A method and device for security testing based on product function test cases
By crawling and classifying functional test cases, the synchronization of safety test and functional test is achieved, which solves the problems of poor synchronization and low accuracy in the existing safety test process, shortens the project cycle and reduces costs.
Patent Information
- Application Number
- CN201811187859.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2018-10-12
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2038-10-12
AI Technical Summary
During the existing security testing process, it is difficult for the security team to conduct functional testing synchronously, resulting in extended project cycles, inaccurate testing, and redundant testing problems.
By crawling functional test cases, classifying them according to product identification, and performing security scans based on functional test cases, synchronizing safety tests and functional tests is achieved.
It greatly shortens the project cycle, reduces the cost of vulnerability repair, improves testing accuracy, and solves the problem of security testers insufficient understanding of the product.
Smart Images

Figure CN111045915B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer technologies, and in particular, to a method and device for security testing based on product function test cases. Background Art
[0002] Security testing is a process of inspecting a product during the life cycle of an IT software product, especially from the basic completion of product development to the release stage, to verify that the product meets the security requirement definition and product quality standards. Existing security testing is carried out after the business team submits a security testing application, and black-box or white-box security testing is performed according to the test requirement document provided by the product manager or the technical document provided by software development. However, for large enterprises, especially large Internet companies, with numerous business lines, it is very difficult for the security team to have the energy to cover all requests of all business lines, and it is also impossible to accurately understand code changes, resulting in a large number of redundant tests, wasting a lot of time and manpower. In the existing security testing process, the business team submits security testing requirements to the security team, and the security team conducts security testing based on the product manual or the technical document of software development. And the security team randomly checks the business systems of the business team at irregular intervals for sampling testing.
[0003] In the implementation process of the above prior art, the following problems exist: Due to the factor of professional division of labor (the security team is not a developer), it is very difficult for security testers to ensure that they have sufficient time to understand the business process and the test requirement specification like business testers; The existing security testing is black-box security testing. When conducting black-box security testing, it is necessary to verify one by one whether each system function point has security risks. However, before the function testing is completed, it is very difficult to ensure the availability of the system function. Therefore, function testing and security testing cannot be guaranteed to be carried out synchronously, delaying the project cycle; Using manually fabricated data for product security testing cannot well fit the product process, affecting the test accuracy. Summary of the Invention
[0004] In view of this, embodiments of the present invention provide a method and device for security testing based on product function test cases, which can enable security testing to be carried out synchronously with function testing, greatly shortening the project cycle, and also greatly reducing the repair cost of vulnerabilities for R & D engineers. Moreover, security testing based on the test cases of function testing can improve the test accuracy.
[0005] To achieve the above object, according to one aspect of embodiments of the present invention, a method for security testing based on product function test cases is provided.
[0006] The method for security testing based on product function test cases in an embodiment of the present invention includes: capturing function test cases within a local area network; classifying the captured function test cases according to product identifiers; determining corresponding function test cases from the classified function test cases according to the identifier of the product to be tested, and performing a security scan on the product to be tested based on the determined function test cases.
[0007] Optionally, after capturing function test cases within a local area network and before classifying the captured function test cases according to product identifiers, it further includes: filtering the captured function test cases according to a preset filtering rule; and persisting the filtered function test cases into a database.
[0008] Optionally, the step of classifying the captured function test cases according to product identifiers includes: labeling the captured function test cases as un-scanned cases; and classifying the un-scanned cases according to product identifiers.
[0009] Optionally, the step of performing a security scan on the product to be tested based on the determined function test cases includes: determining a scanner corresponding to the product to be tested; and sending the determined function test cases to the scanner for security scanning.
[0010] Optionally, after performing a security scan on the product to be tested based on the determined function test cases, it further includes: analyzing the results of the security scan, and statistically calculating the code coverage rate; obtaining the changed files of the source code corresponding to the determined function test cases; and filtering the code coverage rate according to the changed files to determine the coverage rate of the code change part.
[0011] To achieve the above object, according to another aspect of an embodiment of the present invention, there is provided a device for security testing based on product function test cases.
[0012] The device for security testing based on product function test cases in an embodiment of the present invention includes: a capturing module, configured to capture function test cases within a local area network; a classifying module, configured to classify the captured function test cases according to product identifiers; and a scanning module, configured to determine corresponding function test cases from the classified function test cases according to the identifier of the product to be tested, and perform a security scan on the product to be tested based on the determined function test cases.
[0013] Optionally, it further includes a filtering module, configured to filter the captured function test cases according to a preset filtering rule; and persist the filtered function test cases into a database.
[0014] Optionally, the classification module is further configured to label the captured functional test cases as un-scanned cases; and classify the un-scanned cases according to the product identifier.
[0015] Optionally, the scanning module is further configured to determine the scanner corresponding to the product to be tested; and send the determined functional test cases to the scanner for security scanning.
[0016] Optionally, a statistics module is further included, which is configured to analyze the results of the security scanning, count the code coverage rate; obtain the changed files of the source code corresponding to the determined functional test cases; and filter the code coverage rate according to the changed files to determine the coverage rate of the code change part.
[0017] To achieve the above object, according to another aspect of the embodiments of the present invention, an electronic device is provided.
[0018] The electronic device according to the embodiments of the present invention includes: one or more processors; a storage device for storing one or more programs, and when the one or more programs are executed by the one or more processors, the one or more processors implement the method for security testing based on product functional test cases as described in any one of the above.
[0019] To achieve the above object, according to another aspect of the embodiments of the present invention, a computer-readable medium is provided, on which a computer program is stored, and characterized in that when the program is executed by a processor, the method for security testing based on product functional test cases as described in any one of the above is implemented.
[0020] One embodiment of the above invention has the following advantages or beneficial effects: By capturing the functional test cases during the functional testing process to perform synchronous security scanning, the security testing is synchronized with the functional testing, greatly shortening the project cycle and also greatly reducing the repair cost of vulnerabilities for R & D engineers. And, in the embodiments of the present invention, there is no problem of professional division of labor, so the problem that the security testing is inaccurate due to the insufficient understanding of the product by security testers in the prior art is solved. Also, the embodiments of the present invention perform security testing based on the test cases of functional testing, which can improve the accuracy of testing.
[0021] The further effects of the above non-conventional optional methods will be described in combination with specific embodiments below. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] The drawings are used to better understand the present invention and do not constitute an improper limitation to the present invention. Among them:
[0023] Figure 1 is a schematic diagram of the main process of the method for security testing based on product functional test cases according to the embodiments of the present invention;
[0024] Figure 2 It is a schematic diagram of a method for product security testing for services according to an embodiment of the present invention;
[0025] Figure 3 It is a schematic diagram of the main modules of a device for security testing based on product function test cases according to an embodiment of the present invention;
[0026] Figure 4 It is an exemplary system architecture diagram to which an embodiment of the present invention can be applied;
[0027] Figure 5 It is a schematic diagram of the structure of a computer system of a terminal device or a server suitable for implementing an embodiment of the present invention. Detailed implementation manners
[0028] The following describes exemplary embodiments of the present invention with reference to the accompanying drawings. Various details of the embodiments of the present invention are included to assist in understanding, and they should be considered merely exemplary. Therefore, those of ordinary skill in the art should recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of the present invention. Similarly, for the sake of clarity and conciseness, the description below omits descriptions of well-known functions and structures.
[0029] Figure 1 It is a schematic diagram of the main process of a method for security testing based on product function test cases according to an embodiment of the present invention. As Figure 1 shown, the method for security testing based on product function test cases according to an embodiment of the present invention mainly includes:
[0030] Step S101: Capture functional test cases within the local area network. Functional testing, also known as behavioral testing, is to verify each function of the product. According to the functional test cases, test item by item to check whether the product meets the functions required by users. Also, functional testing is also called black box testing or data-driven testing. Only the various functions to be tested need to be considered, without considering the internal structure and code of the entire software. Generally starting from the interface and architecture of the software product, test cases are written according to the requirements, and the input data is evaluated between the expected result and the actual result, so as to make the product meet the requirements of users more. A test case is a set of test inputs, execution conditions, and expected results prepared for a specific goal, in order to test a certain program path or verify whether a specific requirement is met. A local area network (LAN) is a computer communication network that connects various computers, external devices, and databases within a local geographical area (such as within a school, factory, or institution), generally within a radius of a few kilometers. It can be connected to a remote local area network, database, or processing center through a data communication network or a dedicated data circuit to form a larger information processing system. A local area network can realize functions such as file management, application software sharing, printer sharing, scanner sharing, schedule arrangement within a workgroup, email, and fax communication services. Strictly speaking, a local area network is a closed type. It can consist of several or even thousands or tens of thousands of computers in an office.
[0031] Generally, every product needs to undergo functional testing before going online. Therefore, the test cases of functional testing (the real-time traffic of functional testers during the functional testing process) can be captured through a program for the security testing of this product, which can not only reduce the process of fabricating security test data, but also improve the accuracy of security testing. Within a certain local area network, there will be many security test cases. Capturing and classifying and storing these test cases can be used for the security testing of many products.
[0032] Among the captured functional test cases, there are many cases without security risks, such as requests to return pictures. Therefore, after capturing the functional test cases within the local area network, according to the preset filtering rules, filter the captured functional test cases; persist the filtered functional test cases to the database. The filtering rules can be customized. For example, requests without security risks such as.js,.jpg,.css, etc. can be filtered out. Through this filtering process, the test time can be saved.
[0033] Step S102: Classify the captured functional test cases according to the product identifier. The product identifier is used to uniquely identify the functional test cases of the product, such as a domain name, etc. Among them, a domain name (English: Domain Name), abbreviated as domain name or network domain, is a name of a certain computer or computer group on the Internet composed of a string of names separated by dots, and is used to identify the electronic location (sometimes also referring to the geographical location) of the computer during data transmission.
[0034] Specifically, label the captured functional test cases as un-scanned cases; classify the un-scanned cases according to the product identifier. When performing security testing, generally use the cases that have not been security scanned. Therefore, to improve the accuracy of security testing, after capturing the functional test cases, label them as un-scanned cases, such as labeling as 0 for subsequent security testing. Among them, the functional test cases that have been security scanned can be labeled as scanned cases, such as labeling as 1. Also, the captured functional test cases are the functional test cases of many products within the local area network, so it is necessary to classify the captured functional test cases according to the product identifier.
[0035] Step S103: Determine the corresponding functional test cases from the classified functional test cases according to the identifier of the product to be tested, and perform a security scan on the product to be tested based on the determined functional test cases, that is, complete the security test of the product. During the process of performing a security scan on the product to be tested based on the determined functional test cases, determine the scanner corresponding to the product to be tested, and send the determined functional test cases to the scanner for security scanning. The scanner can be a self-developed scanner or a commercial scanner such as Web Vulnerability Scanner, etc.
[0036] Also, after performing a security scan on the product to be tested based on the determined functional test cases, analyze the results of the security scan and calculate the code coverage rate. The code coverage rate (Code Coverage) is an important indicator reflecting the coverage degree of test cases for the software under test, and is also an important indicator for measuring the progress of the testing work. Obtain the changed file (diff file) of the source code corresponding to the determined functional test cases, and filter the code coverage rate according to the changed file to determine the coverage rate of the code changed part. Finally, only display the coverage rate of the code changed part, so as to calculate the security scan coverage rate report based on code changes. After that, it is necessary for manual judgment whether the uncovered code needs to supplement security test cases to continue the security scan, so as to reduce the situation of missed testing and avoid the risk of vulnerability leakage.
[0037] During the process of security testing in the prior art, one can only see which functions of the current project have been tested, such as the login function, but it is not clear which lines of code have been covered during the testing process because this is invisible. Therefore, security testers cannot evaluate whether the system source code changes have been accurately covered after the security testing is completed, and the quality of security testing cannot be guaranteed. In the embodiments of the present invention, based on a code hosting platform such as git, svn, etc., by writing a program to parse the generated diff file, the source code changes of the project can be obtained. Moreover, in the embodiments of the present invention, the agent program can accurately capture the traffic during the security testing requirements or project business testing process, and then replay the captured traffic for security scanning. Finally, through the source code coverage rate statistically by jacoco, it can be accurately determined whether the current security scanning has covered the source code part of the requirements or project changes. If it is fully covered, it indicates that the testing is sufficient; otherwise, it can be clearly seen from the coverage rate statistical result of jacoco which lines of code have not been covered.
[0038] In the embodiments of the present invention, by capturing the functional test cases during the functional testing process to perform synchronous security scanning, the security testing and functional testing are carried out synchronously, greatly shortening the project cycle and also greatly reducing the cost of repairing vulnerabilities for R & D engineers. Moreover, in the embodiments of the present invention, there is no problem of professional division of labor, so the problem in the prior art that the testing is inaccurate due to insufficient understanding of the product by security testers is solved. In addition, based on the test cases of functional testing in the embodiments of the present invention, security testing is carried out, which can improve the accuracy of testing.
[0039] Figure 2 It is a schematic diagram of a method for product security testing for business according to an embodiment of the present invention.
[0040] As Figure 2 shown, based on an agent program, all functional test cases within the local area network are automatically captured, that is, the real-time requests (traffic) of functional testers during the functional testing phase. The captured functional test cases are filtered (i.e., traffic deduplication), unnecessary domain names and static resources are excluded, and at the same time, the requests are persisted in the database.
[0041] Since there may be multiple products or applications under a service, and the captured traffic is all the traffic within the local area network, it is necessary to group the traffic according to the application and allocate the traffic corresponding to an application to a group. Scan all the traffic to be detected stored in the database. This traffic to be detected belongs to the service that needs to be detected. Group all the traffic to be detected based on the application. The grouping rule is to identify by the service number marked during the traffic collection process of the service traffic collection module. Then, queue in sequence according to the service number and distribute to the security scanner for security scanning. The scanner can be a self-developed scanner or a commercial scanner such as Web Vulnerability Scanner (website and server vulnerability scanning software), etc.
[0042] Then, collect the execution results of the scan. The execution results can be the reports of self-developed scans or the scan result reports provided by commercial scanners such as Web Vulnerability Scanner.
[0043] Furthermore, based on the coverage rate statistics technology, conduct a scan quality analysis on the completed scan tasks. For example, for a javaweb project, add an EMMA or jacoco (coverage rate statistics tool) listener to the application. Through this listener, monitor the code execution track of the jvm during the security scan process. After the security scan task is completed, a code service rate statistics report can be issued. Among them, EMMA is an open-source tool for detecting and reporting JAVA code coverage rate, which tracks and records the information of the executed code by inserting bytecode into the.class file. It can not only be well used for small projects and easily obtain the coverage rate report, but also be applicable to large enterprise-level projects.
[0044] In addition, based on the source code version control system, such as svn or git, etc., analyze the diff changed files of the current project, and then filter the coverage rate report based on the changes. Finally, only display the coverage rate of the code change part. Furthermore, a security scan coverage rate report based on code changes can be statistically obtained. After that, it is necessary for manual judgment whether the uncovered code needs to supplement security test cases and continue with the security scan to reduce the situation of missed testing and avoid the risk of vulnerability leakage.
[0045] In the embodiment of the present invention, by collecting the service traffic generated during the functional test process to synchronously perform security test scanning, the second point is to conduct coverage rate statistics by analyzing the code changes of the project to be tested, and accurately locate the uncovered code blocks through the coverage rate statistics results. This can reduce the risk of vulnerability leakage caused by missed testing. Through the above two innovative points, the test quality and test efficiency can be greatly improved, and the project cycle can be greatly shortened.
[0046] Figure 3 is a schematic diagram of the main modules of a security testing device for product function test cases based on an embodiment of the present invention. As Figure 3 shown, the security testing device 300 for product function test cases based on an embodiment of the present invention includes a capture module 301, a classification module 302, and a scanning module 303.
[0047] The capture module 301 is used to capture function test cases within a local area network. The security testing device for product function test cases based on an embodiment of the present invention further includes a filtering module. After the capture module captures function test cases within the local area network, the filtering module filters the captured function test cases according to preset filtering rules, and persists the filtered function test cases to a database.
[0048] The classification module 302 is used to classify the captured function test cases according to product identifiers. The classification module is also used to label the captured function test cases as un-scanned cases; classify the un-scanned cases according to product identifiers.
[0049] The scanning module 303 is used to determine corresponding function test cases from the classified function test cases according to the identifier of the product to be tested, and perform a security scan on the product to be tested based on the determined function test cases. The scanning module is also used to determine the scanner corresponding to the product to be tested; send the determined function test cases to the scanner for security scanning.
[0050] The security testing device for product function test cases based on an embodiment of the present invention further includes a statistics module, which is used to analyze the results of the security scan performed by the scanning module, calculate the code coverage rate; obtain the changed files of the source code corresponding to the determined function test cases; filter the code coverage rate according to the changed files to determine the coverage rate of the code change part.
[0051] In an embodiment of the present invention, by capturing function test cases during the function testing process to perform synchronous security scanning, the security testing is synchronized with the function testing, greatly shortening the project cycle and also greatly reducing the cost of repairing vulnerabilities by R & D engineers. And, in an embodiment of the present invention, there is no problem of professional division of labor, so it solves the problem in the prior art that the testing is inaccurate due to the insufficient understanding of the product by security testers. And, the embodiment of the present invention performs security testing based on the test cases of function testing, which can improve the accuracy of testing.
[0052] Figure 4 shows an exemplary system architecture 400 to which the method for security testing based on product function test cases or the security testing device based on product function test cases according to an embodiment of the present invention can be applied.
[0053] AsFigure 4 As shown in Figure 4 , the system architecture 400 may include terminal devices 401, 402, 403, a network 404, and a server 405. The network 404 is used to provide a medium for communication links between the terminal devices 401, 402, 403 and the server 405. The network 404 may include various connection types, such as wired, wireless communication links, or fiber optic cables, etc.
[0054] Users can use the terminal devices 401, 402, 403 to interact with the server 405 through the network 404 to receive or send messages, etc. Various communication client applications may be installed on the terminal devices 401, 402, 403, such as shopping applications, web browser applications, search applications, instant messaging tools, email clients, social platform software, etc. (for example only).
[0055] The terminal devices 401, 402, 403 may be various electronic devices with a display screen and supporting web browsing, including but not limited to smartphones, tablets, laptop portable computers, and desktop computers, etc.
[0056] The server 405 may be a server that provides various services, such as a background management server that supports the shopping websites browsed by users using the terminal devices 401, 402, 403 (for example only). The background management server can analyze and process data such as product information query requests received, and feedback the processing results to the terminal devices.
[0057] It should be noted that the method for security testing based on product function test cases provided by the embodiments of the present invention is generally executed by the server 405. Correspondingly, the device for security testing based on product function test cases is generally set in the server 405.
[0058] It should be understood that Figure 4 the numbers of terminal devices, networks, and servers in Figure 4 are merely illustrative. According to the implementation requirements, there may be any number of terminal devices, networks, and servers.
[0059] Next, refer to Figure 5 , which shows a schematic structural diagram of a computer system 500 of a terminal device suitable for implementing the embodiments of the present invention. Figure 5 The terminal device shown is merely an example and should not impose any limitations on the functions and usage scope of the embodiments of the present invention.
[0060] As Figure 5As shown, computer system 500 includes a central processing unit (CPU) 501, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 502 or a program loaded from a storage section 508 into a random access memory (RAM) 503. In the RAM 503, various programs and data required for the operation of the system 500 are also stored. The CPU 501, ROM 502, and RAM 503 are connected to each other via a bus 504. An input / output (I / O) interface 505 is also connected to the bus 504.
[0061] The following components are connected to the I / O interface 505: an input section 506 including a keyboard, a mouse, etc.; an output section 507 including a cathode ray tube (CRT), a liquid crystal display (LCD), etc. and a speaker, etc.; a storage section 508 including a hard disk, etc.; and a communication section 509 including a network interface card such as a LAN card, a modem, etc. The communication section 509 performs communication processing via a network such as the Internet. A drive 510 is also connected to the I / O interface 505 as needed. A removable medium 511, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 510 as needed so that a computer program read from it can be installed into the storage section 508 as needed.
[0062] Specifically, according to an embodiment disclosed by the present invention, the process described above with reference to the flowchart can be implemented as a computer software program. For example, an embodiment disclosed by the present invention includes a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program contains program codes for performing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from a network via the communication section 509, and / or installed from the removable medium 511. When the computer program is executed by a central processing unit (CPU) 501, the above functions defined in the system of the present invention are executed.
[0063] It should be noted that the computer-readable medium shown in the present invention can be a computer-readable signal medium, a computer-readable storage medium, or any combination of the two. A computer-readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples of a computer-readable storage medium can include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present invention, a computer-readable storage medium can be any tangible medium that contains or stores a program, which can be used by or in conjunction with an instruction execution system, apparatus, or device. In the present invention, a computer-readable signal medium can include a data signal propagated in a baseband or as part of a carrier wave, which carries computer-readable program code. Such a propagated data signal can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. A computer-readable signal medium can also be any computer-readable medium other than a computer-readable storage medium, which can send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device. The program code contained on a computer-readable medium can be transmitted using any appropriate medium, including but not limited to: wireless, wire, optical fiber, RF, etc., or any suitable combination of the above.
[0064] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present invention. In this regard, each block in a flowchart or block diagram can represent a module, a program segment, or a part of code, and the above module, program segment, or part of code contains one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks can occur in a different order than marked in the accompanying drawings. For example, two consecutive blocks shown can actually be executed substantially in parallel, and they can sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in a block diagram or flowchart, and the combination of blocks in a block diagram or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.
[0065] The modules involved in the embodiments of the present invention can be implemented in software or in hardware. The described modules can also be provided in a processor. For example, it can be described as: a processor includes an acquisition and capture module, a classification module, and a scanning module. Among them, the names of these modules do not constitute a limitation to the module itself in some cases. For example, the capture module can also be described as "a module for capturing functional test cases within a local area network".
[0066] As another aspect, the present invention also provides a computer-readable medium. The computer-readable medium can be included in the device described in the above embodiments; or it can exist independently without being assembled into the device. The above computer-readable medium carries one or more programs. When the one or more programs are executed by the device, the device includes: capturing functional test cases within a local area network; classifying the captured functional test cases according to the product identifier; determining corresponding functional test cases from the classified functional test cases according to the identifier of the product to be tested, and performing a security scan on the product to be tested based on the determined functional test cases.
[0067] In the embodiments of the present invention, by capturing functional test cases during the functional test process to perform synchronous security scanning, the security test is synchronized with the functional test, greatly shortening the project cycle and also greatly reducing the cost of fixing vulnerabilities for R & D engineers. Moreover, the embodiments of the present invention do not involve the issue of professional division of labor, thus solving the problem in the prior art that the test is inaccurate because security testers do not have enough understanding of the product. In addition, the embodiments of the present invention perform security testing based on the test cases of the functional test, which can improve the accuracy of the test.
[0068] The above specific embodiments do not constitute a limitation to the protection scope of the present invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can occur depending on design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. A method for security testing based on product function test cases, characterized in that, it includes: Capturing function test cases within a local area network; The function test cases are real-time traffic during the function testing process before the product goes online; Classifying the captured function test cases according to the product identifier; According to the identifier of the product to be tested, determining the corresponding function test cases from the classified function test cases, and performing a security scan on the product to be tested based on the determined function test cases; Synchronously performing a security test scan by collecting the business traffic generated during the function testing process; Listening to the code execution trace of the JVM during the security scan, and generating a code service rate statistical report after the security scan task is completed; wherein, the information of the executed code is tracked and recorded by inserting bytecode into the.class file.
2. The method according to claim 1, characterized in that, after capturing the function test cases within the local area network and before classifying the captured function test cases according to the product identifier, it further includes: Filtering the captured function test cases according to a preset filtering rule; Persisting the filtered function test cases into a database.
3. The method according to claim 1, characterized in that, The step of classifying the captured function test cases according to the product identifier includes: Marking the captured function test cases as un-scanned cases; Classifying the un-scanned cases according to the product identifier.
4. The method according to claim 1, characterized in that, The step of performing a security scan on the product to be tested based on the determined function test cases includes: Determining the scanner corresponding to the product to be tested; Sending the determined function test cases to the scanner for security scanning.
5. The method according to claim 1, characterized in that, after performing a security scan on the product to be tested based on the determined function test cases, it further includes: Analyzing the result of the security scan and counting the code coverage rate; Obtaining the changed files of the source code corresponding to the determined function test cases; Filtering the code coverage rate according to the changed files to determine the coverage rate of the code changed part.
6. A device for security testing based on product function test cases, characterized in that, it includes: A capturing module, configured to capture function test cases within a local area network; the function test cases are real-time traffic during the function testing process before the product goes online; A classification module, configured to classify the captured function test cases according to the product identifier; A scanning module, configured to determine the corresponding function test cases from the classified function test cases according to the identifier of the product to be tested, and perform a security scan on the product to be tested based on the determined function test cases; Synchronously performing a security test scan by collecting the business traffic generated during the function testing process; The device is also used for: listening to the code execution trace of the JVM during the security scan, and generating a code service rate statistical report after the security scan task is completed; wherein, the information of the executed code is tracked and recorded by inserting bytecode into the.class file.
7. The device according to claim 6, wherein, it further includes a filtering module, configured to filter the captured functional test cases according to preset filtering rules; and persist the filtered functional test cases into a database.
8. The device according to claim 6, wherein, the classification module is further configured to label the captured functional test cases as un-scanned cases; and classify the un-scanned cases according to the product identifier.
9. The device according to claim 6, wherein, the scanning module is further configured to determine the scanner corresponding to the product to be tested; and send the determined functional test cases to the scanner for security scanning.
10. The device according to claim 6, wherein, it further includes a statistics module, configured to analyze the results of the security scan, and calculate the code coverage rate; obtain the changed files of the source code corresponding to the determined functional test cases; filter the code coverage rate according to the changed files to determine the coverage rate of the code changed part.
11. An electronic device, wherein, it includes: one or more processors; a storage device, configured to store one or more programs, when the one or more programs are executed by the one or more processors, the one or more processors implement the method according to any one of claims 1-5.
12. A computer-readable medium, on which a computer program is stored, wherein, when the program is executed by a processor, it implements the method according to any one of claims 1-5.
Citation Information
Patent Citations
Method and system for calculating coverage rate of service functions of software
CN101706751A
Testing method, device and system, terminal equipment and computer readable storage medium
CN107766194A