CNN-Webshell
Yifan Tian, Jiabao Wang, Zhenji Zhou, Shengli Zhou · 2017
Malicious web shell detection is one of the most important methods for protecting the network security. Most state of the art methods are based on malicious keywords matching, where the keywords are usually defined by the domain experts. So its effect depends on the domain experts and it is hard to detect new type of malicious web shells. This paper proposed a new malicious web shell detection approach based on 'word2vec' representation and convolutional neural network (CNN). Firstly, each word, separated from the HTTP requests, is represented as a vector by using the 'word2vec' tool. Next, a web request can be represented as a size-fixed matrix. Finally, a CNN-based model is designed to classify the malicious web shells and the normal ones. Experimental results showed that this approach achieves the best performance, comparing with several other classification methods. To the best of our knowledge, this is the first time that CNN has been applied to malicious web shell detection.