Test management method and device for application program
By automatically identifying and determining the login scenarios and authentication information during the vulnerability scanning process, the problem of no permissions or inability to log in in automated vulnerability scanning is solved, and support for multiple account systems is achieved.
Patent Information
- Application Number
- CN202311669665.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-07
- Publication Date
- 2025-06-13
AI Technical Summary
During the automated vulnerability scanning process, the existing technology cannot effectively identify login scenarios for different access requests, resulting in the inability to provide correct authentication information, and the problem of no permissions or inability to log in is also caused.
By responding to resource access requests, the login scenario corresponding to the access request is automatically identified and determined, and the corresponding authentication information is determined based on the login scenario and the target user identification, and provided to the vulnerability scanner to realize login.
It realizes the automatic identification of different access requests during the automated vulnerability scanning process, provides correct authentication information, solves the problem of no permissions or inability to log in, and supports vulnerability scanning of business systems with multiple account systems.
Smart Images

Figure CN120145383A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer technology, and in particular, to a method and device for testing and managing application programs. Background Art
[0002] With the continuous development of detection technology, security vulnerability testing of application programs can be carried out through dynamic application security testing, which helps to discover and repair security vulnerabilities.
[0003] In the related art, when using dynamic application security testing to perform vulnerability testing on an application program, the login problem during the scanning process is generally solved by presetting login credentials or inputting account passwords. However, this method has a single use scenario and defaults to using globally configured login credentials, and cannot support the scanning of business systems that require authentication for multiple login scenarios. Summary of the Invention
[0004] In view of this, embodiments of the present invention provide a method and device for testing and managing application programs, which can automatically identify the login scenarios of different access requests during the automated vulnerability scanning process, determine the corresponding authentication information according to different login scenarios and target user identifiers, so as to provide authentication fields for the vulnerability scanning program and solve the problem of no permission or inability to log in during the automated vulnerability scanning process.
[0005] To achieve the above object, according to one aspect of the embodiments of the present invention, a method for testing and managing application programs is provided, including:
[0006] Responding to receiving a resource access request, determining a login scenario corresponding to the access request;
[0007] Determining a target user identifier corresponding to the access request according to the login scenario;
[0008] Determining authentication information corresponding to the target user identifier, so as to perform vulnerability scanning according to the authentication information.
[0009] Optionally, determining a login scenario corresponding to the access request includes:
[0010] Obtaining a user identifier, a matching authorization type, and a matching authorization type value from the access request;
[0011] Determining the login scenario according to the user identifier, the matching authorization type, and the matching authorization type value.
[0012] Optionally, the login scenario is a first scenario; determining a target user identifier corresponding to the access request according to the login scenario includes: using the user identifier corresponding to the first scenario as the target user identifier.
[0013] Optionally, the login scenario is the second scenario;
[0014] Determining a target user identifier corresponding to the access request according to the login scenario includes: obtaining a plurality of user identifiers corresponding to the user information of the user identifier in the second scenario, and using each user identifier in the plurality of user identifiers as the target user identifier.
[0015] Optionally, the authentication information includes a plurality of authentication fields and an authentication location. After determining the authentication information corresponding to the target user identifier, it includes:
[0016] Concatenate the plurality of authentication fields and save them at the target location indicated by the authentication location, so as to authenticate the plurality of authentication fields based on the target location.
[0017] Optionally, the login scenario is the third scenario; the matching authorization type value is a nested type value;
[0018] Determining a target user identifier corresponding to the access request according to the login scenario includes: obtaining a plurality of user identifiers corresponding to the user information of the user identifier in the third scenario; using any one of the plurality of user identifiers as the target user identifier;
[0019] Determining the authentication information corresponding to the target user identifier includes: obtaining a plurality of authentication information corresponding to the nested type value of any one of the user identifiers, and using the combination of the plurality of authentication information as the authentication information corresponding to the target user identifier.
[0020] Optionally, the access request is an encrypted access request, and the access request indicates a user identifier. Before determining the login scenario corresponding to the access request, it further includes:
[0021] Obtain the corresponding authentication decryption information according to the user identifier;
[0022] Use the authentication decryption information to decrypt the encrypted access request to obtain a decrypted access request.
[0023] Optionally, before determining the authentication information corresponding to the target user identifier, it further includes:
[0024] Configure the authentication information corresponding to the target user identifier;
[0025] Use the login script corresponding to the login scenario to verify the authentication information to verify whether the authentication information is invalid;
[0026] In the case where the authentication information is invalid, update the authentication information.
[0027] According to another aspect of the embodiments of the present invention, there is provided a test management device for an application program, including:
[0028] A first determination module, which, in response to receiving a resource access request, determines a login scenario corresponding to the access request;
[0029] A second determination module, which determines a target user identifier corresponding to the access request according to the login scenario;
[0030] A third determination module, which determines authentication information corresponding to the target user identifier, so as to perform vulnerability scanning according to the authentication information.
[0031] According to another aspect of the embodiments of the present invention, there is provided an electronic device, including:
[0032] One or more processors;
[0033] A storage device for storing one or more programs,
[0034] When the one or more programs are executed by the one or more processors, the one or more processors implement the test management method for an application program provided by the present invention.
[0035] According to still another aspect of the embodiments of the present invention, there is provided a computer-readable medium, on which a computer program is stored, and when the program is executed by a processor, the test management method for an application program provided by the present invention is implemented.
[0036] One of the embodiments of the above invention has the following advantages or beneficial effects: The test management method for an application program in the embodiments of the present invention, after receiving a resource access request, determines a login scenario corresponding to the access request, then determines a target user identifier corresponding to the access request according to the login scenario, and determines authentication information corresponding to the target user identifier, so as to perform vulnerability scanning using the authentication information. This method can automatically identify the login scenarios of different access requests during the automated vulnerability scanning process, determine the corresponding authentication information according to different login scenarios and target user identifiers, thereby providing authentication fields for the vulnerability scanning program and solving the problems of no permission or inability to log in during the vulnerability scanning process.
[0037] The further effects of the above non-conventional optional manners will be described in combination with specific embodiments below. BRIEF DESCRIPTION OF THE DRAWINGS
[0038] The drawings are used to better understand the present invention and do not constitute an improper limitation of the present invention. Among them:
[0039] Figure 1 is a schematic diagram of the main process of a test management method for an application program according to an embodiment of the present invention;
[0040] Figure 2 It is a schematic diagram of the main process of another application program test management method according to an embodiment of the present invention;
[0041] Figure 3 It is a schematic diagram of the main process of an application program test management method according to an embodiment of the present invention;
[0042] Figure 4 It is a schematic diagram of the main modules of an application program test management device according to an embodiment of the present invention;
[0043] Figure 5 It is an exemplary system architecture diagram to which the embodiments of the present invention can be applied;
[0044] Figure 6 It is a schematic diagram of the structure of a computer system of a terminal device or a server suitable for implementing the embodiments of the present invention. Detailed implementation manners
[0045] The following describes exemplary embodiments of the present invention with reference to the accompanying drawings. Various details of the embodiments of the present invention are included to facilitate understanding, and they should be considered merely exemplary. Therefore, those of ordinary skill in the art should recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of the present invention. Similarly, for the sake of clarity and conciseness, descriptions of well-known functions and structures are omitted below.
[0046] It should be noted that in the technical solutions of the present disclosure, in terms of the collection, gathering, updating, analysis, processing, use, transmission, storage, etc. of user personal information, they all comply with the provisions of relevant laws and regulations, are used for legal purposes, and do not violate public order and good customs. Necessary measures are taken for user personal information to prevent illegal access to user personal information data, and to safeguard user personal information security, network security, and national security.
[0047] Figure 1 It is a schematic diagram of the main process of an application program test management method according to an embodiment of the present invention. As Figure 1 shown, the method includes the following steps:
[0048] Step S101: In response to receiving a resource access request, determine the login scenario corresponding to the access request;
[0049] Step S102: Determine the target user identifier corresponding to the access request according to the login scenario;
[0050] Step S103: Determine the authentication information corresponding to the target user identifier to perform vulnerability scanning according to the authentication information.
[0051] In an embodiment of the present invention, the test management method of the application program can ensure the stable operation of the vulnerability scanning process by providing authentication information for logging in when performing vulnerability scanning on a dynamic application program.
[0052] In an embodiment of the present invention, the resource access request is a request to access resources in the application program. For the resources in the application program, the corresponding relationship between roles, resources, and permissions can be configured, that is, the access permissions of different user roles to resources can be configured. After receiving the user's resource access request, the login scenario corresponding to the access request is determined. The authentication information of the user corresponding to different login scenarios is different. By identifying different login scenarios, the corresponding authentication information is obtained to ensure the normal login status of the vulnerability scanning under different login scenarios.
[0053] In an embodiment of the present invention, as Figure 2 shown, determining the login scenario corresponding to the access request may include:
[0054] Step S201: Obtain the user identifier, matching authorization type, and matching authorization type value from the access request;
[0055] Step S202: Determine the login scenario according to the user identifier, matching authorization type, and matching authorization type value.
[0056] In an embodiment of the present invention, after receiving the access request, the user identifier, matching authorization type, and matching authorization type value can be obtained from the access request. The user identifier can be the user ID and can be used to identify the user identity. The matching authorization type can be at least one of fields such as domain name, path, parameter, etc. The matching authorization type value is the field value corresponding to the matching authorization type. Then, the login scenario can be determined according to the user identifier, matching authorization type, and matching authorization type value.
[0057] In an embodiment of the present invention, after receiving the access request, the source identifier corresponding to the access request can be obtained. The source identifier indicates the user identifier. Then, the matching authorization type and matching authorization type value are obtained from the access request. Then, the login scenario is determined according to the user identifier, matching authorization type, and matching authorization type value.
[0058] In an embodiment of the present invention, after determining the login scenario corresponding to an access request, the target user identifier corresponding to the access request can be determined according to the login scenario, and the authentication information corresponding to the target user identifier can be determined, that is, the decoupling of the login scenario and the authentication information is achieved through the target user identifier. The target user identifier is used to obtain the authentication information, and the authentication information corresponding to the target user identifier can be the authentication information of the target user identifier in this login scenario. That is, the association relationship between the login scenario, the target user identifier, and the authentication information is pre-configured. For example, for any domain name, the user identifier that can access the any domain name is configured, the authentication information corresponding to the user identifier is configured, and the corresponding user information can be obtained through the user identifier, so that the domain name is associated with the user identifier or user information, and the user identifier and user information are associated with the authentication information, and at the same time, the management of roles, resources, and permissions is realized.
[0059] In an embodiment of the present invention, determining the login scenario according to the user identifier, the matching authorization type, and the matching authorization type value may include: when the matching authorization type is the domain name field, the matching authorization type value is the domain name value, and the user information corresponding to the user identifier is one-to-one with the user identifier, the login scenario is the first scenario. The user information includes information such as the login account and login password. Determining the target user identifier corresponding to the access request according to the login scenario includes: using the user identifier corresponding to the first scenario as the target user identifier. Determining the authentication information corresponding to the target user identifier may include: determining the authentication information corresponding to the target user identifier according to the login scenario, that is, obtaining the authentication information of the target user identifier in the first scenario. That is, in the first scenario, the user identifier obtained from the access request can be used as the target user identifier to obtain the corresponding authentication information. That is, for the case where multiple resource access requests are for the same user identifier to access multiple different domain names, the user identifier can be used as the target user identifier to obtain the corresponding authentication information for authentication during vulnerability scanning.
[0060] In an embodiment of the present invention, determining a login scenario according to a user identifier, a matching authorization type, and a matching authorization type value may include: when the matching authorization type is a domain name field, the matching authorization type value is a domain name value, and the user information corresponding to the user identifier corresponds to multiple user identifiers, the login scenario is the second scenario. Determining a target user identifier corresponding to an access request according to the login scenario may include: using each of the multiple user identifiers corresponding to the user information corresponding to the user identifier in the second scenario as the target user identifier. Among them, the multiple user identifiers may correspond to multiple clients, such as a Web side and a mobile side. That is, in the second scenario, for the case where the same user information accesses the same domain name on different clients, each of the multiple user identifiers corresponding to the user information may be used as the target user identifier. Determining authentication information corresponding to the target user identifier, that is, respectively obtaining the authentication information of each target user identifier, and the authentication information corresponding to each target user identifier is different; then, combining the authentication information of each target user identifier to obtain the authentication information corresponding to the login scenario or the access request. Among them, the authentication information includes an authentication field, an authentication position, etc., and combining each authentication information may include concatenating each authentication field. That is to say, in the second scenario, accessing the domain name requires combining multiple authentication fields for use.
[0061] In an embodiment of the present invention, determining a login scenario based on a user identifier, a matching authorization type, and a matching authorization type value includes: when the matching authorization type is the first type, the matching authorization type value is a nested type value, and the user information corresponding to the user identifier corresponds to multiple user identifiers, determining that the login scenario is the third scenario. Wherein, the first type may be a domain name field, and the nested type value may be a nested domain name value, that is, when the matching authorization type is a domain name field, the matching authorization type value is a nested domain name value, and the user information corresponding to the user identifier corresponds to multiple user identifiers, determining that the login scenario is the third scenario. The third scenario may be that the access request needs to be authenticated through a unified login system and then the subsequent authentication logic is performed, that is, the login secondary nesting scenario. Determining the target user identifier corresponding to the access request according to the login scenario may include: using any one of the multiple user identifiers in the third scenario as the target user identifier. Determining the authentication information corresponding to the target user identifier may include: obtaining multiple authentication information corresponding to the nested type value of any one user identifier, and using the combination of the multiple authentication information as the authentication information corresponding to the target user identifier, that is, concatenating multiple authentication fields corresponding to the multiple authentication information. Among them, the multiple authentication information may include the first authentication information for unified login authentication and the second authentication information for performing subsequent authentication logic. When obtaining multiple authentication information corresponding to the nested type value of any one user identifier, obtaining the first authentication information for unified login authentication according to the any one user identifier, and then obtaining the second authentication information for subsequent authentication logic according to the any one user identifier and the first authentication information to obtain multiple authentication information. That is, the second authentication information for subsequent authentication logic is obtained on the basis of obtaining the first authentication information for unified login authentication.
[0062] In an embodiment of the present invention, determining a login scenario based on a user identifier, a matching authorization type, and a matching authorization type value may include: when the matching authorization type is a parameter, the matching authorization type value is a service type, and the user information corresponding to the user identifier corresponds one-to-one with the user identifier, determining that the login scenario is the fourth scenario, and the fourth scenario may be a gateway type scenario. Determining the target user identifier corresponding to the access request according to the login scenario may include: using the user identifier corresponding to the fourth scenario as the target user identifier. Determining the authentication information corresponding to the target user identifier includes: using the authentication information of the user identifier corresponding to the fourth scenario as the authentication information corresponding to the target user identifier. In this fourth scenario, if the domain names are the same but the parameters are different, then the corresponding service types are different, and the authentication information corresponding to different service types is different.
[0063] In an embodiment of the present invention, the authentication information includes an authentication field, an authentication location, and may also include an authentication type, an authorization status, etc. The authentication type corresponds to a login scenario, and the authorization status indicates whether the authentication information is valid. The authentication location is the location where the authentication field is saved, that is, the location where the authentication of the authentication field is performed. The authentication location can be custom-set, such as it can be a cookie or the request header (header) of an access request. If it is necessary to authenticate the authentication information in the request header header of an access request, and the authentication information includes multiple authentication fields, after determining the authentication information corresponding to the target user identifier, the multiple authentication fields are concatenated and saved at the target location indicated by the authentication location, so as to authenticate the multiple authentication fields based on the target location. Among them, the target location can be the request header header of the access request. That is, for authentication based on the header, multiple authentication fields need to be used in combination.
[0064] In an embodiment of the present invention, the access request may be an encrypted access request. For example, the matching authorization type is a parameter, the matching authorization type value is an encrypted domain name value, and the user information corresponding to the user identifier corresponds one-to-one with the user identifier. This login scenario is an interface encryption and decryption scenario, and the parameter may be a network parameter. In this scenario, it is necessary to decrypt the encrypted access request in real time to obtain a valid access request. The access request indicates the user identifier, and the user identifier corresponding to the access request can also be obtained. Then, according to the user identifier, the corresponding authentication decryption information is obtained in combination with this interface encryption and decryption scenario. The encrypted access request can be decrypted by using the authentication decryption information to obtain the decrypted access request, and the authentication information corresponding to the access request can be obtained according to the decrypted access request for vulnerability scanning.
[0065] In an embodiment of the present invention, determining the authentication information corresponding to the target user identifier may further include: obtaining multiple authentication information corresponding to the target user identifier, the multiple authentication information indicating different authentication locations, concatenating the multiple authentication information to obtain authentication information, and saving the authentication information at the location indicated by a preset authentication location for vulnerability scanning.
[0066] In an embodiment of the present invention, before obtaining the authentication information corresponding to the target user identifier, the authentication information corresponding to the target user identifier is configured, that is, the authentication information of different user identifiers is pre-configured, and the user identifier is associated with the authentication information. When configuring the authentication information corresponding to the target user identifier, it can be configured in combination with the login scenario, that is, the authentication information corresponding to the user identifier under different login scenarios is configured.
[0067] In the embodiment of the present invention, after obtaining the authentication information corresponding to the target user identifier, or after configuring the authentication information corresponding to the target user identifier, it also includes: periodically verifying the authentication information using a login script corresponding to the login scenario to verify whether the authentication information is invalid, if so, updating the authentication information, if not, not updating the authentication information to maintain the identity authority. By periodically verifying the authentication information through the login script, it is possible to effectively identify whether the pre-authentication information is invalid, and update the authentication information when it is invalid, so as to maintain the login status during the vulnerability scanning process.
[0068] In an embodiment of the present invention, the login script corresponding to the login scenario is a custom script. Before the login script corresponding to the login scenario is used to verify the authentication information, it also includes: creating a login script corresponding to the login scenario. The login script is a login script customized based on a plug-in. Creating a login script corresponding to the login scenario includes: writing a plug-in code corresponding to the login scenario, wherein the plug-in code contains functions such as verifying whether the authentication information is valid, maintaining identity authority (i.e., authentication information), obtaining new identity authority, and requesting encryption and decryption for calling; compiling the plug-in code to obtain a plug-in compilation file, wherein the Go-based build command can be used for compilation; loading the plug-in file, the plugin.Open function can be used to dynamically load the plug-in file; reflecting the calling function, reflecting the login script in the plug-in through the plugin.Lookup function, that is, realizing the calling of the function in the plug-in through reflection technology. Create corresponding login scripts for different login scenarios. When the login scenario is updated or increased, it can be achieved by adding or updating the login script without modifying or recompiling the main program, i.e., the vulnerability scanning product, and has strong flexibility.
[0069] Figure 3 The invention discloses a test management method for an application program of an embodiment of the present invention. Receive a resource access request, i.e., traffic; perform scene matching to determine a login scene corresponding to the accessed resource; obtain corresponding authentication information according to the login scene; perform vulnerability scanning according to the authentication information; before obtaining the authentication information, associate the user information with the authentication information, and then use a custom login script to verify the identity and authority of the authentication information to determine whether the authentication information is invalid; if so, update the authentication information and associate the updated authentication information with the user information; if not, maintain the identity and authority and do not update the authentication information.
[0070] The test management method of the application program according to the embodiment of the present invention, after receiving a resource access request, determines the login scenario corresponding to the access request, then determines the target user identifier corresponding to the access request according to the login scenario, and determines the authentication information corresponding to the target user identifier, so as to use the authentication information for vulnerability scanning. This method can automatically identify the login scenarios of different access requests during the automated vulnerability scanning process, determine the corresponding authentication information according to different login scenarios and target user identifiers, thereby providing authentication fields for the vulnerability scanning program, and solving the problem of no permission or inability to log in during the vulnerability scanning process, that is, supporting the vulnerability scanning of business systems that support multiple account system authentications; this method verifies whether the authentication information is invalid through a login script to determine whether to update the authentication information, ensuring the validity of the authentication information and the login status; this method can identify the login scenarios that specifically identify the permissions of specific users in a fine-grained manner and obtain the corresponding authentication information; this method realizes the management of permissions and roles and the access control of resources through the association relationship between the login scenario, user information, and authentication information; the login scenario in this method is extensible, so as to facilitate the use of authentication and access control in different login scenarios.
[0071] As Figure 4 shown, on the other hand, the embodiment of the present invention provides a test management device 400 for an application program, including:
[0072] A first determination module 401, in response to receiving a resource access request, determines the login scenario corresponding to the access request;
[0073] A second determination module 402, determines the target user identifier corresponding to the access request according to the login scenario;
[0074] A third determination module 403, determines the authentication information corresponding to the target user identifier, so as to perform vulnerability scanning according to the authentication information.
[0075] In the embodiment of the present invention, the first determination module 401 is further configured to: obtain the user identifier, matching authorization type, and matching authorization type value from the access request; determine the login scenario according to the user identifier, matching authorization type, and matching authorization type value.
[0076] In the embodiment of the present invention, the login scenario is the first scenario; the second determination module 402 is further configured to: use the user identifier corresponding to the first scenario as the target user identifier.
[0077] In the embodiment of the present invention, the login scenario is the second scenario; the second determination module 402 is further configured to: obtain multiple user identifiers corresponding to the user information of the user identifier in the second scenario, and use each user identifier in the multiple user identifiers as the target user identifier.
[0078] In an embodiment of the present invention, the authentication information includes a plurality of authentication fields and an authentication location. The third determination module 403 is further configured to: after determining the authentication information corresponding to the target user identifier, splice the plurality of authentication fields and save them at the target location indicated by the authentication location, so as to authenticate the plurality of authentication fields based on the target location.
[0079] In an embodiment of the present invention, the login scenario is the third scenario; the matching authorization type value is a nested type value; the second determination module 402 is further configured to: obtain a plurality of user identifiers corresponding to the user information of the user identifier in the third scenario; use any one of the plurality of user identifiers as the target user identifier;
[0080] The third determination module 403 is further configured to: obtain a plurality of authentication information corresponding to the nested type value of any user identifier, and use the combination of the plurality of authentication information as the authentication information corresponding to the target user identifier.
[0081] In an embodiment of the present invention, the access request is an encrypted access request, and the access request indicates the user identifier. The first determination module 401 is further configured to: before determining the login scenario corresponding to the access request, further include: obtaining the corresponding authentication decryption information according to the user identifier; using the authentication decryption information to decrypt the encrypted access request to obtain the decrypted access request.
[0082] In an embodiment of the present invention, the third determination module 403 is further configured to: before determining the authentication information corresponding to the target user identifier, configure the authentication information corresponding to the target user identifier; use the login script corresponding to the login scenario to verify the authentication information to verify whether the authentication information is invalid; in the case where the authentication information is invalid, update the authentication information.
[0083] Figure 5 An exemplary system architecture 500 of a test management method for an application program or a test management device for an application program to which embodiments of the present invention can be applied is shown.
[0084] As Figure 5 shown, the system architecture 500 may include terminal devices 501, 502, 503, a network 504, and a server 505. The network 504 is used as a medium for providing a communication link between the terminal devices 501, 502, 503 and the server 505. The network 504 may include various connection types, such as wired, wireless communication links, or fiber optic cables, etc.
[0085] Users can use terminal devices 501, 502, and 503 to interact with server 505 via network 504 to receive or send messages, etc. Various communication client applications can be installed on terminal devices 501, 502, and 503, such as shopping applications, web browser applications, search applications, instant messaging tools, email clients, social platform software, etc. (for example only).
[0086] Terminal devices 501, 502, and 503 can be various electronic devices with a display screen and supporting web browsing, including but not limited to smartphones, tablets, laptop computers, desktop computers, and so on.
[0087] Server 505 can be a server that provides various services, such as a background management server that supports shopping websites browsed by users using terminal devices 501, 502, and 503 (for example only). The background management server can analyze and process data such as product information query requests received, and feedback the processing results (such as target push information, product information - for example only) to the terminal device.
[0088] It should be noted that the test management method of the application program provided by the embodiments of the present invention is generally executed by server 505. Correspondingly, the test management device of the application program is generally set in server 505.
[0089] It should be understood that Figure 5 the numbers of terminal devices, networks, and servers in
[0090] are merely illustrative. According to actual needs, there can be any number of terminal devices, networks, and servers. Figure 6 Shown below is a schematic structural diagram of a computer system 600 of a terminal device suitable for implementing the embodiments of the present invention with reference to Figure 6 The shown terminal device is merely an example and should not impose any limitations on the functions and usage scope of the embodiments of the present invention.
[0091] As Figure 6 shown, computer system 600 includes a central processing unit (CPU) 601, which can perform various appropriate actions and processes according to the program stored in the read-only memory (ROM) 602 or the program loaded from the storage section 608 into the random access memory (RAM) 603. In the RAM 603, various programs and data required for the operation of the system 600 are also stored. The CPU 601, ROM 602, and RAM 603 are connected to each other via a bus 604. The input / output (I / O) interface 605 is also connected to the bus 604.
[0092] The following components are connected to the I / O interface 605: an input section 606 including a keyboard, a mouse, etc.; an output section 607 including a cathode ray tube (CRT), a liquid crystal display (LCD), etc. and a speaker, etc.; a storage section 608 including a hard disk, etc.; and a communication section 609 including a network interface card such as a LAN card, a modem, etc. The communication section 609 performs communication processing via a network such as the Internet. A drive 610 is also connected to the I / O interface 605 as required. A removable medium 611 such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc. is mounted on the drive 610 as required so that a computer program read therefrom is installed into the storage section 608 as required.
[0093] Specifically, according to the embodiments disclosed in the present invention, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, the embodiments disclosed in the present invention include a computer program product which includes a computer program carried on a computer-readable medium, and the computer program includes program codes for performing the methods shown in the flowcharts. In such an embodiment, the computer program can be downloaded and installed from the network via the communication section 609, and / or installed from the removable medium 611. When the computer program is executed by a central processing unit (CPU) 601, the above-described functions defined in the system of the present invention are executed.
[0094] It should be noted that the computer-readable medium shown in the present invention can be a computer-readable signal medium, a computer-readable storage medium, or any combination of the above two. The computer-readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples of the computer-readable storage medium can include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present invention, the computer-readable storage medium can be any tangible medium that contains or stores a program, and this program can be used by or in conjunction with an instruction execution system, apparatus, or device. In the present invention, the computer-readable signal medium can include a data signal propagated in a baseband or as part of a carrier wave, in which the computer-readable program code is carried. Such a propagated data signal can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The computer-readable signal medium can also be any computer-readable medium other than the computer-readable storage medium, and this computer-readable medium can send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted using any appropriate medium, including but not limited to: wireless, wire, optical cable, RF, etc., or any suitable combination of the above.
[0095] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present invention. In this regard, each block in the flowchart or block diagram can represent a module, a program segment, or a part of code, and the above module, program segment, or part of code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram or flowchart, and the combination of blocks in the block diagram or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.
[0096] The modules involved in the embodiments of the present invention can be implemented in software or in hardware. The described modules can also be provided in a processor. For example, it can be described as: a processor includes a first determination module, a second determination module, and a third determination module. Among them, the names of these modules do not constitute a limitation to the module itself in some cases. For example, the first determination module can also be described as "a module for determining a login scenario corresponding to an access request".
[0097] As another aspect, the present invention also provides a computer-readable medium. The computer-readable medium can be included in the device described in the above embodiments; or it can exist separately without being assembled into the device. The above computer-readable medium carries one or more programs. When the one or more programs are executed by the device, the device includes: determining a login scenario corresponding to the access request in response to receiving a resource access request; determining a target user identifier corresponding to the access request according to the login scenario; determining authentication information corresponding to the target user identifier to perform vulnerability scanning according to the authentication information.
[0098] According to the technical solution of the embodiments of the present invention, for the test management method of the application program, after receiving a resource access request, it determines a login scenario corresponding to the access request, then determines a target user identifier corresponding to the access request according to the login scenario, and determines authentication information corresponding to the target user identifier to perform vulnerability scanning using the authentication information. This method can automatically identify the login scenarios of different access requests during the automated vulnerability scanning process, determine the corresponding authentication information according to different login scenarios and target user identifiers, so as to provide authentication fields for the vulnerability scanning program, and solve the problem of no permission or inability to log in during the vulnerability scanning process, that is, support the vulnerability scanning of business systems that support multi-account system authentication; this method verifies whether the authentication information is invalid through a login script to determine whether to update the authentication information, ensuring the effectiveness of the authentication information and the login status; this method can identify the login scenarios that specifically identify the permissions of specific users in a fine-grained manner and obtain the corresponding authentication information; this method realizes the management of permissions and roles and the access control of resources through the association relationship between the login scenario, user information, and authentication information; the login scenario in this method is extensible to facilitate the use of authentication and access control in different login scenarios.
[0099] The above specific embodiments do not constitute a limitation to the protection scope of the present invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can occur depending on design requirements and other factors. Any modifications, equivalent replacements, and improvements made within the spirit and principles of the present invention shall be included within the protection scope of the present invention.
Claims
1. A method for testing management of an application, characterized in that, it includes: Responding to receiving a resource access request, determining a login scenario corresponding to the access request; Determining a target user identifier corresponding to the access request according to the login scenario; Determining authentication information corresponding to the target user identifier, so as to perform vulnerability scanning according to the authentication information.
2. The method according to claim 1, characterized in that, Determining a login scenario corresponding to the access request includes: Obtaining a user identifier, a matching authorization type, and a matching authorization type value from the access request; Determining the login scenario according to the user identifier, the matching authorization type, and the matching authorization type value.
3. The method according to claim 2, characterized in that, The login scenario is the first scenario; Determining a target user identifier corresponding to the access request according to the login scenario includes: using the user identifier corresponding to the first scenario as the target user identifier.
4. The method according to claim 2, characterized in that, The login scenario is the second scenario; Determining a target user identifier corresponding to the access request according to the login scenario includes: obtaining a plurality of user identifiers corresponding to the user information of the user identifier in the second scenario, and using each user identifier in the plurality of user identifiers as the target user identifier.
5. The method according to claim 2, characterized in that, The authentication information includes a plurality of authentication fields and an authentication position. After determining the authentication information corresponding to the target user identifier, it includes: Concatenating the plurality of authentication fields and storing them at the target position indicated by the authentication position, so as to authenticate the plurality of authentication fields based on the target position.
6. The method according to claim 2, characterized in that, The login scenario is the third scenario; the matching authorization type value is a nested type value; Determining a target user identifier corresponding to the access request according to the login scenario includes: obtaining a plurality of user identifiers corresponding to the user information of the user identifier in the third scenario; using any one of the plurality of user identifiers as the target user identifier; Determining the authentication information corresponding to the target user identifier includes: obtaining a plurality of authentication information corresponding to the nested type value of any one of the user identifiers, and using the combination of the plurality of authentication information as the authentication information corresponding to the target user identifier.
7. The method according to claim 1, characterized in that, The access request is an encrypted access request, and the access request indicates a user identifier. Before determining a login scenario corresponding to the access request, it further includes: Obtaining corresponding authentication decryption information according to the user identifier; Using the authentication decryption information to decrypt the encrypted access request to obtain a decrypted access request.
8. The method according to claim 2, characterized in that, Before determining the authentication information corresponding to the target user identifier, it further includes: Configuring the authentication information corresponding to the target user identifier; Verify the authentication information using a login script corresponding to the login scenario to verify whether the authentication information has expired; Update the authentication information in the case where the authentication information has expired.
9. A test management device for an application, characterized in that, comprising: A first determination module, which determines a login scenario corresponding to the access request in response to receiving a resource access request; A second determination module, which determines a target user identifier corresponding to the access request according to the login scenario; A third determination module, which determines authentication information corresponding to the target user identifier to perform vulnerability scanning according to the authentication information.
10. An electronic device, characterized in that, comprising: One or more processors; A storage device for storing one or more programs, When the one or more programs are executed by the one or more processors, the one or more processors implement the method according to any one of claims 1-8.
11. A computer-readable medium, on which a computer program is stored, characterized in that, The program, when executed by a processor, implements the method according to any one of claims 1-8.