首页|期刊导航|实验科学与技术|Tomcat无文件Webshell攻击模型的设计与研究

Tomcat无文件Webshell攻击模型的设计与研究OA

Design and Research of a Fileless Webshell Attack Model for Tomcat

中文摘要英文摘要

随着 Web安全的领域不断扩展,Java语言在服务端的广泛应用导致了 Tomcat无文件 Webshell攻击手段的出现,这使得 Web安全的攻击面扩展到了整个 Web服务相关的框架和组件.该文深入分析了 Tomcat无文件 Webshell的攻击原理,提出了基于流量加密和汇点内置的流量检测规避模型.为了验证这些攻击手段绕过检测的有效性,设计了自动化利用工具,并通过实验验证了攻击原理的可行性以及流量监测规避模型的效果.这些研究成果不仅为防御技术提出了更高要求,也为后续的安全防护提供了重要的参考和借鉴.

As the field of web security continues to expand,the widespread use of the Java language on the server side has led to the emergence of Tomcat fileless WebShell attacks,extending the attack surface of web security to encompass the entire framework and components related to web services.This paper conducts an in-depth analysis of the attack principles of Tomcat fileless WebShell and proposes a traffic detection evasion model based on traffic encryption and built-in sink points.To validate the effectiveness of these attack methods in bypassing detection,an automated exploitation tool is designed,and experiments are conducted to verify the feasibility of the attack principles and the effectiveness of the traffic monitoring evasion model.These research findings not only raise the bar for defense techniques but also provide valuable insights and references for subsequent security protection efforts.

刘仁婷;郑雅洪;李晓冬;吴祖峰;阎玉丽

电子科技大学 信息中心,成都 611731电子科技大学 计算机科学与工程学院,成都 611731电子科技大学 信息中心,成都 611731电子科技大学 信息中心,成都 611731赛尔网络有限公司,北京 100094

信息技术与安全科学

无文件Webshell网络安全流量检测Web安全

fileless Webshellnetwork securitytraffic detectionWeb security

《实验科学与技术》 2026 (3)

1-11,11

四川省科技计划项目(2024YFHZ0213).

10.12179/1672-4550.20240461

评论