TridentShell: An enhanced covert and scalable backdoor injection attack on web applications☆

被引:2
|
作者
Yu, Xiaobo [1 ]
Meng, Weizhi [2 ]
Liu, Yining [1 ]
Zhou, Fei [3 ]
机构
[1] Wuxi Univ, Sch Cyber Secur & Informatizat, Wuxi 214105, Jiangsu, Peoples R China
[2] Tech Univ Denmark, SPTAGE Lab, DTU Compute, Lyngby, Denmark
[3] Guangxi Informat Ctr, Joint Innovat Lab Digital Guangxi Smart Infrastruc, Nanning 530000, Peoples R China
关键词
Backdoor attack; Web shell; Web security; !text type='Java']Java[!/text] application; Static feature detection; NEXT-GENERATION BOTNETS;
D O I
10.1016/j.jnca.2023.103823
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Web backdoor attack is an increasingly prevalent network attack that can result in substantial losses for webmasters. During a cyber-attack, system vulnerabilities and web application flaws are usually used to implant a web shell inside victim servers. To mitigate these threats posed by web shells, research has focused on static feature detection, which has been evolved rapidly in recent years. However, static feature detection has inherent limitations and security risks. In this paper, we present TridentShell, a novel web backdoor attack that can inject an invisible backdoor into a victim server without leaving any traces of the attack. Furthermore, TridentShell can circumvent almost all static detection methods. Unlike existing approaches, which leverage traditional encryption and obfuscation technologies to avoid detection, our proposed attack is intended to blend into the web application server naturally. In this work, we introduce enhancements to the original TridentShell, which is not traceable - in theory - since it uses a blockchain-based decentralized C&C server with better presentation capability. The experimental results show that our TridentShell can effectively compromise five different types of Java application servers (covering around 87% Java application servers in the market), and can scrub any attack traces from the server, making it especially difficult to detect.
引用
收藏
页数:12
相关论文
共 50 条
  • [1] TridentShell: An enhanced covert and scalable backdoor injection attack on web applications
    Yu, Xiaobo
    Meng, Weizhi
    Liu, Yining
    Zhou, Fei
    Journal of Network and Computer Applications, 2024, 223
  • [2] TridentShell: a Covert and Scalable Backdoor Injection Attack on Web Applications
    Yu, Xiaobo
    Meng, Weizhi
    Zhao, Lei
    Liu, Yining
    Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics), 2021, 13118 LNCS : 177 - 194
  • [3] TridentShell: A Covert and Scalable Backdoor Injection Attack on Web Applications
    Yu, Xiaobo
    Meng, Weizhi
    Zhao, Lei
    Liu, Yining
    INFORMATION SECURITY (ISC 2021), 2021, 13118 : 177 - 194
  • [4] Vulnerability & Attack Injection for Web Applications
    Fonseca, Jose
    Vieiraz, Marco
    Madeira, Henrique
    2009 IEEE/IFIP INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS & NETWORKS (DSN 2009), 2009, : 93 - +
  • [5] CSBA: Covert Semantic Backdoor Attack Against Intelligent Connected Vehicles
    Xu, Xiaodong
    Chen, Yue
    Wang, Bizhu
    Bian, Zhiqiang
    Han, Shujun
    Dong, Chen
    Sun, Chen
    Zhang, Wenqi
    Xu, Lexi
    Zhang, Ping
    IEEE TRANSACTIONS ON VEHICULAR TECHNOLOGY, 2024, 73 (11) : 17923 - 17928
  • [6] Link-Backdoor: Backdoor Attack on Link Prediction via Node Injection
    Zheng, Haibin
    Xiong, Haiyang
    Ma, Haonan
    Huang, Guohan
    Chen, Jinyin
    IEEE TRANSACTIONS ON COMPUTATIONAL SOCIAL SYSTEMS, 2024, 11 (02) : 1816 - 1831
  • [7] How to Prevent SQL Injection Attack Based on Web Applications
    Zheng Haiyan
    Wu Weituan
    Zhang Ruili
    PROCEEDINGS OF THE 2015 INTERNATIONAL CONFERENCE ON INDUSTRIAL TECHNOLOGY AND MANAGEMENT SCIENCE (ITMS 2015), 2015, 34 : 854 - 857
  • [8] Federated Learning Backdoor Attack Based on Frequency Domain Injection
    Liu, Jiawang
    Peng, Changgen
    Tan, Weijie
    Shi, Chenghui
    ENTROPY, 2024, 26 (02)
  • [9] 3DFed: Adaptive and Extensible Framework for Covert Backdoor Attack in Federated Learning
    Li, Haoyang
    Ye, Qingqing
    Hu, Haibo
    Li, Jin
    Wang, Leixia
    Fang, Chengfang
    Shi, Jie
    2023 IEEE SYMPOSIUM ON SECURITY AND PRIVACY, SP, 2023, : 1893 - 1907
  • [10] NoSQL Injection Attack Detection in Web Applications Using RESTful Service
    Eassa, Ahmed M.
    Elhoseny, Mohamed
    El-Bakry, Hazem M.
    Salama, Ahmed S.
    PROGRAMMING AND COMPUTER SOFTWARE, 2018, 44 (06) : 435 - 444