500 rub
Journal Highly available systems №3 for 2026 г.
Article in number:
The probability of a successful attack by a malicious actor under the operation of a web backdoor detection system
Type of article: scientific article
DOI: https://doi.org/10.18127/j20729472-202603-11
UDC: 004.056
Authors:

V.Е. Borovkov1, P.G. Klyucharev2

1, 2 Bauman Moscow State Technical University (Moscow, Russia)
1 vbscience@yandex.ru, 2 pk.iu8@yandex.ru

Abstract:

This paper addresses a critical issue in modern information security – countering web backdoors. The relevance of the topic is due to the widespread availability of web applications accessible from the outside, as well as the features of backdoors that make them an exceptionally dangerous tool for intruders. Web backdoors are a popular means of maintaining access for several reasons: their deployment often does not require administrator privileges; they are passive and do not initiate suspicious connections themselves, activating only upon an attacker's command, which complicates their detection by network security systems; furthermore, they are cross-platform and can be stealthily integrated into applications running on any operating system.

The core objective of the research is to create a mathematical framework for the quantitative assessment of risks associated with web backdoors. The authors aim to develop a model that calculates the probability of a successful attacker intrusion, taking into account the effectiveness of a Web Backdoor Detection System (WBDS).

The authors identify several techniques used by attackers to ensure persistence (maintaining access) via web backdoors: source code modification – injecting malicious code directly into web application files (e.g., PHP, ASPX); embedding in compiled code – placing a backdoor in already compiled components; embedding in the runtime environment – modification of web components-stack (web servers, interpreters, etc.); database integration – using database capabilities to host a backdoor; fileless backdoors – placing malicious code in the memory (RAM) of web processes.

As a countermeasure, a two-level modular architecture of the detection system is proposed, where the first-level modules detect web backdoors during the installation phase, and the second-level modules during its use.

The primary scientific contribution of the work is the developed probabilistic-time model. This model integrates parameters from the three key parties in a cyber conflict: the attacker (time required to prepare and execute an attack), the detection system (probability of detection, diagnosis time, and the interval between diagnostics for modules of each level), and the incident response team (mean time to analyze the threat and neutralize the backdoor). Using this model, one can determine whether an attacker will succeed in
executing their malicious actions before the defense mechanisms detect and eliminate the threat.

Practical calculations presented in the study clearly demonstrate that a balanced approach is essential for significantly reducing the probability of a successful attack. This approach must combine not only the technical excellence of security tools, ensuring minimal detection time, but also the high operational efficiency of the information security personnel, which minimizes the overall incident response time. Thus, the model serves as a valuable tool not only for the theoretical assessment of a system's vulnerability but also for the practical planning and optimization of security investments, helping to identify the weakest links in the security chain.

Pages: 126-139
For citation

Borovkov V.Е., Klyucharev P.G. The probability of a successful attack by a malicious actor under the operation of a web backdoor detection system // Highly Available Systems. 2026. V. 22. № 3. P. 126−139. DOI: https://doi.org/10.18127/j20729472-202603-11

References
  1. Gigauri I. Remote Working Concerns During The Covid-19 Pandemic. International Journal of Social Science and Economic Research. 2020. V. 5 (10). P. 2803–2818. DOI: 10.46609/IJSSER.2020.v05i10.005
  2. Haber M.J. Remote Access. Privileged Attack Vectors. 2020. P. 239–250. DOI: 10.1007/978-1-4842-5914-6_18
  3. Hannousse A., Yahiouche S. Handling webshell attacks: A systematic mapping and survey. Computers & Security. 2021. V. 108. DOI: 10.1016/j.cose.2021.102366
  4. Cost of a Data Breach. Report 2022. Key4Biz: sajt. 2022. URL: https://www.key4biz.it/wp-content/uploads/2022/07/Cost-of-a-Data-Breach-Full-Report-2022.pdf (data obrashheniya: 2.12.2024).
  5. MSIL Rewriting. Metalama: sajt. 2024. URL: https://metalama.net/alternatives/msil-rewriting (data obrashheniya: 3.02.2025).
  6. Znaj svoego vraga: sozdayom Node.js-be`kdor. Xabr: sajt. 2020. URL: https://habr.com/ru/companies/ruvds/articles/493706/ (data obrashheniya: 5.02.2024).
  7. Yu X., Meng W., Zhao L., Liu Y. TridentShell: a Covert and Scalable Backdoor Injection Attack on Web Applications. Lecture Notes in Computer Science. 2021. P. 1–18. DOI:10.1007/978-3-030-91356-4_10
  8. SolarWinds | Understanding & Detecting the SUPERNOVA Webshell Trojan. SentinelLABS: sajt. 2020. URL: https://www.sentinelone.com/labs/solarwinds-understanding-detecting-the-supernova-webshell-trojan/ (data obrashheniya: 13.04.2025).
  9. Kak zashhitit`sya ot «bestelesny`x» veb-shellov. Xabr: sajt. 2024. URL: https://habr.com/ru/companies/cyberok/articles/787320/ (data obrashheniya: 13.04.2025).
  10. Pashkov N.N., Drozd V.G. Analiz riskov informacionnoj bezopasnosti i ocenka e`ffektivnosti sistem zashhity` informacii na predpriyatii. Sovremenny`e nauchny`e issledovaniya i innovacii. 2020. № 1 [E`lektronny`j resurs]. URL: https://web.snauka.ru/issues/2020/01/90380 (data obrashheniya: 12.11.2024). (in Russian).
  11. Fadeeva L.N., Lebedev A.V. Teoriya veroyatnostej i matematicheskaya statistika: Uchebnoe posobie. M.: E`KSMO. 2010. 496 s. (in Russian).
  12. Vetcel` E.S., Ovcharov L.A. Teoriya veroyatnostej i ee inzhenerny`e prilozheniya. M.: Vy`sshaya shkola. 2000. 480 s. (in Russian).
  13. Nistratov A.A. Metodika prognozirovaniya texnogenny`x riskov i ee realizaciya s ispol`zovaniem internet-texnologii: diss. kand. texn. nauk: 05.13.17. M., 2013. 150 s. (in Russian).
  14. Yazov Yu.K., Avsent`ev O.S., Avsent`ev A.O., Rubczova I.O. Metod ocenivaniya e`ffektivnosti zashhity` e`lektronnogo dokumentooborota s primeneniem apparata setej Petri – Markova. Informatika i avtomatizaciya (Trudy` SPIIRAN). 2019. № 18(6). S. 1269–1299. DOI: 10.15622/sp.2019.18.6.1269-1300 (in Russian).
  15. Manojlo A.V., Kostogry`zov A.I. O veroyatnostnom prognozirovanii riskov v informacionnoj vojne. Chast` 1. Analiz strategij operacij i kontroperacij dlya matematicheskogo modelirovaniya. Voprosy` kiberbezopasnosti. 2023. № 6(58). S. 2–19. DOI: 10.21681/2311-3456-2023-6-2-19 (in Russian).
  16. Manojlo A.V., Kostogry`zov A.I. O veroyatnostnom prognozirovanii riskov v informacionnoj vojne. Chast` 2. Model`, metody`, primery`. Voprosy` kiberbezopasnosti. 2024. № 1(59). S. 45–60. DOI: 10.21681/2311-3456-2024-1-45-60 (in Russian).
  17. GOST R 59341-2021. Sistemnaya inzheneriya. Zashhita informacii v processe upravleniya informaciej sistemy`. M.: Standartinform. 2021. (in Russian).
  18. Metodicheskie rekomendacii po razrabotke plana reagirovaniya na komp`yuterny`e incidenty` i prinyatiya mer po likvidacii posledstvij komp`yuterny`x atak, provedenny`x v otnoshenii znachimy`x ob``ektov kriticheskoj informacionnoj infrastruktury` Rossijskoj Fede­racii. 2024. [E`lektronny`j resurs]. URL: https://www.mos.ru/dit/documents/informatcionnaia-bezopasnost/view/293497220/ (data obrashheniya: 12.11.2024) (in Russian).
  19. Borovkov V.E., Klyucharev P.G., Denisenko D.I. Metodika ocenivaniya rezul`tativnosti funkcionirovaniya sistem obnaruzheniya veb-be`kdorov. Informatika i avtomatizaciya. 2025. № 24 (1). S. 125–162. DOI 10.15622/ia.24.1.6 (in Russian).
Date of receipt: 03.02.2026
Approved after review: 02.04.2026
Accepted for publication: 31.08.2026