API risk assessment method and device, electronic equipment, chip and storage medium

By establishing the correspondence between the API path to the target database, sensitive value level annotation and access operation type risk index annotation, the problems of high resource consumption, low recognition efficiency, high false alarm rate, and large workload of manual sorting of API lists in existing API security protection technologies are solved, and more accurate and comprehensive psychological evaluation and API security protection effects are achieved.

CN120105423APending Publication Date: 2025-06-06CHINA MOBILE CHENGDU INFORMATION & TELECOMM TECH CO LTD +1
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202311658169.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-12-04
Publication Date
2025-06-06

AI Technical Summary

Technical Problem

Among the existing API security protection technologies, the resource identification based on API full traffic sensitive information consumes a lot, has low recognition efficiency, and has a high false alarm rate; manual sorting of API lists is large, which is easy to remain; existing security products are immature in the encryption detection of sensitive data in the API, relying on penetration testing or data security assessment to discover risks; users have a large standard deviation in the judgment of API rating, and need to continue to manually participate in updating API ratings; security protection capabilities are tightly coupled with API registration business logic, which is not conducive to flexible business deployment.

Method used

By establishing the corresponding relationship between the API path to the target database, sensitive value level annotation and access operation type risk index annotation, comprehensively assess the risk level of the API to provide more accurate and comprehensive psychological evaluation results.

Benefits of technology

Compared with traditional methods, resource consumption is reduced, identification efficiency is improved, and false alarm rate is reduced; the workload of manually sorting out API lists is reduced, the deviation of API rating and the need for continuous updates is improved, and the flexibility and accuracy of API security protection is improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120105423A_ABST
    Figure CN120105423A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses an API risk assessment method, an API risk assessment device, electronic equipment, a chip and a computer readable storage medium, and the method comprises the steps that a corresponding relation between an API path and a target database is established, and the target database is a database accessed by an API; sensitive value grade labeling is carried out on sensitive data attributes in the target database; carrying out risk index labeling on the access operation type; based on the corresponding relation from the API path to the target database, the sensitive data attribute in the target database after sensitive value grade labeling and the access operation type after risk index labeling, risk evaluation is conducted on the API, and an evaluation result is obtained.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of safety technology, and in particular to an API risk assessment method, an API risk assessment device, an electronic device, a chip, and a computer-readable storage medium. Background Art

[0002] In the related technology, the security protection of the Application Programming Interface (API) is mainly achieved by sniffing the characteristic values ​​in the API requests and responses and analyzing the access behavior. When the abnormal access characteristics are matched, the corresponding protection strategy will be triggered. Among them, the security protection means for sensitive data in the API is mainly through identifying the sensitive data in the API traffic, and adopting differentiated protection strategies according to the API sensitivity level. There are two sources of monitored APIs: the full amount of API assets automatically detected, and the API list provided by the R&D team; among them, sensitive information identification based on the full API traffic consumes a lot of resources. The identification process is easily disturbed by irrelevant information in the Http request body, resulting in low identification efficiency and a high false alarm rate; the list of sensitive APIs provided by the R&D team is manually sorted, and for medium and large business systems, the sorting workload is large and easy to be left behind. Summary of the invention

[0003] Embodiments of the present application provide an API risk assessment method, an API risk assessment device, an electronic device, a chip, and a computer-readable storage medium.

[0004] The technical solution of the embodiment of the present application is implemented as follows:

[0005] In a first aspect, an embodiment of the present application provides an API risk assessment method, comprising:

[0006] Establishing a correspondence between an API path and a target database, wherein the target database is a database accessed by the API;

[0007] Labeling sensitive data attributes in the target database with sensitivity levels;

[0008] Label the access operation type with a risk index;

[0009] Based on the correspondence between the API path and the target database, the sensitive data attributes in the target database after the sensitivity value level is marked, and the access operation type after the risk index is marked, the API is risk assessed to obtain an assessment result.

[0010] In a second aspect, an embodiment of the present application provides an API risk assessment device, comprising:

[0011] Acquisition unit: used to establish a correspondence between the API path and the target database, where the target database is the database accessed by the API;

[0012] Annotation unit: used to annotate sensitive data attributes in the target database with sensitivity value levels; and also used to annotate access operation types with risk indexes;

[0013] Evaluation unit: used to perform risk assessment on the API based on the correspondence between the API path and the target database, the sensitive data attributes in the target database after sensitivity value level annotation, and the access operation type after risk index annotation to obtain an assessment result.

[0014] In a third aspect, the present application provides an electronic device comprising: a processor and a memory, the memory being used to store a computer program, the processor being used to call and run the computer program stored in the memory, and execute any one of the API risk assessment methods provided in the embodiments of the present application.

[0015] In a fourth aspect, the present application provides a chip, comprising: a processor, for calling and running a computer program from a memory, so that a device equipped with the chip executes any one of the API risk assessment methods provided in the embodiments of the present application.

[0016] In a fifth aspect, the present application provides a computer-readable storage medium for storing a computer program, wherein the computer program enables a computer to execute any one of the API risk assessment methods provided in the embodiments of the present application.

[0017] The API risk assessment method provided in the embodiment of the present application performs a comprehensive risk score based on the sensitivity of the database information accessed by the API and the access operations. Compared with API security assessment performed by identifying sensitive data in the traffic, it is more accurate, the scoring results are more comprehensive and reasonable, and it consumes less resources. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] Figure 1 Schematic diagram of the implementation process of the API risk assessment method provided in the embodiment of the present application Figure 1 ;

[0019] Figure 2 A schematic diagram of the structure of an API risk assessment device provided in an embodiment of the present application;

[0020] Figure 3 A schematic structural diagram of an electronic device provided in an embodiment of the present application;

[0021] Figure 4 A schematic structural diagram of a chip provided in an embodiment of the present application. DETAILED DESCRIPTION

[0022] The following will describe the technical solutions in the embodiments of the present application in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.

[0023] It should be noted that in the embodiments of the present application, the term "and / or" is only a description of the association relationship of the associated objects, indicating that three relationships may exist. For example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone. In addition, in the embodiments of the present application, the character " / " generally indicates that the associated objects before and after are in an "or" relationship.

[0024] In the description of the embodiments of the present application, the term "corresponding" may indicate a direct or indirect correspondence between two items, or an association relationship between the two items, or a relationship between indication and being indicated, configuration and being configured, and the like.

[0025] To facilitate understanding of the technical solutions of the embodiments of the present application, the relevant technologies of the embodiments of the present application are described below. The following related technologies can be arbitrarily combined with the technical solutions of the embodiments of the present application as optional solutions, and they all belong to the protection scope of the embodiments of the present application.

[0026] At present, data has been fully integrated into all aspects of production, life, office, social governance and infrastructure construction, bringing greater challenges to data protection work at different levels of the country, industry and enterprise. With the rapid development of network technology, some universities or enterprises have replaced traditional paper-based exams with online exams, which has greatly improved the quality and efficiency of the exams themselves. However, data security is an issue that cannot be ignored in smart exam industry products. Smart exam products should not only have the ability to effectively prevent various external virus attacks, but also have the ability to strictly protect candidates' personal information and fully ensure the security of sensitive data related to the exam.

[0027] In the field of network security, Web API is one of the main targets of external networks, and attacks against API are becoming the first choice for black and gray industries and hackers. Compared with traditional forms and web pages, Web API carries more valuable data and has lower attack costs. Attacking API to obtain high-value data has become a common method for more and more illegal elements. Once API security is compromised and sensitive data is illegally used by hackers in the data-sensitive education industry, it may seriously damage the legitimate rights and interests of educational institutions and candidates, and bring huge risks to society.

[0028] Two solutions are proposed in the related art:

[0029] Solution 1: Web API security protection mainly detects the characteristic values ​​in API requests and responses and analyzes access behaviors. When abnormal access characteristics are matched, the corresponding protection strategy will be triggered. Among them, the security protection means for sensitive data in API is mainly to identify sensitive data in API traffic and adopt differentiated protection strategies according to the sensitivity level of API. There are two sources of monitored APIs: the full amount of API assets automatically detected and the API list provided by the R&D team.

[0030] Solution 2: During the API registration phase, users classify the API according to their actual business conditions and select the corresponding security protection level.

[0031] The above scheme still has the following technical problems:

[0032] 1. Sensitive information identification based on the entire API flow consumes a lot of resources. The identification process is easily disturbed by irrelevant information in the HTTP request body, resulting in low identification efficiency and high false alarm rate. In addition, there may be a long time difference before the security protection product identifies the sensitive API through the flow, which will make it impossible to carry out targeted protection for the sensitive API within this time window.

[0033] 2. The list of sensitive APIs provided by the R&D team is manually sorted. For medium and large business systems, the sorting workload is large and easy to be left behind.

[0034] 3. Smart exams belong to the data-sensitive education industry. Even if HTTPS is used, highly sensitive data still needs to be encrypted separately. However, current security products are not mature enough to detect whether sensitive data in APIs is encrypted, and to a large extent still rely on penetration testing or data security assessments to discover such risks.

[0035] 4. Allow users to rate the API. Different users may have different judgment criteria for decrypting sensitive information.

[0036] 5. During the business iteration process, continuous manual participation is required to update the API classification.

[0037] 6. It is necessary to tightly couple security protection capabilities with API registration business logic, which is not conducive to flexible business deployment.

[0038] 7. For medium and large business systems, the workload of manual grading is large.

[0039] Figure 1 Schematic diagram of the implementation process of the API risk assessment method provided in the embodiment of the present application Figure 1 ,like Figure 1As shown, the embodiment of the present application provides an API risk assessment method, the method comprising the following steps:

[0040] Step 101: Establish a correspondence between an API path and a target database, where the target database is a database accessed by the API.

[0041] In an optional implementation manner of the present application, the establishing a correspondence between the API path and the target database includes:

[0042] Obtain a first relationship, a second relationship, and a third relationship; wherein the first relationship represents a corresponding relationship between the API and a first function, the first function being a first-layer backend function that first processes an access request when the API receives an access request; the second relationship represents a corresponding relationship between a second function and a target database, the second function being the last function in the function call chain of the API that accesses information of the target database; the third relationship represents a complete function call chain from the first function to the second function;

[0043] Based on the first relationship, the second relationship and the third relationship, a corresponding relationship from the API path to the target database is established.

[0044] Exemplarily, the first relationship, the second relationship and the third relationship may be obtained by scanning source code.

[0045] Based on the source code type, determine the corresponding Backus-Naur form (the accurate Backus-Naur form can be obtained through the standard file of the programming language), generate a code analyzer with the help of open source tools, complete the lexical analysis and syntax analysis of the code, and establish an abstract syntax tree. Here, the code types include but are not limited to C, C++, Python, Golang and Java, and the open source tools can use but are not limited to flex and bison.

[0046] In the abstract syntax tree, find all the subtrees of function definitions, traverse all the subtrees of function definitions, and obtain the first relation, the second relation, and the third relation.

[0047] The first relationship can be obtained by the following method to determine whether there is HTTP request processing logic: if there is processing of HTTP method, path, parameter, HTTP return code and other features in the function parameters or implementation, it is determined to be an HTTP processing function. If it is determined to be an HTTP request function, the access path is extracted and the key information KEY-1 (API i , Function j ), that is, the first relationship; if it is determined to be a non-HTTP processing function, KEY-1 is not recorded, and the next subtree is analyzed.

[0048] The second relationship can be obtained in the following way to determine the logic of database access: whether the Backus-Naur form of relational database access is hit (the Backus-Naur form is obtained through the relational database SQL language specification). If there is database access, the objects (library, table, column) and access operations (add, delete, modify, query) of the database access are extracted through the paradigm, and the mapping relationship between the function and the database is recorded to obtain the key information KEY-2 (Function i , Database j , Table k , Column l ,Operation m ), that is, the second relationship; if it is determined that there is no database access behavior, KEY-2 is not recorded and the analysis of the next subtree continues.

[0049] The third relationship can be obtained by the following method to determine whether there is a function call logic: find out whether there are other functions called in the function except itself. If there are other functions called, record all the called functions, build a directed graph of function calls, and obtain the key information KEY-3 (Function i ,......,Function N ), that is, the third relationship. If there is no downward call chain, KEY-3 only records its own content.

[0050] Exemplarily, the correspondence between the API path and the target database may be represented as shown in Table 1:

[0051]

[0052] Table 1

[0053] It should be noted that a second function can access one or more target databases, and this application does not limit this.

[0054] In an optional implementation manner of the present application, the correspondence between the second function and the target database includes at least one of the following correspondences:

[0055] The corresponding relationship between the second function and the target database name;

[0056] The corresponding relationship between the second function and access to the table in the target database;

[0057] The corresponding relationship between the second function and accessing the column in the table in the target database; and

[0058] The corresponding relationship between the second function and the access operation type.

[0059] Based on this, in an optional implementation manner of the present application, obtaining the first relationship, the second relationship, and the third relationship includes:

[0060] Analyze the source code and build an abstract syntax tree;

[0061] All subtrees of function definitions in the abstract syntax tree are traversed to obtain the first relation, the second relation, and the third relation.

[0062] Step 102: label the sensitive data attributes in the target database with sensitivity levels.

[0063] Exemplarily, a connection is established with a specified target database through the target database access information (such as database access address, port, account) written in advance in the configuration file by the user. The target database can be one or more, but all require database read permissions. After the connection is established, the corresponding attributes of the database, column, and table are obtained through database scanning and structure scanning, and a database ledger is established, as shown in Table 2:

[0064]

[0065]

[0066] Table 2

[0067] The corresponding sensitivity level is marked on the data structure attribute table, that is, all designated columns in the table that are sensitive are marked, and no marking is performed on columns that are not sensitive. For example, the data classification table after marking the sensitivity value level is shown in Table 3:

[0068]

[0069]

[0070] Table 3

[0071] It should be noted that the sensitivity value level labeling can be automatically labeled by a grading and classification labeling device, or it can be manually labeled by an administrator on a classification and grading device, and this application does not limit this.

[0072] Step 103: Mark the access operation type with a risk index.

[0073] For example, if the access operation type is add, delete, modify, or query operation, a corresponding risk index OR is assigned to different access operation types, as shown in Table 4:

[0074] Operational Risk Index 0.5 0.9 1 0.8 Database Operations increase delete change check

[0075] Table 4

[0076] The risk system judgment basis in Table 3 is: when facing a threat, the loss caused by malicious operations on the database. It should be noted that the risk index can be marked according to the actual situation, and the specific index value is not limited in this application.

[0077] Step 104: Based on the correspondence between the API path and the target database, the sensitive data attributes in the target database after the sensitivity value level is marked, and the access operation type after the risk index is marked, the API is risk assessed to obtain an assessment result.

[0078] In an optional implementation manner of the present application, based on the correspondence between the API path and the target database, the sensitive data attributes in the target database after the sensitivity value level is marked, and the access operation type after the risk index is marked, the API is risk assessed to obtain an assessment result, including:

[0079] Based on the correspondence between the API path and the target database, the sensitive data attributes in the target database after the sensitivity value level is marked, and the access operation type after the risk index is marked, the risk score of the API is calculated using the following formula:

[0080]

[0081] Among them, a i,j is the sensitive value of the jth sensitive field of the ith table accessed by the API, OR i Indicates the risk index corresponding to the type of API access operation to the i-th data table. The total sensitivity value of all sensitive fields that represent API access, RI 1 The weight of the total sensitivity value of all sensitive fields accessed by the API, RI 2 The weight of the maximum sensitive value among all sensitive fields accessed by the API;

[0082] Based on the risk score of the API, the assessment result is obtained.

[0083] It should be noted that the number of sensitive fields in different databases may be different, so the value of n corresponding to different databases may be different.

[0084] The correspondence between the API path and the target database is combined with the classification information of the database sensitivity value level through the common attribute (Databasej, Tablek, Columnl), and the risk score of the API is calculated using the formula in the above embodiment.

[0085] The total sensitivity value of the fields that the API accesses is included in the API risk assessment. The highest sensitivity level of the sensitive fields that the API accesses is included in the assessment. Even if an API accesses fewer sensitive fields, the higher the sensitivity level, the greater the negative impact of data leakage on the API. Therefore, the corresponding API score will be higher, and the weight RI will be higher. 1 and RI 2 The value can be determined based on actual conditions and is not limited in this application.

[0086] For multi-table access: for example, when an API simultaneously accesses sensitive fields in K tables (K ≥ 2), all accessed sensitive fields are included in the calculation, and the database access operation risk index OR takes the maximum value of all corresponding database operation risk indexes.

[0087] The embodiment of the present application performs comprehensive risk scoring based on the total field sensitivity value, field sensitivity level, database access operations, and multi-table access conditions. The results are more objective and can better reflect the real security management and control needs. Moreover, the API comprehensive risk scoring dimension "field sensitivity level" refers to the sensitivity of the database information accessed by the API, which is more accurate than API classification by identifying sensitive data in the traffic.

[0088] For example, the field sensitivity level score is set to 0-4 points, 4 points is the highest sensitivity level, 0 points is a non-sensitive field, i,j ∈[0,4],f(API)∈[0,100),RI 1 =40, RI 2 =20. Further, the API risk level can be divided according to the API score, as shown in Table 5:

[0089]

[0090] Table 5

[0091] Schematically, the API comprehensive risk assessment report is shown in Table 6 below:

[0092]

[0093]

[0094] Table 6

[0095] In practical application, the API comprehensive risk assessment report can also be converted into structured data.

[0096] In an optional implementation manner of the present application, the method further includes:

[0097] Based on the evaluation result, a security policy is matched.

[0098] For example, the following security strategy can be adopted in the request response phase:

[0099] (1) For APIs with a risk level of 4, when access anomalies (such as high-frequency access, UA anomalies, IP anomalies, suspicious access time intervals, etc.) are detected, the request source’s access to this type of API will be blocked.

[0100] (2) For APIs with risk levels 1-3, when access anomalies (such as high-frequency access, UA anomalies, IP anomalies, suspicious access time intervals, etc.) are detected, the request source’s response to requests for this type of API will be delayed.

[0101] For data risk monitoring:

[0102] (1) For all API accesses with a risk level of 4, key information of the request is recorded, and exception information is simultaneously recorded for log auditing by the sensitive data management center.

[0103] (2) For API access with risk levels of 1-3, when abnormal access is detected (such as high-frequency access, access during suspicious time periods, etc.), key information of the request is recorded for log audit by the sensitive data management center.

[0104] By applying for the API risk assessment method and matching security strategies based on the assessment results, the protection window period of security products for sensitive APIs can be effectively shortened.

[0105] The API risk assessment method provided in the embodiment of the present application can be applied to continuous integration (CI), so that each version has a matching API comprehensive risk score report, and the API level information in the security protection product can be updated as soon as the system is upgraded to improve the protection effect. It can also be applied to other scenarios. For example, the R&D team can use sensitive field information and sensitive API lists to promptly discover whether sensitive data has transmission, storage and display risks during product iteration; it can also be provided to security vendors when conducting data security assessments on business systems, for security vendors to assess the plaintext transmission risks of sensitive information in APIs and other data security risks. In the software development stage, the APIs involved in accessing sensitive information in the database are identified simultaneously, assisting the R&D team to promptly discover and resolve the risks of plaintext transmission of sensitive information in the API during version iteration, and reduce the risk of sensitive data leakage in the business system from the root in advance. This application does not limit this.

[0106] The present application also provides an API risk assessment device 200, referring to Figure 2 The API risk assessment device 200 in this embodiment includes:

[0107] Acquisition unit 210: used to establish a correspondence between an API path and a target database, where the target database is a database accessed by the API;

[0108] The labeling unit 220 is used to label the sensitive data attributes in the target database with sensitivity levels; and is also used to label the access operation types with risk indexes;

[0109] Evaluation unit 230: used to perform risk evaluation on the API based on the correspondence between the API path and the target database, the sensitive data attributes in the target database after sensitivity value level annotation, and the access operation type after risk index annotation to obtain an evaluation result.

[0110] In an embodiment of the present application, the acquisition unit 210 is specifically used to acquire a first relationship, a second relationship, and a third relationship; wherein the first relationship represents a correspondence between the API and a first function, and the first function is a first-layer backend function that first processes the access request when the API receives an access request; the second relationship represents a correspondence between the second function and a target database, and the second function is the last function in the function call chain of the API that accesses the target database information; the third relationship represents a complete function call chain from the first function to the second function; based on the first relationship, the second relationship, and the third relationship, a correspondence between the API path and the target database is established.

[0111] In an embodiment of the present application, the correspondence between the second function and the target database includes at least one of the following correspondences: a correspondence between the second function and the name of the target database; a correspondence between the second function and access to a table in the target database; a correspondence between the second function and access to a column in a table in the target database; and a correspondence between the second function and an access operation type.

[0112] In the embodiment of the present application, the acquisition unit 210 is specifically used to analyze the source code and establish an abstract syntax tree; traverse the subtrees of all function definitions in the abstract syntax tree to acquire the first relationship, the second relationship and the third relationship.

[0113] In the embodiment of the present application, the evaluation unit 230 is specifically used to calculate the risk score of the API based on the corresponding relationship between the API path and the target database, the sensitive data attributes in the target database after the sensitivity value level is marked, and the access operation type after the risk index is marked, using the following formula:

[0114]

[0115] Among them, a i,j is the sensitive value of the jth sensitive field of the ith table accessed by the API, OR i Indicates the risk index corresponding to the type of API access operation to the i-th data table. The total sensitivity value of all sensitive fields that represent API access, RI 1 The weight of the total sensitivity value of all sensitive fields accessed by the API, RI 2 is the weight of the maximum sensitive value among all sensitive fields accessed by the API; and the assessment result is obtained based on the risk score of the API.

[0116] In the embodiment of the present application, the evaluation unit 230 is further configured to match a security policy based on the evaluation result.

[0117] Those skilled in the art should understand that Figure 2 The implementation functions of each unit in the API risk assessment device 200 shown can be understood by referring to the relevant description of the aforementioned method. Figure 2 The functions of each unit in the API risk assessment device 200 shown can be implemented by a program running on a processor, or can be implemented by a specific logic circuit.

[0118] Figure 3 It is a schematic structural diagram of an electronic device 300 provided in an embodiment of the present application. Figure 3 The electronic device 300 shown includes a processor 310, which can call and run a computer program from a memory to implement the method in the embodiment of the present application.

[0119] Alternatively, if Figure 3 As shown, the electronic device 300 may further include a memory 320. The processor 310 may call and run a computer program from the memory 320 to implement the method in the embodiment of the present application.

[0120] The memory 320 may be a separate device independent of the processor 310 , or may be integrated into the processor 310 .

[0121] Alternatively, if Figure 3 As shown, the electronic device 300 may further include a transceiver 330, and the processor 310 may control the transceiver 330 to communicate with other devices, specifically, may send information or data to other devices, or receive information or data sent by other devices.

[0122] The transceiver 330 may include a transmitter and a receiver. The transceiver 330 may further include an antenna, and the number of the antennas may be one or more.

[0123] The electronic device 300 may specifically be an API risk assessment device of an embodiment of the present application, and the electronic device 300 may implement the corresponding processes implemented by the API risk assessment device in each method of the embodiment of the present application, which will not be described in detail here for the sake of brevity.

[0124] Figure 4 It is a schematic structural diagram of the chip of an embodiment of the present application. Figure 4 The chip 400 shown includes a processor 410, which can call and run a computer program from a memory to implement the method in the embodiment of the present application.

[0125] Alternatively, if Figure 4 As shown, the chip 400 may further include a memory 420. The processor 410 may call and run a computer program from the memory 420 to implement the method in the embodiment of the present application.

[0126] The memory 420 may be a separate device independent of the processor 410 , or may be integrated into the processor 410 .

[0127] Optionally, the chip 400 may further include an input interface 430. The processor 410 may control the input interface 430 to communicate with other devices or chips, and specifically, may obtain information or data sent by other devices or chips.

[0128] Optionally, the chip 400 may further include an output interface 440. The processor 410 may control the output interface 440 to communicate with other devices or chips, and specifically, may output information or data to other devices or chips.

[0129] The chip can be applied to the API risk assessment device in the embodiment of the present application, and the chip can implement the corresponding processes implemented by the API risk assessment device in each method of the embodiment of the present application. For the sake of brevity, it will not be repeated here.

[0130] It should be understood that the chip mentioned in the embodiments of the present application can also be called a system-level chip, a system chip, a chip system or a system-on-chip chip, etc.

[0131] It should be understood that the processor of the embodiment of the present application may be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the above method embodiment can be completed by the hardware integrated logic circuit or software instructions in the processor. The above processor can be a general processor, a digital signal processor (Digital Signal Processor, DSP), an application-specific integrated circuit (Application Specific Integrated Circuit, ASIC), a field programmable gate array (Field Programmable Gate Array, FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components. The methods, steps and logic block diagrams disclosed in the embodiments of the present application can be implemented or executed. The general processor can be a microprocessor or the processor can also be any conventional processor. The steps of the method disclosed in the embodiment of the present application can be directly embodied as a hardware decoding processor to perform, or the hardware and software modules in the decoding processor are combined and performed. The software module can be located in a random access memory, a flash memory, a read-only memory, a programmable read-only memory or an electrically erasable programmable memory, a register, and other mature storage media in the art. The storage medium is located in the memory, and the processor reads the information in the memory and completes the steps of the above method in combination with its hardware.

[0132] It can be understood that the memory in the embodiments of the present application can be a volatile memory or a non-volatile memory, or can include both volatile and non-volatile memories. Among them, the non-volatile memory can be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory can be a random access memory (RAM), which is used as an external cache. By way of example and not limitation, many forms of RAM are available, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), and direct RAM bus random access memory (DR RAM). It should be noted that the memory of the systems and methods described herein is intended to include, but is not limited to, these and any other suitable types of memory.

[0133] It should be understood that the above-mentioned memory is exemplary but not restrictive. For example, the memory in the embodiments of the present application may also be static random access memory (static RAM, SRAM), dynamic random access memory (dynamic RAM, DRAM), synchronous dynamic random access memory (synchronous DRAM, SDRAM), double data rate synchronous dynamic random access memory (double data rate SDRAM, DDR SDRAM), enhanced synchronous dynamic random access memory (enhanced SDRAM, ESDRAM), synchronous link dynamic random access memory (synch link DRAM, SLDRAM) and direct memory bus random access memory (Direct Rambus RAM, DR RAM), etc. That is to say, the memory in the embodiments of the present application is intended to include but not limited to these and any other suitable types of memory.

[0134] The embodiment of the present application also provides a computer-readable storage medium for storing a computer program. The computer-readable storage medium can be applied to the API risk assessment device in the embodiment of the present application, and the computer program enables the computer to execute the corresponding processes implemented by the API risk assessment device in each method of the embodiment of the present application, which will not be described in detail here for the sake of brevity.

[0135] Those of ordinary skill in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.

[0136] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0137] In the several embodiments provided in the present application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are only schematic. For example, the division of the units is only a logical function division. There may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0138] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0139] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

[0140] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application can be essentially or partly embodied in the form of a software product that contributes to the prior art. The computer software product is stored in a storage medium, including several instructions for a computer device (which can be a personal computer, a server, or an API risk assessment device, etc.) to perform all or part of the steps of the methods described in each embodiment of the present application. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM), random access memory (RAM), disk or optical disk, and other media that can store program codes.

[0141] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any technician familiar with the technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.

Claims

1. A risk assessment method for application program interface (API). It is characterized in that include: Establishing a correspondence between an API path and a target database, wherein the target database is a database accessed by the API; Labeling sensitive data attributes in the target database with sensitivity levels; Label the access operation type with a risk index; Based on the correspondence between the API path and the target database, the sensitive data attributes in the target database after the sensitivity value level is marked, and the access operation type after the risk index is marked, the API is risk assessed to obtain an assessment result.

2. The API risk assessment method according to claim 1, It is characterized in that in, The establishing of the correspondence between the API path and the target database includes: Obtain a first relationship, a second relationship, and a third relationship; wherein the first relationship represents a corresponding relationship between the API and a first function, the first function being a first-layer backend function that first processes an access request when the API receives an access request; the second relationship represents a corresponding relationship between a second function and a target database, the second function being the last function in the function call chain of the API that accesses information of the target database; the third relationship represents a complete function call chain from the first function to the second function; Based on the first relationship, the second relationship and the third relationship, a corresponding relationship from the API path to the target database is established.

3. The API risk assessment method according to claim 2, It is characterized in that The correspondence between the second function and the target database includes at least one of the following correspondences: The corresponding relationship between the second function and the target database name; The corresponding relationship between the second function and access to the table in the target database; The corresponding relationship between the second function and accessing the column in the table in the target database; as well as, The corresponding relationship between the second function and the access operation type.

4. The API risk assessment method according to claim 2, It is characterized in that The obtaining of the first relationship, the second relationship and the third relationship includes: Analyze the source code and build an abstract syntax tree; All subtrees of function definitions in the abstract syntax tree are traversed to obtain the first relation, the second relation, and the third relation.

5. The API risk assessment method according to claim 1, It is characterized in that Based on the correspondence between the API path and the target database, the sensitive data attributes in the target database after the sensitivity value level is marked, and the access operation type after the risk index is marked, the API is risk assessed to obtain an assessment result, including: Based on the correspondence between the API path and the target database, the sensitive data attributes in the target database after the sensitivity value level is marked, and the access operation type after the risk index is marked, the risk score of the API is calculated using the following formula: Among them, a i,j is the sensitive value of the jth sensitive field of the ith table accessed by the API, OR i Indicates the risk index corresponding to the type of API access operation to the i-th data table. The total sensitivity value of all sensitive fields that represent API access, RI 1 The weight of the total sensitivity value of all sensitive fields accessed by the API, RI 2 The weight of the maximum sensitive value among all sensitive fields accessed by the API; Based on the risk score of the API, the assessment result is obtained.

6. The API risk assessment method according to any one of claims 1 to 5, It is characterized in that Also includes: Based on the evaluation result, a security policy is matched.

7. An API risk assessment device, It is characterized in that include: Acquisition unit: used to establish a correspondence between the API path and the target database, where the target database is the database accessed by the API; Annotation unit: used to annotate sensitive data attributes in the target database with sensitivity value levels; and also used to annotate access operation types with risk indexes; Evaluation unit: used to perform risk assessment on the API based on the correspondence between the API path and the target database, the sensitive data attributes in the target database after sensitivity value level annotation, and the access operation type after risk index annotation to obtain an assessment result.

8. An electronic device, It is characterized in that include: A processor and a memory, the memory being used to store a computer program, the processor being used to call and run the computer program stored in the memory to execute the API risk assessment method as described in any one of claims 1 to 6.

9. A chip, It is characterized in that include: A processor, used to call and run a computer program from a memory so that a device equipped with the chip executes the API risk assessment method as described in any one of claims 1 to 6.

10. A computer-readable storage medium, It is characterized in that Used to store a computer program, wherein the computer program enables a computer to execute the API risk assessment method according to any one of claims 1 to 6.

Citation Information

Cited By

  • Data volume synchronization method and device, equipment and medium

    CN121116177A