arXiv · 2502.19257
Poster: Long PHP webshell files detection based on sliding window attention
Abstract
Webshell is a type of backdoor, and web applications are widely exposed to webshell injection attacks. Therefore, it is important to study webshell detection techniques. In this study, we propose a webshell detection method. We first convert PHP source code to opcodes and then extract Opcode Double-Tuples (ODTs). Next, we combine CodeBert and FastText models for feature representation and classification. To address the challenge that deep learning methods have difficulty detecting long webshell files, we introduce a sliding window attention mechanism. This approach effectively captures malicious behavior within long files. Experimental results show that our method reaches high accuracy in webshell detection, solving the problem of traditional methods that struggle to address new webshell variants and anti-detection techniques.
Explore related subjects
Keep this discovery
Zhiqiang Wang, Haoyu Wang, Lu Hao. 2025-02-26. Poster: Long PHP webshell files detection based on sliding window attention. https://arxiv.org/abs/2502.19257
Cite the original work for its findings. Save a collection to share your selection of sources.