HoneyContainer: Container-based Webshell Command Injection Defending and Backtracking

Kuan Chien Wang, Wei Jun Cheng, Jie Zhang, Min Te Sun, Kazuya Sakai, Wei Shinn Ku

研究成果: 書貢獻/報告類型會議論文篇章同行評審

摘要

The web server is a vulnerable component in enterprise systems, susceptible to a variety of attack strategies. Of these, webshell attacks are particularly insidious, as they can be uploaded through legitimate paths and executed using network traffic that is indistinguishable from that of normal users. Despite the existence of several proposed detection methods for identifying webshell attacks, attackers can still easily evade them. To address this issue, we present HoneyContainer, an architecture designed to detect webshell-based command injection attacks, trace the origin of the attacker, and redirect malicious traffic to a honeypot container. Our prototype implementation of Honey-Container has been validated using 214 webshell files, with results demonstrating its ability to detect all shell command injection events and redirect malicious traffic. Our evaluations also indicate that the overhead caused by HoneyContainer is minimal and unlikely to be noticeable by normal users. The source code is released at https://github.com/wei-juncheng/webshell

原文???core.languages.en_GB???
主出版物標題2023 Silicon Valley Cybersecurity Conference, SVCC 2023
發行者Institute of Electrical and Electronics Engineers Inc.
ISBN(電子)9798350321579
DOIs
出版狀態已出版 - 2023
事件2023 IEEE Silicon Valley Cybersecurity Conference, SVCC 2023 - San Jose, United States
持續時間: 17 5月 202319 5月 2023

出版系列

名字2023 Silicon Valley Cybersecurity Conference, SVCC 2023

???event.eventtypes.event.conference???

???event.eventtypes.event.conference???2023 IEEE Silicon Valley Cybersecurity Conference, SVCC 2023
國家/地區United States
城市San Jose
期間17/05/2319/05/23

指紋

深入研究「HoneyContainer: Container-based Webshell Command Injection Defending and Backtracking」主題。共同形成了獨特的指紋。

引用此