Flow chart-based method for automatically detecting logic loopholes of electronic commerce websites

An e-commerce website, automatic detection technology, applied in business, electronic digital data processing, software testing/debugging, etc., can solve problems such as low efficiency, insufficient accuracy of automatic crawling pages, etc., to improve accuracy and solve missed loopholes Types of questions, effects of ensuring accuracy

Inactive Publication Date: 2016-01-27
SHANDONG UNIV +1
View PDF4 Cites 11 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

[0005] In order to solve the above problems, the present invention proposes a method for automatically detecting logic loopholes in e-commerce websites based on flow charts. This method generates flow charts through the traces of users using e-commerce sites, and uses the flow charts as the basic basis for the automatic detection process. On the basis of the flow chart, the crawler is used to expand, which solves the problem of insufficient accuracy and low efficiency of the traditional automatic crawling page

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Flow chart-based method for automatically detecting logic loopholes of electronic commerce websites
  • Flow chart-based method for automatically detecting logic loopholes of electronic commerce websites
  • Flow chart-based method for automatically detecting logic loopholes of electronic commerce websites

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0035] The present invention will be further described below in conjunction with the accompanying drawings and embodiments.

[0036] Such as figure 1 Shown is a system structure diagram of the present invention.

[0037] The trace collection and flow chart generation part of the system uses BurpSuite combined with its extension as a proxy, and the BurpSuite proxy interface is called in the extension to obtain the user's operation trace on the e-commerce website, analyze the parameters and cookies information and extract the url, parameters and cookies Information, structured as a trace.txt file for forming a flowchart. Therefore, the complexity of trace collection is O(1); the flowchart generation part reads the generated trace.txt file, filters out irrelevant content and stores its structured content into nodes, so the complexity is O(n).

[0038] Among them, the BurpSuite extension plug-in implementation steps are as follows:

[0039] Input: http request messages[] captur...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

PUM

No PUM Login to view more

Abstract

The invention discloses a flow chart-based method for automatically detecting logic loopholes of electronic commerce websites. The method comprises the following steps: collecting the traces of a user using an electronic commerce website through an agency and structuring the traces into a flow chart; expanding the existing flow chart, seeking the undiscovered electronic commerce flows and integrating the undiscovered electronic commerce flows into the existing flow chart; and analyzing the expanded flow chart, recognizing the functions, embodied in the flow chart, of the electronic commerce website, carrying out logic loophole detection on the electronic commerce website by using a generated test example so as to generate a test result, calculating the similarity between the a page returned by the test and a page returned by the input flow chart, and comparing the similarity with a threshold to determine whether corresponding loopholes exist or not. According to the flow chart-based method for automatically detecting logic loopholes of electronic commerce websites, the problems that the traditional alogical loophole detection tools are low in crawler crawling efficiency and the operation of covering all the test parameters requires plenty of time are solved, so that the method is more suitable for the comprehensive detection of the logic loopholes of the electronic commerce websites.

Description

technical field [0001] The invention relates to a method for automatically detecting logic loopholes in an e-commerce website based on a flowchart. Background technique [0002] The current method of detecting logic loopholes in e-commerce websites is traditional manual detection. The method is proposed based on the defects exposed in the process of traditional manual analysis of logic vulnerabilities of e-commerce websites: [0003] (1) At present, traditional e-commerce website logic vulnerability detection can only be done manually, and manual detection usually relies on agents intercepting request-response pairs between e-commerce websites and shoppers and modifying the parameters. Due to the large number of parameters in the shopping process, it is very easy to miss the test parameters and cause false positives. Since most logic vulnerabilities need to keep a single variable of the tested parameter in the detection process (otherwise, even if an error is detected, it ...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

Application Information

Patent Timeline
no application Login to view more
Patent Type & Authority Applications(China)
IPC IPC(8): G06F11/36G06F17/30G06Q30/00
Inventor 郭山清杨浩鹏周睿刘士军许信顺崔立真张燕
Owner SHANDONG UNIV
Who we serve
  • R&D Engineer
  • R&D Manager
  • IP Professional
Why Eureka
  • Industry Leading Data Capabilities
  • Powerful AI technology
  • Patent DNA Extraction
Social media
Try Eureka
PatSnap group products