Single-page application dynamic vulnerability backtracking detection method based on state atlas
The state graph-based method for SPA vulnerability detection addresses the limitations of existing tools by capturing dynamic content and enabling backtracking, enhancing detection coverage and efficiency.
Patent Information
- Application Number
- CN202510402151.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-01
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2045-04-01
AI Technical Summary
Existing single-page application vulnerability detection methods cannot effectively identify asynchronously loaded dynamic content and cross-page vulnerability chains, and cannot fall back to historical status for detection.
By building a state map, monitoring front-end applications, recording page jump relationships and DOM structures, injecting test loads, cross-state backtracking and DOM differences analysis, and positioning cross-page vulnerability chains.
Dynamic vulnerability backtracking detection for single-page applications is realized, the coverage and efficiency of vulnerability detection is improved, and the vulnerability chains triggered across pages and multiple states can be identified, reducing false triggering and redundant operations.
Smart Images

Figure CN120316780A_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present invention relate to the field of information security technology, and in particular, to a method for dynamically detecting and backtracking vulnerabilities of single-page applications based on a state graph. Background Art
[0002] Currently, for vulnerability detection of SPA (Single Page Web Application), such as crawlers based on HTML parsing, only the initial static structure of the page is analyzed, resulting in complete omission of dynamically loaded content (such as pop-ups triggered by user interaction, dynamic forms, or modules rendered by AJAX requests). At the same time, current detection technologies only support one-way state advancement (such as from page A to page B, and then to page C), and cannot roll back to historical states (such as returning from page C to page B), thus unable to identify cross-page vulnerability chains (such as input parameters on page B triggering an XSS vulnerability when rendering page C).
[0003] In view of this, the present invention is proposed. Summary of the Invention
[0004] The embodiments of the present invention provide a method for dynamically detecting and backtracking vulnerabilities of single-page applications based on a state graph to solve the above technical problems.
[0005] In a first aspect, the embodiments of the present invention provide a method for dynamically detecting and backtracking vulnerabilities of single-page applications based on a state graph, including:
[0006] By monitoring the front-end application, a state graph is constructed, where the state graph uses each front-end application page as a node, and the jump relationship between each front-end application page as an edge between nodes, and each node attribute includes the DOM structure and timing information of each front-end application page when it is loaded each time;
[0007] Inject test payloads into the front-end application pages. During the test, every time a new front-end application page is detected, the following operations are sequentially performed:
[0008] S1-1. If the new front-end application page triggers a vulnerability, roll back to the initial front-end application page in the state graph to reproduce other vulnerability entry points of the initial front-end application page;
[0009] S1-2. If the new front-end application page does not trigger a vulnerability, determine the backtracking depth of the superior front-end application page in the state graph according to the abnormal situation of the new front-end application page; and for the end page of the backtracking, compare the DOM structure after backtracking with the initial DOM structure in the state graph to determine the area where the DOM structure has changed; scan for vulnerabilities in this area to locate the vulnerability chain caused by cross-page data transfer.
[0010] In a second aspect, an embodiment of the present invention provides an electronic device, which includes:
[0011] One or more processors;
[0012] A memory for storing one or more programs,
[0013] When the one or more programs are executed by the one or more processors, the one or more processors implement the single-page application dynamic vulnerability backtracking detection method based on a state graph according to any embodiment.
[0014] In a third aspect, an embodiment of the present invention further provides a computer-readable storage medium, on which a computer program is stored, and when the program is executed by a processor, it implements the single-page application dynamic vulnerability backtracking detection method based on a state graph according to any embodiment.
[0015] In summary, an embodiment of the present invention proposes a single-page application dynamic vulnerability backtracking detection method based on a state graph, which realizes multi-dimensional vulnerability mining and risk analysis in SPA applications through deep integration of runtime state tracking and automated interaction simulation of the front-end framework. Different from traditional vulnerability detection methods, this embodiment dynamically executes JavaScript code based on a headless browser, can capture asynchronously loaded content (such as pop-ups triggered by user clicks, dynamic forms, and AJAX rendering modules), and effectively breaks through the limitation that traditional tools only analyze static page structures.
[0016] The method of this embodiment constructs a traceable state graph, accurately records each page jump, data change, and user interaction behavior, can backtrack between multiple historical states, and track the formation process of the vulnerability chain. For example, some input data is submitted on page A, and after being processed on page B, an XSS vulnerability may be triggered on page C. The system can backtrack to the state of page A and, through differential analysis, discover the vulnerability chain triggered across pages and multiple states. Through this backtracking mechanism, the present invention breaks through the limitation that traditional tools cannot trigger multi-step vulnerability chain detection and improves the vulnerability mining ability of dynamic Web applications.
[0017] Specifically, through the cross-state backtracking mechanism, dynamic state tracking and backtracking are realized in a single-page application. Different from traditional static analysis methods, the device can accurately track and analyze data flow when the application reverts from one state (such as a payment page) to a historical state (such as an order page). By constructing a state graph, the device records the change path from one state to another state, and combines with the DOM difference analysis algorithm to efficiently identify the vulnerability chain that may be triggered during state changes. This innovative mechanism can accurately capture potential vulnerabilities in cross-page and cross-state interactions, significantly improving the coverage rate and efficiency of vulnerability detection; Brief Description of the Drawings
[0018] In order to more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the following will briefly introduce the drawings required for the description of the specific embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0019] Figure 1 is a flowchart of a method for dynamically detecting and backtracking vulnerabilities in a single-page application based on a state graph provided by an embodiment of the present invention;
[0020] Figure 2 is a flowchart of another method for dynamically detecting and backtracking vulnerabilities in a single-page application based on a state graph provided by an embodiment of the present invention;
[0021] Figure 3 is a schematic structural diagram of an electronic device provided by an embodiment of the present invention. Detailed Description of the Embodiments
[0022] To make the objectives, technical solutions, and advantages of the present invention clearer, the following will clearly and completely describe the technical solutions of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, rather than all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts fall within the scope of protection of the present invention.
[0023] In the description of the present invention, it should be noted that the orientation or positional relationship indicated by the terms "center", "upper", "lower", "left", "right", "vertical", "horizontal", "inner", "outer", etc. is based on the orientation or positional relationship shown in the drawings, and is only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore cannot be understood as a limitation of the present invention. In addition, the terms "first", "second", and "third" are only used for descriptive purposes and cannot be understood as indicating or implying relative importance.
[0024] In the description of the present invention, it should also be noted that unless otherwise clearly defined and limited, the terms "installed", "connected", and "connected" should be understood in a broad sense. For example, it can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be directly connected or indirectly connected through an intermediate medium, and it can be the internal communication of two elements. For those of ordinary skill in the art, the specific meanings of the above terms in the present invention can be understood according to specific situations.
[0025] Figure 1 It is a flowchart of a method for dynamically detecting and backtracking vulnerabilities of single-page applications based on a state graph provided by an embodiment of the present invention. This method is applicable to the situation of detecting vulnerabilities in SPAs, aiming to improve the accuracy, efficiency, and comprehensiveness of single-page application vulnerability detection, especially in the detection of dynamic interactions, state backtracking, and cross-page vulnerability chains, and solve the problem that existing vulnerability detection methods cannot handle the complexity and multi-state interactions of SPAs. This method is executed by an electronic device, such as Figure 1 shown, and specifically includes the following steps:
[0026] S110. By monitoring the front-end application, a state graph is constructed, where the state graph takes each front-end application page as a node, and the jump relationship between each front-end application page as an edge between nodes. Each node attribute includes the DOM (Document Object Model) structure and timing information when each front-end application page is loaded each time.
[0027] The state graph of this embodiment is used to record the dynamic jump relationship between each front-end application page and the timing change information of the page in the user interaction behavior. This state graph can be gradually generated during the actual user interaction, or can be gradually generated when specifically detecting vulnerabilities for SPAs.
[0028] Optionally, when the current page of the front-end application is loaded each time, if the page is not loaded for the first time, a node of the current page can be generated in the state graph of the front-end application, and the current DOM structure and its timing information of the page are stored in the attributes of the node; if the page is not loaded for the first time, the current DOM structure and its timing information can be directly stored in the attributes of the corresponding node. In addition, if the current front-end application page jumps from other front-end application pages, a directed edge is established between the node and the node of the other front-end application page in the state graph, so as to record the jump relationship between the nodes.
[0029] In a specific embodiment, when loading a certain SPA page, the initialization of the SPA page is first performed, and the DOM structure of the page in this loading is obtained. Then, a deep analysis is performed on the DOM structure, and combined with the front-end framework of the SPA (such as React, Vue, Angular, etc.), the state management mechanism of the SPA (such as Redux, Vuex) is identified. Next, by hijacking the API, a state graph is dynamically constructed, and the key information of each state node (such as URL, DOM hash value, global state snapshot, etc.) is recorded; when the user performs a route jump (for example, from the product list page to the details page), a new node is generated and associated with the parent node to form a tree structure. In this embodiment, by analyzing the API of the framework, the state changes, route jumps, and user interaction sequences of the front-end application are monitored to ensure that all possible interaction operations generated by the user can be comprehensively captured. The state graph generated thereby can be traced back between different states, providing a data basis for cross-page and cross-state vulnerability chain detection.
[0030] S120. Inject a test payload (Payload) into the front-end application page. During the test, every time a new front-end application page is detected, the following operations are sequentially performed:
[0031] S1-1. If the new front-end application page triggers a vulnerability, trace back to the initial front-end application page in the state graph to reproduce other vulnerability entry points of the initial front-end application page;
[0032] S1-2. If the new front-end application page does not trigger a vulnerability, determine the trace-back depth to the upper-level front-end application page in the state graph according to the abnormal situation of the new front-end application page; and for the end page of the trace-back, compare the traced-back DOM structure with the initial DOM structure in the state graph to determine the area where the DOM structure has changed; scan the area for vulnerabilities to locate the vulnerability chain caused by cross-page data transfer.
[0033] In this embodiment, the user interaction behaviors are automatically simulated to trigger the interaction and jump operations in each front-end application page, and test cases for vulnerability detection are automatically injected into each front-end application page to detect and locate vulnerabilities or vulnerability chains.
[0034] In a specific embodiment, the regular operations and high-risk operations (such as delete, reset buttons) can be distinguished through a rule engine and a semantic analysis model, and the high-risk operations in the user interaction behaviors to be simulated are isolated to avoid interruption of scanning or data corruption caused by accidental triggering during the monitoring process. After isolation, by simulating regular user interaction behaviors (such as clicking buttons, submitting forms, entering content), key operations are triggered directionally, and a test Payload (such as an XSS vector <script>alert(1)< / script> ) is injected to cover all potential vulnerabilities.
[0035] During this process, whenever a new state is detected (i.e., a new front-end application page, such as a payment completion page), by backtracking the state graph, it is restored to the historical state (i.e., the front-end application page at the previous level or previous levels of this page in the state graph, such as an order page). At this time, the following two situations will occur:
[0036] Situation 1: A vulnerability has been triggered in the new state. In this case, it is possible to backtrack to the initial UI to ensure that the vulnerability entry can be reproduced, and then return to S110. Based on the extended state graph of the page after backtracking, continue to detect the next test case. Here, the reproducibility of the vulnerability entry means that the link from the initial page to the new state has been detected, but the links from other entries in the initial page to other lower-level pages have not been detected. It is necessary to restore these entries to start the detection of other links by simulating user behavior.
[0037] Situation 2: No vulnerability has been triggered in the new state. In this case, it cannot be considered that there is no vulnerability in the current operation link. It is possible that the vulnerability does not manifest in the new state but has changed the information of the upper-level front-end application page. Therefore, in this embodiment, supplementary detection is performed through page backtracking. According to the abnormal situation of the new front-end application page, the following three alternative implementation manners are provided in this embodiment:
[0038] The first alternative implementation manner: If data integrity anomalies (such as parameter loss, form overwrite) are found in the new front-end application page, then backtrack to the upper-level front-end application page of the new front-end application page in the state graph. For example, after the phenomenon of parameter loss such as order ID and user ID is found on the current page, although no vulnerability warning is issued for the current page, it is possible that the vulnerability rule has been triggered on the previous page (such as tampering with the order ID, user ID, etc.). At this time, it is possible to backtrack to the upper-level front-end application page according to the state graph and wait for further detection later.
[0039] The second alternative implementation. If high-risk operation anomalies (such as payment, deletion, permission change, etc.) are found in the new front-end application page, determine the trigger point of the high-risk operation and roll back to the front-end application page where the trigger point is located. Optionally, the trigger point usually manifests as a certain page element, such as a certain function entry or button element in the page; the trigger point of the high-risk operation can be determined by parsing the names of function entries and button elements in each level of the superior pages, so as to determine the depth of rollback. For example, after a high-risk operation "payment" is found on the current page, the names of function entries or button elements in each level of the upper-level pages can be detected. If the similarity of a certain name to "payment" is the highest, the page element corresponding to this name is the trigger point. This element may be located on the upper-level page of the new front-end application page or on several upper-level pages of the new front-end application page. Take the page where this element is located as the end page of the backtracking and wait for further detection later.
[0040] The third alternative implementation. If there is no obvious anomaly in the new front-end application page, perform the minimum-depth backtracking. Exemplarily, if the minimum backtracking depth is set to 1 level, return to the upper-level front-end application page of the final state graph and wait for further detection later.
[0041] Furthermore, after the backtracking of the above three alternative implementations is completed, for the end page of the backtracking, perform a differential analysis on the DOM structure after the end page is rolled back and the original DOM of the end page in the state graph, and focus on scanning the changed area to accurately locate the vulnerability chain caused by cross-state data transmission. Optionally, if a vulnerability is detected in the changed area, the jump chain from the upper-level front-end application page of the end page to the new front-end application page is positioned as the vulnerability chain caused by cross-page data transmission.
[0042] Whether it is Case 1 or Case 2, after the above backtracking is completed, the rolled-back DOM structure and its timing information can be used as the attributes of the end page of the backtracking, incorporated into the state graph, and this DOM structure is marked as having been backtracked to avoid repeated backtracking in subsequent detections.
[0043] In addition to the above cross-state backtracking mechanism, this embodiment can also perform real-time monitoring on front-end storage. If it is found that sensitive data is stored in plain text or transmitted without encryption, it is marked as a potential vulnerability. Exemplarily, real-time monitoring can be performed on front-end storage such as LocalStorage and IndexedDB, and the storage and transmission behaviors of sensitive data (such as Token, user information, etc.) during state changes can be analyzed; if it is found that sensitive data is stored in plain text or transmitted without encryption, an alarm can be generated and marked as a potential vulnerability.
[0044] Finally, when all DOM structures in the state graph are marked as having been traced back, the state trace-back mechanism exits; the vulnerabilities and vulnerability chains detected in the cross-state trace-back mechanism, along with each potential vulnerability detected in the front-end storage implementation monitoring, are jointly used to generate a vulnerability detection report.
[0045] The implementation process of the entire above method can also be combined with Figure 2 to be understood. In this figure, according to the execution entities of each key step, the electronic device that executes the entire method is divided into a browser instance module, an API hijacking module, a DOM parsing module, a state graph construction module, a state management integration module, an intelligent event filtering engine, a cross-state trace-back detection module, a front-end storage monitoring module, and a vulnerability report generation module. Each module cooperates with each other to jointly complete the method of this embodiment.
[0046] In summary, this embodiment proposes a method for dynamically detecting and tracing back vulnerabilities in single-page applications based on a state graph. By deeply integrating the runtime state tracking and automated interaction simulation of the front-end framework, it realizes multi-dimensional vulnerability mining and risk analysis in SPA applications. Different from traditional vulnerability detection methods, this embodiment dynamically executes JavaScript code based on a headless browser, can capture asynchronously loaded content (such as pop-ups triggered by user clicks, dynamic forms, and AJAX rendering modules), and effectively breaks through the limitation that traditional tools only analyze static page structures.
[0047] The method of this embodiment combines the front-end framework API hijacking mechanism (such as route jumps, global state changes, etc.). By constructing a traceable state graph, it accurately records each page jump, data change, and user interaction behavior, and can trace back between multiple historical states to track the formation process of the vulnerability chain. For example, some input data is submitted on page A and may trigger an XSS vulnerability on page C after being processed on page B. The system can trace back to the state of page A and, through differential analysis, discover the vulnerability chain triggered across pages and multiple states. Through this trace-back mechanism, the present invention breaks through the limitation that traditional tools cannot trigger multi-step vulnerability chain detection and improves the vulnerability mining ability of dynamic Web applications.
[0048] To sum up, the method of this embodiment can achieve the following beneficial effects:
[0049] 1. Through a cross - state backtracking mechanism, the dynamic state tracking and backtracking are realized in a single - page application. Different from traditional static analysis methods, the device can accurately track and analyze data flow when the application reverts from one state (such as a payment page) to a historical state (such as an order page). By constructing a state map, the device records the change path from one state to another, and combines with the DOM difference analysis algorithm to efficiently identify the vulnerability chain that may be triggered during state changes. This innovative mechanism can accurately capture potential vulnerabilities in cross - page and cross - state interactions, significantly improving the coverage rate and efficiency of vulnerability detection;
[0050] 2. An intelligent event filtering engine is built - in, which can accurately distinguish between regular operations and high - risk operations (such as deleting accounts, resetting permissions, form submissions, etc.). The device automatically identifies and preferentially triggers high - risk operations for vulnerability scanning through semantic analysis technology. By simulating user interaction behaviors (such as clicking, inputting, and submitting), the device ensures comprehensive coverage of all potential vulnerabilities, especially accurate detection when involving sensitive data and high - risk operations, reducing false triggers and redundant operations, and improving detection efficiency;
[0051] 3. Real - time monitor the local storage behavior of the application, and analyze the storage and transmission of sensitive data (such as Tokens, user information, etc.) during state changes. Through regular expression rules (such as matching sensitive information like Tokens, passwords, etc.), sensitive data stored improperly or transmitted without encryption can be identified in a timely manner. Once it is detected that sensitive data is stored in plain text or transmitted through an insecure channel, an alarm will be generated immediately and marked as a potential vulnerability to ensure the full protection of sensitive data in the application.
[0052] Figure 3 The structural schematic diagram of an electronic device provided by an embodiment of the present invention is as follows Figure 3 As shown, the device includes a processor 60, a memory 61, an input device 62, and an output device 63; the number of processors 60 in the device can be one or more, Figure 3 Taking one processor 60 as an example; the processor 60, memory 61, input device 62, and output device 63 in the device can be connected through a bus or other means, Figure 3 Taking the connection through a bus as an example.
[0053] The memory 61, as a computer - readable storage medium, can be used to store software programs, computer - executable programs, and modules, such as the program instructions / modules corresponding to the dynamic vulnerability backtracking detection method for single - page applications based on the state map in the embodiments of the present invention. The processor 60 executes various functional applications and data processing of the device by running the software programs, instructions, and modules stored in the memory 61, that is, realizes the above - mentioned dynamic vulnerability backtracking detection method for single - page applications based on the state map.
[0054] The memory 61 may mainly include a program storage area and a data storage area. Among them, the program storage area may store an operating system and application programs required for at least one function; the data storage area may store data created according to the use of the terminal, etc. In addition, the memory 61 may include a high-speed random access memory, and may also include a non-volatile memory, such as at least one magnetic disk storage device, a flash memory device, or other non-volatile solid-state storage devices. In some instances, the memory 61 may further include a memory remotely provided with respect to the processor 60, and these remote memories may be connected to the device through a network. Examples of the above network include but are not limited to the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0055] The input device 62 can be used to receive input digital or character information, and generate key signal inputs related to the user settings and function control of the device. The output device 63 may include display devices such as a display screen.
[0056] An embodiment of the present invention also provides a computer-readable storage medium, on which a computer program is stored, and when the program is executed by a processor, it implements the single-page application dynamic vulnerability backtracking detection method based on a state map in any embodiment.
[0057] The computer storage medium of the embodiment of the present invention may adopt any combination of one or more computer-readable media. The computer-readable medium may be a computer-readable signal medium or a computer-readable storage medium. The computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples (non-exhaustive list) of the computer-readable storage medium include: an electrical connection having one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In this document, the computer-readable storage medium may be any tangible medium that contains or stores a program, and the program can be used by or in combination with an instruction execution system, apparatus, or device.
[0058] A computer-readable signal medium may include a data signal propagated in a baseband or as part of a carrier wave, carrying computer-readable program code. Such a propagated data signal may take many forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the foregoing. A computer-readable signal medium may also be any computer-readable medium other than a computer-readable storage medium, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device.
[0059] The program code contained on a computer-readable medium may be transmitted using any appropriate medium, including but not limited to wireless, wireline, optical fiber cable, RF, etc., or any suitable combination of the foregoing.
[0060] The computer program code for performing the operations of the present invention may be written in one or more programming languages or combinations thereof. The programming languages include object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the C language or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, executed as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on the remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., through the Internet using an Internet service provider).
[0061] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them. Although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements on some or all of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the technical solutions of the embodiments of the present invention.
Claims
1. A dynamic vulnerability backtracking detection method for single-page applications based on a state atlas, characterized in that, including: By monitoring the front-end applications, a state graph is constructed, where the state graph takes each front-end application page as a node and the jump relationships between each front-end application page as the edges between the nodes. Each node attribute includes the DOM structure and timing information of each front-end application page every time it is loaded; Inject test payloads into the front-end application pages. During the test, every time a new front-end application page is detected, the following operations are sequentially performed: S1-1. If the new front-end application page triggers a vulnerability, trace back to the initial front-end application page in the state graph to reproduce other vulnerability entry points of the initial front-end application page; S1-2. If the new front-end application page does not trigger a vulnerability, determine the backtracking depth of the upper-level front-end application page in the state graph according to the abnormal situation of the new front-end application page; and for the end page of the backtracking, compare the backtracked DOM structure with the initial DOM structure in the state graph to determine the area where the DOM structure has changed; scan the area for vulnerabilities to locate the vulnerability chain caused by cross-page data transfer.
2. The method according to claim 1, wherein The construction of the state graph by monitoring the front-end applications includes: Load the current page of the front-end application and generate a node for the current page in the state graph of the front-end application; Store the current DOM structure and its timing information of the current page into the attributes of the node; If the current page jumps from other front-end application pages, establish an edge between the node and the node of the other front-end application page in the state graph.
3. The method according to claim 1, characterized in that, The determination of the backtracking depth of the upper-level front-end application page in the state graph according to the abnormal situation of the new front-end application page includes: If data integrity abnormality is found in the new front-end application page, trace back to the upper-level front-end application page of the new front-end application page in the state graph; If a high-risk operation abnormality is found in the new front-end application page, determine the page element that triggers the high-risk operation and trace back to the front-end application page where the page element is located; If no abnormality is found in the new front-end application page, perform the minimum depth backtracking.
4. The method according to claim 1, characterized in that, The scanning of the area for vulnerabilities to locate the vulnerability chain caused by cross-page data transfer includes: If a vulnerability is detected in the area, locate the jump chain from the upper-level front-end application page of the end page to the new front-end application page as the vulnerability chain caused by cross-page data transfer.
5. The method according to claim 1, characterized in that, After the scanning of the area for vulnerabilities to locate the vulnerability chain caused by cross-page data transfer, it further includes: Incorporate the backtracked DOM structure into the state graph and mark it as backtracked to avoid subsequent repeated backtracking.
6. The method according to claim 1, characterized in that The injection of test payloads into the current front-end application page includes: Distinguish normal operations and high-risk operations through a rule engine and a semantic analysis model; Simulate user interaction behaviors with high-risk operations removed to trigger front-end application pages at all levels and inject test payloads.
7. The method according to claim 1, wherein It also includes: Monitor the front-end storage in real time. If sensitive data is stored in plain text or transmitted without encryption, mark it as a potential vulnerability.
8. The method according to claim 7, characterized in that, After performing real-time monitoring on the front-end storage and marking potential vulnerabilities if sensitive data is stored in plain text or transmitted without encryption, the method further includes: Generating a detection report based on each potential vulnerability, as well as the vulnerabilities and vulnerability chains identified each time S1-1 and S1-2 are executed.
9. An electronic device, characterized in that, Including: One or more processors; A memory for storing one or more programs, When the one or more programs are executed by the one or more processors, the one or more processors implement the state-graph-based dynamic vulnerability backtracking detection method for single-page applications according to any one of claims 1-8.
10. A computer-readable storage medium, characterized in that, A computer program is stored thereon, and when the program is executed by a processor, the state-graph-based dynamic vulnerability backtracking detection method for single-page applications according to any one of claims 1-8 is implemented.
Citation Information
Patent Citations
XSS vulnerability detection method based on simulating browser behavior
CN104881608A
State transition diagram based XSS (cross-site scripting) vulnerability detection method
CN106845248A
XSS (Cross Site Scripting) vulnerability detection method and device
CN108846286A
Vulnerability detection method and device, storage medium and electronic equipment
CN114491560A
Page fuzzing test method and device for single-page application program and electronic equipment
CN117407888A