Otomatisasi Deteksi Dan Mitigasi Webshell PHP Menggunakan Algoritma Random Forest
DOI:
https://doi.org/10.47065/bulletincsr.v6i5.1290Keywords:
Webshell; Random Forest; File Monitoring; PHP; Cyber SecurityAbstract
PHP webshells pose a serious threat to web-based applications, enabling attackers to gain unauthorized access and remotely control servers. Varied obfuscation techniques make these webshells difficult to detect using conventional keyword-based scanning. This research aims to develop a real-time PHP webshell detection and mitigation system based on File Integrity Monitoring (FIM) using the Random Forest algorithm. Feature extraction is derived from VLD opcode function calls (with a regex fallback), PHP variable frequency, webshell signatures, and statistical features (entropy and compression ratio). Processing efficiency is maintained through a streaming method for large files (? 5 MB) and a Watchdog-based FIM mechanism optimized with path filtering, event debouncing, and an asynchronous queue. The research contributes a hybrid feature extraction mechanism combining internal instruction indicators (opcodes) and statistical randomness metrics (entropy) to recognize complex obfuscation patterns and integrates a Random Forest classification model with an active FIM-based mitigation architecture capable of autonomous, automated response actions. Testing on 1,207 samples from a balanced dataset (20% test set) showed the Random Forest model achieving an overall accuracy of 97%. Specifically, the webshell class achieved 96% precision, 99% recall, and a 97% F1-score (555 True Positives and 29 False Negatives), while the normal class achieved 99% precision, 95% recall, and a 97% F1-score (616 True Negatives and 7 False Positives). The study is limited to monitoring PHP source code files, relies on a server environment with the VLD extension installed, and focuses mitigation actions on real-time file quarantine. Functional testing confirmed the system's ability to perform monitoring, classification, quarantine outside the web root, and Telegram Bot notifications automatically and in real-time.
Downloads
References
A. I. A. Azkiya and B. Santoso, “Indonesian Journal of Computer Science,” Indones. J. Comput. Sci., vol. 13, no. 1, pp. 1227–1240, 2023, [Online]. Available: http://ijcs.stmikindonesia.ac.id/ijcs/index.php/ijcs/article/view/3135
F. Arman, A. Wahyu Azinar, A. Senja Fitrani, and A. Eviyanti, “Implementasi Monitoring Dan Pencegahan Serangan Defacement Judi Online Menggunakan Wazuh,” JATI (Jurnal Mhs. Tek. Inform., vol. 10, no. 1, pp. 1309–1317, 2026, doi: 10.36040/jati.v10i1.16988.
A. Ikhwanudin, T. Toifur, A. Syamhalim, M. Yusuf, F. A. Yusri, and M. J. Ardiansyah, “Evaluasi Keamanan Fitur Unggah Berkas Pada Situs Web,” vol. 10, no. 2, pp. 2066–2072, 2026, doi: 10.36040/jati.v10i2.17273.
H. J. Lee, S. J. Hwang, M. Pratiwi, and Y. H. Choi, Obfuscated PHP Webshell Detection Using the Webshell Tailored TextRank Algorithm, vol. 1, no. 1. Association for Computing Machinery, 2024. doi: 10.1145/3605098.3635940.
M. Djamalyanto, L. Widyawati, Husain, and I. P. Hariyadi, “Implementasi Security Information And Event Management Untuk Untuk Mencegah Serangan Deface Pada Server Terintegrasi Telegram,” vol. 11, no. 1, pp. 31–42, 2025, doi: 10.30742/melekitjournal.v11i1.398.
T. Arya Saputra, S. Wahyu, M. Hadi Arfian, and N. Budi Santoso, “Implementation of IT Security Operations Management Application For Cyber Security Threat Monitoring,” JEPIN (Jurnal Edukasi dan Penelitian Informatika), vol. 12, no. 1, pp. 63–74, 2026, doi: 10.26418/jp.v12i1.105673.
R. Yuranda and E. S. Negara, “Application of Deep Learning Algorithm for Web Shell Detection in Web Application Security System,” J. Sisfokom (Sistem Inf. dan Komputer), vol. 13, no. 3, pp. 330–336, 2024, doi: 10.32736/sisfokom.v13i3.2234.
M. Firman Prayogi, A. Fahrudi Setiawan, and F. Xaverius Ariwibisono, “Perancangan Sistem Keamanan Web Menggunakan Metode Random Forest,” JATI (Jurnal Mhs. Tek. Inform., vol. 9, no. 6, pp. 10650–10657, 2025, doi: 10.36040/jati.v9i6.15457.
Z. Wang, H. Wang, S. Yuan, and Z. Tian, “Incremental learning research for webshell detection,” J. King Saud Univ. - Comput. Inf. Sci., vol. 37, no. 8, pp. 1–27, 2025, doi: 10.1007/s44443-025-00235-8.
Y. Zhao et al., “Malicious webshell family dataset for webshell multi-classification research,” Vis. Informatics, vol. 8, no. 1, pp. 47–55, 2024, doi: 10.1016/j.visinf.2023.06.008.
Y. , I. R. , Syamsul Bahri, “Analisa Log Web Server Untuk Mengetahui Pola Perilaku Pengunjung Website Menggunakan Teknik Regular Expressions,” Coding J. Komput. dan Apl., vol. 7, no. 01, pp. 120–130, 2019, doi: 10.26418/coding.v7i01.32692.
A. Hannousse and S. Yahiouche, “Multi-language Webshell dataset,” 2021, Mendeley Data: V2. doi: 10.17632/wt8m6bcwbr.2.
J. Caesario, Nofiyati, and D. K. Wibowo, “Identification and Classification of Cyber Attacks on ELDIRU UNSOED using Random Forest Algorithm,” J. Tek. Inform., vol. 6, no. 4, pp. 2785–2794, 2025, doi: 10.52436/1.jutif.2025.6.4.5239.
I. Siswanto et al., “Implementasi Algoritma Random Forest untuk Deteksi Serangan Siber pada Jaringan Komputer,” Siematic, vol. 1, no. 1, p. 2025. https://ejurnal.ibisa.ac.id/index.php/ji/article/view/439
L. Oriana, A. Dwi, S. Wati, A. P. Ramahdani, N. N. Safira, and E. Ismanto, “Peningkatan Kinerja Model Random Forest untuk Deteksi Kecurangan Kartu Kredit Menggunakan RandomizedSearchCV,” J. Fasilkom, vol. 15, no. 2, pp. 229–237, 2025, , doi: 10.37859/jf.v15i2.9832.
A. Kamil, D. Rizaludin, and A. T. Ni’mah, “Implementasi Wazuh FIM (File Integrity Monitoring) untuk Perlindungan Keamanan Sistem Informasi pada Unit Kegiatan Mahasiswa di Universitas Trunojoyo Madura,” Sains Data J. Stud. Mat. dan Teknol., vol. 2, no. 2, pp. 80–92, 2024, doi: 10.52620/sainsdata.v2i2.127.
G. A. Magapu, S. Sai, R. Kodandapuram, V. Ashok, and R. Tatiparthi, “Detect, React, Recover: A Hands-On Ransomware Defense System”, ResearchGate, 2025, doi: 10.13140/RG.2.2.36642.34242.
E. A. Winanto, Y. Novianto, S. Sharipuddin, I. S. Wijaya, and P. A. Jusia, “Peningkatan Performa Deteksi Serangan Menggunakan Metode Pca Dan Random Forest,” J. Teknol. Inf. dan Ilmu Komput., vol. 11, no. 2, pp. 285–290, 2024, doi: 10.25126/jtiik.20241127678.
Z. Alamin and Ritzkal, “Real-Time Phishing Detection Using Google Safe Browsing API and Machine Learning,” Journix J. Informatics Comput., vol. 1, no. 2, pp. 51–62, 2025, doi: 10.63866/journix.v1i2.8.
T. Meliana, J. Jemakmun, and S. Suryayusra, “Pelatihan Sistem Deteksi Intruksi Menggunakan Wazuh Berbasis Notifikasi Real-Time Telegram di Universitas Bina Darma,” J. Pengabdi. Masy. Bangsa, vol. 4, no. 4, pp. 1282–1289, 2026, doi: 10.59837/jpmba.v4i4.4413.
Bila bermanfaat silahkan share artikel ini
Berikan Komentar Anda terhadap artikel Otomatisasi Deteksi Dan Mitigasi Webshell PHP Menggunakan Algoritma Random Forest
ARTICLE HISTORY
How to Cite
Issue
Section
Copyright (c) 2026 Najib Khoirul Rizal, Wahyu Widodo

This work is licensed under a Creative Commons Attribution 4.0 International License.
Authors who publish with this journal agree to the following terms:
- Authors retain copyright and grant the journal right of first publication with the work simultaneously licensed under Creative Commons Attribution 4.0 International License that allows others to share the work with an acknowledgment of the work's authorship and initial publication in this journal.
- Authors are able to enter into separate, additional contractual arrangements for the non-exclusive distribution of the journal's published version of the work (e.g., post it to an institutional repository or publish it in a book), with an acknowledgment of its initial publication in this journal.
- Authors are permitted and encouraged to post their work online (e.g., in institutional repositories or on their website) prior to and during the submission process, as it can lead to productive exchanges, as well as earlier and greater citation of published work (Refer to The Effect of Open Access).













