Tongxin xuebao (Jun 2016)

Research on Webshell-based botnet

  • Ke LI,
  • Bin-xing FANG,
  • Xiang CUI,
  • Qi-xu LIU,
  • Zhi-tao YAN

Journal volume & issue
Vol. 37
pp. 11 – 19

Abstract

Read online

With the rapid rising of Web server-based botnets,traditional channel models were unable to predict threats from them.Based on improving traditional Webshell control method,a command and control channel model based on tree structure was proposed.The model was widely applicable and stealthy and the simulation experimental results show it can achieve rapid and reliable commands delivery.After summarizing the limitations of current defenses against the proposed model,the model’s inherent vulnerabilities is analyzed and feasible defense strategies are put forward.

Keywords