Web application vulnerability detection method, device and computer-readable storage medium
By loading vulnerability detection probes in web containers, information is obtained from multiple heterogeneous vulnerability information sources, the problem of insufficient comprehensiveness, timeliness and accuracy of vulnerability detection in the existing technology is solved, and real-time, comprehensive and accurate vulnerability detection of web applications is achieved.
Patent Information
- Application Number
- CN202111123173.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-09-24
- Publication Date
- 2025-08-19
- Estimated Expiration
- 2041-09-24
AI Technical Summary
The existing web application vulnerability detection methods based on RASP technology are insufficient in terms of comprehensiveness, timeliness and accuracy, and cannot penetrate into the code level and have a single source of vulnerability information.
Load vulnerability detection probes in the web container, obtain security vulnerability information from various heterogeneous vulnerability information sources such as CVE, CNNVD, the first vulnerability library, the second vulnerability library and the third vulnerability library, and judge whether there are vulnerabilities in the web application to be tested based on this information.
Through the comprehensive utilization of multi-source heterogeneous vulnerability information, the comprehensiveness, accuracy and timeliness of vulnerability detection are improved, and vulnerabilities can be detected in real time during the operation of web applications.
Smart Images

Figure CN114021051B_ABST
Abstract
Description
Technical field
[0001] The present application relates to the field of computer technology, and in particular to a web application vulnerability detection method, device, and computer-readable storage medium. [Background Technology]
[0002] In related technologies, vulnerability detection for web applications is typically implemented using a single security testing technique, such as DAST (Dynamic Application Security Testing), SAST (Static Application Security Testing), and IAST (Interactive Application Security Testing). These security testing techniques can only be used during the testing and development phases of web applications and cannot provide real-time protection for web applications in production. Furthermore, similar to SAST, they require the web application's source code, which poses a significant risk of privacy breaches (such as intellectual property).
[0003] To address this, RASP (Runtime Application Self-Protection) technology has been introduced to web application vulnerability detection. Currently, vulnerability detection methods based on RASP technology typically combine rule matching with hardware-based WAF (Web Application Firewall). While these methods analyze network traffic, they don't delve deeply into the web application's code level. Furthermore, the source of vulnerability information is relatively limited, resulting in less comprehensive, timely, and accurate web application vulnerability detection.
[0004] Therefore, it is necessary to improve the above vulnerability detection method based on RASP technology. [Summary of the invention]
[0005] The present application provides a web application vulnerability detection method, device, and computer-readable storage medium, aiming to solve the problem of low comprehensiveness, timeliness, and accuracy in vulnerability detection of web applications in related technologies.
[0006] In order to solve the above technical problems, the first aspect of the embodiments of the present application provides a vulnerability detection method for a web application, comprising:
[0007] Load vulnerability detection probes in the web container;
[0008] By using the vulnerability detection probe, a plurality of security vulnerability information with heterogeneity between each other is obtained from a plurality of vulnerability information sources;
[0009] According to the security vulnerability information, it is determined whether the web application to be tested has a security vulnerability.
[0010] A second aspect of an embodiment of the present application provides a vulnerability detection device for a web application, comprising: a storage device and one or more processors; the storage device is used to store one or more programs, wherein, when one or more of the programs are executed by one or more of the processors, the one or more processors execute the vulnerability detection method for a web application as described in the first aspect of the embodiment of the present application.
[0011] A third aspect of the embodiments of the present application provides a computer-readable storage medium having executable instructions stored thereon. When the executable instructions are executed, the vulnerability detection method for a web application as described in the first aspect of the embodiments of the present application is executed.
[0012] From the above description, it can be seen that compared with the related art, the beneficial effects of this application are:
[0013] First, security vulnerability information is obtained from a variety of vulnerability information sources, wherein the security vulnerability information includes multiple security vulnerability information, and the multiple security vulnerability information has heterogeneity; then, based on the security vulnerability information, it is judged whether the web application to be tested has security vulnerabilities. It can be seen that the security vulnerability information used in this application comes from a variety of vulnerability information sources, which makes the security vulnerability information used more comprehensive, thereby effectively improving the comprehensiveness of vulnerability detection for the web application to be tested; the multiple security vulnerability information used in this application has heterogeneity, that is, there are large differences between the multiple security vulnerability information used, and they do not completely belong to the same category of security vulnerabilities, thereby effectively improving the accuracy of vulnerability detection for the web application to be tested. In addition, when this application is implemented based on RASP technology, it can be used to use the vulnerability detection probe preset in the web container of the web application to be tested to judge whether the web application to be tested has security vulnerabilities in real time based on the security vulnerability information during the operation of the web application to be tested, thereby effectively improving the timeliness of vulnerability detection for the web application to be tested.
Brief Description of the Drawings
[0014] In order to more clearly illustrate the relevant technologies or the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required for use in the description of the relevant technologies or the embodiments of the present application. Obviously, the drawings described below are only some embodiments of the present application, not all embodiments. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0015] Figure 1 A flowchart of a web application vulnerability detection method provided in an embodiment of the present application;
[0016] Figure 2 Provided in the embodiments of this application Figure 1 A first flow chart of step 103;
[0017] Figure 3 Provided in the embodiments of this application Figure 1 A second flow chart of step 103;
[0018] Figure 4 Provided in the embodiments of this application Figure 1 A third flow diagram of step 103;
[0019] Figure 5 Provided in the embodiments of this application Figure 1 A fourth flow chart of step 103;
[0020] Figure 6 A module block diagram of a web application vulnerability detection device provided in an embodiment of the present application;
[0021] Figure 7 A module block diagram of a computer-readable storage medium provided in an embodiment of the present application. [Specific implementation method]
[0022] In order to make the purpose, technical solutions and advantages of the present application more obvious and easy to understand, the present application will be clearly and completely described below in conjunction with the embodiments of the present application and the corresponding drawings, wherein the same or similar reference numerals throughout represent the same or similar elements or elements with the same or similar functions. It should be understood that the various embodiments of the present application described below are merely used to explain the present application and are not used to limit the present application. That is, based on the various embodiments of the present application, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of this application. In addition, the technical features involved in the various embodiments of the present application described below can be combined with each other as long as they do not conflict with each other.
[0023] In related technologies, vulnerability detection methods based on RASP technology typically combine WAF rule matching with hardware. These methods analyze network traffic but do not delve deeply into the code level of web applications. Furthermore, the source of vulnerability information is relatively limited, resulting in low comprehensiveness, timeliness, and accuracy in vulnerability detection for web applications. Therefore, embodiments of the present application provide a vulnerability detection method for web applications.
[0024] See also Figure 1 , Figure 1 A flow chart of a vulnerability detection method for a web application provided in an embodiment of the present application. Figure 1 As can be seen from the figure, the web application vulnerability detection method provided in the embodiment of the present application includes the following steps 101 to 103.
[0025] Step 101: Load a vulnerability detection probe into a web container.
[0026] In this embodiment of the application, a vulnerability detection probe must first be loaded into the web container of the web application to be tested. Specifically, this embodiment of the application is implemented based on RASP technology; in this case, the loaded vulnerability detection probe is a RASP probe, and technicians can use the loaded RASP probe to understand the running status of the web application to be tested in real time.
[0027] Step 102: Using vulnerability detection probes, obtain multiple security vulnerability information that are heterogeneous from multiple vulnerability information sources.
[0028] In the embodiment of the present application, after the vulnerability detection probe is loaded, security vulnerability information needs to be obtained from multiple vulnerability information sources. It is understandable that, because there are multiple vulnerability information sources, the obtained security vulnerability information includes multiple items; moreover, the multiple security vulnerability information items do not belong to the same category of security vulnerabilities, that is, there are significant differences between the multiple security vulnerability information items, or in other words, the multiple security vulnerability information items have heterogeneity.
[0029] As an implementation method, the vulnerability information source may include the CVE (Common Vulnerabilities & Exposures) vulnerability library and the CNNVD vulnerability library (China National Vulnerability Database of Information Security). In this case, it is necessary to obtain the corresponding security vulnerability information from the CVE vulnerability library and the CNNVD vulnerability library respectively. Of course, it is not limited to this. In other implementation methods, the vulnerability information source may also include a first vulnerability library, a second vulnerability library, and a third vulnerability library; wherein the first vulnerability library is a collection of security vulnerabilities detected when vulnerability detection is performed on a web application using IAST technology; the second vulnerability library is a collection of security vulnerabilities detected when vulnerability detection is performed on a web application using SAST technology; and the third vulnerability library is a collection of security vulnerabilities detected when vulnerability detection is performed on a web application using DAST technology. In this case, it is necessary to obtain the corresponding security vulnerability information from the CVE vulnerability library, the CNNVD vulnerability library, the first vulnerability library, the second vulnerability library, and the third vulnerability library respectively.
[0030] In this embodiment, since the CVE vulnerability library, CNNVD vulnerability library, first vulnerability library, second vulnerability library, and third vulnerability library belong to different categories of vulnerability libraries, there are significant differences between the multiple security vulnerability information obtained, that is, the multiple security vulnerability information has heterogeneity. In actual applications, technicians can select at least two vulnerability libraries from the above multiple categories of vulnerability libraries as the vulnerability information source for this application.
[0031] As an implementation method, when new security vulnerability information appears in multiple vulnerability information sources, the obtained security vulnerability information can be updated in real time. That is, when new security vulnerability information appears in multiple vulnerability information sources, the new security vulnerability information is obtained from multiple vulnerability information sources, thereby ensuring the comprehensiveness of the obtained security vulnerability information in real time.
[0032] It should be understood that the above-mentioned implementation mode is only a preferred implementation of the embodiment of the present application, and is not the only limitation of the embodiment of the present application on the number and type of vulnerability information sources, and the updating method of the obtained security vulnerability information; in this regard, those skilled in the art can flexibly set it according to the actual application scenario based on the embodiment of the present application.
[0033] Step 103: Determine whether the web application to be tested has a security vulnerability based on the security vulnerability information.
[0034] In the embodiment of the present application, after obtaining security vulnerability information from multiple vulnerability information sources, it is necessary to perform vulnerability detection on the web application to be tested based on the obtained security vulnerability information to determine whether the web application to be tested has security vulnerabilities.
[0035] As an implementation method, please refer to Figure 2 , Figure 2 Provided in the embodiments of this application Figure 1 The first flow chart of step 103; Figure 2 As can be seen from FIG, step 103 may specifically include the following steps:
[0036] Step 1031: Obtain the information flow in the web application to be tested.
[0037] In this embodiment, when determining whether a web application to be tested has a security vulnerability based on the security vulnerability information, it is necessary to first obtain the information flow in the web application to be tested; wherein the obtained information flow is used to combine with the obtained security vulnerability information to determine whether the web application to be tested has a security vulnerability.
[0038] Step 1032: Compare the multiple security vulnerability information with the information flow respectively to obtain a first comparison result.
[0039] In this embodiment, after obtaining the information flow in the web application to be tested, it is necessary to compare the obtained multiple security vulnerability information with the obtained information flow respectively and obtain a first comparison result; wherein the first comparison result is used to determine whether the web application to be tested has a security vulnerability.
[0040] Step 1033: Determine whether the web application to be tested has a security vulnerability based on the first comparison result.
[0041] If the first comparison result is that at least one of the multiple security vulnerability information is consistent with the information flow, it is confirmed that the web application to be tested has a security vulnerability.
[0042] In this embodiment, after obtaining the first comparison result, it is possible to determine whether the web application under test has a security vulnerability based on the first comparison result. Specifically, when the first comparison result indicates that at least one of the multiple pieces of security vulnerability information obtained is consistent with the obtained information flow, it is confirmed that the web application under test has a security vulnerability. It will be understood that the consistency of at least one piece of the multiple pieces of security vulnerability information obtained with the obtained information flow indicates that a corresponding security vulnerability exists in the obtained information flow, i.e., that a corresponding security vulnerability exists in the web application under test.
[0043] As another implementation, please refer to Figure 3 , Figure 3 Provided in the embodiments of this application Figure 1 The second flow diagram of step 103; Figure 3 As can be seen from the figure, step 103 may specifically include the following steps:
[0044] Step 1031: Obtain the information flow in the web application to be tested.
[0045] In this embodiment, when determining whether a web application to be tested has a security vulnerability based on the security vulnerability information, it is necessary to first obtain the information flow in the web application to be tested; wherein the obtained information flow is used to combine with the obtained security vulnerability information to determine whether the web application to be tested has a security vulnerability.
[0046] Step 1032: Compare the multiple security vulnerability information with the information flow respectively to obtain a first comparison result.
[0047] In this embodiment, after obtaining the information flow in the web application to be tested, it is necessary to compare the obtained multiple security vulnerability information with the obtained information flow respectively and obtain a first comparison result; wherein the first comparison result is used to determine whether the web application to be tested has a security vulnerability.
[0048] Step 1033: Determine whether the web application to be tested has a security vulnerability based on the first comparison result.
[0049] If the first comparison result is that at least one of the multiple security vulnerability information is consistent with the information flow, it is confirmed that the web application to be tested has a security vulnerability.
[0050] In this embodiment, after obtaining the first comparison result, it is possible to determine whether the web application under test has a security vulnerability based on the first comparison result. Specifically, when the first comparison result indicates that at least one of the multiple pieces of security vulnerability information obtained is consistent with the obtained information flow, it is confirmed that the web application under test has a security vulnerability. It will be understood that the consistency of at least one piece of the multiple pieces of security vulnerability information obtained with the obtained information flow indicates that a corresponding security vulnerability exists in the obtained information flow, i.e., that a corresponding security vulnerability exists in the web application under test.
[0051] Step 1034: If the first comparison result shows that the multiple security vulnerability information are inconsistent with the information flow, the multiple security vulnerability information are randomly combined to obtain multiple random security vulnerability information.
[0052] In this embodiment, when determining whether a web application under test has a security vulnerability based on a first comparison result, if the first comparison result indicates that none of the multiple acquired security vulnerability information is consistent with the acquired information flow, then this indicates that the corresponding security vulnerability does not exist in the acquired information flow, i.e., the web application under test does not have a corresponding security vulnerability. However, during actual operation of the web application under test, if its information flow includes a security vulnerability, the included security vulnerability may not necessarily be a single security vulnerability but may also be a combination and / or variation of multiple security vulnerabilities. Therefore, in this embodiment, when the first comparison result indicates that none of the multiple acquired security vulnerability information is consistent with the acquired information flow, the multiple acquired security vulnerability information may also be randomly combined to obtain multiple random security vulnerability information; wherein the obtained multiple random security vulnerability information is used to compare with the acquired information flow to determine whether the web application under test has a security vulnerability. For example, the multiple security vulnerability information obtained can be randomly combined first, and then the security vulnerability information after each combination can be mutated to a certain extent to obtain multiple random security vulnerability information; or, the multiple security vulnerability information obtained can be mutated to a certain extent first, and then the security vulnerability information after each mutation can be randomly combined to obtain multiple random security vulnerability information.
[0053] Of course, this is not limited to this. In other implementations, the multiple security vulnerability information obtained may be randomly combined to obtain multiple random security vulnerability information; or, the multiple security vulnerability information obtained may be mutated to a certain extent to obtain multiple random security vulnerability information.
[0054] Step 1035: Compare the multiple random security vulnerability information with the information flow respectively to obtain a second comparison result.
[0055] In this embodiment, after obtaining multiple random security vulnerability information, it is necessary to compare the multiple random security vulnerability information with the obtained information flow respectively and obtain a second comparison result; wherein the second comparison result is used to determine whether the web application to be tested has a security vulnerability.
[0056] Step 1036: Determine whether the web application to be tested has a security vulnerability based on the second comparison result.
[0057] If the second comparison result is that at least one of the multiple random security vulnerability information is consistent with the information flow, it is confirmed that the web application to be tested has a security vulnerability.
[0058] In this embodiment, after obtaining the second comparison result, it can be determined whether the web application under test has a security vulnerability based on the second comparison result. Specifically, when the second comparison result indicates that at least one of the plurality of random security vulnerability information obtained is consistent with the acquired information flow, it is confirmed that the web application under test has a security vulnerability. It will be understood that the consistency of at least one of the plurality of random security vulnerability information obtained with the acquired information flow indicates that a corresponding random security vulnerability exists in the acquired information flow, i.e., that the web application under test has a corresponding random security vulnerability.
[0059] In this embodiment, when the first comparison result indicates that the multiple acquired security vulnerability information is inconsistent with the acquired information flow, the multiple acquired security vulnerability information is randomly combined to obtain multiple random security vulnerability information. Based on the second comparison result between the acquired information flow and the multiple random security vulnerability information, it is determined whether the web application under test has a security vulnerability. This shows that this embodiment performs vulnerability detection on the web application under test based not only on the first comparison result but also on the second comparison result, thereby effectively increasing the probability of vulnerability detection.
[0060] As another implementation method, please refer to Figure 4 , Figure 4 Provided in the embodiments of this application Figure 1 The third flow diagram of step 103 in FIG. Figure 4 As can be seen from the figure, step 103 may specifically include the following steps:
[0061] Step 1031 ′: obtain the information flow in the web application to be tested.
[0062] In this embodiment, when determining whether a web application to be tested has a security vulnerability based on the security vulnerability information, it is necessary to first obtain the information flow in the web application to be tested; wherein the obtained information flow is used to combine with the obtained security vulnerability information to determine whether the web application to be tested has a security vulnerability.
[0063] Step 1032 ′: compare the multiple security vulnerability information with the information flow respectively to obtain correlation information between each security vulnerability information and the information flow.
[0064] In this embodiment, after obtaining the information flow in the web application to be tested, it is necessary to compare the obtained multiple security vulnerability information with the obtained information flow respectively, and obtain correlation information between each security vulnerability information and the information flow; wherein each correlation information is used to determine whether the web application to be tested has a security vulnerability.
[0065] Step 1033 ′: determine whether the web application to be tested has a security vulnerability based on the correlation information and the first preset correlation threshold.
[0066] When at least one of the correlation information is greater than or equal to a first preset correlation threshold, it is determined that a security vulnerability exists in the web application to be tested.
[0067] In this embodiment, after obtaining the correlation information between each security vulnerability information and the information flow, it is possible to determine whether the web application under test has a security vulnerability based on the correlation information and a first preset correlation threshold. Specifically, when at least one of the correlation information is greater than or equal to the first preset correlation threshold, it is determined that the web application under test has a security vulnerability. It will be understood that when at least one of the correlation information is greater than or equal to the first preset correlation threshold, it indicates that at least one of the information flows included in the web application under test has an extremely high correlation with one or more security vulnerability information, i.e., the web application under test has the corresponding security vulnerability.
[0068] As another embodiment, please refer to Figure 5 , Figure 5 Provided in the embodiments of this application Figure 1 The fourth flow diagram of step 103 in FIG. Figure 5 As can be seen from the figure, step 103 may specifically include the following steps:
[0069] Step 1031 ′: obtain the information flow in the web application to be tested.
[0070] In this embodiment, when determining whether a web application to be tested has a security vulnerability based on the security vulnerability information, it is necessary to first obtain the information flow in the web application to be tested; wherein the obtained information flow is used to combine with the obtained security vulnerability information to determine whether the web application to be tested has a security vulnerability.
[0071] Step 1032 ′: compare the multiple security vulnerability information with the information flow respectively to obtain correlation information between each security vulnerability information and the information flow.
[0072] In this embodiment, after obtaining the information flow in the web application to be tested, it is necessary to compare the obtained multiple security vulnerability information with the obtained information flow respectively, and obtain correlation information between each security vulnerability information and the information flow; wherein each correlation information is used to determine whether the web application to be tested has a security vulnerability.
[0073] Step 1033 ′: determine whether the web application to be tested has a security vulnerability based on the correlation information and the first preset correlation threshold.
[0074] When at least one of the correlation information is greater than or equal to a first preset correlation threshold, it is determined that a security vulnerability exists in the web application to be tested.
[0075] In this embodiment, after obtaining the correlation information between each security vulnerability information and the information flow, it is possible to determine whether the web application under test has a security vulnerability based on the correlation information and a first preset correlation threshold. Specifically, when at least one of the correlation information is greater than or equal to the first preset correlation threshold, it is determined that the web application under test has a security vulnerability. It will be understood that when at least one of the correlation information is greater than or equal to the first preset correlation threshold, it indicates that at least one of the information flows included in the web application under test has an extremely high correlation with one or more security vulnerability information, i.e., the web application under test has the corresponding security vulnerability.
[0076] Step 1034 ′: when all correlation information is less than the first preset correlation threshold, the information flow whose correlation information is greater than or equal to the second preset correlation threshold is input into the preset attack model to simulate the attack on the web application to be tested and obtain the simulation result.
[0077] The second preset correlation threshold is smaller than the first preset correlation threshold.
[0078] In this embodiment, when all correlation information is less than a first preset correlation threshold, it indicates that the information flows included in the web application under test have a low correlation with all security vulnerability information. However, this does not mean that the information flows included in the web application will not attack the web application; in this case, it is also necessary to consider information flows in the web application under test that have a moderate correlation with each security vulnerability information. Therefore, when all correlation information is less than the first preset correlation threshold, it is necessary to input information flows with correlation information greater than or equal to a second preset correlation threshold into a preset attack model to simulate attacks on the web application under test and obtain simulation results. The simulation results are used to determine whether the web application under test has security vulnerabilities.
[0079] Step 1035 ′: determine whether the web application to be tested has any security vulnerabilities based on the simulation results.
[0080] If the simulation result shows that the web application to be tested is attacked, it is confirmed that the web application to be tested has a security vulnerability.
[0081] In this embodiment, after obtaining the simulation results, it is possible to determine whether the web application under test has a security vulnerability based on the simulation results. Specifically, if the simulation result indicates that the web application under test is under attack, it is confirmed that the web application under test has a security vulnerability. It is understood that the simulation result indicating that the web application under test is under attack indicates that, although the correlation between the information flow included in the web application under test and the security vulnerability information is not high, it will still attack the web application under test, indicating that the web application under test has a corresponding security vulnerability.
[0082] It should be understood that the above implementation is only a preferred implementation of the embodiment of the present application, and is not the only limitation of the specific process of step 103 in the embodiment of the present application; in this regard, those skilled in the art can flexibly set it according to the actual application scenario based on the embodiment of the present application.
[0083] In summary, the embodiment of the present application first obtains security vulnerability information from multiple vulnerability information sources, wherein the security vulnerability information includes multiple security vulnerability information, and the multiple security vulnerability information has heterogeneity; then, based on the security vulnerability information, it is determined whether the web application under test has a security vulnerability. It can be seen that the security vulnerability information used by the embodiment of the present application comes from multiple vulnerability information sources, making the security vulnerability information used more comprehensive, thereby effectively improving the comprehensiveness of vulnerability detection for the web application under test; the multiple security vulnerability information used by the embodiment of the present application has heterogeneity, that is, there are large differences between the multiple security vulnerability information used, and they do not completely belong to the same category of security vulnerabilities, thereby effectively improving the accuracy of vulnerability detection for the web application under test. In addition, when the embodiment of the present application is implemented based on RASP technology, it can use the vulnerability detection probe preset in the web container of the web application under test to determine whether the web application under test has a security vulnerability in real time based on the security vulnerability information during the operation of the web application under test, thereby effectively improving the timeliness of vulnerability detection for the web application under test.
[0084] In some embodiments, if a security vulnerability exists in the web application to be tested, relevant information of the existing security vulnerability may be output, so that technical personnel can clearly understand the existing security vulnerability and can deal with the existing security vulnerability in a targeted manner.
[0085] Furthermore, when obtaining security vulnerability information from multiple vulnerability information sources, processing strategies corresponding to the multiple security vulnerability information can be obtained simultaneously. Based on this, if there are security vulnerabilities in the web application to be tested, the existing security vulnerabilities can be processed according to the corresponding processing strategies, and the processing results can be output, so that the technicians can clearly understand the processing process of the existing security vulnerabilities. Here, it is necessary to explain that if the security vulnerability existing in the web application to be tested is a random security vulnerability corresponding to the random security vulnerability information, then since the random security vulnerability information is randomly generated during the vulnerability detection of the web application to be tested, it is not known in advance by the technicians, and the corresponding processing strategies cannot be set in advance, the random security vulnerability corresponding to the random security vulnerability information existing in the web application to be tested can be output, and the technicians can decide how to deal with the random security vulnerability based on the output random security vulnerability.
[0086] As an implementation manner, the processing strategy corresponding to the security vulnerability information may include but is not limited to blocking attacks on existing security vulnerabilities, reporting attacks on existing security vulnerabilities, and writing attacks on existing security vulnerabilities into logs.
[0087] It should be understood that the above-mentioned implementation mode is only a preferred implementation of the embodiment of the present application, and is not the only limitation of the processing strategy corresponding to the security vulnerability information in the embodiment of the present application; in this regard, those skilled in the art can flexibly set it according to the actual application scenario based on the embodiment of the present application.
[0088] Please see further Figure 6 , Figure 6 This is a module block diagram of a web application vulnerability detection device provided in an embodiment of the present application.
[0089] like Figure 6 As shown, an embodiment of the present application further provides a web application vulnerability detection device 600, comprising a storage device 610 and one or more processors 620; wherein the storage device 610 is used to store one or more programs, and when the one or more programs are executed by the one or more processors 620, the one or more processors 620 execute the web application vulnerability detection method provided in the embodiment of the present application.
[0090] In some embodiments, the web application vulnerability detection device 600 may further include a bus 630 for communication between the storage device 610 and the one or more processors 620 .
[0091] Please see further Figure 7 , Figure 7 A module block diagram of a computer-readable storage medium provided in an embodiment of the present application.
[0092] like Figure 7 As shown, the embodiment of the present application further provides a computer-readable storage medium 700, on which executable instructions 710 are stored. When the executable instructions 710 are executed, the vulnerability detection method for the web application provided in the embodiment of the present application is executed.
[0093] The steps of the methods or algorithms described in conjunction with the embodiments disclosed herein may be implemented directly using hardware, a software module executed by a processor, or a combination of the two. The software module may be placed in a random access memory (RAM), internal memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, a hard disk, a removable disk, a CD-ROM, or any other form of storage medium known in the art.
[0094] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the process or function described in this application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server or data center to another website, computer, server or data center via a wired (e.g., coaxial cable, optical fiber, digital subscriber line) or wireless (e.g., infrared, wireless, microwave, etc.) method. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more available media integrated. The available medium can be a magnetic medium (e.g., a floppy disk, a hard disk, a magnetic tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid-state drive).
[0095] It should be noted that the various embodiments in this application are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. Similarities between the various embodiments can be referred to in conjunction with each other. For product-related embodiments, since they are similar to method-related embodiments, their description is relatively simple. For relevant details, refer to the description of the method-related embodiments.
[0096] It should also be noted that, in the present application, relational terms such as first and second, etc. are merely used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article, or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article, or device. In the absence of further restrictions, an element defined by the statement "comprising a ..." does not exclude the presence of other identical elements in the process, method, article, or device comprising the element.
[0097] The above description of the disclosed embodiments is intended to enable one skilled in the art to implement or use the present disclosure. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present disclosure. Therefore, the present disclosure is not limited to the embodiments shown herein but is intended to be applied in the broadest manner consistent with the principles and novel features disclosed herein.
Claims
1. A web application vulnerability detection method, characterized in that: include: Load vulnerability detection probes in the web container; By using the vulnerability detection probe, a plurality of security vulnerability information with heterogeneity between each other is obtained from a plurality of vulnerability information sources; Obtaining an information flow in the web application to be tested; comparing the plurality of security vulnerability information with the information flow to obtain a first comparison result; and determining whether the web application to be tested has a security vulnerability based on the first comparison result; wherein, if the first comparison result shows that at least one of the plurality of security vulnerability information is consistent with the information flow, then confirming that the web application to be tested has a security vulnerability; If the first comparison result is that the multiple security vulnerability information are inconsistent with the information flow, the multiple security vulnerability information are randomly combined and / or mutated to obtain multiple random security vulnerability information; the multiple random security vulnerability information are respectively compared with the information flow to obtain a second comparison result; based on the second comparison result, it is determined whether the web application to be tested has a security vulnerability; wherein, if the second comparison result is that at least one of the multiple random security vulnerability information is consistent with the information flow, it is confirmed that the web application to be tested has a security vulnerability.
2. The web application vulnerability detection method according to claim 1, wherein: The vulnerability information sources include: at least two of the CVE vulnerability library, the CNNVD vulnerability library, the first vulnerability library, the second vulnerability library and the third vulnerability library; Among them, the first vulnerability library is a collection of security vulnerabilities detected when vulnerability detection is performed on web applications using IAST technology; the second vulnerability library is a collection of security vulnerabilities detected when vulnerability detection is performed on web applications using SAST technology; the third vulnerability library is a collection of security vulnerabilities detected when vulnerability detection is performed on web applications using DAST technology.
3. The web application vulnerability detection method according to claim 1, wherein: Determining whether the web application to be tested has a security vulnerability based on the security vulnerability information includes: Get the information flow in the web application under test; Comparing the plurality of security vulnerability information with the information flow respectively to obtain correlation information between each security vulnerability information and the information flow; Determine whether the web application to be tested has a security vulnerability based on each of the correlation information and a first preset correlation threshold; wherein, when at least one of the correlation information is greater than or equal to the first preset correlation threshold, it is confirmed that the web application to be tested has a security vulnerability.
4. The web application vulnerability detection method according to claim 3, wherein: After determining whether the web application to be tested has a security vulnerability based on the correlation information and the first preset correlation threshold, the method further includes: When each of the correlation information is less than the first preset correlation threshold, inputting the information flow whose correlation information is greater than or equal to a second preset correlation threshold into a preset attack model to simulate an attack on the web application to be tested, and obtaining a simulation result; wherein the second preset correlation threshold is less than the first preset correlation threshold; According to the simulation result, it is determined whether the web application to be tested has a security vulnerability; if the simulation result shows that the web application to be tested is attacked, it is confirmed that the web application to be tested has a security vulnerability.
5. The web application vulnerability detection method according to any one of claims 1 to 4, characterized in that: Also includes: Obtaining respective processing strategies for a plurality of the security vulnerability information; After determining whether the web application to be tested has a security vulnerability based on the security vulnerability information, the method further includes: If the web application to be tested has a security vulnerability, the existing security vulnerability is processed according to the corresponding processing strategy, and the processing result is output.
6. The web application vulnerability detection method according to claim 5, wherein: The processing of the existing security vulnerabilities according to the corresponding processing strategy includes at least one of the following: Block attacks on existing security vulnerabilities; Report attacks on existing security vulnerabilities; Write attacks on existing security vulnerabilities into the log.
7. A web application vulnerability detection device, characterized in that: include: a storage device and one or more processors; The storage device is used to store one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors are enabled to perform the method according to any one of claims 1 to 6.
8. A computer-readable storage medium, characterized in that The computer-readable storage medium stores executable instructions, and when the executable instructions are executed, the method according to any one of claims 1 to 6 is performed.
Citation Information
Patent Citations
Transaction risk assessment method and device and electronic equipment
CN110046997A
Bug detection method and device, storage medium and electronic equipment
CN112528296A