Vertical unauthorized vulnerability detection method and device, equipment, medium and program product

By acquiring and analyzing the full-link user behavior data in the system under test, constructing a permission differential set and generating test cases, the problems of high false positive rate and incomplete test cases in vertical unauthorized vulnerability detection are solved, and automated and accurate vulnerability detection is achieved.

CN120705038APending Publication Date: 2025-09-26CHINA MOBILE INFORMATION TECHNOLOGY CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510782055.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-12
Publication Date
2025-09-26

AI Technical Summary

Technical Problem

The existing vertical privilege escalation vulnerability detection solutions have problems such as high misjudgment rate, incomplete and unnecessary test cases.

Method used

By obtaining the full-link user behavior data corresponding to each role in the system under test, determining the permission difference set corresponding to each role, constructing the first and second permission-unauthorized test cases, and performing vertical permission-unauthorized vulnerability detection.

Benefits of technology

Comprehensive test case coverage is achieved, misjudgments are eliminated, the error rate of judgment results is reduced, manual intervention is reduced, and detection efficiency is improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120705038A_ABST
    Figure CN120705038A_ABST
Patent Text Reader

Abstract

The invention provides a vertical unauthorized vulnerability detection method and device, equipment, a medium and a program product, and the method comprises the steps: obtaining user full-link behavior data corresponding to each role under a detected system; determining a permission difference set corresponding to each role; the permissions in the permission difference set are permissions which are not possessed by other roles except the role; constructing a first unauthorized test case according to the first data corresponding to each permission difference set; the first unauthorized test case is used for detecting whether a user in the first role has the authority of a second role; constructing a second unauthorized test case according to the user full-link behavior data; the second unauthorized test case is used for detecting whether unauthorized access can be carried out under each role; and performing vertical unauthorized vulnerability detection according to the first unauthorized test case and the second unauthorized test case. According to the scheme, the problems that an existing vertical unauthorized vulnerability detection scheme is high in judgment result misjudgment rate and incomplete and unnecessary in test case can be solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of communication technology, and in particular to a method, device, equipment, medium and program product for detecting vertical unauthorized access vulnerabilities. Background Art

[0002] Existing vertical privilege escalation vulnerability detection solutions have the following two main problems:

[0003] 1. Test case coverage and test efficiency: The test case coverage of existing technical solutions is incomplete and not comprehensive. Theoretically, there may be scenarios where vertical unauthorized URLs exist, and all of them need to be covered during testing. In addition, the detection efficiency is not high, and in theory, invalid test cases that do not involve vertical unauthorized URLs need to be reduced.

[0004] 2. Vulnerability judgment method. The vulnerability judgment method of existing technology has a large misjudgment and requires a lot of manual intervention: most of them are based on the test response of black box testing, which needs to be compared with the normal response and the similarity is judged by setting a threshold. This method has a large misjudgment and requires a lot of manual intervention. It is even unable to identify situations where there is no return value.

[0005] From the above, the existing vertical privilege escalation vulnerability detection solutions have problems such as high misjudgment rate of judgment results, incomplete and unnecessary test cases, etc. Summary of the Invention

[0006] The purpose of this application is to provide a vertical privilege escalation vulnerability detection method, device, equipment, medium and computer program product to solve the problems in the existing vertical privilege escalation vulnerability detection scheme, such as high error rate of judgment results, incomplete and unnecessary test cases.

[0007] To solve the above technical problems, the present invention provides a method for detecting vertical privilege escalation vulnerabilities, including:

[0008] Obtain the user full-link behavior data corresponding to each role in the tested system; the user full-link behavior data includes: behavior data of all operations within the authority scope corresponding to the role;

[0009] Determine a permission difference set corresponding to each of the roles; the permissions in the permission difference set are permissions that other roles except the role do not have;

[0010] Constructing a first permission violation test case based on the first data corresponding to each permission difference set in the user full-link behavior data; the first permission violation test case is used to detect whether the user under the first role has the permission of the second role;

[0011] Constructing a second unauthorized access test case based on the user's full-link behavior data; the second unauthorized access test case is used to detect whether unauthorized access is possible under each of the roles;

[0012] Perform vertical unauthorized access vulnerability detection based on the first unauthorized access test case and the second unauthorized access test case.

[0013] Optionally, obtaining the full-link user behavior data corresponding to each role in the system under test includes:

[0014] Perform instrumentation operations on the target nodes in the system under test to obtain the full-link user behavior data corresponding to each role in the system under test.

[0015] Optionally, determining the permission difference set corresponding to each role includes:

[0016] Obtaining the intersection of permissions between every two roles in the system under test;

[0017] According to the permission intersection, the permission difference set corresponding to each of the roles is determined.

[0018] Optionally, constructing a first unauthorized access test case based on the first data corresponding to each permission difference set in the user full-link behavior data includes:

[0019] Replacing the user authentication information in the first data corresponding to the permission difference set corresponding to the second role with the authentication information of the user under the first role, to obtain deformed data corresponding to the first data; the second role is any role under the system under test, and the first role is any role under the system under test except the second role;

[0020] Obtaining a first unauthorized test case according to the deformed data corresponding to the first data corresponding to each of the permission difference sets;

[0021] And / or, constructing a second unauthorized test case based on the user's full-link behavior data includes:

[0022] The user identity authentication information in the user full-link behavior data is cleared to obtain a second unauthorized test case.

[0023] Optionally, the authority corresponding to the role is represented by a triple, and the triple includes: a uniform resource locator URL, an application programming interface API, and a structured query language SQL statement;

[0024] The performing of vertical privilege escalation vulnerability detection according to the first privilege escalation test case and the second privilege escalation test case includes:

[0025] Running the first and second unauthorized test cases to obtain running data;

[0026] Determine whether a vertical privilege escalation vulnerability exists based on the operational data.

[0027] The present application also provides a device for detecting vertical privilege escalation vulnerabilities, including:

[0028] The first acquisition module is used to obtain the user full-link behavior data corresponding to each role in the tested system; the user full-link behavior data includes: behavior data of all operations within the authority scope corresponding to the role;

[0029] A first determining module is configured to determine a permission difference set corresponding to each of the roles; the permissions in the permission difference set are permissions that other roles except the role do not have;

[0030] A first construction module is configured to construct a first permission violation test case based on the first data corresponding to each permission difference set in the user full-link behavior data; the first permission violation test case is configured to detect whether a user in the first role has the permission of the second role;

[0031] A second construction module is used to construct a second unauthorized access test case based on the user's full-link behavior data; the second unauthorized access test case is used to detect whether unauthorized access is possible under each of the roles;

[0032] The first detection module is used to perform vertical unauthorized access vulnerability detection based on the first unauthorized access test case and the second unauthorized access test case.

[0033] Optionally, obtaining the full-link user behavior data corresponding to each role in the system under test includes:

[0034] Perform instrumentation operations on the target nodes in the system under test to obtain the full-link user behavior data corresponding to each role in the system under test.

[0035] Optionally, determining the permission difference set corresponding to each role includes:

[0036] Obtaining the intersection of permissions between every two roles in the system under test;

[0037] According to the permission intersection, the permission difference set corresponding to each of the roles is determined.

[0038] Optionally, constructing a first unauthorized access test case based on the first data corresponding to each permission difference set in the user full-link behavior data includes:

[0039] Replacing the user authentication information in the first data corresponding to the permission difference set corresponding to the second role with the authentication information of the user under the first role, to obtain deformed data corresponding to the first data; the second role is any role under the system under test, and the first role is any role under the system under test except the second role;

[0040] Obtaining a first unauthorized test case according to the deformed data corresponding to the first data corresponding to each of the permission difference sets;

[0041] And / or, constructing a second unauthorized test case based on the user's full-link behavior data includes:

[0042] The user identity authentication information in the user full-link behavior data is cleared to obtain a second unauthorized test case.

[0043] Optionally, the authority corresponding to the role is represented by a triple, and the triple includes: a uniform resource locator URL, an application programming interface API, and a structured query language SQL statement;

[0044] The performing of vertical privilege escalation vulnerability detection according to the first privilege escalation test case and the second privilege escalation test case includes:

[0045] Running the first and second unauthorized test cases to obtain running data;

[0046] Determine whether a vertical privilege escalation vulnerability exists based on the operational data.

[0047] The embodiment of the present application further provides a vertical overreach vulnerability detection device, comprising: a processor;

[0048] The processor is used to obtain user full-link behavior data corresponding to each role in the tested system; the user full-link behavior data includes: behavior data of all operations within the authority scope corresponding to the role;

[0049] Determine a permission difference set corresponding to each of the roles; the permissions in the permission difference set are permissions that other roles except the role do not have;

[0050] Constructing a first permission violation test case based on the first data corresponding to each permission difference set in the user full-link behavior data; the first permission violation test case is used to detect whether the user under the first role has the permission of the second role;

[0051] Constructing a second unauthorized access test case based on the user's full-link behavior data; the second unauthorized access test case is used to detect whether unauthorized access is possible under each of the roles;

[0052] Perform vertical unauthorized access vulnerability detection based on the first unauthorized access test case and the second unauthorized access test case.

[0053] Optionally, obtaining the full-link user behavior data corresponding to each role in the system under test includes:

[0054] Perform instrumentation operations on the target nodes in the system under test to obtain the full-link user behavior data corresponding to each role in the system under test.

[0055] Optionally, determining the permission difference set corresponding to each role includes:

[0056] Obtaining the intersection of permissions between every two roles in the system under test;

[0057] According to the permission intersection, the permission difference set corresponding to each of the roles is determined.

[0058] Optionally, constructing a first unauthorized access test case based on the first data corresponding to each permission difference set in the user full-link behavior data includes:

[0059] Replacing the user authentication information in the first data corresponding to the permission difference set corresponding to the second role with the authentication information of the user under the first role, to obtain deformed data corresponding to the first data; the second role is any role under the system under test, and the first role is any role under the system under test except the second role;

[0060] Obtaining a first unauthorized test case according to the deformed data corresponding to the first data corresponding to each of the permission difference sets;

[0061] And / or, constructing a second unauthorized test case based on the user's full-link behavior data includes:

[0062] The user identity authentication information in the user full-link behavior data is cleared to obtain a second unauthorized test case.

[0063] Optionally, the authority corresponding to the role is represented by a triple, and the triple includes: a uniform resource locator URL, an application programming interface API, and a structured query language SQL statement;

[0064] The performing of vertical privilege escalation vulnerability detection according to the first privilege escalation test case and the second privilege escalation test case includes:

[0065] Running the first and second unauthorized test cases to obtain running data;

[0066] Determine whether a vertical privilege escalation vulnerability exists based on the operational data.

[0067] An embodiment of the present application also provides a vertical privilege escalation vulnerability detection device, comprising a memory, a processor, and a program stored in the memory and executable on the processor; when the processor executes the program, the above-mentioned vertical privilege escalation vulnerability detection method is implemented.

[0068] An embodiment of the present application also provides a readable storage medium on which a program is stored. When the program is executed by a processor, the steps in the above-mentioned vertical privilege escalation vulnerability detection method are implemented.

[0069] An embodiment of the present application also provides a computer program product, including computer instructions, which, when executed by a processor, implement the steps of the above-mentioned vertical privilege escalation vulnerability detection method.

[0070] The beneficial effects of the above technical solution of this application are as follows:

[0071] In the above scheme, the vertical unauthorized access vulnerability detection method obtains the full-link behavior data of users corresponding to each role under the tested system; the full-link behavior data of users include: behavior data of all operations within the scope of authority corresponding to the role; determines the permission difference set corresponding to each role; the permissions in the permission difference set are permissions that other roles except the role do not have; according to the first data corresponding to each permission difference set in the full-link behavior data of users, a first unauthorized access test case is constructed; the first unauthorized access test case is used to detect whether the user under the first role has the authority of the second role; according to the full-link behavior data of users, a second unauthorized access test case is constructed. An unauthorized access test case; the second unauthorized access test case is used to detect whether unauthorized access is possible under each of the roles; vertical unauthorized access vulnerability detection is performed based on the first unauthorized access test case and the second unauthorized access test case; it can support the construction of comprehensive test cases, and can eliminate test cases that misjudge vulnerabilities in scenarios where two users have overlapping permissions, thereby obtaining comprehensive, necessary and misjudgment-eliminating test cases, and then supporting automatic vulnerability detection based on this, avoiding manual intervention as much as possible, reducing the misjudgment rate of judgment results, and well solving the problems of high misjudgment rate of judgment results, incomplete and unnecessary test cases in the vertical unauthorized access vulnerability detection scheme in the existing technology. BRIEF DESCRIPTION OF THE DRAWINGS

[0072] Figure 1 A flowchart of a vertical privilege escalation vulnerability detection method according to an embodiment of the present application;

[0073] Figure 2 This is a schematic diagram of a specific implementation flow of the vertical privilege escalation vulnerability detection method according to an embodiment of the present application;

[0074] Figure 3 This is a schematic diagram of the structure of a vertical unauthorized vulnerability detection device according to an embodiment of the present application;

[0075] Figure 4 This is a schematic diagram of the structure of a vertical unauthorized vulnerability detection device according to an embodiment of the present application. DETAILED DESCRIPTION

[0076] In order to make the technical problems, technical solutions and advantages to be solved by this application clearer, a detailed description will be given below with reference to the accompanying drawings and specific embodiments.

[0077] The following first introduces the relevant contents of this plan.

[0078] Vertical privilege escalation occurs when a user in a certain role can access specific functions of users in other roles. Specifically, there are two scenarios:

[0079] (1) A scenario is that a user in a certain role can access specific functions of users in other roles, such as ordinary user A can access the management page of administrator user B.

[0080] (2) Another scenario is that anonymous users can access functions or data that require authentication.

[0081] If a URL (Uniform Resource Locator) request in an application system has a vertical privilege escalation vulnerability, it can manifest as: anonymous users or unauthorized users can successfully access the URL, the access response is successful, or the user operation exceeds the "normal" permissions for adding, deleting, modifying, and querying database table fields. All vertical privilege escalation vulnerability detection technologies need to consider the following three basic aspects:

[0082] 1. Coverage of test cases. In theory, there may be scenarios where vertical unauthorized URLs are accessed, and all of them need to be covered during testing.

[0083] 2. Detection efficiency. In theory, it is necessary to reduce invalid test cases that do not have vertical overreach. This is the other side of the same coin as coverage.

[0084] 3. Vulnerability judgment method: what data does the testing tool collect and what vulnerability judgment model is used.

[0085] Based on the above, this application provides a vertical privilege escalation vulnerability detection method to address the problems in the existing vertical privilege escalation vulnerability detection solutions, such as high misjudgment rate, incomplete and unnecessary test cases. Figure 1 As shown, including:

[0086] Step 11: Obtain the full-link user behavior data corresponding to each role in the system under test; the full-link user behavior data includes: behavior data of all operations within the authority scope corresponding to the role;

[0087] Step 12: Determine the permission difference set corresponding to each of the roles; the permissions in the permission difference set are permissions that other roles except the role do not have;

[0088] Constructing a first permission violation test case based on the first data corresponding to each permission difference set in the user full-link behavior data; the first permission violation test case is used to detect whether a user under the first role has the permission of the second role (for example, whether an ordinary user can access the administrator's management page);

[0089] Construct a second unauthorized access test case based on the user's full-link behavior data; the second unauthorized access test case is used to detect whether unauthorized access is possible under each of the roles (for example, whether an anonymous user can access functions or data that require identity verification).

[0090] Step 13: Perform vertical privilege escalation vulnerability detection based on the first privilege escalation test case and the second privilege escalation test case.

[0091] The vertical unauthorized access vulnerability detection method provided in the embodiment of the present application obtains the user full-link behavior data corresponding to each role under the tested system; the user full-link behavior data includes: the behavior data of all operations within the authority range corresponding to the role; determines the permission difference set corresponding to each role; the permissions in the permission difference set are permissions that other roles except the role do not have; according to the first data corresponding to each permission difference set in the user full-link behavior data, constructs a first unauthorized access test case; the first unauthorized access test case is used to detect whether the user under the first role has the permission of the second role; according to the user full-link behavior data, constructs a second unauthorized access test case. Two unauthorized access test cases; the second unauthorized access test case is used to detect whether unauthorized access is possible under each of the roles; vertical unauthorized access vulnerability detection is performed based on the first unauthorized access test case and the second unauthorized access test case; it can support the construction of comprehensive test cases, and can eliminate test cases that misjudge vulnerabilities in scenarios where two users have overlapping permissions, so as to obtain comprehensive, necessary and misjudgment-eliminating test cases, and then support automatic vulnerability detection based on this, avoid manual intervention as much as possible, reduce the misjudgment rate of judgment results, and well solve the problems of high misjudgment rate of judgment results and incomplete and unnecessary test cases in the vertical unauthorized access vulnerability detection scheme in the existing technology.

[0092] Among them, the acquisition of the user full-link behavior data corresponding to each role under the tested system includes: performing a plug-in operation on the target node in the tested system to obtain the user full-link behavior data corresponding to each role under the tested system. In this way, the user full-link behavior data can be accurately and automatically acquired, and the data can be the relevant full-link behavior data for the access request. In this solution, the role information of the corresponding user can be supplemented in the user full-link behavior data, but it is not limited to this.

[0093] In the embodiment of the present application, determining the permission difference set corresponding to each of the roles includes: obtaining the permission intersection between each two roles in the system under test; and determining the permission difference set corresponding to each of the roles based on the permission intersection. In this way, the permission difference set can be accurately obtained.

[0094] Among them, the first unauthorized access test case is constructed based on the first data corresponding to each of the permission difference sets in the user's full-link behavior data, including: replacing the user identity authentication information in the first data corresponding to the permission difference set corresponding to the second role with the identity authentication information of the user under the first role, to obtain the deformed data corresponding to the first data; the second role is any role under the system under test, and the first role is any role under the system under test except the second role; the first unauthorized access test case is obtained based on the deformed data corresponding to the first data corresponding to each of the permission difference sets; and / or, the second unauthorized access test case is constructed based on the user's full-link behavior data, including: setting the user identity authentication information in the user's full-link behavior data to blank, to obtain the second unauthorized access test case. In this way, the first unauthorized access test case and / or the second unauthorized access test case can be accurately obtained; this solution can be implemented by performing verification information replacement on the permission difference set of the normal permission set of at least one user of each role under the tested system; and / or performing verification information clearing on the normal permission set; and then excluding the intersection of user permissions to form a test instance of unauthorized access and unauthorized access; thereby obtaining a comprehensive, necessary and misjudgment-eliminating instance.

[0095] In the embodiments of the present application, the permissions corresponding to the roles are represented by triples, and the triples include: Uniform Resource Locator (URL), Application Programming Interface (API), and Structured Query Language (SQL) statements; the vertical privilege escalation vulnerability detection according to the first privilege escalation test case and the second privilege escalation test case includes: running the first privilege escalation test case and the second privilege escalation test case to obtain running data; determining whether there is a vertical privilege escalation vulnerability according to the running data. In this way, the vertical privilege escalation vulnerability detection can be accurately implemented. Among them, determining whether there is a vertical privilege escalation vulnerability according to the running data may include: determining that there is a vertical privilege escalation vulnerability when the triple corresponding to the permission in the running data does not belong to the permission set of the corresponding user; and / or, determining that there is a vertical privilege escalation vulnerability when the triple exists in the running data, but not limited thereto.

[0096] The following is an example of the vertical privilege escalation vulnerability detection method provided in the embodiments of the present application.

[0097] In view of the above technical problems, the embodiments of the present application provide a vertical privilege escalation vulnerability detection method, which involves the following two aspects of improvements:

[0098] I. Test case coverage and test efficiency;

[0099] In this solution, by means of stubbing and logging of the tested system, the full-link behavior logs of users are obtained, the role information of the users of the tested system is read, and the role information in the full-link behavior logs of users is supplemented. At least one user is constructed for each role of the tested system, and each user traverses all operations of the user role at least once. Thus, the function and data permissions of each role can be statistically analyzed, and the role permission set expressed in <URL, API (Application Programming Interface), SQL (Structured Query Language) statements> can be obtained. Next, a vertical privilege escalation test case URL is constructed based on the role permission set. In this way, through the operation of the role permission set, the above required test URL information can be accurately obtained, ensuring the coverage of the test cases and avoiding the test of URLs that certainly do not have vertical privilege escalation.

[0100] II. Vulnerability judgment method;

[0101] This solution traverses and tests the URLs of the difference sets of the operation permission sets of different roles, extracts the key elements <URL, API, SQL> in the trace log based on the trace log formed by the accessed requests. During the privilege escalation test, after replacing the user information (assumed to be user A), the original user (assumed to be user B) request information is replayed for testing. When the request is successfully executed and the returned response is the same as the original response, it is judged whether the actual permissions of this user (user A) are in the permission set of the user's affiliated role. If not, there is a vertical privilege escalation.

[0102] As described above, by inserting stubs at multiple key nodes in the system call link of the system under test, this solution can solve the problem of collecting test response context data. Furthermore, after users of each role have traversed the operations, a set of function and data permissions for each role can be formed. Whether there is vertical privilege escalation is determined by whether the function and data permissions of the user in the test case are within the set of function and data permissions of the role to which the user belongs. If not, there is vertical privilege escalation. When judging vulnerabilities, more request-response context information is relied on, and the false positive rate is lower.

[0103] Specifically, this solution traverses the function operations of each role under normal circumstances to establish a set of role function and data permissions, that is, a role permission whitelist, and then detects vertical privilege escalation vulnerabilities based on this. As Figure 2 shown, this solution includes the following content:

[0104] Build an internal view-level user role data permission whitelist once: Let users of all roles in the application system (corresponding to the system under test above) operate normally once. Data can be automatically collected through an application probe to obtain a full-link data tracking log of user behavior (which can correspond to the above-mentioned full-link behavior data of users). Statistics are performed by role to obtain a set of data permissions at the internal view level (API call chain and SQL operations) of the user role in the application system and a set of application request URLs.

[0105] Automatically mine and detect vertical privilege escalation vulnerabilities: Based on the set of application user role request URLs, start the request playback to verify information (detect unauthorized access privilege escalation vulnerabilities), and start the request playback to change user verification information (detect vertical privilege escalation vulnerabilities). Data can be automatically collected through an application probe to obtain a full-link data tracking log of user behavior. Extract user information, API call chain, and SQL operation statements from this log to form a permission representation, and judge whether this permission representation is within the permission set of this user. If so, there is no vertical privilege escalation (vulnerability); if not, there is vertical privilege escalation (vulnerability).

[0106] Based on the above, the key steps for vulnerability detection in this solution include:

[0107] (1) Analysis of user behavior tracking logs: For user operation behaviors, real-time internal observation data of the application system is collected and a full-link tracking log of users is formed to determine the settings of operations and data permissions owned by different roles at the beginning of system design (meeting business requirements).

[0108] (2) Construction of a vulnerability detection model: Based on the tracking log, analyze and statistically construct a set of function and data permissions for each role expressed by <URL, API, SQL statement> as permission elements, and test cases for detecting vertical privilege escalation vulnerabilities can be extracted through set operations.

[0109] (3) Vulnerability mining and detection: Input the real-time behavior data of vulnerability test requests into the vulnerability detection model for detection, thereby determining whether there is vertical overreach.

[0110] The following is a specific example to illustrate each part of this plan.

[0111] (1) Analyze and summarize role operation functions and data permission sets;

[0112] This solution can use instrumentation technology to automatically track program usage at important nodes such as the user management layer, API framework, and database access layer of the application system under test, monitor program call behavior within the application system, and obtain key information about the entire link of user requests. This information is then sent to the vulnerability detection system server, and a full-link tracking log of user request behavior is formed (which corresponds to the above-mentioned instrumentation operation for the target node in the system under test, and obtains the full-link user behavior data corresponding to each role in the system under test). The tracking log does not rely on the business system's own log. The tracking log includes the following key information: user name, role, URL, API call chain, and SQL statement.

[0113] Create users for different roles in the system under test. Assume that the system under test has three roles: R a 、R b 、R c , create a user for each of these three roles, and get three users Ra_user1, Rb_user1, and Rc_user1. This assumption does not affect the generality.

[0114] Each role uses at least one user, and on the web (network) interface, all functions of the user are normally traversed and operated. The user's operation will form a user behavior tracking log (which can correspond to the above-mentioned user full-link behavior data). These tracking logs are statistically analyzed and key information such as roles, URLs, APIs, SQL statements, etc. are extracted to form R a 、R b 、R c The function and data permission sets of these three roles are respectively The element of the permission set is represented by p, which can be composed of a URL, an API, and an SQL statement (the permissions corresponding to the above roles can be represented by a triple, the triple includes: Uniform Resource Locator URL, Application Programming Interface API and Structured Query Language SQL statement), which can be represented as a triple (u, a, s), then a permission set similar to the following will be formed:

[0115] -For character R a , its (function and) data permission set It can be expressed as:

[0116]

[0117] Among them I a Is an index set representing the role R a The index of all permissions possessed.

[0118] -For character R b , its data permission set It can be expressed as:

[0119]

[0120] Among them I b Is an index set representing the role The index of all permissions possessed.

[0121] -For character R c , its data permission set It can be expressed as:

[0122]

[0123] Among them I c Is an index set representing the role R c The index of all permissions possessed.

[0124] In this solution, we can further define a function that maps each role to its corresponding permission set. Specifically, for role R, the function f can be defined as:

[0125] f(R)={(u i , a i , s i )|i∈I R};

[0126] Among them I R It is an index set that represents the index of all permissions possessed by role R.

[0127] (2) Vulnerability detection model construction;

[0128] Assume the role R a 、R b 、R c There is a certain intersection in the permission sets of the roles R a 、R b 、R c The following analysis is applicable regardless of the intersection or inclusion relationship between the permission sets.

[0129] (1) About the character Ra , R b , R c The common functions they all have can be expressed as:

[0130] P1=P Ra ∩P Rb ∩P Rc ;

[0131] (2) About the character R b and R c All have common functions, but do not include the role R a The function can be expressed as:

[0132] P2=(P Rb ∩P Rc )\P1;

[0133] (3) About the character R a and R c All have common functions, but do not include the role R b The function can be expressed as:

[0134] P3=(P Ra ∩P Rc )\P1;

[0135] (4) About the character R a and R b All have common functions, but do not include the role R c The function can be expressed as:

[0136] P4=(P Ra ∩P Rb )\P1;

[0137] (5) About the character R a The unique features can be expressed as:

[0138] P5=P Ra \(P1∪P3∪P4);

[0139] (6) About the character R b The unique features can be expressed as:

[0140] P6=P Rb \(P1∪P2∪P4);

[0141] (7) About the character R c The unique features can be expressed as:

[0142] P7=P Rc \(P1∪P2∪P3);

[0143] set up Represents the role R a 、R b 、R c In this solution, the following set operations can be defined to describe the intersection and difference of permissions between different roles:

[0144] The vertical privilege escalation vulnerability detection model is built based on the role's operation and data permission set. Representative character R a 、R b 、R c In a (vertical) privilege escalation vulnerability test, if the constructed privilege escalation test case causes a user's actual permissions to exceed the privilege escalation whitelist of the role to which the user belongs, then a privilege escalation vulnerability can be determined.

[0145] For example: permission sets P5, P6, and P7 represent roles R respectively. a 、R b 、R c Assume that R c is the system administrator role of a business system, and R a If it is a common business operation role, then P7 should include the creation and management of business system users, the creation of roles, the allocation of role permissions, etc. a The user can operate the functions in the P7 set, which is obviously an unauthorized behavior, does not meet the permission division requirements at the beginning of system design, and is not within the scope of role R. a Permission whitelist Among.

[0146] (3) Vertical privilege escalation vulnerability detection:

[0147] 1. Construct an unauthorized test URL;

[0148] Determine the scope of vertical privilege escalation vulnerability detection. Vertical privilege escalation may occur in two places:

[0149] (1) One is that users of a certain role can access specific functions of users of other roles, such as ordinary user A can access the management page of system administrator user B.

[0150] (2) Another is that anonymous users (i.e. non-logged-in users) can access functions or data that require authentication.

[0151] Among them, privilege escalation not only occurs when a so-called low-privilege user can access the functions or data of a high-privilege user, but also when a so-called high-privilege user accesses the functions or data that are exclusive to low-privilege users. That is, privilege escalation occurs when users with different roles can access the exclusive functions of other users. Then, the URL set of possible vertical privilege escalation vulnerabilities can be expressed as:

[0152] Vul(1)=Vul1∪Vul2∪Vul3;

[0153] in:

[0154] Vul1 = {URL | URL∈P5};

[0155] Vul2 = {URL | URL∈P6};

[0156] Vul3 = {URL | URL∈P7};

[0157] Among them, P5, P5, and P7 represent the role R a 、R b 、R c Unique permissions.

[0158] In addition, the set of URLs with (vertical) unauthorized access vulnerabilities for anonymous users can be represented as Vul(2), as follows:

[0159] Vul(2)={URL|URL∈(P Ra ∪P Rb ∪P Rc )};

[0160] Among them, Vul(2) represents all URLs that require authentication to access but can be accessed by anonymous users.

[0161] 2. (Vertical) privilege escalation vulnerability detection;

[0162] Let Vul(1) be the set of URLs that may have vertical privilege escalation vulnerabilities, and Vul(2) be the set of URLs that may be accessed by anonymous users without authorization. Based on the full-link tracking log of user request behavior, the following sets are defined:

[0163] - That is: Role R a The set of URLs belonging to Vul(1) accessed by user Ra_user1; representing role R a User Ra_user1 has access rights within the scope of his or her permissions.

[0164] - That is: Role R bThe set of URLs belonging to Vul(1) accessed by user Rb_user1; represents the role R b User Rb_user1 has access rights within the scope of his or her permissions.

[0165] - That is: Role R c The set of URLs belonging to Vul(1) accessed by user Rc_user1; represents the role R c User Rc_user1 has access rights within the scope of his or her permissions.

[0166] In this solution, the transformed URL set T url_1 It is obtained by replacing the user authentication parameters (such as cookies or tokens) in URL (Ra-user1), URL (Rb_user1) and URL (Rc-user1). The specific definitions are as follows:

[0167] {url|The cookie of user Ra_user1 (or user Rc_user1; which may correspond to the identity authentication information of the user under the first role) replaces the cookie in all request URLs of user Rb_usCrr1 in the P6 set (which may correspond to the user identity authentication information in the first data corresponding to the permission difference set corresponding to the second role)};

[0168] {url|cookie of user Rb_user1 (or cookie of user Rc_user1; which may correspond to the identity authentication information of the user under the first role) replaces the cookie in all request URLs of user Ra_user1 in the P5 set (which may correspond to the user identity authentication information in the first data corresponding to the permission difference set corresponding to the second role)};

[0169] {url|The cookie of user Ra_user1 (or the cookie of user Rb_user1; which may correspond to the identity authentication information of the user under the first role) replaces the cookie in all request URLs of user Rc_user1 in the P7 set (which may correspond to the user identity authentication information in the first data corresponding to the permission difference set corresponding to the second role)};

[0170] Based on the above transformations, the first unauthorized access test case in this application can be obtained, and the above related operations can correspond to the above-mentioned acquisition of user full-link behavior data corresponding to each role under the tested system; the user full-link behavior data includes: behavior data of all operations within the authority range corresponding to the role; determining the permission difference set corresponding to each of the roles; the permissions in the permission difference set are permissions that other roles except the role do not have; constructing the first unauthorized access test case based on the first data corresponding to each of the permission difference sets in the user full-link behavior data; the first unauthorized access test case is used to detect whether the user under the first role has the authority of the second role; the determination of the permission difference set corresponding to each of the roles includes: obtaining the The intersection of permissions between every two roles under the system under test; determining the permission difference set corresponding to each role based on the permission intersection; constructing a first unauthorized access test case based on the first data corresponding to each permission difference set in the user's full-link behavior data, including: replacing the user authentication information in the first data corresponding to the permission difference set corresponding to the second role with the authentication information of the user under the first role, and obtaining deformed data corresponding to the first data; the second role is any role under the system under test, and the first role is any role under the system under test except the second role; obtaining a first unauthorized access test case based on the deformed data corresponding to the first data corresponding to each permission difference set.

[0171] In addition, based on Vul(2), we can extract the access request URLs of the three users Ra_user1, Rb_user1 and Rc_user1 that belong to the request traffic of Vul(2), and set the cookies (verification information) in all request URLs to empty, and obtain the transformed URL set T url-2 ; Corresponding to the above, a second unauthorized access test case is constructed based on the user's full-link behavior data; the second unauthorized access test case is used to detect whether unauthorized access is possible under each of the roles; the second unauthorized access test case is constructed based on the user's full-link behavior data, including: setting the user identity authentication information in the user's full-link behavior data to blank to obtain the second unauthorized access test case.

[0172] Based on the above transformed set, the transformed URL set T can be replayed url_1 and T url_2All traffic (such as automatically executing a process once according to the user's operation process by the system) initiates a vertical privilege escalation vulnerability test (which can correspond to the above-mentioned vertical privilege escalation vulnerability detection according to the first privilege escalation test case and the second privilege escalation test case). Specifically, this solution can still use the stubbing technology to capture and replay request responses, form user behavior tracking log data, extract <URL, API, SQL statements> from the log data, and compare with the permission whitelist of this user role to determine whether there is a vulnerability; for example, extract <URL m , API m , SQL m > that does not belong to the permission set Then there is a vertical privilege escalation vulnerability in this URL (it can also be considered that in the case where the operation based on the deformed set is successful, such as successfully extracting the permission elements <URL, API, SQL>, it is determined that there is a vertical privilege escalation vulnerability in this URL, but not limited to this); for another example, for the extracted tracking log in the anonymous state, if the permission elements <URL, API, SQL> are successfully extracted from it, it can be determined that there is an unauthorized access (vertical) privilege escalation vulnerability in this URL; this part of the content can correspond to the above-mentioned vertical privilege escalation vulnerability detection according to the first privilege escalation test case and the second privilege escalation test case, including: running the first privilege escalation test case and the second privilege escalation test case to obtain running data; determining whether there is a vertical privilege escalation vulnerability according to the running data; wherein, determining whether there is a vertical privilege escalation vulnerability according to the running data includes: determining that there is a vertical privilege escalation vulnerability when the triple corresponding to the permission in the running data does not belong to the permission set of the corresponding user; and / or, determining that there is a vertical privilege escalation vulnerability when the triple exists in the running data.

[0173] As described above, the solution provided by the embodiment of this application involves the following content:

[0174] 1. The comprehensiveness and accuracy of the coverage of vertical privilege escalation test cases;

[0175] This solution automatically obtains the fine-grained role permission sets expressed in <URL, API, SQL statements> for all roles of the system under test by inserting probes at multiple key nodes in the system call chain of the system under test, as long as at least one user of each role in the system under test traverses all its functional operations (by using the automatic probe insertion method to conduct internal observation on the running space of the system under test, the full-link tracking information of the user request behavior during traversal operations can be obtained without modifying the application source code of the system to be detected); by performing operations on the role permission sets, the required test URL information can be obtained, and then by replacing the user authentication information (such as cookie or token), a deformed request URL can be formed for replay testing. This ensures the coverage and accuracy of test cases and greatly improves the detection rate of vertical privilege escalation vulnerabilities.

[0176] 2. The differences in collecting test response data and the judgment methods for the existence of vulnerabilities;

[0177] The first problem to be solved by this solution is the problem of collecting test response context data. By inserting probes, monitoring, and forming tracking logs of user request behaviors at multiple key nodes in the system call chain of the system under test, the tracking logs do not depend on the logs of the business system itself. Secondly, based on the full-link tracking logs of user behaviors, a vulnerability detection model is formed, that is, the white list of permissions for user roles.

[0178] Replay all traffic of the deformed URL. Still through the probe insertion technology, obtain the full-link tracking logs of user behaviors of the replay traffic; if permission elements <URL, API, SQL> are successfully extracted from the log data, use them as inputs to the vulnerability detection model to determine whether <URL, API, SQL> is in the white list of permissions for this user. If not, there is a (vertical) privilege escalation vulnerability. This judgment method is simple and effective, greatly reducing the false positive rate of vertical privilege escalation vulnerabilities.

[0179] In summary, this solution has the following advantages:

[0180] 1. The test cases are comprehensively covered, greatly improving the detection rate of vulnerabilities, and the automation degree is very high;

[0181] 2. The context information of the test response data collection is richer. Only need to judge whether it is within the white list of permissions. The calculation is simple and effective, which can greatly reduce the false positive rate of vulnerability judgment.

[0182] It should be noted here that this solution has relatively wide applicability for detecting application system business logic vulnerabilities (vertical privilege escalation vulnerabilities).

[0183] The embodiment of this application also provides a vertical privilege escalation vulnerability detection device, as Figure 3 shown, including:

[0184] The first acquisition module 31 is used to obtain the user full-link behavior data corresponding to each role in the tested system; the user full-link behavior data includes: behavior data of all operations within the authority scope corresponding to the role;

[0185] A first determining module 32 is configured to determine a permission difference set corresponding to each of the roles; the permissions in the permission difference set are permissions that other roles do not have except the role;

[0186] A first construction module 33 is configured to construct a first permission violation test case based on the first data corresponding to each permission difference set in the user full-link behavior data; the first permission violation test case is configured to detect whether the user in the first role has the permission of the second role;

[0187] A second construction module 34 is configured to construct a second unauthorized access test case based on the user's full-link behavior data; the second unauthorized access test case is configured to detect whether unauthorized access is possible under each of the roles;

[0188] The first detection module 35 is configured to perform vertical unauthorized access vulnerability detection based on the first unauthorized access test case and the second unauthorized access test case.

[0189] The vertical unauthorized access vulnerability detection device provided in the embodiment of the present application obtains the user full-link behavior data corresponding to each role under the tested system; the user full-link behavior data includes: behavior data of all operations within the authority range corresponding to the role; determines the permission difference set corresponding to each role; the permissions in the permission difference set are permissions that other roles except the role do not have; constructs a first unauthorized access test case based on the first data corresponding to each permission difference set in the user full-link behavior data; the first unauthorized access test case is used to detect whether the user under the first role has the permission of the second role; constructs a second unauthorized access test case based on the user full-link behavior data. Two unauthorized access test cases; the second unauthorized access test case is used to detect whether unauthorized access is possible under each of the roles; vertical unauthorized access vulnerability detection is performed based on the first unauthorized access test case and the second unauthorized access test case; it can support the construction of comprehensive test cases, and can eliminate test cases that misjudge vulnerabilities in scenarios where two users have overlapping permissions, so as to obtain comprehensive, necessary and misjudgment-eliminating test cases, and then support automatic vulnerability detection based on this, avoid manual intervention as much as possible, reduce the misjudgment rate of judgment results, and well solve the problems of high misjudgment rate of judgment results and incomplete and unnecessary test cases in the vertical unauthorized access vulnerability detection scheme in the existing technology.

[0190] Among them, obtaining the user full-link behavior data corresponding to each role under the system under test includes: performing insertion and tracking operations on the target nodes in the system under test to obtain the user full-link behavior data corresponding to each role under the system under test.

[0191] In an embodiment of the present application, determining the permission difference set corresponding to each of the roles includes: obtaining the permission intersection between every two of the roles in the system under test; and determining the permission difference set corresponding to each of the roles based on the permission intersection.

[0192] Among them, the first unauthorized access test case is constructed based on the first data corresponding to each of the permission difference sets in the user's full-link behavior data, including: replacing the user identity authentication information in the first data corresponding to the permission difference set corresponding to the second role with the identity authentication information of the user under the first role, to obtain the deformed data corresponding to the first data; the second role is any role under the system under test, and the first role is any role under the system under test except the second role; the first unauthorized access test case is obtained based on the deformed data corresponding to the first data corresponding to each of the permission difference sets; and / or, the second unauthorized access test case is constructed based on the user's full-link behavior data, including: setting the user identity authentication information in the user's full-link behavior data to blank, to obtain the second unauthorized access test case.

[0193] In an embodiment of the present application, the permissions corresponding to the role are represented by a triple, and the triple includes: a uniform resource locator URL, an application programming interface API, and a structured query language SQL statement; the vertical unauthorized access vulnerability detection is performed based on the first unauthorized access test case and the second unauthorized access test case, including: running the first unauthorized access test case and the second unauthorized access test case to obtain operation data; and determining whether there is a vertical unauthorized access vulnerability based on the operation data.

[0194] Among them, the implementation embodiments of the above-mentioned vertical authority overflow vulnerability detection method are all applicable to the embodiments of the vertical authority overflow vulnerability detection device and can also achieve the same technical effects.

[0195] The present application also provides a vertical overreach vulnerability detection device, such as Figure 4 As shown, it includes: a processor 41;

[0196] The processor 41 is configured to obtain user full-link behavior data corresponding to each role in the system under test; the user full-link behavior data includes behavior data of all operations within the authority scope corresponding to the role;

[0197] Determine a permission difference set corresponding to each of the roles; the permissions in the permission difference set are permissions that other roles except the role do not have;

[0198] Constructing a first permission violation test case based on the first data corresponding to each permission difference set in the user full-link behavior data; the first permission violation test case is used to detect whether the user under the first role has the permission of the second role;

[0199] Constructing a second unauthorized access test case based on the user's full-link behavior data; the second unauthorized access test case is used to detect whether unauthorized access is possible under each of the roles;

[0200] Perform vertical unauthorized access vulnerability detection based on the first unauthorized access test case and the second unauthorized access test case.

[0201] The vertical unauthorized access vulnerability detection device provided in the embodiment of the present application obtains the user full-link behavior data corresponding to each role under the tested system; the user full-link behavior data includes: behavior data of all operations within the authority range corresponding to the role; determines the permission difference set corresponding to each role; the permissions in the permission difference set are permissions that other roles except the role do not have; constructs a first unauthorized access test case based on the first data corresponding to each permission difference set in the user full-link behavior data; the first unauthorized access test case is used to detect whether the user under the first role has the permission of the second role; constructs a second unauthorized access test case based on the user full-link behavior data. Two unauthorized access test cases; the second unauthorized access test case is used to detect whether unauthorized access is possible under each of the roles; vertical unauthorized access vulnerability detection is performed based on the first unauthorized access test case and the second unauthorized access test case; it can support the construction of comprehensive test cases, and can eliminate test cases that misjudge vulnerabilities in scenarios where two users have overlapping permissions, so as to obtain comprehensive, necessary and misjudgment-eliminating test cases, and then support automatic vulnerability detection based on this, avoid manual intervention as much as possible, reduce the misjudgment rate of judgment results, and well solve the problems of high misjudgment rate of judgment results and incomplete and unnecessary test cases in the vertical unauthorized access vulnerability detection scheme in the existing technology.

[0202] Among them, obtaining the user full-link behavior data corresponding to each role under the system under test includes: performing insertion and tracking operations on the target nodes in the system under test to obtain the user full-link behavior data corresponding to each role under the system under test.

[0203] In an embodiment of the present application, determining the permission difference set corresponding to each of the roles includes: obtaining the permission intersection between every two of the roles in the system under test; and determining the permission difference set corresponding to each of the roles based on the permission intersection.

[0204] Among them, the first unauthorized access test case is constructed based on the first data corresponding to each of the permission difference sets in the user's full-link behavior data, including: replacing the user identity authentication information in the first data corresponding to the permission difference set corresponding to the second role with the identity authentication information of the user under the first role, to obtain the deformed data corresponding to the first data; the second role is any role under the system under test, and the first role is any role under the system under test except the second role; the first unauthorized access test case is obtained based on the deformed data corresponding to the first data corresponding to each of the permission difference sets; and / or, the second unauthorized access test case is constructed based on the user's full-link behavior data, including: setting the user identity authentication information in the user's full-link behavior data to blank, to obtain the second unauthorized access test case.

[0205] In an embodiment of the present application, the permissions corresponding to the role are represented by a triple, and the triple includes: a uniform resource locator URL, an application programming interface API, and a structured query language SQL statement; the vertical unauthorized access vulnerability detection is performed based on the first unauthorized access test case and the second unauthorized access test case, including: running the first unauthorized access test case and the second unauthorized access test case to obtain operation data; and determining whether there is a vertical unauthorized access vulnerability based on the operation data.

[0206] Among them, the implementation embodiments of the above-mentioned vertical privilege escalation vulnerability detection method are all applicable to the embodiments of the vertical privilege escalation vulnerability detection device and can also achieve the same technical effects.

[0207] An embodiment of the present application also provides a vertical privilege escalation vulnerability detection device, comprising a memory, a processor, and a program stored in the memory and executable on the processor; when the processor executes the program, the above-mentioned vertical privilege escalation vulnerability detection method is implemented.

[0208] Among them, the implementation embodiments of the above-mentioned vertical privilege escalation vulnerability detection method are all applicable to the embodiments of the vertical privilege escalation vulnerability detection device and can also achieve the same technical effects.

[0209] An embodiment of the present application also provides a readable storage medium on which a program is stored. When the program is executed by a processor, the steps in the above-mentioned vertical privilege escalation vulnerability detection method are implemented.

[0210] Among them, the implementation embodiments of the above-mentioned vertical authority overflow vulnerability detection method are all applicable to the embodiments of the readable storage medium and can also achieve the same technical effects.

[0211] An embodiment of the present application also provides a computer program product, including computer instructions. When the computer instructions are executed by a processor, the various processes of the method embodiment of the above-mentioned vertical privilege escalation vulnerability detection method are implemented, and the same technical effect can be achieved. To avoid repetition, they will not be repeated here.

[0212] It should be noted that many functional components described in this specification are referred to as modules in order to more particularly emphasize the independence of their implementation methods.

[0213] In embodiments of the present application, modules can be implemented in software so that they can be executed by various types of processors. For example, an identified executable code module can include one or more physical or logical blocks of computer instructions, for example, which can be constructed as objects, processes, or functions. Nevertheless, the executable code of the identified module does not need to be physically located together, but can include different instructions stored in different locations, which, when logically combined together, constitute the module and achieve the specified purpose of the module.

[0214] In fact, executable code module can be a single instruction or many instructions, and can even be distributed on a plurality of different code segments, distributed in the middle of different programs, and distributed across a plurality of memory devices.Similarly, operating data can be identified in the module, and can be implemented and organized in the data structure of any appropriate type according to any appropriate form.Described operating data can be collected as a single data set, or can be distributed in different locations (including on different storage devices), and can only be present on a system or network as an electronic signal at least in part.

[0215] When a module can be implemented using software, given the current state of hardware technology, those skilled in the art can build corresponding hardware circuits to implement the corresponding functions of the module, regardless of cost. The hardware circuits may include conventional very large scale integration (VLSI) circuits or gate arrays, as well as existing semiconductors such as logic chips and transistors, or other discrete components. Modules may also be implemented using programmable hardware devices, such as field programmable gate arrays, programmable array logic, or programmable logic devices.

[0216] The above is a preferred embodiment of the present application. It should be pointed out that for ordinary personnel in this technical field, several improvements and modifications can be made without departing from the principles described in the present application. These improvements and modifications should also be regarded as the scope of protection of the present application.

Claims

1. A vertical privilege escalation vulnerability detection method, characterized in that: include: Obtain the full-link user behavior data corresponding to each role in the system under test; The user's full-link behavior data includes: behavior data of all operations within the authority scope corresponding to the role; Determine a permission difference set corresponding to each of the roles; the permissions in the permission difference set are permissions that other roles except the role do not have; Constructing a first permission violation test case based on the first data corresponding to each permission difference set in the user full-link behavior data; the first permission violation test case is used to detect whether the user under the first role has the permission of the second role; Constructing a second unauthorized access test case based on the user's full-link behavior data; the second unauthorized access test case is used to detect whether unauthorized access is possible under each of the roles; Perform vertical unauthorized access vulnerability detection based on the first unauthorized access test case and the second unauthorized access test case.

2. The vertical privilege escalation vulnerability detection method according to claim 1, characterized in that: The acquisition of user full-link behavior data corresponding to each role in the tested system includes: Perform instrumentation operations on the target nodes in the system under test to obtain the full-link user behavior data corresponding to each role in the system under test.

3. The vertical privilege escalation vulnerability detection method according to claim 1, characterized in that: Determining the permission difference set corresponding to each of the roles includes: Obtaining the intersection of permissions between every two roles in the system under test; According to the permission intersection, the permission difference set corresponding to each of the roles is determined.

4. The vertical privilege escalation vulnerability detection method according to claim 1, characterized in that: The step of constructing a first unauthorized test case based on the first data corresponding to each permission difference set in the user full-link behavior data includes: Replacing the user authentication information in the first data corresponding to the permission difference set corresponding to the second role with the authentication information of the user under the first role, to obtain deformed data corresponding to the first data; the second role is any role under the system under test, and the first role is any role under the system under test except the second role; Obtaining a first unauthorized test case according to the deformed data corresponding to the first data corresponding to each of the permission difference sets; And / or, constructing a second unauthorized test case based on the user's full-link behavior data includes: The user identity authentication information in the user full-link behavior data is cleared to obtain a second unauthorized test case.

5. The vertical privilege escalation vulnerability detection method according to claim 1, characterized in that: The permissions corresponding to the role are represented by a triple, which includes: a uniform resource locator URL, an application programming interface API, and a structured query language SQL statement; The performing of vertical privilege escalation vulnerability detection according to the first privilege escalation test case and the second privilege escalation test case includes: Running the first and second unauthorized test cases to obtain running data; Determine whether a vertical privilege escalation vulnerability exists based on the operational data.

6. A vertical unauthorized vulnerability detection device, characterized in that: include: The first acquisition module is used to obtain the full-link user behavior data corresponding to each role in the tested system; The user's full-link behavior data includes: behavior data of all operations within the authority scope corresponding to the role; A first determining module is configured to determine a permission difference set corresponding to each of the roles; the permissions in the permission difference set are permissions that other roles except the role do not have; A first construction module is configured to construct a first permission violation test case based on the first data corresponding to each permission difference set in the user full-link behavior data; the first permission violation test case is configured to detect whether a user in the first role has the permission of the second role; A second construction module is used to construct a second unauthorized access test case based on the user's full-link behavior data; the second unauthorized access test case is used to detect whether unauthorized access is possible under each of the roles; The first detection module is used to perform vertical unauthorized access vulnerability detection based on the first unauthorized access test case and the second unauthorized access test case.

7. The vertical unauthorized access vulnerability detection device according to claim 6, characterized in that: The acquisition of user full-link behavior data corresponding to each role in the tested system includes: Perform instrumentation operations on the target nodes in the system under test to obtain the full-link user behavior data corresponding to each role in the system under test.

8. The vertical unauthorized access vulnerability detection device according to claim 6, characterized in that: Determining the permission difference set corresponding to each of the roles includes: Obtaining the intersection of permissions between every two roles in the system under test; According to the permission intersection, the permission difference set corresponding to each of the roles is determined.

9. The vertical unauthorized access vulnerability detection device according to claim 6, characterized in that: The step of constructing a first unauthorized test case based on the first data corresponding to each permission difference set in the user full-link behavior data includes: Replacing the user authentication information in the first data corresponding to the permission difference set corresponding to the second role with the authentication information of the user under the first role, to obtain deformed data corresponding to the first data; the second role is any role under the system under test, and the first role is any role under the system under test except the second role; Obtaining a first unauthorized test case according to the deformed data corresponding to the first data corresponding to each of the permission difference sets; And / or, constructing a second unauthorized test case based on the user's full-link behavior data includes: The user identity authentication information in the user full-link behavior data is cleared to obtain a second unauthorized test case.

10. The vertical unauthorized access vulnerability detection device according to claim 6, characterized in that: The permissions corresponding to the role are represented by a triple, which includes: a uniform resource locator URL, an application programming interface API, and a structured query language SQL statement; The performing of vertical privilege escalation vulnerability detection according to the first privilege escalation test case and the second privilege escalation test case includes: Running the first and second unauthorized test cases to obtain running data; Determine whether a vertical privilege escalation vulnerability exists based on the operational data.

11. A vertical unauthorized vulnerability detection device, characterized in that: include: processor; The processor is used to obtain the full-link behavior data of users corresponding to each role in the tested system; The user's full-link behavior data includes: behavior data of all operations within the authority scope corresponding to the role; Determine a permission difference set corresponding to each of the roles; the permissions in the permission difference set are permissions that other roles except the role do not have; Constructing a first permission violation test case based on the first data corresponding to each permission difference set in the user full-link behavior data; the first permission violation test case is used to detect whether the user under the first role has the permission of the second role; Constructing a second unauthorized access test case based on the user's full-link behavior data; the second unauthorized access test case is used to detect whether unauthorized access is possible under each of the roles; Perform vertical unauthorized access vulnerability detection based on the first unauthorized access test case and the second unauthorized access test case.

12. A vertical privilege escalation vulnerability detection device, comprising a memory, a processor, and a program stored in the memory and executable on the processor; characterized in that: When the processor executes the program, the vertical privilege escalation vulnerability detection method according to any one of claims 1 to 5 is implemented.

13. A readable storage medium having a program stored thereon, characterized in that: When the program is executed by a processor, the steps of the vertical privilege escalation vulnerability detection method according to any one of claims 1 to 5 are implemented.

14. A computer program product, characterized in that The method comprises computer instructions, which, when executed by a processor, implement the steps of the vertical privilege escalation vulnerability detection method according to any one of claims 1 to 5.