relation: https://eprints.uet.vnu.edu.vn/eprints/id/eprint/3375/ title: GuruWS: A Hybrid Platform for Detecting Malicious Web Shells and Web Application Vulnerabilities creator: Le, Van Giap creator: Nguyen, Huu Tung creator: Pham, Duy Phuc creator: Nguyen, Ngoc Hoa subject: Information Technology (IT) subject: Scopus-indexed journals subject: ISI-indexed journals description: Web application/service is now omnipresent but its security risks, such as malware and vulnerabilities, are indeed underestimated. In this paper, we propose a protective, extensible and hybrid platform, named GuruWS, for automatically detecting both web application vulnerabilities and malicious web shells. Based on the original PHP vulnerability scanner THAPS, we propose E-THAPS which implements a novel detection mechanism, an improved SQL injection, Cross-site Scripting and vulnerability detection capabilities. For malicious web shell detection, taint analysis and pattern matching methods are chosen to be implemented in GuruWS. A number of extensive experiments are carried out to prove the outstanding performance of our proposed platform in comparison with several existing solutions in detecting either web application vulnerabilities or malicious web shells. publisher: Springer date: 2018-12-19 type: Article type: NonPeerReviewed identifier: Le, Van Giap and Nguyen, Huu Tung and Pham, Duy Phuc and Nguyen, Ngoc Hoa (2018) GuruWS: A Hybrid Platform for Detecting Malicious Web Shells and Web Application Vulnerabilities. Transactions on Computational Collective Intelligence, 11370 (XXXII). pp. 182-208. ISSN 2190-9288 relation: https://link.springer.com/chapter/10.1007/978-3-662-58611-2_5 relation: 10.1007/978-3-662-58611-2_5