Otomatisasi Deteksi Dan Mitigasi Webshell PHP Menggunakan Algoritma Random Forest


Authors

  • Najib Khoirul Rizal Sekolah Tinggi Manajemen Informatika dan Ilmu Komputer El Rahma Yogyakarta, Yogyakarta, Indonesia
  • Wahyu Widodo Sekolah Tinggi Manajemen Informatika dan Ilmu Komputer El Rahma Yogyakarta, Yogyakarta, Indonesia

DOI:

https://doi.org/10.47065/bulletincsr.v6i5.1290

Keywords:

Webshell; Random Forest; File Monitoring; PHP; Cyber Security

Abstract

PHP webshells pose a serious threat to web-based applications, enabling attackers to gain unauthorized access and remotely control servers. Varied obfuscation techniques make these webshells difficult to detect using conventional keyword-based scanning. This research aims to develop a real-time PHP webshell detection and mitigation system based on File Integrity Monitoring (FIM) using the Random Forest algorithm. Feature extraction is derived from VLD opcode function calls (with a regex fallback), PHP variable frequency, webshell signatures, and statistical features (entropy and compression ratio). Processing efficiency is maintained through a streaming method for large files (? 5 MB) and a Watchdog-based FIM mechanism optimized with path filtering, event debouncing, and an asynchronous queue. The research contributes a hybrid feature extraction mechanism combining internal instruction indicators (opcodes) and statistical randomness metrics (entropy) to recognize complex obfuscation patterns and integrates a Random Forest classification model with an active FIM-based mitigation architecture capable of autonomous, automated response actions. Testing on 1,207 samples from a balanced dataset (20% test set) showed the Random Forest model achieving an overall accuracy of 97%. Specifically, the webshell class achieved 96% precision, 99% recall, and a 97% F1-score (555 True Positives and 29 False Negatives), while the normal class achieved 99% precision, 95% recall, and a 97% F1-score (616 True Negatives and 7 False Positives). The study is limited to monitoring PHP source code files, relies on a server environment with the VLD extension installed, and focuses mitigation actions on real-time file quarantine. Functional testing confirmed the system's ability to perform monitoring, classification, quarantine outside the web root, and Telegram Bot notifications automatically and in real-time.

Downloads

Download data is not yet available.

References

A. I. A. Azkiya and B. Santoso, “Indonesian Journal of Computer Science,” Indones. J. Comput. Sci., vol. 13, no. 1, pp. 1227–1240, 2023, [Online]. Available: http://ijcs.stmikindonesia.ac.id/ijcs/index.php/ijcs/article/view/3135

F. Arman, A. Wahyu Azinar, A. Senja Fitrani, and A. Eviyanti, “Implementasi Monitoring Dan Pencegahan Serangan Defacement Judi Online Menggunakan Wazuh,” JATI (Jurnal Mhs. Tek. Inform., vol. 10, no. 1, pp. 1309–1317, 2026, doi: 10.36040/jati.v10i1.16988.

A. Ikhwanudin, T. Toifur, A. Syamhalim, M. Yusuf, F. A. Yusri, and M. J. Ardiansyah, “Evaluasi Keamanan Fitur Unggah Berkas Pada Situs Web,” vol. 10, no. 2, pp. 2066–2072, 2026, doi: 10.36040/jati.v10i2.17273.

H. J. Lee, S. J. Hwang, M. Pratiwi, and Y. H. Choi, Obfuscated PHP Webshell Detection Using the Webshell Tailored TextRank Algorithm, vol. 1, no. 1. Association for Computing Machinery, 2024. doi: 10.1145/3605098.3635940.

M. Djamalyanto, L. Widyawati, Husain, and I. P. Hariyadi, “Implementasi Security Information And Event Management Untuk Untuk Mencegah Serangan Deface Pada Server Terintegrasi Telegram,” vol. 11, no. 1, pp. 31–42, 2025, doi: 10.30742/melekitjournal.v11i1.398.

T. Arya Saputra, S. Wahyu, M. Hadi Arfian, and N. Budi Santoso, “Implementation of IT Security Operations Management Application For Cyber Security Threat Monitoring,” JEPIN (Jurnal Edukasi dan Penelitian Informatika), vol. 12, no. 1, pp. 63–74, 2026, doi: 10.26418/jp.v12i1.105673.

R. Yuranda and E. S. Negara, “Application of Deep Learning Algorithm for Web Shell Detection in Web Application Security System,” J. Sisfokom (Sistem Inf. dan Komputer), vol. 13, no. 3, pp. 330–336, 2024, doi: 10.32736/sisfokom.v13i3.2234.

M. Firman Prayogi, A. Fahrudi Setiawan, and F. Xaverius Ariwibisono, “Perancangan Sistem Keamanan Web Menggunakan Metode Random Forest,” JATI (Jurnal Mhs. Tek. Inform., vol. 9, no. 6, pp. 10650–10657, 2025, doi: 10.36040/jati.v9i6.15457.

Z. Wang, H. Wang, S. Yuan, and Z. Tian, “Incremental learning research for webshell detection,” J. King Saud Univ. - Comput. Inf. Sci., vol. 37, no. 8, pp. 1–27, 2025, doi: 10.1007/s44443-025-00235-8.

Y. Zhao et al., “Malicious webshell family dataset for webshell multi-classification research,” Vis. Informatics, vol. 8, no. 1, pp. 47–55, 2024, doi: 10.1016/j.visinf.2023.06.008.

Y. , I. R. , Syamsul Bahri, “Analisa Log Web Server Untuk Mengetahui Pola Perilaku Pengunjung Website Menggunakan Teknik Regular Expressions,” Coding J. Komput. dan Apl., vol. 7, no. 01, pp. 120–130, 2019, doi: 10.26418/coding.v7i01.32692.

A. Hannousse and S. Yahiouche, “Multi-language Webshell dataset,” 2021, Mendeley Data: V2. doi: 10.17632/wt8m6bcwbr.2.

J. Caesario, Nofiyati, and D. K. Wibowo, “Identification and Classification of Cyber Attacks on ELDIRU UNSOED using Random Forest Algorithm,” J. Tek. Inform., vol. 6, no. 4, pp. 2785–2794, 2025, doi: 10.52436/1.jutif.2025.6.4.5239.

I. Siswanto et al., “Implementasi Algoritma Random Forest untuk Deteksi Serangan Siber pada Jaringan Komputer,” Siematic, vol. 1, no. 1, p. 2025. https://ejurnal.ibisa.ac.id/index.php/ji/article/view/439

L. Oriana, A. Dwi, S. Wati, A. P. Ramahdani, N. N. Safira, and E. Ismanto, “Peningkatan Kinerja Model Random Forest untuk Deteksi Kecurangan Kartu Kredit Menggunakan RandomizedSearchCV,” J. Fasilkom, vol. 15, no. 2, pp. 229–237, 2025, , doi: 10.37859/jf.v15i2.9832.

A. Kamil, D. Rizaludin, and A. T. Ni’mah, “Implementasi Wazuh FIM (File Integrity Monitoring) untuk Perlindungan Keamanan Sistem Informasi pada Unit Kegiatan Mahasiswa di Universitas Trunojoyo Madura,” Sains Data J. Stud. Mat. dan Teknol., vol. 2, no. 2, pp. 80–92, 2024, doi: 10.52620/sainsdata.v2i2.127.

G. A. Magapu, S. Sai, R. Kodandapuram, V. Ashok, and R. Tatiparthi, “Detect, React, Recover: A Hands-On Ransomware Defense System”, ResearchGate, 2025, doi: 10.13140/RG.2.2.36642.34242.

E. A. Winanto, Y. Novianto, S. Sharipuddin, I. S. Wijaya, and P. A. Jusia, “Peningkatan Performa Deteksi Serangan Menggunakan Metode Pca Dan Random Forest,” J. Teknol. Inf. dan Ilmu Komput., vol. 11, no. 2, pp. 285–290, 2024, doi: 10.25126/jtiik.20241127678.

Z. Alamin and Ritzkal, “Real-Time Phishing Detection Using Google Safe Browsing API and Machine Learning,” Journix J. Informatics Comput., vol. 1, no. 2, pp. 51–62, 2025, doi: 10.63866/journix.v1i2.8.

T. Meliana, J. Jemakmun, and S. Suryayusra, “Pelatihan Sistem Deteksi Intruksi Menggunakan Wazuh Berbasis Notifikasi Real-Time Telegram di Universitas Bina Darma,” J. Pengabdi. Masy. Bangsa, vol. 4, no. 4, pp. 1282–1289, 2026, doi: 10.59837/jpmba.v4i4.4413.


Bila bermanfaat silahkan share artikel ini

Berikan Komentar Anda terhadap artikel Otomatisasi Deteksi Dan Mitigasi Webshell PHP Menggunakan Algoritma Random Forest

Dimensions Badge

ARTICLE HISTORY

Published: 2026-08-10

Abstract View: 0 times
PDF Download: 0 times

How to Cite

Rizal, N. K., & Widodo, W. (2026). Otomatisasi Deteksi Dan Mitigasi Webshell PHP Menggunakan Algoritma Random Forest . Bulletin of Computer Science Research, 6(5), 1978-1987. https://doi.org/10.47065/bulletincsr.v6i5.1290

Issue

Section

Articles