Obfuscated PHP Webshell Detection Using the Webshell Tailored TextRank Algorithm
H. Lee, Seon-Jin Hwang, Millati Pratiwi, Yoon-Ho Choi · 2024
Webshells, which are malicious tools that enable unauthorized command execution on web pages, pose threats, such as server attacks and data breaches. In response, system administrators continuously monitor web vulnerabilities and potential webshell attacks. However, attackers often obfuscate webshells to avoid detection. Existing static webshell detection methods commonly rely on static statistical features and focus on obfuscation characteristics. Consequently, this approach may inadvertently increase the likelihood of falsely identifying an obfuscated normal file as a webshell. That is, if obfuscated general files are incorporated into a dataset for algorithm and information protection purposes, an obfuscation bias problem arises, thereby diminishing the webshell detection efficacy. To mitigate this, we propose a webshell detection methodology that leverages a webshell-tailored TextRank algorithm. This approach aims to detect webshells without introducing the biases associated with obfuscation techniques. This method involves deobfuscating the source code and generating a feature matrix from the operation code (opcode) and Abstract Syntax Tree (AST) derived from the code. Its performance was compared with those of machine learning algorithms such as Random Forest (RF), Support Vector Machines (SVM), and Extreme Gradient Boosting (XGBoost).