Unlock instant, AI-driven research and patent intelligence for your innovation.

Website security detection system and method combined with web automation and proxy interception

A security detection and automated testing technology, applied in transmission systems, electrical components, etc., can solve the problems of difficult development, time-consuming, and inability to meet the needs of website security detection, and achieve the effect of reducing detection difficulty and improving efficiency.

Active Publication Date: 2020-12-04
北京赛宁网安科技有限公司
View PDF6 Cites 0 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

The problem with the web automation testing method applied to website security detection is that it can only set the existing web page elements, and cannot add, delete, or modify the HTTP header content and HTTP message body content, and cannot secure the content of interest to the target website. detection
[0005] To sum up, for the website security detection problem of custom encryption and decryption algorithm, the existing technology has the following shortcomings that need to be further improved: 1. Adopt the proxy interception method, if it is not processed according to the custom encryption and decryption algorithm, it cannot pass the server authentication and cannot Perform security detection; if you process custom encryption and decryption algorithms, you need to customize and develop plug-ins, and usually the encryption and decryption algorithms are obfuscated, which has poor readability, is difficult to develop, and takes a lot of time. The detection cannot be completed in a short time
2. With the automated testing method, only the existing web page elements can be set, and the content of the HTTP header and the main body of the HTTP message cannot be added, deleted, or modified. need

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Website security detection system and method combined with web automation and proxy interception
  • Website security detection system and method combined with web automation and proxy interception

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0030] The technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only some of the embodiments of the present invention, not all of them. Based on the embodiments of the present invention, all other embodiments obtained by persons of ordinary skill in the art without making creative efforts fall within the protection scope of the present invention.

[0031] Such as figure 2 As shown, a website security detection system combining Web automation and proxy interception disclosed in the embodiment of the present invention is mainly composed of an automation script module, a Web automation test module and a proxy interception module. Among them, the automation script module mainly implements browser driver loading, webpage input element content loading through automation script, simulates user op...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

PUM

No PUM Login to View More

Abstract

The invention discloses a website security detection system and method combining Web automation and proxy interception. The system mainly comprises an automation script module, a Web automation test module and a proxy interception module. The automatic script module realizes browser driver loading, webpage input element content loading, user operation simulation and the like, wherein all or part of the webpage input elements adopt an encryption and decryption algorithm for user input content when the website transmits information; the Web automatic test module is used for analyzing the automatic script and realizing webpage request and response; and the proxy interception module is used for intercepting, modifying and forwarding the network data packet according to the processing rule, wherein the modification comprises adding, deleting and / or modifying HTTP header content and content irrelevant to an encryption and decryption algorithm in HTTP message main body content. The method canbe applied to website detection of the customized encryption and decryption algorithm, the detection difficulty is reduced, the efficiency is improved, and the authentication problem of the customized encryption and decryption algorithm can be solved in a short time.

Description

technical field [0001] The invention relates to a website security detection system and method combined with Web automation and proxy interception, belonging to the fields of network security and penetration testing. Background technique [0002] The common web security detection method adopts the method of proxy interception, such as figure 1 As shown, taking the Burp Suite tool as an example, Burp Suite intercepts all network traffic passing through the proxy, such as the client's request data and the server's return information. Burp Suite mainly intercepts the traffic of HTTP and HTTPS protocols. Through interception, Burp Suite can perform various processing on the data requested by the client and the return returned by the server in the way of a middleman, so as to achieve the purpose of security assessment and testing. For conventional websites, the proxy interception security detection method can meet the security detection requirements of the website. [0003] Whe...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

Application Information

Patent Timeline
no application Login to View More
Patent Type & Authority Patents(China)
IPC IPC(8): H04L29/06H04L29/08
CPCH04L63/0281H04L63/0428H04L63/1408H04L67/02
Inventor 孙勇谢峥朱先锋高庆官
Owner 北京赛宁网安科技有限公司