Vertical unauthorized detection system based on dynamic role configuration and automatic batch testing

By using dynamic role configuration and automated batch testing, combined with Jenkins and JMeter, the problems of low efficiency, insufficient coverage and scattered results in vertical privilege escalation detection are solved. This enables efficient and real-time multi-role combination testing and result analysis, and supports rapid adaptation to new permission models.

CN120950381APending Publication Date: 2025-11-14BOSI DIGITAL TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510932328.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-07
Publication Date
2025-11-14

AI Technical Summary

Technical Problem

In existing technologies, vertical overreach detection is inefficient, has insufficient coverage, fragmented results analysis, and weak task scheduling capabilities, making it difficult to cope with large-scale systems and complex permission models.

Method used

The system adopts dynamic role configuration and automated batch testing, combined with Jenkins scheduling center and JMeter test engine. Role combinations are defined through CSV test case management module, user access is simulated using permissions, and time-series storage and visual dashboards are integrated for real-time analysis.

Benefits of technology

It achieves efficient multi-role combination testing, with coverage increased to 99%, real-time visualization of results, and system availability up to 99.9%. It also supports rapid adaptation to new permission models and shortens the development cycle.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120950381A_ABST
    Figure CN120950381A_ABST
Patent Text Reader

Abstract

The invention discloses a vertical unauthorized detection system based on dynamic role configuration and automatic batch testing. The vertical unauthorized detection system comprises a CSV test case management module; an authority simulation module; the test scheduling and execution module is used for integrating a Jenkins scheduling center and a JMeter test engine; a time sequence storage module; and a visual billboard module. Through combination of a Jenkins dispatching center and a JMeter test engine, unauthorized detection of thousands of interfaces can be completed at a time, and the efficiency is improved by more than 90% compared with manual test; and moreover, an allowable role combination field is defined in the test case file, a multi-role combination test is covered, more than 99% of permission boundary scenes can be covered, and repeated work of a traditional single-role test is avoided.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of data security technology, and in particular to a vertical privilege escalation detection system based on dynamic role configuration and automated batch testing. Background Technology

[0002] Vertical privilege escalation is a significant issue in information security, referring to low-privilege users unauthorized access to the resources or functions of high-privilege users. Current technologies commonly employ manual testing and single-script testing methods. Manual testing relies on manually verifying interface permissions one by one, resulting in low efficiency and coverage, making it unsuitable for large-scale systems. Single-script testing, on the other hand, only involves writing test cases for specific interfaces, lacking batch execution and dynamic expansion capabilities.

[0003] In summary, the shortcomings of existing technologies and their causes are analyzed as follows:

[0004] ① Low testing efficiency

[0005] Disadvantages: Manual testing is extremely time-consuming and difficult to cover scenarios with multiple roles (such as overlapping permissions for roles 2, 3, and 4); automated scripts with fixed roles cannot dynamically adapt to complex permission models.

[0006] Cause: Lack of dynamic role configuration mechanism, such as failure to use standardized files (such as CSV) to define multiple role combinations (allowed_roles field), resulting in rigid test case generation.

[0007] ②Insufficient coverage

[0008] Disadvantages: Existing tools only verify basic status codes (such as 500) and ignore multi-dimensional response content verification (such as keyword matching from expected_response1 to expected_response5), making it easy to miss hidden vulnerabilities.

[0009] Reason: The test logic is too simple, it does not implement intelligent matching of multiple conditions for the response content, and it does not support parameterized input (such as param1, param2) enough.

[0010] ③Results analysis is scattered

[0011] Disadvantages: Test results are scattered in local logs or independent reports, lacking unified storage and real-time visualization capabilities, making it difficult to quickly locate abnormal interfaces (such as services with a sudden increase in failure rate).

[0012] Cause: The lack of integration with time-series databases (such as InfluxDB) and visualization tools (such as Grafana) leads to delays in data aggregation and analysis.

[0013] ④ Weak task scheduling capability

[0014] Disadvantages: Multi-environment and multi-service testing relies on manual triggering and cannot be executed in batches as needed (such as testing MaiChang and ZhanLue R&D centers at the same time), and abnormal tasks are prone to interrupting the overall process.

[0015] Reasons: Lack of a distributed scheduling framework (such as Jenkins Pipeline), simple task distribution logic, and error isolation mechanism. Summary of the Invention

[0016] The purpose of this invention is to provide a vertical privilege escalation detection system based on dynamic role configuration and automated batch testing. It can complete privilege escalation detection of thousands of interfaces in a single run by combining the Jenkins scheduling center and the JMeter testing engine.

[0017] This invention is achieved through the following technical solution:

[0018] A vertical privilege escalation detection system based on dynamic role configuration and automated batch testing includes:

[0019] The CSV test case management module is used to define and manage test case files. The test case files include fields such as interface path, request method, allowed role combination, multi-dimensional response keyword, expected status code, and request parameter.

[0020] The permission simulation module can execute an external token generation program, parse the allowed role combination field in the test case file, and dynamically generate multi-permission user access tokens to simulate access behavior from low-permission roles to high-permission roles.

[0021] The test scheduling and execution module integrates the Jenkins scheduling center and the JMeter test engine. The Jenkins scheduling center is used to distribute and schedule multiple test tasks; the JMeter test engine uses access tokens generated by the permission simulation module to simulate users with different permission levels to initiate HTTP interface requests to the system under test, collect response results and compare them with the expected status code field.

[0022] The time-series storage module can partition and store the response results collected by the JMeter test engine according to the timestamp of the test batch, and combine the data calculation and processing mechanism to verify and statistically analyze the response results, forming real-time response datasets and historical response datasets.

[0023] The visualization dashboard module can query real-time response datasets and historical response datasets from the time-series storage module and finally display the visualization results.

[0024] Compared with previous technologies, the beneficial effects of the present invention are as follows:

[0025] 1. By combining the Jenkins scheduling center with the JMeter testing engine, thousands of interfaces can be tested for unauthorized access in a single run, improving efficiency by more than 90% compared to manual testing. Moreover, the test case file defines fields that allow role combinations, covering multi-role combination testing and covering more than 99% of permission boundary scenarios, avoiding the repetitive work of traditional single-role testing.

[0026] 2. Use the Grafana dashboard module to display key metrics such as success rate and failure interface distribution in real time. You can also filter by time range for historical comparison. Furthermore, you can use the Shell script module to automatically generate HTML test reports and compress and archive them after the test is completed.

[0027] 3. The task isolation mechanism of the Jenkins scheduling center can ensure that the failure of a single service does not affect the whole system, and the system availability reaches 99.9%.

[0028] 4. When adding a new business system, there is no need to modify the core test logic. It supports quick adaptation to the new permission model by adding a new CSV test case file or adjusting the allowed_roles field, which can significantly shorten the development cycle of the new business system. Attached Figure Description

[0029] Figure 1 This is a block diagram of the modules of the present invention;

[0030] Figure 2 This is a flowchart of the present invention;

[0031] Figure 3 This is a flowchart illustrating how the test execution results are written to the InfluxDB storage module according to the present invention. Detailed Implementation

[0032] The present invention will now be described in detail with reference to the accompanying drawings, but the scope of protection of the present invention is not limited to the following description:

[0033] like Figure 1 and Figure 2 As shown, the vertical privilege escalation detection system based on dynamic role configuration and automated batch testing includes:

[0034] The CSV test case management module is used to define and manage test case files. The test case files include the interface path field, the request method field, the allowed role combination field, the multi-dimensional response keyword field (expected_response1-5), the expected status code field (expected_status), and the request parameter fields (param1, param2).

[0035] The permission simulation module can execute an external token generation program, parse the allowed role combination field in the test case file, and dynamically generate multi-permission user access tokens to simulate access behavior from low-permission roles to high-permission roles.

[0036] The test scheduling and execution module integrates the Jenkins scheduling center and the JMeter test engine. The Jenkins scheduling center is used to distribute and schedule multiple test tasks. The JMeter test engine uses access tokens generated by the permission simulation module to simulate users with different permission levels to initiate HTTP interface requests to the system under test, collect response results, and compare them with the expected status code field. The real-time response dataset generated by the JMeter test engine includes response results, total number of interfaces, number of deduplicated interfaces, number of abnormal interfaces, number of unauthorized interfaces, and interface request success rate.

[0037] The time-series storage module can partition and store the response results collected by the JMeter test engine according to the timestamp of the test batch, and combine the data calculation and processing mechanism to verify and statistically analyze the response results, forming real-time response datasets and historical response datasets.

[0038] The visualization dashboard module can query real-time response datasets and historical response datasets from the time-series storage module and finally display the visualization results. The visualization results of the visualization dashboard module include trend charts of interface request success rates, exception and privilege escalation information charts, and comparison charts of real-time response datasets and historical response datasets.

[0039] It also includes a Shell script module, which can automatically sort through historical response datasets, generate data directories with timestamps, compress real-time response datasets and historical response datasets into archive files, and finally send the archive files to the administrator's email address. It should be noted that the Shell script module can choose whether to send the archive files to the administrator's email address, which can be set according to the needs of the administrator / user. In the embodiments of the present invention, an email alarm function is set when the success rate is less than 99%.

[0040] It also includes a task isolation mechanism that works with the Jenkins scheduling center. When an erroneous task is scheduled by the Jenkins scheduling center, the task isolation mechanism can isolate the task and control the Jenkins scheduling center to retry the task or skip the task execution.

[0041] Furthermore, the number of abnormal interfaces refers to the number of interfaces that reported abnormalities after the task was executed, and the number of unauthorized interfaces refers to the number of interfaces where assertions failed or unauthorized access occurred.

[0042] In this invention, the Jenkins scheduling center, as a continuous integration platform, supports parallel execution of test tasks across multiple nodes, ensuring good scalability and stability even under high load scenarios. The JMeter testing engine, a powerful open-source performance testing tool, can simulate various roles, scenarios, and request behaviors to efficiently verify interface permissions. By combining the Jenkins scheduling center and the JMeter testing engine, thousands of interfaces can be checked for unauthorized access in a single run, improving efficiency by over 90% compared to manual testing. Furthermore, the test case file defines fields allowing role combinations, covering multi-role combination testing and encompassing over 99% of permission boundary scenarios, avoiding the repetitive work of traditional single-role testing.

[0043] Furthermore, the time-series storage module is an InfluxDB storage module; the visualization dashboard module is a Grafana dashboard module.

[0044] like Figure 2 As shown, the vertical over-authority detection process of the present invention is as follows:

[0045] ① Test preparation phase:

[0046] The CSV test case management module is used to load and prepare test case files. The test case files define the fields shown in the table below:

[0047]

[0048] The CSV test case management module supports adding and deleting test case files and modifying field definitions; the permission simulation module reads the test case file, parses the allowed role combination field (allowed_roles), and dynamically configures role relationships based on this field; the system generates user access tokens sequentially from low-privilege roles to high-privilege roles by repeatedly calling the generateToken.sh script, providing identity credentials for the subsequent test execution phase;

[0049] ② Test execution phase:

[0050] In this phase, the Jenkins scheduling center is responsible for distributing test tasks to the JMeter testing engine. Upon receiving the user token generated and passed in by the `generateToken.sh` script, the JMeter testing engine, combined with parameterized configurations (such as CSV files or command-line variables), executes all test tasks for each user identity, simulating HTTP requests and capturing the response results of the system under test. Specifically, during this process, the JMeter testing engine, through integrated components, writes the response results of each request to the InfluxDB storage module's database, partitioned by test batch timestamp. After all tests are completed, the JMeter testing engine can also use data processing mechanisms to verify and statistically analyze all response results, including the total number of interfaces, the number of deduplicated interfaces, the number of abnormal interfaces, the number of privilege-exceeding interfaces, and the interface request success rate. These results are also written to the InfluxDB storage module's database, partitioned by test batch timestamp, forming a complete real-time response dataset. Figure 3 The diagram shows the specific process of writing to the InfluxDB storage module;

[0051] ③ Results processing stage:

[0052] The Grafana dashboard module generates and displays trend charts of interface request success rates, anomaly and privilege escalation information charts, and comparison charts between real-time and historical response datasets by querying real-time and historical response datasets. Meanwhile, the Shell script module can automatically organize historical response datasets, generate data directories with timestamps, compress real-time and historical datasets into archive files, and finally send them to the administrator's email address to realize email alert functionality.

[0053] Taking a simple e-commerce platform as an example, this study examines vertical privilege escalation detection based on user roles. The platform has four roles: User (Role 1), Customer Service (Role 2), Product Administrator (Role 3), and System Administrator (Role 4). The goal is to ensure that users with lower privileges cannot access or modify functions with higher privileges. Two test objectives are shown in the table below:

[0054]

[0055] The test results are shown in the table below:

[0056]

[0057] Test Target 1: Roles 2 and 4 are allowed access roles. Roles 1 and 3 were tested together. The test_status of both roles was 403 (indicating no access permission status code), and the test_response showed message:"The currently logged-in user has no operation permission" and message:"No operation permission" respectively. These are the expected responses defined in the multi-dimensional response keyword fields (expected_response1-5).

[0058] Therefore, in test objective 1, no privilege escalation occurred, the total number of interfaces was 2, the number of deduplicated interfaces was 0, the number of abnormal interfaces was 0, the number of privilege escalation cases was 0, and the interface request success rate was 100%.

[0059] Test Target 2: Role 4 is an authorized access role. Roles 1, 2, and 3 were tested in combination. Roles 1 and 2 both returned a test_status of 403, and their test_responses contained "message":"Current logged-in user has no permission to operate" and "message":"Access denied," respectively. This indicates that neither role 1 nor 2 exceeded their privileges. However, role 3 returned a test_status of 200, and its test_response contained "message":"OK," indicating that role 3 successfully exceeded its privileges.

[0060] Therefore, in test objective 2, the total number of interfaces is 3, the number of deduplicated interfaces is 0, the number of abnormal interfaces is 0, the number of privilege violations is 1, and the interface request success rate is approximately 66.7%.

[0061] Although the present invention has been illustrated and described through specific embodiments and alternative methods, it should be understood that various changes and modifications may be made without departing from the spirit and scope of the invention. Therefore, it should be understood that the present invention is not limited in any sense except by the appended claims and their equivalents.

Claims

1. A vertical privilege escalation detection system based on dynamic role configuration and automated batch testing, characterized in that, include: The CSV test case management module is used to define and manage test case files; The test case file includes the interface path field, request method field, allowed role combination field, multi-dimensional response keyword field, expected status code field, and request parameter field. The permission simulation module can execute an external token generation program, parse the allowed role combination field in the test case file, and dynamically generate multi-permission user access tokens to simulate access behavior from low-permission roles to high-permission roles. The test scheduling and execution module integrates the Jenkins scheduling center and the JMeter test engine. The Jenkins scheduling center is used to distribute and schedule multiple test tasks; the JMeter test engine uses access tokens generated by the permission simulation module to simulate users with different permission levels to initiate HTTP interface requests to the system under test, collect response results and compare them with the expected status code field. The time-series storage module can partition and store the response results collected by the JMeter test engine according to the timestamp of the test batch, and combine the data calculation and processing mechanism to verify and statistically analyze the response results, forming real-time response datasets and historical response datasets. The visualization dashboard module can query real-time response datasets and historical response datasets from the time-series storage module and finally display the visualization results.

2. The vertical privilege escalation detection system based on dynamic role configuration and automated batch testing according to claim 1, characterized in that: The real-time response dataset generated by the JMeter testing engine includes response results, total number of interfaces, number of deduplicated interfaces, number of abnormal interfaces, number of unauthorized interfaces, and interface request success rate.

3. The vertical privilege escalation detection system based on dynamic role configuration and automated batch testing according to claim 2, characterized in that: The visualization results of the visualization dashboard module include a trend chart of interface request success rate, an exception and privilege escalation information chart, and a comparison chart of real-time response dataset and historical response dataset.

4. The vertical privilege escalation detection system based on dynamic role configuration and automated batch testing according to claim 1, characterized in that: It also includes a Shell script module, which can automatically sort through historical response datasets, generate data directories with timestamps, compress real-time response datasets and historical response datasets into archive files, and finally send the archive files to the administrator's email address.

5. The vertical privilege escalation detection system based on dynamic role configuration and automated batch testing according to claim 1, characterized in that: It also includes a task isolation mechanism that works with the Jenkins scheduling center. When an erroneous task is scheduled by the Jenkins scheduling center, the task isolation mechanism can isolate the task and control the Jenkins scheduling center to retry the task or skip the task execution.

6. The vertical privilege escalation detection system based on dynamic role configuration and automated batch testing according to claim 1, characterized in that: The time-series storage module is an InfluxDB storage module.

7. The vertical privilege escalation detection system based on dynamic role configuration and automated batch testing according to claim 1, characterized in that: The visualization dashboard module is the Grafana dashboard module.