which can further improve the detection accuracy.

[0068] On the basis of the above embodiment, in order to further improve the accuracy of webshell file detection, the initial file can also be detected whether it is a suspicious webshell file before obtaining the upload behavior features of the initial file during uploading, and if so, the upload behavior features of the initial file during uploading are obtained again.

[0069] That is, first, it is preliminarily judged whether the initial file is a suspicious file, and if so, it is judged by combining the upload behavior features and the operation behavior features, and if not, it is judged based on the operation behavior features.

[0070] Here, the way to determine whether the initial file is a suspicious webshell file can include: obtaining a traffic feature of network traffic when the initial file is uploaded, and then detecting whether the initial file is a suspicious webshell file according to the traffic feature.

[0071] The traffic features herein include at least one of the following: a key field, a request feature, a file suffix, and a server response feature.

[0072] For example, if a request log of an uploaded initial file is found, the request mode is a POST request, the request feature includes an upload field (i.e., a key field), the file suffix format is.php,.asp,.jsp, etc., and the server response feature is 200 OK, if at least one of these traffic features is detected, the initial file can be considered as a suspicious webshell file.

[0073] For the suspicious webshell file, subsequent upload behavior features and operation behavior features can be combined for further detection. If the initial file is not a suspicious webshell file, operation behavior features can be used for detection, i.e., whether there is a behavior of operating the initial file in the next step, which is conducive to detecting suspicious webshell files in files already existing on the server and detecting webshell files created directly on the server or modified from existing files on the server.

[0074] In the above implementation process, it is first detected whether the initial file is a suspicious webshell file, so that the initial file is preliminarily detected, and then upload behavior features and operation behavior features are combined for detection, so as to increase the accuracy of subsequent detection.

[0075] In some embodiments, if the initial file is uploaded, and based on the traffic features and the upload behavior features of the initial file, it is detected that the initial file is not a suspicious webshell file, it is possible that the webshell file is hidden deeply, such as a webshell file modified from existing files on the server. For this case, a first hash value of the initial file when uploaded can be calculated, and then when the operation behavior features of the initial file are detected subsequently, a second hash value of the initial file is calculated, and then it is determined whether the first hash value and the second hash value are the same. If they are not the same, and there are the operation behavior features exemplified in the above embodiments, it can be determined that the initial file is a webshell file. In this way, an attacker can first upload a normal file to escape the initial detection of the server when the file is uploaded, and then modify the initial file after a period of time to modify it into a webshell file.

[0076] According to the detection method of the embodiment of the application, the webshell file can be detected well, so the server can read the detected webshell file at intervals, and then input the related characteristics (such as traffic characteristics, upload behavior characteristics and operation behavior characteristics) of the file into the neural network model to train the neural network model. Of course, some positive samples (that is, normal files) can also be added during training, so that the neural network model obtained through training can be obtained. In this way, when the webshell file is detected through the above method, the neural network model is used to detect the webshell file again. If the result output by the neural network model still considers that the file is a webshell file, it can be considered that the probability of the initial file being a webshell file is greater, thereby further improving the accuracy of the webshell file detection.

[0077] Please refer to Figure 2 , Figure 2 A structural block diagram of a webshell file detection device 200 provided by the embodiment of the application is shown in FIG. 2. The device 200 can be a module, a program segment or code on an electronic device. It should be understood that the device 200 corresponds to the method embodiment described above, and can perform each step involved in the method embodiment. The specific functions of the device 200 can be referred to the description above. To avoid repetition, the detailed description is appropriately omitted here. Figure 1 Figure 1 The device 200 can perform each step involved in the method embodiment. The specific functions of the device 200 can be referred to the description above. To avoid repetition, the detailed description is appropriately omitted here.

[0078] Optionally, the device 200 includes:

[0079] A file acquisition module 210, configured to acquire an uploaded initial file;

[0080] A feature acquisition module 220, configured to acquire operation behavior characteristics of the initial file;

[0081] A file detection module 230, configured to determine whether the initial file is a webshell file according to the operation behavior characteristics.

[0082] Optionally, the feature acquisition module 220 is further configured to acquire upload behavior characteristics of the initial file when the initial file is uploaded.

[0083] The file detection module 230 is configured to determine whether the initial file is a webshell file according to the upload behavior characteristics and the operation behavior characteristics.

[0084] Optionally, the upload behavior characteristics include at least one of the following: a name of the initial file, a time of uploading the initial file, a path of uploading the initial file, and an IP address of the initial file.

[0085] ​Optionally, the file detection module 230 is further configured to detect whether the initial file is a suspicious webshell file; if so, it acquires the upload behavior characteristics of the initial file during upload.

[0086] Optionally, the file detection module 230 is further configured to obtain the network traffic characteristics when the initial file is uploaded; and detect whether the initial file is a suspicious webshell file based on the traffic characteristics.

[0087] Optionally, the traffic characteristics include at least one of the following: key fields, request characteristics, file extensions, and server response characteristics.

[0088] Optionally, the operational behavior characteristics include at least one of the following: session characteristics, operation instructions, database operation behavior characteristics, file operation behavior characteristics, and access behavior characteristics.

[0089] It should be noted that those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working process of the device described above can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.

[0090] Please refer to Figure 3 , Figure 3 This application provides a schematic diagram of the structure of an electronic device for executing a webshell file detection method. The electronic device may include: at least one processor 310, such as a CPU; at least one communication interface 320; at least one memory 330; and at least one communication bus 340. The communication bus 340 is used to establish direct communication between these components. In this embodiment, the communication interface 320 is used for signaling or data communication with other node devices. The memory 330 may be high-speed RAM or non-volatile memory, such as at least one disk storage device. Optionally, the memory 330 may also be at least one storage device located remotely from the aforementioned processor. The memory 330 stores computer-readable instructions. When these computer-readable instructions are executed by the processor 310, the electronic device performs the aforementioned... Figure 1 The method and process are shown.

[0091] Understandable. Figure 3 The structure shown is for illustrative purposes only; the electronic device may also include components that are more advanced than those shown. Figure 3 The more or fewer components shown, or having the same Figure 3 The different configurations shown. Figure 3 The components shown can be implemented using hardware, software, or a combination thereof.

[0092] The embodiment of the present application provides a computer readable storage medium, which stores a computer program, and the computer program is executed by a processor to perform the method as Figure 1 The method performed by the electronic device in the method embodiment is shown.

[0093] The embodiment discloses a computer program product, which comprises a computer program stored on a non-transitory computer readable storage medium, and the computer program comprises program instructions, and when the program instructions are executed by a computer, the computer can execute the method provided by each method embodiment, for example, comprising:

[0094] Obtaining an uploaded initial file;

[0095] Obtaining an operation behavior feature of the initial file;

[0096] Determining whether the initial file is a webshell file according to the operation behavior feature.

[0097] To sum up, the embodiment of the present application provides a webshell file detection method, device and electronic equipment, the method obtains the operation behavior feature of the initial file, and then determines whether the initial file is a webshell file according to the operation behavior feature. The operation behavior feature can reflect some operation behaviors of an attacker, so the webshell file can be accurately detected by analyzing the operation behavior feature. Compared with the detection mode of feature matching, the detection effect of the scheme on the obfuscated webshell file is better, and the detection precision is higher.

[0098] In the embodiments provided in the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. The device embodiments described above are only schematic. For example, the division of the units is only a logical function division, and other division manners can be used in actual implementation. For example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the units shown or discussed can be indirect coupling or communication connection through some communication interfaces, and can be electrical, mechanical or other forms.

[0099] In addition, the units described as separate components can or can not be physically separate, and the components shown as units can or can not be physical units, that is, they can be located in one place, or can be distributed on a plurality of network units. According to actual needs, some or all of the units can be selected to achieve the purpose of the embodiment.

[0100] Further, each functional module in each embodiment of the present application can be integrated together to form an independent part, or each module can exist independently, or two or more modules can be integrated to form an independent part.

[0101] In this document, relational terms such as first and second and the like can be used solely to distinguish one entity or action from another entity or action without necessarily requiring or implying any actual such relationship or order between such entities or actions.

[0102] The above description is merely illustrative of the application, and not in limitation of the principles of the application. Any modification and change of the application, which can be made by those skilled in the art without departing from the spirit and principle of the application, shall be included in the scope of the application.

Claims

1. A method for detecting webshell files, characterized in that, The method includes: Retrieve the initial file uploaded; Obtain the operation behavior characteristics of the initial file, wherein the operation behavior characteristics include: session characteristics, operation instructions, database operation behavior characteristics, file operation behavior characteristics, and access behavior characteristics; Determine whether the initial file is a webshell file based on the operational behavior characteristics; Before obtaining the operational behavior characteristics of the initial file, the method further includes: The upload behavior characteristics of the initial file upload are obtained, wherein the upload behavior characteristics include: the name of the initial file, the time of the initial file upload, the path of the initial file upload, and the IP address of the initial file; The step of determining whether the initial file is a webshell file based on the operational behavior characteristics includes: Based on the upload behavior characteristics and the operation behavior characteristics, determine whether the initial file is a webshell file; The step of determining whether the initial file is a webshell file based on the upload behavior characteristics and the operation behavior characteristics includes: The initial file is detected based on the upload behavior characteristics to obtain a first detection weight; The initial file is detected based on the aforementioned operational behavior characteristics to obtain a second detection weight; Determine whether the initial file is a webshell file based on the first detection weight and the second detection weight; Prior to obtaining the upload behavior characteristics during the initial file upload, the method further includes: Detect whether the initial file is a suspicious webshell file; If so, proceed with the following steps: obtain the upload behavior characteristics during the initial file upload; The step of detecting whether the initial file is a suspicious webshell file includes: Obtain the network traffic characteristics when uploading the initial file, the traffic characteristics including at least one of the following: key fields, request characteristics, file extension, and server response characteristics; Based on the traffic characteristics, detect whether the initial file is a suspicious webshell file; The method further includes: If the initial file is not a suspicious webshell file based on both the traffic characteristics and the upload behavior characteristics, then the initial file is detected based on the operation behavior characteristics. The step of detecting the initial file based on the operational behavior characteristics includes: Calculate the first hash value of the initial file at the time of upload and the second hash value of the initial file when the operation behavior characteristics of the initial file are detected; Determine whether the first hash value and the second hash value are the same. If they are not the same and the initial file is determined to be a webshell file based on the operation behavior characteristics, then the initial file is determined to be a webshell file.

2. A webshell file detection device, characterized in that, The device includes: The file acquisition module is used to acquire the initial file uploaded. The feature acquisition module is used to acquire the operation behavior features of the initial file, wherein the operation behavior features include: session features, operation instructions, database operation behavior features, file operation behavior features, and access behavior features; The file detection module is used to determine whether the initial file is a webshell file based on the operation behavior characteristics. The feature acquisition module is further configured to acquire upload behavior features during the initial file upload, wherein the upload behavior features include: the name of the initial file, the time of the initial file upload, the path of the initial file upload, and the IP address of the initial file; The file detection module is specifically used to detect the initial file based on the upload behavior characteristics to obtain a first detection weight; to detect the initial file based on the operation behavior characteristics to obtain a second detection weight; and to determine whether the initial file is a webshell file based on the first detection weight and the second detection weight. The file detection module is further configured to detect whether the initial file is a suspicious webshell file; if so, the following step is executed: obtaining the upload behavior characteristics of the initial file during upload. The file detection module is further configured to obtain network traffic characteristics when the initial file is uploaded, the traffic characteristics including at least one of the following: key fields, request characteristics, file extensions, and server response characteristics; and to detect whether the initial file is a suspicious webshell file based on the traffic characteristics. The file detection module is further configured to detect the initial file based on the operation behavior characteristics if both the traffic characteristics and the upload behavior characteristics detect that the initial file is not a suspicious webshell file. The file detection module is used to calculate the first hash value of the initial file when it is uploaded and the second hash value of the initial file when the operation behavior characteristics of the initial file are detected; determine whether the first hash value and the second hash value are the same; if they are not the same and the initial file is determined to be a webshell file according to the operation behavior characteristics, then the initial file is determined to be a webshell file.

3. An electronic device, characterized in that, It includes a processor and a memory, the memory storing computer-readable instructions that, when executed by the processor, perform the method as described in claim 1.

4. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it performs the method as described in claim 1.

Citation Information

Patent Citations

  • Method and device for detecting webshell file

    CN112668005A

  • Attack detection method, device and equipment and medium

    CN113329032A