通信学报 ›› 2016, Vol. 37 ›› Issue (6): 11-19.doi: 10.11959/j.issn.1000-436x.2016118

• 学术论文 • 上一篇    下一篇

基于Webshell的僵尸网络研究

李可1,2,方滨兴1,崔翔1,2,刘奇旭2,严志涛2   

  1. 1 北京邮电大学计算机学院,北京 100876
    2 中国科学院信息工程研究所,北京 100093
  • 出版日期:2016-06-25 发布日期:2017-08-04
  • 基金资助:
    国家自然科学基金资助项目;国家高技术研究发展计划(“863”计划)基金资助项目

Research on Webshell-based botnet

Ke LI1,2,Bin-xing FANG1,Xiang CUI1,2,Qi-xu LIU2,Zhi-tao YAN2   

  1. 1 School of Computer,Beijing University of Posts and Telecommunications,Beijing 100876,China
    2 Institute of Information Engineering,Chinese Academy of Sciences,Beijing 100093,China
  • Online:2016-06-25 Published:2017-08-04
  • Supported by:
    The National Natural Science Foundation of China;The National High Technology Research and Development Program(863 Program)

摘要:

以Web服务器为控制目标的僵尸网络逐渐兴起,传统命令控制信道模型无法准确预测该类威胁。对传统Webshell控制方式进行改进,提出一种树状拓扑结构的信道模型。该模型具备普适和隐蔽特性,实验证明其命令传递快速可靠。总结传统防御手段在对抗该模型时的局限性,分析该信道的固有脆弱性,提出可行的防御手段。

关键词: 僵尸网络, 命令与控制, 信道预测, Webshell

Abstract:

With the rapid rising of Web server-based botnets,traditional channel models were unable to predict threats from them.Based on improving traditional Webshell control method,a command and control channel model based on tree structure was proposed.The model was widely applicable and stealthy and the simulation experimental results show it can achieve rapid and reliable commands delivery.After summarizing the limitations of current defenses against the proposed model,the model’s inherent vulnerabilities is analyzed and feasible defense strategies are put forward.

Key words: botnet, command and control, channel prediction, Webshell

No Suggested Reading articles found!