%A Van Giap Le %A Huu Tung Nguyen %A Duy Phuc Pham %A Ngoc Hoa Nguyen %J Transactions on Computational Collective Intelligence %T GuruWS: A Hybrid Platform for Detecting Malicious Web Shells and Web Application Vulnerabilities %X Web application/service is now omnipresent but its security risks, such as malware and vulnerabilities, are indeed underestimated. In this paper, we propose a protective, extensible and hybrid platform, named GuruWS, for automatically detecting both web application vulnerabilities and malicious web shells. Based on the original PHP vulnerability scanner THAPS, we propose E-THAPS which implements a novel detection mechanism, an improved SQL injection, Cross-site Scripting and vulnerability detection capabilities. For malicious web shell detection, taint analysis and pattern matching methods are chosen to be implemented in GuruWS. A number of extensive experiments are carried out to prove the outstanding performance of our proposed platform in comparison with several existing solutions in detecting either web application vulnerabilities or malicious web shells. %N XXXII %P 182-208 %V 11370 %D 2018 %I Springer %R 10.1007/978-3-662-58611-2_5 %L SisLab3375