发明名称 APPARATUS AND METHOD FOR DETECTING WEBSHELL IN REAL TIME USING KERNEL-BASED FILE EVENT NOTIFICATION FUNCTION
摘要 The present invention relates to a web-shell direction technology, and more specifically, to a device for detecting a web-shell on a real-time basis by using a kernel-based file event inspection function and a method thereof. The device includes: a web page inspection module which inspects the status of an inspection target file and a backup file in a web page to inspect whether the web page is forged; a kernel-based collection and analysis module which uses the file event inspection function in a kernel mode to collect the file event information generated with respect to files in the directory of the web page on a real-time basis and inspects whether the files in the directory are forged by referencing the collected file event information; a web-shell inspection module which inspects whether the forged file is a web-shell file by using the forgery inspection result generated by the kernel-based collection and analysis module and the forgery inspection result of the web page inspection module; and an inspection corresponding module which notifies the web-shell file inspection result generated by the web-shell file inspection module and collects the content corresponding thereto.
申请公布号 KR20160003584(A) 申请公布日期 2016.01.11
申请号 KR20150176770 申请日期 2015.12.11
申请人 WINS CO., LTD. 发明人 HAN, CHEOL KYU
分类号 G06F21/55;G06F21/57;G06F21/64 主分类号 G06F21/55
代理机构 代理人
主权项
地址