TridentShell: a Covert and Scalable Backdoor Injection Attack on Web Applications

Xiaobo Yu, Weizhi Meng, Lei Zhao, Yining Liu

Research output: Chapter in Book/Report/Conference proceedingArticle in proceedingsResearchpeer-review

Abstract

Web backdoor attack is a kind of popular network attack, which can cause a serious damage to websites. In practice, cyber attackers often exploit vulnerabilities in the system or web applications to implant a backdoor to a web server. To address this challenge, static feature detection is believed to be an effective solution. However, it may also leave a potential security “hole” that could be exploited by intruders. In this paper, we propose a novel backdoor attack method called TridentShell, which can inject a webshell into the memory of web application server without leaving attack traces. Our attack is able to bypass almost all types of static detection methods. In particular, it attempts to blend itself into the web server and erase attack traces automatically, instead of encrypting or obfuscating the content of webshell to avoid detection. Besides, TridentShell can still be executed even when the webmasters restrict the access to web directory. In the evaluation, we showcase how TridentShell can successfully inject a webshell into five different types of Java application servers (covering around 87% Java application servers in the market), and can remove the attack traces on the server (increasing the detection difficulty).

Original languageEnglish
Title of host publicationInternational Conference on Information Security
PublisherSpringer
Publication date2021
Pages177-194
ISBN (Print)978-3-030-91355-7
DOIs
Publication statusPublished - 2021
Event24th International Conference on Information Security - Grand Mirage Resort, Denpasar, Indonesia
Duration: 10 Nov 202112 Nov 2021

Conference

Conference24th International Conference on Information Security
LocationGrand Mirage Resort
Country/TerritoryIndonesia
CityDenpasar
Period10/11/202112/11/2021
SeriesLecture Notes in Computer Science
Volume13118
ISSN0302-9743

Keywords

  • Backdoor attack
  • Webshell
  • Web security
  • Java application
  • Static feature detection

Fingerprint

Dive into the research topics of 'TridentShell: a Covert and Scalable Backdoor Injection Attack on Web Applications'. Together they form a unique fingerprint.

Cite this