Application test method, device and electronic equipment
Patent Information
- Application Number
- CN202211435393.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-11-16
- Publication Date
- 2026-08-28
- Estimated Expiration
- 2042-11-16
AI Technical Summary
[0004]本发明实施例提供了一种应用测试方法、装置及电子设备,以至少解决相关技术中应用上线前进行测试时,步骤繁多杂糅,出现的测试效率低的技术问题
[0015]在本发明实施例中,获取预定应用的预定代码的静态需求规则,并基于静态需求规则测试预定代码,得到静态需求测试结果。在静态需求测试结果为测试通过的情况下,获取预定代码的结构测试规则,并基于结构测试规则测试预定代码,得到结构测试结果。在结构测试结果为测试通过的情况下,获取预定漏洞库,并基于预定漏洞库漏洞匹配预定代码,得到漏洞测试结果。在漏洞测试结果为测试通过的情况下,获取冒烟测试脚本,并基于冒烟测试脚本冒烟测试预定代码,得到冒烟测试结果。在冒烟测试结果为测试通过的情况下,获取黑盒测试脚本,并基于黑盒测试脚本测试预定代码,得到黑盒测试结果。依据黑盒测试结果,确定预定应用的目标测试结果,即能够全面自动化的进行应用各方面的测试,因为自动获取了规则、库或脚本进行测试,大大提升了测试应用的便捷性,而且自动化的进行顺序测试,提高了测试效率,进而解决了相关技术中应用上线前进行测试时,步骤繁多杂糅,出现的测试效率低的技术问题。
Smart Images

Figure CN115688121B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data security, and more specifically, to an application testing method, apparatus, and electronic device. Background Technology
[0002] Application security testing is an important part of application testing. It has a wide range of vulnerabilities, and manual testing is costly in terms of manpower. Furthermore, due to the lack of sound mechanisms for registering and tracking issues during manual testing, application security quality monitoring is weak, making it impossible to assess whether the system meets quality requirements when it goes live.
[0003] There is currently no effective solution to the above problems. Summary of the Invention
[0004] This invention provides an application testing method, apparatus, and electronic device to at least solve the technical problem of low testing efficiency caused by numerous and complicated steps when testing applications before they go online in related technologies.
[0005] According to one aspect of the present invention, an application testing method is provided, comprising: obtaining static requirement rules for predetermined code of a predetermined application, and testing the predetermined code based on the static requirement rules to obtain a static requirement test result, wherein the static requirement rules include predetermined operations included in the predetermined application and rules matching the defined functions corresponding to the predetermined operations; if the static requirement test result is a pass, obtaining structural test rules for the predetermined code, and testing the predetermined code based on the structural test rules to obtain a structural test result, wherein the structural test rules include data format rules; if the structural test result is a pass, obtaining the predetermined... The system uses a vulnerability database and matches the predetermined code with vulnerabilities from the database to obtain vulnerability test results. If the vulnerability test results are satisfactory, a smoke test script is obtained, and the predetermined code is tested using the smoke test script to obtain smoke test results. The smoke test script is pre-generated based on smoke test cases for the predetermined code. If the smoke test results are satisfactory, a black-box test script is obtained, and the predetermined code is tested using the black-box test script to obtain black-box test results. The black-box test script is pre-generated based on a predetermined device and the predetermined code. Based on the black-box test results, the target test results for the predetermined application are determined.
[0006] Optionally, after determining the target test result of the predetermined application based on the black-box test result, the process includes: if the black-box test result is a pass, evaluating the predetermined application in a predetermined aspect to obtain an evaluation score; and if the evaluation score is higher than a predetermined threshold, obtaining a result indicating that the predetermined application is ready for deployment.
[0007] Optionally, obtaining the predetermined vulnerability database includes: obtaining a test environment for testing the predetermined application, and version information of the test framework and test components of the test environment; and determining the predetermined vulnerability database based on the test environment, the test framework, and the test component version information.
[0008] Optionally, obtaining the black-box test script includes: determining the hardware interface protocol of the predetermined device; and generating the black-box test script based on the predetermined code and the hardware interface protocol.
[0009] Optionally, the method includes: if any one of the static requirements test results, the structural test results, the vulnerability test results, the smoke test results, and the black-box test results indicates a test failure during the test, determining fault information; based on the fault information, determining whether the fault is an automatically repairable fault; if the automatically repair result indicates a self-repairable fault, automatically repairing the fault and re-executing the test in which the test result indicates a test failure during the test.
[0010] Optionally, the method includes: if the automatic repair result is an unrepairable fault, sending the fault information to a predetermined terminal.
[0011] Optionally, before obtaining the static requirement rules of the predetermined code of the predetermined application, and testing the predetermined code based on the static requirement rules to obtain the static requirement test results, the process includes: setting up a test environment for testing the predetermined application, and compiling the predetermined code of the predetermined application in the test environment.
[0012] According to one aspect of the present invention, an application testing apparatus is provided, comprising: a first testing module, configured to acquire static requirement rules of predetermined code for a predetermined application, and test the predetermined code based on the static requirement rules to obtain a static requirement test result, wherein the static requirement rules include predetermined operations included in the predetermined application and rules matching the defined functions corresponding to the predetermined operations; a second testing module, configured to, if the static requirement test result is a pass, acquire structural test rules of the predetermined code, and test the predetermined code based on the structural test rules to obtain a structural test result, wherein the structural test rules include data format rules; and a third testing module, configured to, if the structural test result is a pass, acquire predetermined... The system employs a vulnerability database and matches the predetermined code with vulnerabilities from the database to obtain vulnerability test results. A fourth testing module, if the vulnerability test result is a pass, obtains a smoke test script and performs a smoke test on the predetermined code based on the smoke test script to obtain smoke test results. The smoke test script is pre-generated based on smoke test cases for the predetermined code. A fifth testing module, if the smoke test result is a pass, obtains a black-box test script and performs a black-box test on the predetermined code to obtain black-box test results. The black-box test script is pre-generated based on a predetermined device and the predetermined code. A sixth testing module, based on the black-box test results, determines the target test result for the predetermined application.
[0013] According to one aspect of the present invention, an electronic device is provided, comprising: a processor; and a memory for storing processor-executable instructions; wherein the processor is configured to execute the instructions to implement the application testing method described in any of the preceding embodiments.
[0014] According to one aspect of the present invention, a computer-readable storage medium is provided, wherein when the instructions in the computer-readable storage medium are executed by a processor of an electronic device, the electronic device is enabled to perform the application testing method described in any of the preceding claims.
[0015] In this embodiment of the invention, static requirement rules for predetermined code of a predetermined application are obtained, and the predetermined code is tested based on these rules to obtain static requirement test results. If the static requirement test results are satisfactory, structural test rules for the predetermined code are obtained, and the predetermined code is tested based on these rules to obtain structural test results. If the structural test results are satisfactory, a predetermined vulnerability database is obtained, and the predetermined code is matched with vulnerabilities in the database to obtain vulnerability test results. If the vulnerability test results are satisfactory, a smoke test script is obtained, and the predetermined code is smoke-tested based on this script to obtain smoke test results. If the smoke test results are satisfactory, a black-box test script is obtained, and the predetermined code is tested based on this script to obtain black-box test results. Based on the black-box test results, the target test results for the predetermined application are determined. This enables fully automated testing of all aspects of the application. Because rules, databases, or scripts are automatically obtained for testing, the convenience of testing the application is greatly improved. Furthermore, the automated sequential testing improves testing efficiency, thus solving the technical problem of low testing efficiency caused by numerous and complex steps when testing applications before deployment in related technologies. Attached Figure Description
[0016] The accompanying drawings, which are included to provide a further understanding of the invention and form part of this application, illustrate exemplary embodiments of the invention and, together with their description, serve to explain the invention and do not constitute an undue limitation thereof. In the drawings:
[0017] Figure 1 This is a flowchart of an application testing method according to an embodiment of the present invention;
[0018] Figure 2 This is a structural block diagram of an application testing device according to an embodiment of the present invention. Detailed Implementation
[0019] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.
[0020] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0021] First, some nouns or terms that appear in the description of the embodiments of this application shall be interpreted as follows:
[0022] Structural testing, also known as white-box testing, transparent-box testing, logic-driven testing, or code-based testing, is a test case design methodology. The "box" refers to the software being tested, and "white-box" means the box is visible, meaning its internal components and how it operates are clear. Coverage criteria for white-box testing include logical coverage, loop coverage, and basic path testing. Logical coverage includes statement coverage, decision coverage, condition coverage, decision / condition coverage, condition combination coverage, and modified condition decision coverage.
[0023] Black-box testing: This involves testing to ensure each function works correctly. In this method, the program is treated as a closed black box. Testing is performed on the program interface without considering its internal structure or characteristics. It only checks whether the program functions correctly according to the requirements specification and whether it can appropriately receive input data and produce correct output. Black-box testing focuses on the external structure of the program, disregarding its internal logic, and primarily tests the software interface and functionality.
[0024] Smoke testing: The process of validating code changes before embedding them into the product's source tree. After reviewing the code, smoke testing is the most cost-effective way to identify and fix software defects. Smoke tests are designed to confirm that changes in the code will function as expected and will not compromise the stability of the overall version.
[0025] Example 1
[0026] According to an embodiment of the present invention, an embodiment of an application testing method is provided. It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Furthermore, although a logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order than that shown here.
[0027] Figure 1 This is a flowchart of an application testing method according to an embodiment of the present invention, such as... Figure 1 As shown, the method includes the following steps:
[0028] Step S102: Obtain the static requirement rules of the pre-defined code of the pre-defined application, and test the pre-defined code based on the static requirement rules to obtain the static requirement test results. The static requirement rules include the pre-defined operations included in the pre-defined application and the rules that match the limited functions corresponding to the pre-defined operations.
[0029] In step S102 of this application, it is necessary to obtain the static requirement rules of the predetermined code for the intended application. This test is applied during the requirement formulation and system design phases. In this test, it is necessary to confirm whether a specific security-related modification is involved. Based on a pre-designed security data dictionary and the modification requirement list and system overall design modification point list archived in the system, text matching is performed to determine the static requirement rules. The determined static requirement rules are the rules that match the predetermined operations included in the intended application and the corresponding limited functions, such as scenario + security modification type. Specifically, for example, login + password transmission encryption, image verification code + random generation, order refund + anti-replay, message board + anti-SQL (Structured Query Language) injection, etc. Static document checking is incorporated into the continuous integration pipeline. When security-related modification content is detected, the predetermined code is tested based on the static requirement rules to obtain the static requirement test results.
[0030] Step S104: If the static requirements test result is that the test is passed, obtain the structure test rules of the predetermined code, and test the predetermined code based on the structure test rules to obtain the structure test result. The structure test rules include data format rules.
[0031] In step S104 described in this application, it is necessary to obtain the structure test rules of the predetermined code, such as data format rules. This test is applied during the development phase. In this test, it is necessary to confirm whether the code contains data that conforms to IP format / email format / phone number format without being de-identified, data that conforms to simple transcoding format (which may be data that needs to be encrypted but has only been transcoded), SQL statements that do not escape variables, etc., to ensure that the data conforms to the target format and whether the encryption and de-identification meet the requirements, thus ensuring a certain level of security.
[0032] Step S106: If the structural test result is that the test is passed, obtain the predetermined vulnerability database, and match the predetermined code based on the vulnerabilities in the predetermined vulnerability database to obtain the vulnerability test result;
[0033] In step S106 described in this application, a predetermined vulnerability database needs to be obtained, such as a vulnerability database that already contains a list of vulnerabilities that can be accessed and a list of vulnerabilities that cannot be accessed. By filtering based on the list of vulnerabilities that can be accessed and the list of vulnerabilities that cannot be accessed, the recorded vulnerabilities can be filtered out, thus ensuring the security of the code.
[0034] Step S108: If the vulnerability test result is that the test is passed, obtain the smoke test script, and smoke test the predetermined code based on the smoke test script to obtain the smoke test result. The smoke test script is pre-generated based on the smoke test cases of the predetermined code.
[0035] In step S108 described in this application, the scope of security testing is defined by security test cases triggered in the requirements formulation and system design phases, as well as security test cases supplemented in the test design phase. The corresponding smoke test scripts are obtained, which enables rapid testing of basic functions and improves testing efficiency.
[0036] Step S110: If the smoke test result is a pass, obtain the black box test script, and test the predetermined code based on the black box test script to obtain the black box test result. The black box test script is pre-generated based on the predetermined device and predetermined code.
[0037] In step S110 described in this application, black-box testing allows us to understand the problems and functions that users may encounter from the user's perspective, and enables us to perform highly efficient testing.
[0038] Step S112: Based on the black-box test results, determine the target test results for the intended application.
[0039] In step S112 described in this application, after the black-box test is performed and the black-box test results are obtained, since the entire automated testing process has been completed, the target test results of the predetermined application can also be determined, thus realizing integrated testing of the application.
[0040] Through the above steps, the static requirement rules for the predetermined code of the application are obtained, and the predetermined code is tested based on these rules to obtain static requirement test results. If the static requirement test results are successful, the structural test rules for the predetermined code are obtained, and the predetermined code is tested based on these rules to obtain structural test results. If the structural test results are successful, a predetermined vulnerability database is obtained, and the predetermined code is matched with vulnerabilities in the database to obtain vulnerability test results. If the vulnerability test results are successful, a smoke test script is obtained, and the predetermined code is smoke-tested based on this script to obtain smoke test results. If the smoke test results are successful, a black-box test script is obtained, and the predetermined code is tested based on this script to obtain black-box test results. Based on the black-box test results, the target test results for the predetermined application are determined. This enables fully automated testing of all aspects of the application. Because rules, databases, and scripts are automatically obtained for testing, the convenience of testing the application is greatly improved. Furthermore, the automated sequential testing improves testing efficiency, thus solving the technical problem of low testing efficiency caused by numerous and complex steps when testing applications before deployment in related technologies.
[0041] As an optional embodiment, step S112, after determining the target test result of the predetermined application based on the black-box test result, includes: if the black-box test result is a pass, evaluating the predetermined application in a predetermined aspect to obtain an evaluation score; if the evaluation score is higher than a predetermined threshold, obtaining the online result that the predetermined application can be launched.
[0042] In this embodiment, the predetermined aspects can be various. For example, it could be a comprehensive score in testing, a data volume stress test on the application, or an experience score given by testers. It could also be a security quality assessment based on pre-defined quality thresholds to determine whether the application can be launched. For instance, it could require a 100% problem repair rate and a 100% case execution rate at each stage before launch. There are no limitations here, and the settings can be customized according to the actual application and scenario. If the assessment score is higher than the predetermined threshold, the application is deemed ready for launch, thus enabling the application to go live.
[0043] It should be noted that applications launched during the same period can be quantitatively scored at different time points to compare the quality of application A and application B during the same period, as well as the current and past quality of application A. Applications that fail to meet quality standards can be taken offline or prohibited from being launched.
[0044] As an optional embodiment, obtaining a predetermined vulnerability database includes: obtaining a test environment for testing a predetermined application, and version information of the test framework and test components of the test environment; and determining the predetermined vulnerability database based on the test environment, the test framework, and the test component version information.
[0045] In this embodiment, a predetermined vulnerability library is determined based on the environment, framework, and component version information configured during deployment. This determines the vulnerability library corresponding to the test environment, test framework, and test build version information, which facilitates better vulnerability matching.
[0046] As an optional embodiment, obtaining a black-box test script includes: determining the hardware interface protocol of a predetermined device; and generating a black-box test script based on predetermined code and the hardware interface protocol.
[0047] In this embodiment, it is possible to determine whether the protocol interface can implement the function corresponding to the interface, that is, to consider whether the input can be entered correctly and whether the output can output the correct result on the interface. This is to achieve the test of basic functions.
[0048] As an optional embodiment, if any one of the test results—static requirements test result, structural test result, vulnerability test result, smoke test result, and black-box test result—results in a test failure during the test, the fault information is determined; based on the fault information, it is determined whether the fault is an automatically repairable fault; if the automatically repair result is an automatically repairable fault, the fault is automatically repaired, and the test that resulted in the test failure during the test is re-executed.
[0049] In this embodiment, if the static requirements test result indicates a test failure during testing, the system will automatically raise an issue to track the failure and determine if it is a self-repairable failure. If the automatic repair result indicates a self-repairable failure, the failure will be automatically repaired, and the test that resulted in the failure will be re-executed until no further failures are found, at which point the issue will be closed. Similarly, if the structural test result indicates a test failure during testing, the system will automatically raise an issue to track the failure and determine if it is a self-repairable failure. If the automatic repair result indicates a self-repairable failure, the failure will be automatically repaired, and the test that resulted in the failure will be re-executed until no further failures are found, at which point the issue will be closed. Finally, if the vulnerability test result indicates a test failure during testing, and the failure is either on the fail list or not on the pass list, the system will automatically raise an issue to track the failure and determine if it is a self-repairable failure. If the automatic repair result indicates a self-repairable failure, the failure will be automatically repaired, and the test that resulted in the failure will be re-executed until the vulnerability screening criteria are met, at which point the issue will be closed. If the smoke test result indicates a test failure during testing, an automatic issue will be raised for follow-up. The system will determine if the failure is self-repairable and will automatically repair the fault. If the automatic repair result indicates a self-repairable fault, the fault will be automatically repaired, and the test that resulted in the test failure will be re-executed until the test no longer fails, at which point the issue will be closed. Similarly, if the black-box test result indicates a test failure during testing, an automatic issue will be raised for follow-up. The system will determine if the failure is self-repairable and will automatically repair the fault. If the automatic repair result indicates a self-repairable fault, the fault will be automatically repaired, and the test that resulted in the test failure will be re-executed until the test no longer fails, at which point the issue will be closed.
[0050] As an optional embodiment, if the automatic repair result is an unrepairable fault, fault information is sent to a predetermined terminal.
[0051] In this embodiment, when the static requirements test result indicates a test failure that cannot be automatically repaired, manual intervention by security and quality assurance personnel is required, and the static requirements inspection rules must be updated promptly. Similarly, when the structural test result indicates a test failure that cannot be automatically repaired, manual intervention by security and quality assurance personnel is necessary for certain special cases, such as simple transcoding not always encrypting data that should be encrypted but wasn't, and the structural test rules must be updated promptly. Likewise, when the vulnerability test result indicates a test failure that cannot be automatically repaired, manual intervention by security and quality assurance personnel is necessary for certain special cases, such as using a vulnerability that was not registered in the latest version of the vulnerability list, resulting in a missed vulnerability, and the predetermined vulnerability database must be updated promptly. Similarly, when the smoke test result indicates a test failure that cannot be automatically repaired, manual intervention by security and quality assurance personnel is necessary for certain special cases, and the smoke test script must be updated promptly. Finally, when the black-box test result indicates a test failure that cannot be automatically repaired, manual intervention by security and quality assurance personnel is necessary for certain special cases, and the black-box test script must be updated promptly.
[0052] As an optional embodiment, before obtaining the static requirement rules of the predetermined code of the predetermined application and testing the predetermined code based on the static requirement rules to obtain the static requirement test results, the following steps are taken: setting up a test environment for testing the predetermined application and compiling the predetermined code of the predetermined application in the test environment.
[0053] In this embodiment, the process of setting up the environment and compiling the code can be automated. The deployment package corresponding to the predetermined code can be directly called to realize the setup of the environment and the compilation of the code. The environment that can perform the above operations can be deployed directly, which helps to speed up the integrated testing process.
[0054] It should be noted that, for the sake of simplicity, the foregoing method embodiments are all described as a series of actions. However, those skilled in the art should understand that the present invention is not limited to the described order of actions, because according to the present invention, some steps can be performed in other orders or simultaneously. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are preferred embodiments, and the actions and modules involved are not necessarily essential to the present invention.
[0055] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods according to the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions to cause a terminal device (which may be a mobile phone, computer, server, or network device, etc.) to execute the methods of the various embodiments of the present invention.
[0056] Example 2
[0057] According to embodiments of the present invention, an apparatus for implementing the above-described application testing method is also provided. Figure 2 This is a structural block diagram of an application testing device according to an embodiment of the present invention, such as... Figure 2 As shown, the device includes: a first test module 202, a second test module 204, a third test module 206, a fourth test module 208, a fifth test module 210, and a sixth test module 212. The device will be described in detail below.
[0058] The first testing module 202 is used to obtain the static requirement rules of the predetermined code of the predetermined application, and test the predetermined code based on the static requirement rules to obtain the static requirement test results. The static requirement rules include predetermined operations included in the predetermined application and rules matching the corresponding functional limitations. The second testing module 204, connected to the first testing module 202, is used to obtain the structural test rules of the predetermined code if the static requirement test results are passed, and test the predetermined code based on the structural test rules to obtain the structural test results. The structural test rules include data format rules. The third testing module 206, connected to the second testing module 204, is used to obtain a predetermined vulnerability database if the structural test results are passed, and match vulnerabilities in the predetermined vulnerability database with predetermined code. The system performs several tests, including: First, it obtains a smoke test script and tests predetermined code to obtain a smoke test result. Second, it obtains a smoke test script based on the smoke test script and pre-generated smoke test cases for the predetermined code. Third, it obtains a black-box test script based on the smoke test result and tests predetermined code to obtain a black-box test result. Fourth, it obtains a smoke test script based on the smoke test cases for the predetermined code. Fifth, it obtains a black-box test script based on the smoke test result and tests predetermined code to obtain a black-box test result. Sixth, it obtains a black-box test script based on the black-box test result and determines the target test result for the predetermined application.
[0059] It should be noted that the first test module 202, the second test module 204, the third test module 206, the fourth test module 208, the fifth test module 210 and the sixth test module 212 mentioned above correspond to steps S102 to S112 in the implementation of the application test method. The multiple modules and the corresponding steps implement the same instances and application scenarios, but are not limited to the content disclosed in the above embodiment 1.
[0060] Example 3
[0061] According to another aspect of the present invention, an electronic device is also provided, comprising: a processor; and a memory for storing processor-executable instructions, wherein the processor is configured to execute instructions to implement the application testing method described above.
[0062] Example 4
[0063] According to another aspect of the present invention, a computer-readable storage medium is also provided, which, when the instructions in the computer-readable storage medium are executed by a processor of an electronic device, enables the electronic device to perform any of the above-described application testing methods.
[0064] The sequence numbers of the above embodiments of the present invention are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.
[0065] In the above embodiments of the present invention, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments.
[0066] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. The device embodiments described above are merely illustrative; for example, the division of units can be a logical functional division, and in actual implementation, there may be other division methods. For instance, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the displayed or discussed mutual coupling, direct coupling, or communication connection may be through some interfaces; the indirect coupling or communication connection between units or modules may be electrical or other forms.
[0067] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0068] Furthermore, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0069] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, read-only memory (ROM), random access memory (RAM), portable hard drives, magnetic disks, or optical disks.
[0070] The above description is only a preferred embodiment of the present invention. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principle of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.
Claims
1. An application testing method, characterized in that, include: Obtain the static requirement rules of the predetermined code of the predetermined application, and test the predetermined code based on the static requirement rules to obtain the static requirement test results. The static requirement rules include the predetermined operations included in the predetermined application and the rules that match the limiting functions corresponding to the predetermined operations. If the static requirements test result is a pass, the structural test rules of the predetermined code are obtained, and the predetermined code is tested based on the structural test rules to obtain the structural test result. The structural test rules include data format rules. If the structure test result is a pass, a predetermined vulnerability database is obtained, and the predetermined code is matched with vulnerabilities in the predetermined vulnerability database to obtain the vulnerability test result; If the vulnerability test result is a pass, a smoke test script is obtained, and the predetermined code is smoke-tested based on the smoke test script to obtain a smoke test result. The smoke test script is pre-generated based on smoke test cases of the predetermined code. If the smoke test result is a pass, a black-box test script is obtained, and the predetermined code is tested based on the black-box test script to obtain the black-box test result. The black-box test script is pre-generated based on the predetermined device and the predetermined code. Based on the black-box test results, the target test results for the intended application are determined.
2. The method according to claim 1, characterized in that, After determining the target test result of the predetermined application based on the black-box test results, the process includes: If the black-box test result is a pass, the predetermined application will be evaluated in a predetermined aspect to obtain an evaluation score; If the evaluation score is higher than a predetermined threshold, the application is deemed ready for deployment.
3. The method according to claim 1, characterized in that, The acquisition of the predetermined vulnerability database includes: Obtain the test environment for testing the predetermined application, including the test framework and test component version information of the test environment; Based on the test environment, the test framework, and the test build version information, the predetermined vulnerability database is determined.
4. The method according to claim 1, characterized in that, The acquisition of the black-box test script includes: Determine the hardware interface protocol of the predetermined device; The black-box test script is generated based on the predetermined code and the hardware interface protocol.
5. The method according to claim 1, characterized in that, include: If any one of the static requirements test results, the structural test results, the vulnerability test results, the smoke test results, and the black-box test results indicates a test failure during the test, the fault information is determined. Based on the fault information, determine whether the fault is an automatic repair result of a self-repairing fault; If the automatic repair result indicates a self-repairable fault, the fault is automatically repaired, and the test result indicating a test fault occurred during the test is re-executed.
6. The method according to claim 5, characterized in that, include: If the automatic repair result indicates an unrepairable fault, the fault information is sent to a predetermined terminal.
7. The method according to any one of claims 1 to 6, characterized in that, Before obtaining the static requirement rules for the predetermined code of the predetermined application, and testing the predetermined code based on the static requirement rules to obtain the static requirement test results, the process includes: Set up a test environment to test the predetermined application, and compile the predetermined code of the predetermined application in the test environment.
8. An application testing device, characterized in that, include: The first testing module is used to obtain the static requirement rules of the predetermined code of the predetermined application, and test the predetermined code based on the static requirement rules to obtain the static requirement test results. The static requirement rules include the predetermined operations included in the predetermined application and the rules that match the limiting functions corresponding to the predetermined operations. The second testing module is used to obtain the structural testing rules of the predetermined code when the static requirements test result is a pass, and to test the predetermined code based on the structural testing rules to obtain the structural test result, wherein the structural testing rules include data format rules; The third testing module is used to obtain a predetermined vulnerability database and match the predetermined code based on the vulnerabilities in the predetermined vulnerability database, if the structure test result is a pass, to obtain the vulnerability test result. The fourth testing module is used to obtain a smoke test script when the vulnerability test result is a pass, and to perform a smoke test on the predetermined code based on the smoke test script to obtain a smoke test result, wherein the smoke test script is pre-generated based on smoke test cases of the predetermined code; The fifth testing module is used to obtain a black-box test script when the smoke test result is a pass, and to test the predetermined code based on the black-box test script to obtain a black-box test result. The black-box test script is pre-generated based on the predetermined device and the predetermined code. The sixth testing module is used to determine the target test results of the predetermined application based on the black-box test results.
9. An electronic device, characterized in that, include: processor; Memory used to store the processor's executable instructions; The processor is configured to execute the instructions to implement the application testing method as described in any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that, When the instructions in the computer-readable storage medium are executed by the processor of the electronic device, the electronic device is able to perform the application test method as described in any one of claims 1 to 7.
Citation Information
Patent Citations
Vulnerability detection method and system
CN114048488A
Software development operation test system based on Internet
CN114519000A