Improving Convolutional Neural Network-Based Webshell Detection Through Reinforcement Learning

被引:4
|
作者
Wu, Yalun [1 ]
Song, Minglu [1 ]
Li, Yike [1 ]
Tian, Yunzhe [1 ]
Tong, Endong [1 ]
Niu, Wenjia [1 ]
Jia, Bowei [1 ]
Huang, Haixiang [1 ]
Li, Qiong [1 ]
Liu, Jiqiang [1 ]
机构
[1] Beijing Jiaotong Univ, Beijing Key Lab Secur & Privacy Intelligent Trans, Beijing 100044, Peoples R China
来源
INFORMATION AND COMMUNICATIONS SECURITY (ICICS 2021), PT I | 2021年 / 12918卷
基金
中国国家自然科学基金; 国家重点研发计划;
关键词
Webshell detection; Feature selection; Unexpected behavior feature; Reinforcement learning; Convolutional neural network;
D O I
10.1007/978-3-030-86890-1_21
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Webshell detection is highly important for network security protection. Conventional methods are based on keywords matching, which heavily relies on experiences of domain experts when facing emerging malicious webshells of various kinds. Recently, machine learning, especially supervised learning, is introduced for webshell detection and has proved to be a great success. As one of state-of-the-art work, neural network (NN) is designed to input a large number of features and enable deep learning. Thus, how to properly combine the advantages of automatic feature selection and the advantages of expert knowledge-based way has become a key issue. Considering that special features to indicate unexpected webshell behaviors for a target business system are usually simple but effective, in this work, we propose a novel approach for improving webshell detection based on convolutional neural network (CNN) through reinforcement learning. We utilize the reinforcement learning of asynchronous advantage actor-critic (A3C) for automatic feature selection, aiming to maximize the expected accuracy of the CNN classifier on a validation dataset by sequentially interacting with the feature space. Moreover, considering the sparseness of feature values, we build the CNN classifier with two convolutional layers and a global pooling. Extensive experiments and analysis have been conducted to demonstrate the effectiveness of our proposed method.
引用
收藏
页码:368 / 383
页数:16
相关论文
共 50 条
  • [1] Automatic and Accurate Detection of Webshell Based on Convolutional Neural Network
    Lv, Zhuo-Hang
    Yan, Han-Bing
    Mei, Rui
    CYBER SECURITY, CNCERT 2018, 2019, 970 : 73 - 85
  • [2] Convolutional neural network-based surgical instrument detection
    Cai, Tongbiao
    Zhao, Zijian
    TECHNOLOGY AND HEALTH CARE, 2020, 28 : S81 - S88
  • [3] CNN-Webshell: Malicious Web Shell Detection with Convolutional Neural Network
    Tian, Yifan
    Wang, Jiabao
    Zhou, Zhenji
    Zhou, Shengli
    PROCEEDINGS OF 2017 VI INTERNATIONAL CONFERENCE ON NETWORK, COMMUNICATION AND COMPUTING (ICNCC 2017), 2017, : 75 - 79
  • [4] A convolutional neural network-based flame detection method in video sequence
    Zhen Zhong
    Minjuan Wang
    Yukun Shi
    Wanlin Gao
    Signal, Image and Video Processing, 2018, 12 : 1619 - 1627
  • [5] A convolutional neural network-based flame detection method in video sequence
    Zhong, Zhen
    Wang, Minjuan
    Shi, Yukun
    Gao, Wanlin
    SIGNAL IMAGE AND VIDEO PROCESSING, 2018, 12 (08) : 1619 - 1627
  • [6] Internal multiple suppression with convolutional neural network-based transfer learning
    Liu, Xiaozhou
    Hu, Tianyue
    Liu, Tao
    Wei, Zhefeng
    Xiao, Yanjun
    Xie, Fei
    Duan, Wensheng
    Cui, Yongfu
    Peng, Gengxin
    JOURNAL OF GEOPHYSICS AND ENGINEERING, 2023, 20 (01) : 145 - 158
  • [7] A Convolutional Neural Network-Based Method for Small Traffic Sign Detection
    Zhou S.
    Zhi X.
    Liu D.
    Ning H.
    Jiang L.
    Shi F.
    Tongji Daxue Xuebao/Journal of Tongji University, 2019, 47 (11): : 1626 - 1632
  • [8] A Convolutional Neural Network-based Approach For Image Analysis and Injection Detection
    Titouna, Chafiq
    Nait-Abdesselam, Farid
    2024 IEEE INTERNATIONAL CONFERENCE ON ADVANCED VIDEO AND SIGNAL BASED SURVEILLANCE, AVSS 2024, 2024,
  • [9] Convolutional neural network-based damage detection method for building structures
    Oh, Byung Kwan
    Glisic, Branko
    Park, Hyo Seon
    SMART STRUCTURES AND SYSTEMS, 2021, 27 (06) : 903 - 916
  • [10] Accelerating convolutional neural network-based malware traffic detection through ant-colony clustering
    Huang, He
    Deng, Haojiang
    Sheng, Yiqiang
    Ye, Xiaozhou
    JOURNAL OF INTELLIGENT & FUZZY SYSTEMS, 2019, 37 (01) : 409 - 423