WEB Application Configuration Detection Method, Device, Storage Medium and Computer Device

The method improves WEB application configuration detection accuracy by using a task script package to identify scanning items and perform precise configuration file scanning, addressing the issues of low accuracy and false positives in traditional methods.

CN113448640BActive Publication Date: 2025-07-15TENCENT TECHNOLOGY (SHENZHEN) CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202010161936.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-03-10
Publication Date
2025-07-15
Estimated Expiration
2040-03-10

AI Technical Summary

Technical Problem

Traditional WEB application configuration detection methods have high false alarm rate, low accuracy, and low availability of scan results.

Method used

By receiving the WEB application configuration detection command, downloading and decompressing the task script data packet, determining the item to be scanned, obtaining service port information, parsing the configuration file to obtain path information, performing configuration file scanning and detection, and obtaining accurate scanning results.

Benefits of technology

Improve the accuracy of scanning detection and ensure the reliability and accuracy of scanning results.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113448640B_ABST
    Figure CN113448640B_ABST
Patent Text Reader

Abstract

The present application relates to a method, device, storage medium, and computer device for WEB application configuration detection. The method includes: receiving a WEB application configuration detection command; downloading and decompressing a preset task script data packet according to the WEB application configuration detection command to obtain a to-be-executed script, an external device information table, a scanned whitelist device table, and scan item information; comparing the scanned whitelist device table and the scan item information according to the to-be-executed script to determine to-be-scanned items; obtaining and comparing the external device information table according to the service port information of the to-be-scanned items to obtain the path information of the WEB application service; obtaining the configuration file of the WEB application service according to the path information, and parsing the configuration file to obtain the directory path information of the WEB application service; performing configuration file scan detection according to the path information and the directory path information to obtain a scan result file and feedback. The solution provided by the present application can achieve improved accuracy of scan detection.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer technologies, and particularly to a method, device, storage medium, and computer device for detecting WEB (World Wide Web) application configurations. Background Art

[0002] With the development of computer technologies, WEB application configuration detection technologies have emerged. WEB application configuration detection technologies refer to detecting whether the configurations of business WEB services are secure and compliant, mainly used to enhance the security of the business environment. The commonly used WEB application configuration detection method is to comprehensively scan the directories of physical machines or containers, and determine whether the business WEB application configurations are secure and compliant according to the scan results.

[0003] However, when the traditional WEB application configuration detection method performs a comprehensive scan, there are many false alarms in the scan results, the availability of the scan results is low, and there is a problem of low scan detection accuracy. Summary of the Invention

[0004] Based on this, in view of the technical problem of low scan detection accuracy of the traditional WEB application configuration detection method, it is necessary to provide a method, device, storage medium, and computer device for detecting WEB application configurations.

[0005] A method for detecting WEB application configurations includes:

[0006] Receiving a WEB application configuration detection command;

[0007] Downloading and decompressing a preset task script data packet according to the WEB application configuration detection command to obtain a to-be-executed script, an external device information table, a scanned whitelist device table, and scan item information;

[0008] Comparing the scanned whitelist device table and the scan item information according to the to-be-executed script to determine to-be-scanned items;

[0009] Obtaining and comparing the external device information table according to the service port information of the to-be-scanned items to obtain the path information of the WEB application service;

[0010] Obtaining the configuration file of the WEB application service according to the path information, and parsing the configuration file to obtain the directory path information of the WEB application service;

[0011] Performing configuration file scan detection according to the path information and the directory path information to obtain a scan result file and feedback.

[0012] A method for detecting WEB application configurations includes:

[0013] When a scan task file is detected, parse the scan task file to determine the set of IP (Internet Protocol) addresses of the objects to be detected;

[0014] According to the set of IP addresses of the objects to be detected, send a WEB application configuration detection command to each object to be detected. The WEB application configuration detection command is used to instruct each object to be detected to download and decompress a preset task script data packet to obtain an executable script, an external device information table, a scan whitelist device table, and scan item information. According to the executable script, compare the scan whitelist device table and the scan item information to determine the items to be scanned, obtain and compare the external device information table according to the service port information of the items to be scanned to obtain the path information of the WEB application service, obtain the configuration file of the WEB application service according to the path information, parse the configuration file to obtain the directory path information of the WEB application service, and perform a configuration file scan detection according to the path information and the directory path information to obtain a scan result file and feedback it;

[0015] Receive the scan result file.

[0016] A WEB application configuration detection device, the device includes:

[0017] A receiving module, used to receive a WEB application configuration detection command;

[0018] A download and decompression module, used to download and decompress a preset task script data packet according to the WEB application configuration detection command to obtain an executable script, an external device information table, a scan whitelist device table, and scan item information;

[0019] A comparison module, used to compare the scan whitelist device table and the scan item information according to the executable script to determine the items to be scanned;

[0020] A processing module, used to obtain and compare the external device information table according to the service port information of the items to be scanned to obtain the path information of the WEB application service;

[0021] An analysis module, used to obtain the configuration file of the WEB application service according to the path information and parse the configuration file to obtain the directory path information of the WEB application service;

[0022] A scan detection module, used to perform a configuration file scan detection according to the path information and the directory path information to obtain a scan result file and feedback it.

[0023] A WEB application configuration detection device, the device includes:

[0024] A detection module, used to parse the scan task file to determine the set of IP addresses of the objects to be detected when a scan task file is detected;

[0025] An indication module, configured to issue a WEB application configuration detection command to each object to be detected according to the set of IP addresses of the objects to be detected. The WEB application configuration detection command is used to instruct each object to be detected to download and decompress a preset task script data packet, obtain an executable script, an external device information table, a scanned whitelist device table, and scan item information, compare the scanned whitelist device table and the scan item information according to the executable script to determine the items to be scanned, obtain and compare the external device information table according to the service port information of the items to be scanned to obtain the path information of the WEB application service, obtain the configuration file of the WEB application service according to the path information, parse the configuration file to obtain the directory path information of the WEB application service, perform a configuration file scan detection according to the path information and the directory path information, obtain a scan result file and feedback it;

[0026] A result receiving module, configured to receive the scan result file.

[0027] A computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the following steps are implemented:

[0028] Receive a WEB application configuration detection command;

[0029] Download and decompress a preset task script data packet according to the WEB application configuration detection command to obtain an executable script, an external device information table, a scanned whitelist device table, and scan item information;

[0030] Compare the scanned whitelist device table and the scan item information according to the executable script to determine the items to be scanned;

[0031] Obtain and compare the external device information table according to the service port information of the items to be scanned to obtain the path information of the WEB application service;

[0032] Obtain the configuration file of the WEB application service according to the path information, and parse the configuration file to obtain the directory path information of the WEB application service;

[0033] Perform a configuration file scan detection according to the path information and the directory path information, obtain a scan result file and feedback it.

[0034] A computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the following steps are implemented:

[0035] When a scan task file is detected, parse the scan task file to determine the set of IP addresses of the objects to be detected;

[0036] According to the set of IP addresses of the objects to be detected, a WEB application configuration detection command is sent to each object to be detected. The WEB application configuration detection command is used to instruct each object to be detected to download and decompress a preset task script data packet, obtaining an executable script, an external device information table, a scanned whitelist device table, and scan item information. According to the executable script, the scanned whitelist device table and the scan item information are compared to determine the items to be scanned. The service port information of the items to be scanned is obtained and compared with the external device information table to obtain the path information of the WEB application service. According to the path information, the configuration file of the WEB application service is obtained, and the configuration file is parsed to obtain the directory path information of the WEB application service. According to the path information and the directory path information, a configuration file scan detection is performed to obtain a scan result file and feedback it;

[0037] Receive the scan result file.

[0038] A computer device includes a memory and a processor. The memory stores a computer program, and when the computer program is executed by the processor, the following steps are implemented:

[0039] Receive a WEB application configuration detection command;

[0040] According to the WEB application configuration detection command, download and decompress a preset task script data packet, obtaining an executable script, an external device information table, a scanned whitelist device table, and scan item information;

[0041] According to the executable script, compare the scanned whitelist device table and the scan item information to determine the items to be scanned;

[0042] Obtain the service port information of the items to be scanned and compare it with the external device information table to obtain the path information of the WEB application service;

[0043] According to the path information, obtain the configuration file of the WEB application service, and parse the configuration file to obtain the directory path information of the WEB application service;

[0044] According to the path information and the directory path information, perform a configuration file scan detection to obtain a scan result file and feedback it.

[0045] A computer device includes a memory and a processor. The memory stores a computer program, and when the computer program is executed by the processor, the following steps are implemented:

[0046] When a scan task file is detected, parse the scan task file to determine the set of IP addresses of the objects to be detected;

[0047] According to the set of IP addresses of the objects to be detected, send a WEB application configuration detection command to each object to be detected. The WEB application configuration detection command is used to instruct each object to be detected to download and decompress a preset task script data packet, obtaining an executable script, an external device information table, a scanned whitelist device table, and scan item information. According to the executable script, compare the scanned whitelist device table and the scan item information to determine the items to be scanned. Obtain and compare the external device information table according to the service port information of the items to be scanned to obtain the path information of the WEB application service. According to the path information, obtain the configuration file of the WEB application service, parse the configuration file to obtain the directory path information of the WEB application service, perform a configuration file scan detection according to the path information and the directory path information, obtain a scan result file and feedback it;

[0048] Receive the scan result file.

[0049] The above WEB application configuration detection method, device, storage medium, and computer device can, after receiving the WEB application configuration detection command, download and parse a preset task script data packet, obtain an executable script, an external device information table, a scanned whitelist device table, and scan item information. According to the executable script, compare the scanned whitelist device table and the scan item information to determine the items to be scanned. Obtain and compare the external device information table according to the service port information of the items to be scanned to obtain the path information of the WEB application service. According to the path information, obtain the configuration file of the WEB application service, parse the configuration file to obtain the directory path information of the WEB application service, perform a configuration file scan detection according to the path information and the directory path information, obtain a scan result file and feedback it. Throughout the process, accurate path information and directory path information can be obtained, so that accurate configuration file scan detection can be performed according to the path information and the directory path information, obtain an accurate scan result file and feedback it, improving the accuracy of the scan detection. Brief Description of the Drawings

[0050] Figure 1 It is an application environment diagram of the WEB application configuration detection method in an embodiment;

[0051] Figure 2 It is a schematic flowchart of the WEB application configuration detection method in an embodiment;

[0052] Figure 3 It is a schematic diagram of the WEB application configuration detection method in an embodiment;

[0053] Figure 4 It is a schematic flowchart of the WEB application configuration detection method in another embodiment;

[0054] Figure 5 It is also an application environment diagram of the WEB application configuration detection method in an embodiment;

[0055] Figure 6 It is a schematic flowchart of a WEB application configuration detection method in another embodiment;

[0056] Figure 7 It is a schematic diagram of a WEB application configuration detection method in another embodiment;

[0057] Figure 8 It is a schematic diagram of a WEB application configuration detection method in another embodiment;

[0058] Figure 9 It is a schematic diagram of a WEB application configuration detection method in yet another embodiment;

[0059] Figure 10 It is a structural block diagram of a WEB application configuration detection device in an embodiment;

[0060] Figure 11 It is a structural block diagram of a WEB application configuration detection device in another embodiment;

[0061] Figure 12 It is a structural block diagram of a computer device in an embodiment. Specific implementation manners

[0062] In order to make the objectives, technical solutions and advantages of the present application clearer, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.

[0063] Figure 1 It is an application environment diagram of a WEB application configuration detection method in an embodiment. Refer to Figure 1, the WEB application configuration detection method is applied to a WEB application configuration detection system. The WEB application configuration detection system includes a terminal 110 and a server 120. The terminal 110 and the server 120 are connected through a network. The terminal 110 receives a WEB application configuration detection command sent by the server 120, downloads and decompresses a preset task script data packet according to the WEB application configuration detection command, obtains an executable script, an external device information table, a scanned whitelist device table, and scan item information, compares the scanned whitelist device table and the scan item information according to the executable script to determine the items to be scanned, obtains and compares the external device information table according to the service port information of the items to be scanned to obtain the path information of the WEB application service, obtains the configuration file of the WEB application service according to the path information, parses the configuration file to obtain the directory path information of the WEB application service, performs a configuration file scan detection according to the path information and the directory path information, and obtains and feedbacks a scan result file. The terminal 110 may specifically be a desktop terminal or a mobile terminal, and the mobile terminal may specifically be at least one of a mobile phone, a tablet computer, a laptop computer, etc. The server 120 may be implemented by an independent server or a server cluster composed of multiple servers.

[0064] As Figure 2 shown, in one embodiment, a WEB application configuration detection method is provided. In this embodiment, it is mainly exemplified by the method being applied to the terminal 110 in the above Figure 1 . Referring to Figure 2 , the WEB application configuration detection method specifically includes the following steps S202 to S212.

[0065] S202: Receive a WEB application configuration detection command.

[0066] Among them, the WEB application configuration detection command refers to a command sent by the server to instruct the terminal to perform WEB application configuration detection. After determining the IP address set of the terminals to be detected, the server will send a WEB application configuration detection command to each terminal to be detected according to the IP address set of the terminals to be detected. Specifically, the server will send the WEB application configuration detection command to each terminal to be detected through the command channel of the scheduling background.

[0067] S204: Download and decompress a preset task script data packet according to the WEB application configuration detection command, and obtain an executable script, an external device information table, a scanned whitelist device table, and scan item information.

[0068] Among them, the WEB application configuration detection command includes a download instruction, an extraction instruction, and an execution entry script instruction. The download instruction is used to instruct the terminal to download a preset task script data packet by accessing a specified server. The extraction instruction is used to instruct the terminal to extract the downloaded task script data packet. The execution entry script instruction is used to instruct the terminal to execute the entry script in the to-be-executed script in the task script data packet obtained after extraction. The task script data packet refers to a script data packet generated by the server for WEB application configuration detection, which includes a to-be-executed script, an external device information table, a scanned whitelist device table, and scan item information.

[0069] Among them, the to-be-executed script refers to a script to be executed for WEB application configuration detection, including an entry script, etc. The external device information table refers to a corresponding information table of external devices - monitoring ports of external devices communicating with the server. Specifically, the external device can be a machine or a container. The server presets a timing thread for synchronizing the external device information table. Through the external device information table, it is possible to know the external devices that are working and the corresponding ports. The scanned whitelist device table refers to a preset device table that is exempt from scanning. Specifically, for the terminal, the device exempt from scanning refers to a container exempt from scanning. For the server, the device exempt from scanning refers to a terminal exempt from scanning. For example, the terminal can determine the container exempt from scanning according to the scanned whitelist device table and does not scan this container. The server can determine the terminal exempt from scanning according to the scanned whitelist device table, and thus does not issue a WEB application configuration detection command to this terminal. The scan item information refers to scan item configuration information, including scan task information. Specifically, the scan item information can specifically be task MD5 (Message-Digest) data, that is, scan item information represented by a string. The terminal can determine the scan task information by parsing the task MD5 data. For example, the scan task information can specifically be container information in the terminal to be scanned. Another example is that the scan task information can specifically be to check for dangerous and insecure files under the WEB directory. Another example is that the scan task information can specifically be to check for sensitive and dangerous directories under the WEB service directory.

[0070] In one embodiment, downloading and extracting a preset task script data packet according to the WEB application configuration detection command includes:

[0071] Extracting the server download address and task script identifier carried in the WEB application configuration detection command;

[0072] Accessing the server according to the server download address and downloading the task script data packet according to the task script identifier;

[0073] Extracting the task script data packet.

[0074] Among them, the server download address refers to the address of the server from which the task script data packet can be downloaded. For example, the server can specifically be a dedicated file server. The task script identifier is used to identify the task script data packet to be downloaded. Specifically, the terminal will extract the server download address and the task script identifier carried in the WEB application configuration detection command according to the download instruction in the WEB application configuration detection command, access the server according to the server download address, request the task script data packet from the server according to the task script identifier, download the task script data packet, and then decompress the task script data packet according to the decompression instruction in the WEB application configuration detection command after the download is completed.

[0075] In the above embodiment, the preset task script data packet is downloaded and decompressed according to the WEB application configuration detection command, so as to obtain the task script data packet.

[0076] S206: Compare the scanned whitelist device table and the scan item information according to the script to be executed, and determine the item to be scanned.

[0077] Among them, the item to be scanned refers to the scan item corresponding to the scan task information in the scan item information. For example, the item to be scanned can specifically refer to the container in the terminal to be scanned. For another example, the item to be scanned can also specifically refer to the terminal to be scanned. Specifically, after obtaining the script to be executed, the terminal will execute the entry script in the script to be executed according to the execution entry script instruction in the WEB application configuration detection command, and determine the item to be scanned according to the scan task information in the scan item information and the scanned whitelist device table. Among them, when it is determined according to the scan task information that the scan object is a physical machine, the terminal can directly determine itself as the item to be scanned and perform a full machine scan. When it is determined according to the scan task information that the scan object is a container, the terminal will compare the scanned whitelist device table and the container information in the scan object information to determine the item to be scanned (i.e., the container to be scanned).

[0078] In one embodiment, comparing the scanned whitelist device table and the scan item information according to the script to be executed to determine the item to be scanned includes:

[0079] Execute the script to be executed, and obtain a set of alternative scan items corresponding to the scan item information;

[0080] Compare each device information in the scanned whitelist device table with each alternative scan item in the set of alternative scan items, and screen out the item to be scanned from the set of alternative scan items.

[0081] Among them, the alternative scan item set refers to the set of alternative scan items corresponding to the scan task information in the scan item information. For example, the alternative scan item set can specifically refer to the set of alternative scan containers. By executing the to-be-executed script, the terminal can obtain the set of alternative scan items corresponding to the scan item information. After obtaining the set of alternative scan items, the terminal needs to filter out the to-be-scanned items from the set of alternative scan items by comparing each device information in the scan whitelist device table with each alternative scan item in the set of alternative scan items. Specifically, the device information of each device exempt from scanning is stored in the scan whitelist device table. By comparing each device information in the scan whitelist device table with each alternative scan item in the set of alternative scan items, the items exempt from scanning in the set of alternative scan items can be determined, and the to-be-scanned items that need to be scanned can be filtered out from the set of alternative scan items according to the items exempt from scanning. In this way, the scan items that need to be scanned can be determined, so that only the scan items that need to be scanned are scanned, which can improve the efficiency and accuracy of scanning.

[0082] S208: Obtain and compare the external device information table according to the service port information of the to-be-scanned item to obtain the path information of the WEB application service.

[0083] Among them, the service port information of the to-be-scanned item refers to the port information monitored by the WEB service process of the to-be-scanned item. The path information of the WEB application service refers to the path information of the WEB application service obtained by viewing the status of the WEB service process. Specifically, the terminal can obtain the service port information and the WEB service process identifier of the to-be-scanned item through a low-consumption command (such as the ss command). By comparing the service port information of the to-be-scanned item with the device-port information correspondence table in the external device information table, the port that actually provides WEB services externally can be determined. According to the WEB service process identifier of this port, the path information of the WEB application service can be obtained at the specified path. For example, the terminal can locate the path information of the WEB application service by obtaining the cwd and exe paths under / proc / pid (i.e., the WEB service process identifier).

[0084] In one embodiment, obtaining and comparing the external device information table according to the service port information of the to-be-scanned item to obtain the path information of the WEB application service includes:

[0085] Obtain the service port information and the local IP address of the to-be-scanned item;

[0086] Compare the device-port information correspondence table in the external device information table according to the service port information and the local IP address to obtain the target service port information;

[0087] Obtain the WEB service process identifier corresponding to the target service port information, and obtain the path information of the WEB application service according to the WEB service process identifier.

[0088] Among them, the local IP address refers to the IP address of the terminal. The device-port information correspondence table stores the correspondence information between external devices and ports. By querying the device-port information correspondence table, the actual external port of the device can be determined. The target service port information refers to the information of the port that provides the WEB application service externally for the item to be scanned. The WEB service process identifier refers to the identifier used to identify the WEB service process. For example, the WEB service process identifier can specifically be the PID (port ID, port identity number) of the WEB service process.

[0089] Specifically, the terminal will obtain the service port information and local IP address of the item to be scanned, and compare the device-port information correspondence table in the external device information table according to the service port information and local IP address. In the device-port information correspondence table, the device is represented by IP. By comparing the device-port information correspondence table with the service port information and local IP address, the target service port information corresponding to the local IP address can be determined, and then the WEB service process identifier corresponding to the target service port information can be obtained. Based on the WEB service process identifier, the path information of the WEB application service can be obtained.

[0090] For example, the terminal can use the ss command to obtain the service port information and local IP address of the item to be scanned, compare the device-port information correspondence table in the external device information table according to the service port information and local IP address, find the target service port information of the actual external service corresponding to the item to be scanned, obtain the PID corresponding to the target service port interface information, and obtain the cwd and exe paths under / proc / pid to locate the path information of the WEB application service.

[0091] In the above embodiments, by obtaining and comparing the external device information table according to the service port information of the item to be scanned, the path information of the WEB application service is obtained.

[0092] S210: Obtain the configuration file of the WEB application service according to the path information, and parse the configuration file to obtain the directory path information of the WEB application service.

[0093] Among them, the directory path information of the WEB application service refers to the information of the path where the configuration files and other WEB application service information of the WEB application service are stored. Specifically, the terminal can go to this path according to the path information to obtain the configuration file of the WEB application service. For example, the configuration file can specifically be an nginx service file. Another example is that the configuration file can specifically be an httpd service file. Still another example is that the configuration file can specifically be a python WEB framework file. The directory path information of the WEB application service can be obtained by parsing the configuration file. For example, when the configuration file is specifically an nginx service file, the directory path information can be determined by looking at configurations such as root / alias. Another example is that when the configuration file is specifically an httpd service file, the directory path information can be determined by looking at configurations such as Directory. Still another example is that when the configuration file is specifically a python WEB framework file, the directory path information can be determined by looking at the HOME path information of the program.

[0094] S212: Perform a configuration file scan and detection based on the path information and the directory path information, obtain a scan result file, and feed it back.

[0095] Among them, the scan result file refers to a file generated based on the scan result. For example, the scan result file includes the scan results written in sequence in a unified reporting format. Specifically, the reporting format can be in the form of key=value. For illustration, when the nginx service is improperly configured and the nginx directory index is opened, the result form will include CUST_nginx_index= / etc / nginx / nginx.conf (indicating that the configuration directory index in / etc / nginx / nginx.conf is opened and the configuration is improper). Specifically, performing a configuration file scan and detection based on the path information and the directory path information means scanning and detecting all configuration files under the path and the directory path. After obtaining the scan result file, the terminal will feed back the scan result file to the sender of the WEB application configuration detection command.

[0096] In one embodiment, performing a configuration file scan and detection based on the path information and the directory path information, obtaining a scan result file, and feeding it back includes:

[0097] Perform a configuration file scan and detection on the configuration files under the path based on the path information and the directory path information to obtain a scan result file;

[0098] Upload the scan result file to the sender of the WEB application configuration detection command.

[0099] Specifically, the terminal will perform a configuration file scan and detection on all configuration files under the path according to the path information and the directory path information, and obtain a scan result file. The scan result file includes the scan results of misconfigurations written in the scan order. Among them, the scan results can be represented in a unified reporting format. For example, the reporting format can be in the form of key=value. When the nginx service is misconfigured and the nginx directory index is opened, the result form will include CUST_nginx_index= / etc / nginx / nginx.conf (indicating that the configuration directory index in / etc / nginx / nginx.conf is opened and misconfigured). After obtaining the scan result file, the terminal will upload the scan result file to the sender of the WEB application configuration detection command. For example, the terminal can upload the scan result file to the sender of the WEB application configuration detection command via HTTP (HyperText Transfer Protocol).

[0100] In the above embodiment, the configuration file scan and detection are performed according to the path information and the directory path information, an accurate scan result file is obtained, and the scan result file is fed back.

[0101] In the above WEB application configuration detection method, after receiving the WEB application configuration detection command, it can download and parse the preset task script data packet to obtain the script to be executed, the external device information table, the scan whitelist device table, and the scan item information. According to the script to be executed, compare the scan whitelist device table and the scan item information to determine the items to be scanned, obtain and compare the external device information table according to the service port information of the items to be scanned to obtain the path information of the WEB application service, obtain the configuration file of the WEB application service according to the path information, parse the configuration file to obtain the directory path information of the WEB application service, perform a configuration file scan and detection according to the path information and the directory path information, and obtain and feed back the scan result file. Throughout the process, accurate path information and directory path information can be obtained, so that accurate configuration file scan and detection can be performed according to the path information and the directory path information, and an accurate scan result file can be obtained and fed back, improving the accuracy of the scan and detection.

[0102] In one embodiment, the WEB application configuration detection method of the present application is illustrated by the schematic diagram as Figure 3 shown.

[0103] The terminal receives a WEB application configuration detection command, extracts the server download address and task script identifier carried in the WEB application configuration detection command, accesses the server according to the server download address, downloads the task script data packet according to the task script identifier, decompresses the task script data packet to obtain the script to be executed, the external device information table, the scanned whitelist device table, and the scan item information (task MD5), executes the script to be executed to determine the items to be scanned and obtains the local IP information. Among them, if it is determined to be a container scanning task according to the scan item information, the container to be scanned can be determined by comparing the scanned whitelist device table and the alternative scan container set in the scan item information. If it is determined not to be a container scanning task according to the scan item information, the item to be scanned is determined to be a physical machine (i.e., the terminal). After determining the items to be scanned, obtain the service port and process information (including PID) of the item to be scanned through the ss command, match the external device information table according to the service port and local IP information (i.e., match the WEB service process), obtain the target service port information, obtain the WEB service process identifier (PID) corresponding to the target service port information, obtain the path information of the WEB application service according to the WEB service process identifier, obtain the configuration file of the WEB application service according to the path information, parse the configuration file to obtain the directory path information of the WEB application service, perform a configuration file scan and detection on the configuration file under the path according to the path information and the directory path information, obtain a scan result file (i.e., write the result to a local file), and upload the scan result file to the sender of the WEB application configuration detection command (i.e., report the result).

[0104] In one embodiment, as Figure 4 shown, the WEB application configuration detection method of the present application is described through a most detailed embodiment, and this embodiment includes steps S402 to step S424.

[0105] S402: Receive a WEB application configuration detection command;

[0106] S404: Extract the server download address and task script identifier carried in the WEB application configuration detection command;

[0107] S406: Access the server according to the server download address and download the task script data packet according to the task script identifier;

[0108] S408: Decompress the task script data packet to obtain the script to be executed, the external device information table, the scanned whitelist device table, and the scan item information;

[0109] S410: Execute the script to be executed to obtain an alternative scan item set corresponding to the scan item information;

[0110] S412: Compare the device information in the scanned whitelist device table with each alternative scan item in the alternative scan item set, and filter out the items to be scanned from the alternative scan item set;

[0111] S414: Obtain the service port information and local IP address of the item to be scanned;

[0112] S416: Compare the device-port information correspondence table in the external device information table according to the service port information and local IP address to obtain the target service port information;

[0113] S418: Obtain the WEB service process identifier corresponding to the target service port information, and obtain the path information of the WEB application service according to the WEB service process identifier;

[0114] S420: Obtain the configuration file of the WEB application service according to the path information, and parse the configuration file to obtain the directory path information of the WEB application service;

[0115] S422: Perform a configuration file scan detection on the configuration file under the path according to the path information and directory path information to obtain a scan result file;

[0116] S424: Upload the scan result file to the sender of the WEB application configuration detection command.

[0117] Figure 5 It is an application environment diagram of the WEB application configuration detection method in an embodiment. Refer to Figure 5, the WEB application configuration detection method is applied to a WEB application configuration detection system. The WEB application configuration detection system includes a server 510 and an object to be detected 520. The object to be detected 520 and the server 510 are connected through a network. When the server 510 detects a scan task file, it parses the scan task file to determine the IP address set of the object to be detected 520. According to the IP address set of the object to be detected 520, it issues a WEB application configuration detection command to each object to be detected 520. The WEB application configuration detection command is used to instruct each object to be detected 520 to download and decompress a preset task script data packet to obtain an executable script, an external device information table, a scanned whitelist device table, and scan item information. According to the executable script, it compares the scanned whitelist device table and the scan item information to determine the items to be scanned, obtains and compares the external device information table according to the service port information of the items to be scanned to obtain the path information of the WEB application service, obtains the configuration file of the WEB application service according to the path information, parses the configuration file to obtain the directory path information of the WEB application service, performs a configuration file scan detection according to the path information and the directory path information, obtains a scan result file and feeds it back, and receives the scan result file. The object to be detected 520 can specifically be a desktop terminal or a mobile terminal, and the mobile terminal can specifically be at least one of a mobile phone, a tablet computer, a laptop computer, etc. The server 510 can be implemented by an independent server or a server cluster composed of multiple servers.

[0118] As Figure 6 shown, in one embodiment, a WEB application configuration detection method is provided. In this embodiment, it is mainly exemplified that this method is applied to the server 510 in the above Figure 5 . Referring to Figure 6 , the WEB application configuration detection method specifically includes the following steps S602 to step S606.

[0119] S602: When detecting a scan task file, parse the scan task file to determine the IP address set of the object to be detected.

[0120] Among them, the scan task file refers to a file generated according to a scan task. For example, the scan task can specifically be to scan a device corresponding to any IP. Another example is that the scan task can specifically also be to scan a device corresponding to any function. Specifically, when the scan task is to scan a device corresponding to any function, the server needs to determine the IP corresponding to the device that can implement this function according to this function. Specifically, the scan task file can be named in the form of MD5, and the content therein includes IP address information and / or function module information. The object to be detected refers to the terminal device to be detected.

[0121] Specifically, after detecting the scan task file, the server will parse the scan task file, extract the set of alternative IP addresses of the objects to be detected, obtain the preset scan whitelist device information table, compare each device information in the scan whitelist device information table with each alternative IP address of the objects to be detected in the set of alternative IP addresses of the objects to be detected, determine the IP addresses that are exempt from scanning, and extract the set of IP addresses of the objects to be detected from the set of alternative IP addresses of the objects to be detected according to the IP addresses that are exempt from scanning.

[0122] Further, parsing the scan task file and extracting the set of alternative IP addresses of the objects to be detected includes: Parsing the scan task file can obtain scan task information. When the scan task information is a set of IP addresses, the set of IP addresses is used as the set of alternative IP addresses of the objects to be detected. When the scan task information is function module information, determine the set of target devices that implement the functions corresponding to the function module, and obtain the set of IP addresses of the set of target devices as the set of alternative IP addresses of the objects to be detected.

[0123] In one embodiment, before detecting the scan task file and parsing the scan task file to determine the set of IP addresses of the objects to be detected, the WEB application configuration detection method further includes:

[0124] Regularly obtain the external device information table;

[0125] Receive scan task information and scan parameters. The scan parameters include configuration detection script data and the scan whitelist device information table;

[0126] According to the scan configuration file, the external device information table, and the scan parameters in the scan task information, create a task script data packet, and extract the specified scan object information in the scan task information, and generate a scan task file according to the specified scan object information.

[0127] Among them, the server will regularly obtain the external device information table at preset time intervals. The preset time interval can be set by itself as needed. As Figure 7 shown, the server will receive the scan task information and scan parameters input by the user through the front-end display interface, etc.

[0128] S604: According to the set of IP addresses of the objects to be detected, send the WEB application configuration detection command to each object to be detected. The WEB application configuration detection command is used to instruct each object to be detected to download and decompress a preset task script data packet, obtain the script to be executed, the external device information table, the scanned whitelist device table, and the scan item information. According to the script to be executed, compare the scanned whitelist device table and the scan item information to determine the items to be scanned, obtain and compare the external device information table based on the service port information of the items to be scanned, obtain the path information of the WEB application service, obtain the configuration file of the WEB application service according to the path information, parse the configuration file to obtain the directory path information of the WEB application service, perform configuration file scan detection based on the path information and the directory path information, obtain the scan result file and feedback.

[0129] S606: Receive the scan result file.

[0130] Specifically, after receiving the scan result file, the server will query the preset device responsibility data table according to the IP address in the scan result file, determine the device responsibility information corresponding to the IP address, and generate a WEB application configuration detection result table according to the device responsibility information. The preset device responsibility data table can be set by itself according to needs, and it includes the responsible person information corresponding to each device. For example, the device responsibility data table includes the business module responsible person, the main and standby machine responsible person, and the device attribution function module information corresponding to each device. The WEB application configuration detection result table refers to a database table including device responsible person information, container name / IP information / module information, and non-compliance information, etc. The non-compliance information can be extracted from the scan result file, and the non-compliance information refers to the configuration information that does not meet the specifications.

[0131] Furthermore, after obtaining the WEB application configuration detection result table, the server will also push a security work order to the device responsible person's terminal according to the device responsible person information in the WEB application configuration detection result table. The security work order is used to instruct the device responsible person to perform business repair on the non-compliant configuration for which he is responsible.

[0132] After receiving the WEB application configuration detection command, the above WEB application configuration detection method can download and parse a preset task script data packet to obtain a script to be executed, an external device information table, a scanned whitelist device table, and scan item information. According to the script to be executed, compare the scanned whitelist device table and the scan item information to determine the items to be scanned, obtain and compare the external device information table based on the service port information of the items to be scanned to obtain the path information of the WEB application service, obtain the configuration file of the WEB application service according to the path information, parse the configuration file to obtain the directory path information of the WEB application service, perform a configuration file scan detection based on the path information and the directory path information, obtain a scan result file and feedback it. Throughout the process, accurate path information and directory path information can be obtained, so that accurate configuration file scan detection can be performed based on the path information and the directory path information, an accurate scan result file can be obtained and feedback can be provided, improving the accuracy of the scan detection.

[0133] In one embodiment, the solution of the present application is illustrated by a schematic diagram as Figure 8 shown.

[0134] Server timed baseline check (timely obtain the external device information table, receive scan task information and scan parameters, where the scan parameters include configured detection script data and the scanned whitelist device information table), create a task script data packet (i.e., task script packaging) according to the scan configuration file, external device information table, and scan parameters in the scan task information, and extract the specified scan object information in the scan task information. Generate a scan task file according to the specified scan object information, parse the scan task file to determine the set of IP addresses of the objects to be detected, and send WEB application configuration detection commands to each object to be detected (including physical machines without containers and physical machines with containers) through the background scheduling system according to the set of IP addresses of the objects to be detected. The WEB application configuration detection command is used to instruct each object to be detected to download and decompress a preset task script data packet to obtain the script to be executed, the external device information table, the scanned whitelist device table, and the scan item information. According to the script to be executed, compare the scanned whitelist device table and the scan item information to determine the items to be scanned, obtain and compare the external device information table according to the service port information of the items to be scanned to obtain the path information of the WEB application service, obtain the configuration file of the WEB application service according to the path information, parse the configuration file to obtain the directory path information of the WEB application service, perform configuration file scan detection according to the path information and the directory path information, obtain a scan result file and feedback (i.e., execute the decompressed package), receive the scan result file, query the preset device responsibility data table according to the IP address in the scan result file to determine the device responsibility information corresponding to the IP address, generate a WEB application configuration detection result table according to the device responsibility information, and push a security work order to the device responsible person's terminal according to the device responsible person information in the WEB application configuration detection result table. The security work order is used to instruct the device responsible person to perform business repair on the non-compliant configurations for which the person is responsible.

[0135] In one embodiment, the solution of this application is illustrated by a schematic diagram as Figure 9 shown.

[0136] The server periodically obtains the external device information table (i.e., external RS information), receives the scanning task information (obtained according to the scanning actions added by the user) and scanning parameters input by the user. The scanning parameters include the configured detection script data (obtained according to the scanning scripts written by the user) and the scanned whitelist device information table (obtained according to the whitelisting strategy configured by the user). According to the scanning configuration file, external device information table, and scanning parameters in the scanning task information, a task script data packet is created (i.e., a task script package is generated), and the specified scanning object information in the scanning task information is extracted. A scanning task file is generated according to the specified scanning object information (i.e., a task file is generated). The scanning task file is parsed to extract the set of alternative IP addresses of the objects to be detected. The scanned whitelist device information table is obtained, and the physical machines that have been added to the whitelist are determined according to the IP address information in the scanned whitelist device information table. The set of IP addresses of the objects to be detected is extracted from the set of alternative IP addresses of the objects to be detected according to the physical machines that have been added to the whitelist. The WEB application configuration detection command is sent to each object to be detected through the background scheduling system according to the set of IP addresses of the objects to be detected, instructing each object to be detected to download and decompress the preset task script data packet to obtain the script to be executed, external device information table, scanned whitelist device table, and scanning item information. According to the script to be executed, the scanned whitelist device table and scanning item information are compared to determine the items to be scanned. Among them, if it is determined to be a container scanning task according to the scanning item information, the container to be scanned can be determined by comparing the scanned whitelist device table and the alternative scanning container set in the scanning item information (i.e., to confirm whether the container has been added to the whitelist). If it is determined not to be a container scanning task according to the scanning item information, the item to be scanned is determined to be a physical machine (i.e., a terminal). The path information of the WEB application service is obtained by comparing the service port information of the item to be scanned with the external device information table and according to the obtained information. The configuration file of the WEB application service is obtained according to the path information. The directory path information of the WEB application service is obtained by parsing the configuration file. The configuration file is scanned and detected according to the path information and directory path information to obtain a scanning result file, and the scanning result file is fed back through the connection result reporting interface.

[0137] Figure 4 It is a schematic flowchart of the WEB application configuration detection method in an embodiment. It should be understood that although Figure 4 the steps in the flowchart are shown in sequence according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless there is a clear indication in this article, the execution of these steps has no strict order limit, and these steps can be executed in other orders. Moreover, Figure 4At least a part of the steps may include multiple sub-steps or multiple stages, and these sub-steps or stages are not necessarily executed and completed at the same moment, but can be executed at different moments, and the execution order of these sub-steps or stages is not necessarily sequential, but can be executed alternately or in turn with at least a part of other steps or sub-steps or stages of other steps.

[0138] As Figure 10 shown, in one embodiment, a WEB application configuration detection device is provided, and the device includes a receiving module 1001, a downloading and decompressing module 1002, a comparison module 1003, a processing module 1004, a parsing module 1005, and a scanning and detecting module 1006.

[0139] The receiving module 1001 is configured to receive a WEB application configuration detection command.

[0140] The downloading and decompressing module 1002 is configured to download and decompress a preset task script data packet according to the WEB application configuration detection command, and obtain a to-be-executed script, an external device information table, a scanning whitelist device table, and scanning item information.

[0141] In one embodiment, the downloading and decompressing module 1002 includes:

[0142] An extraction unit, configured to extract a server download address and a task script identifier carried in the WEB application configuration detection command;

[0143] A downloading unit, configured to access a server according to the server download address and download a task script data packet according to the task script identifier;

[0144] A decompressing unit, configured to decompress the task script data packet.

[0145] The comparison module 1003 is configured to compare the scanning whitelist device table and the scanning item information according to the to-be-executed script, and determine to-be-scanned items.

[0146] In one embodiment, the comparison module 1003 includes:

[0147] An execution unit, configured to execute the to-be-executed script and obtain an alternative scanning item set corresponding to the scanning item information;

[0148] A screening unit, configured to compare each device information in the scanning whitelist device table and each alternative scanning item in the alternative scanning item set, and screen out to-be-scanned items from the alternative scanning item set.

[0149] The processing module 1004 is configured to obtain and compare the external device information table according to the service port information of the to-be-scanned items, and obtain path information of the WEB application service.

[0150] In one embodiment, the processing module 1004 includes:

[0151] An obtaining unit, configured to obtain the service port information and the local IP address of the item to be scanned;

[0152] A comparison unit, configured to compare the device-port information correspondence table in the external device information table according to the service port information and the local IP address, so as to obtain the target service port information;

[0153] A path obtaining unit, configured to obtain the WEB service process identifier corresponding to the target service port information, and obtain the path information of the WEB application service according to the WEB service process identifier.

[0154] A parsing module 1005, configured to obtain the configuration file of the WEB application service according to the path information, and parse the configuration file to obtain the directory path information of the WEB application service.

[0155] A scan detection module 1006, configured to perform a configuration file scan detection according to the path information and the directory path information, and obtain and feedback a scan result file.

[0156] In one embodiment, the scan detection module 1006 includes:

[0157] A scan detection unit, configured to perform a configuration file scan detection on the configuration files under the path according to the path information and the directory path information, so as to obtain a scan result file;

[0158] An uploading unit, configured to upload the scan result file to the sender of the WEB application configuration detection command.

[0159] After receiving the WEB application configuration detection command, the above-mentioned WEB application configuration detection device can download and parse a preset task script data packet to obtain an executable script, an external device information table, a scan whitelist device table, and scan item information. According to the executable script, compare the scan whitelist device table and the scan item information to determine the item to be scanned, obtain and compare the external device information table according to the service port information of the item to be scanned, so as to obtain the path information of the WEB application service, obtain the configuration file of the WEB application service according to the path information, parse the configuration file to obtain the directory path information of the WEB application service, perform a configuration file scan detection according to the path information and the directory path information, obtain and feedback a scan result file. In the whole process, accurate path information and directory path information can be obtained, so that accurate configuration file scan detection can be performed according to the path information and the directory path information, and an accurate scan result file can be obtained and feedback, improving the accuracy of the scan detection.

[0160] Such as Figure 11As shown, in one embodiment, a WEB application configuration detection device is provided. The device includes a detection module 1101, an indication module 1102, and a result receiving module 1103.

[0161] The detection module 1101 is configured to, when detecting a scan task file, parse the scan task file to determine a set of IP addresses of objects to be detected.

[0162] The indication module 1102 is configured to, according to the set of IP addresses of objects to be detected, send a WEB application configuration detection command to each object to be detected. The WEB application configuration detection command is used to instruct each object to be detected to download and decompress a preset task script data packet to obtain an executable script, an external device information table, a scan whitelist device table, and scan item information. According to the executable script, compare the scan whitelist device table and the scan item information to determine items to be scanned. Obtain and compare the external device information table according to the service port information of the items to be scanned to obtain path information of the WEB application service. According to the path information, obtain a configuration file of the WEB application service, parse the configuration file to obtain directory path information of the WEB application service, perform a configuration file scan detection according to the path information and the directory path information, obtain a scan result file, and feedback it.

[0163] The result receiving module 1103 is configured to receive the scan result file.

[0164] After receiving the WEB application configuration detection command, the above-mentioned WEB application configuration detection device can download and parse a preset task script data packet to obtain an executable script, an external device information table, a scan whitelist device table, and scan item information. According to the executable script, compare the scan whitelist device table and the scan item information to determine items to be scanned. Obtain and compare the external device information table according to the service port information of the items to be scanned to obtain path information of the WEB application service. According to the path information, obtain a configuration file of the WEB application service, parse the configuration file to obtain directory path information of the WEB application service, perform a configuration file scan detection according to the path information and the directory path information, obtain a scan result file, and feedback it. Throughout the process, accurate path information and directory path information can be obtained, so that accurate configuration file scan detection can be performed according to the path information and the directory path information, an accurate scan result file can be obtained and feedback, improving the accuracy of the scan detection.

[0165] Figure 12 The internal structure diagram of a computer device in one embodiment is shown. The computer device may specifically be Figure 1 the terminal 110 in Figure 5 , or may also be Figure 12As shown, the computer device includes a processor, a memory, a network interface, an input device, and a display screen connected via a system bus. Among them, the memory includes a non-volatile storage medium and an internal memory. The non-volatile storage medium of the computer device stores an operating system and may also store a computer program. When the computer program is executed by the processor, the processor can implement the WEB application configuration detection method. The internal memory may also store a computer program. When the computer program is executed by the processor, the processor can execute the WEB application configuration detection method. The display screen of the computer device can be a liquid crystal display screen or an electronic ink display screen. The input device of the computer device can be a touch layer covering the display screen, or a button, a trackball, or a touchpad provided on the housing of the computer device, or an external keyboard, touchpad, or mouse, etc.

[0166] Those skilled in the art can understand that Figure 12 the structure shown in is only a block diagram of some structures related to the solution of this application, and does not constitute a limitation on the computer device to which the solution of this application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine some components, or have different component arrangements.

[0167] In one embodiment, the WEB application configuration detection device provided by this application can be implemented in the form of a computer program, and the computer program can run on a computer device such as Figure 12 shown. Each program module constituting the WEB application configuration detection device can be stored in the memory of the computer device. For example, Figure 10 the receiving module, the downloading and decompressing module, the comparison module, the processing module, the parsing module, and the scanning and detection module shown. Another example is the detection module, the indication module, and the result receiving module shown in Figure 11 The computer program composed of each program module enables the processor to execute the steps in the WEB application configuration detection method described in each embodiment of this application in this specification.

[0168] For example, Figure 12 the computer device shown can be connected via Figure 10The receiving module in the WEB application configuration detection device shown executes receiving a WEB application configuration detection command. The computer device can execute, through the download and decompression module, downloading and decompressing a preset task script data packet according to the WEB application configuration detection command to obtain a to-be-executed script, an external device information table, a scanned whitelist device table, and scanned item information. The computer device can execute, through the comparison module, comparing the scanned whitelist device table and the scanned item information according to the to-be-executed script to determine to-be-scanned items. The computer device can execute, through the processing module, obtaining and comparing the external device information table according to the service port information of the to-be-scanned items to obtain the path information of the WEB application service. The computer device can execute, through the parsing module, obtaining the configuration file of the WEB application service according to the path information and parsing the configuration file to obtain the directory path information of the WEB application service. The computer device can execute, through the scanning and detection module, performing configuration file scanning and detection according to the path information and the directory path information to obtain a scan result file and feedback it.

[0169] For another example, Figure 12 the computer device shown can, through Figure 11 the detection module in the WEB application configuration detection device shown, when detecting a scan task file, parse the scan task file to determine a set of IP addresses of to-be-detected objects. The computer device can execute, through the instruction module, according to the set of IP addresses of to-be-detected objects, sending a WEB application configuration detection command to each to-be-detected object. The WEB application configuration detection command is used to instruct each to-be-detected object to download and decompress a preset task script data packet to obtain a to-be-executed script, an external device information table, a scanned whitelist device table, and scanned item information, comparing the scanned whitelist device table and the scanned item information according to the to-be-executed script to determine to-be-scanned items, obtaining and comparing the external device information table according to the service port information of the to-be-scanned items to obtain the path information of the WEB application service, obtaining the configuration file of the WEB application service according to the path information, parsing the configuration file to obtain the directory path information of the WEB application service, performing configuration file scanning and detection according to the path information and the directory path information to obtain a scan result file and feedback it. The computer device can execute, through the result receiving module, receiving the scan result file.

[0170] In one embodiment, a computer device is provided, including a memory and a processor. The memory stores a computer program. When the computer program is executed by the processor, the processor executes the steps of the above-mentioned WEB application configuration detection method. Here, the steps of the WEB application configuration detection method can be the steps in the WEB application configuration detection method of each of the above embodiments.

[0171] In one embodiment, a computer-readable storage medium is provided, storing a computer program, which, when executed by a processor, causes the processor to execute the steps of the above WEB application configuration detection method. The steps of the WEB application configuration detection method here may be the steps in the WEB application configuration detection methods of the above various embodiments.

[0172] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it may include the processes of the embodiments of the above various methods. Among them, any reference to a memory, storage, database, or other medium used in the various embodiments provided in the present application may include at least one of non-volatile and volatile memories. Non-volatile memory may include read-only memory (ROM), magnetic tape, floppy disk, flash memory, or optical memory, etc. Volatile memory may include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc.

[0173] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered to be within the scope described in this specification.

[0174] The above-described embodiments merely represent several implementation manners of the present application. The description thereof is relatively specific and detailed, but it should not be construed as a limitation on the patent scope of the present application. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all belong to the protection scope of the present application. Therefore, the protection scope of the patent of the present application should be subject to the appended claims.

Claims

1. A WEB application configuration detection method, comprising: Receiving a WEB application configuration detection command; Downloading and decompressing a preset task script data packet according to the WEB application configuration detection command to obtain a to-be-executed script, an external device information table, a scanned whitelist device table, and scan item information; Comparing the scanned whitelist device table and the scan item information according to the to-be-executed script to determine to-be-scanned items; Obtaining service port information and a local IP address of the to-be-scanned items; Comparing the device-port information correspondence table in the external device information table according to the service port information and the local IP address to obtain target service port information; Obtaining a WEB service process identifier corresponding to the target service port information, and obtaining path information of the WEB application service according to the WEB service process identifier; Obtaining a configuration file of the WEB application service according to the path information, and parsing the configuration file to obtain directory path information of the WEB application service; Performing configuration file scan detection according to the path information and the directory path information, obtaining a scan result file and feeding it back.

2. The method according to claim 1, wherein The downloading and decompressing the preset task script data packet according to the WEB application configuration detection command includes: Extracting a server download address and a task script identifier carried in the WEB application configuration detection command; Accessing a server according to the server download address, and downloading a task script data packet according to the task script identifier; Decompressing the task script data packet.

3. The method according to claim 1, wherein The comparing the scanned whitelist device table and the scan item information according to the to-be-executed script to determine to-be-scanned items includes: Executing the to-be-executed script to obtain a set of alternative scan items corresponding to the scan item information; Comparing each device information in the scanned whitelist device table with each alternative scan item in the set of alternative scan items, and screening out to-be-scanned items from the set of alternative scan items.

4. The method according to claim 1, characterized in that, The performing configuration file scan detection according to the path information and the directory path information, obtaining a scan result file and feeding it back includes: Performing configuration file scan detection on the configuration files under the path according to the path information and the directory path information to obtain a scan result file; Uploading the scan result file to the sender of the WEB application configuration detection command.

5. A WEB application configuration detection method, comprising: When a scan task file is detected, parsing the scan task file to determine a set of IP addresses of objects to be detected; According to the set of IP addresses of the objects to be detected, send a WEB application configuration detection command to each object to be detected. The WEB application configuration detection command is used to instruct each object to be detected to download and decompress a preset task script data packet, obtain an executable script, an external device information table, a scanned whitelist device table, and scanned item information. According to the executable script, compare the scanned whitelist device table with the scanned item information to determine the items to be scanned, obtain the service port information and local IP address of the items to be scanned, compare the device-port information correspondence table in the external device information table according to the service port information and the local IP address to obtain the target service port information, obtain the WEB service process identifier corresponding to the target service port information, obtain the path information of the WEB application service according to the WEB service process identifier, obtain the configuration file of the WEB application service according to the path information, parse the configuration file to obtain the directory path information of the WEB application service, perform a configuration file scan detection according to the path information and the directory path information, obtain a scan result file and feedback it; Receive the scan result file.

6. A WEB application configuration detection device, characterized in that, The device includes: A receiving module, configured to receive a WEB application configuration detection command; A download and decompression module, configured to download and decompress a preset task script data packet according to the WEB application configuration detection command to obtain an executable script, an external device information table, a scanned whitelist device table, and scanned item information; A comparison module, configured to compare the scanned whitelist device table with the scanned item information according to the executable script to determine the items to be scanned; The processing module includes an acquisition unit, a comparison unit, and a path acquisition unit. The acquisition unit is configured to acquire the service port information and local IP address of the items to be scanned. The comparison unit is configured to compare the device-port information correspondence table in the external device information table according to the service port information and the local IP address to obtain the target service port information. The path acquisition unit is configured to acquire the WEB service process identifier corresponding to the target service port information and obtain the path information of the WEB application service according to the WEB service process identifier; A parsing module, configured to obtain the configuration file of the WEB application service according to the path information and parse the configuration file to obtain the directory path information of the WEB application service; A scan detection module, configured to perform a configuration file scan detection according to the path information and the directory path information to obtain a scan result file and feedback it.

7. The device according to claim 6, characterized in that, The download and decompression module includes an extraction unit, a download unit, and a decompression unit. The extraction unit is configured to extract the server download address and task script identifier carried in the WEB application configuration detection command. The download unit is configured to access the server according to the server download address and download the task script data packet according to the task script identifier. The decompression unit is configured to decompress the task script data packet.

8. The device according to claim 6, characterized in that The comparison module includes an execution unit, a screening unit, and a processing unit; the execution unit is configured to execute the to-be-executed script, obtain a set of alternative scan items corresponding to the scan item information, and the screening unit is configured to compare each device information in the scan whitelist device table with each alternative scan item in the set of alternative scan items, and screen out the to-be-scanned items from the set of alternative scan items.

9. The device according to claim 6, wherein The scan detection module includes a scan detection unit and an upload unit; the scan detection unit is configured to perform a configuration file scan detection on the configuration files under the path according to the path information and the directory path information, to obtain a scan result file, and the upload unit is configured to upload the scan result file to the sender of the WEB application configuration detection command.

10. A WEB application configuration detection device, characterized in that, The device includes: a detection module, configured to, when detecting a scan task file, parse the scan task file to determine a set of IP addresses of objects to be detected; an indication module, configured to, according to the set of IP addresses of objects to be detected, send a WEB application configuration detection command to each object to be detected, where the WEB application configuration detection command is used to instruct each object to be detected to download and decompress a preset task script data packet, to obtain a to-be-executed script, an external device information table, a scan whitelist device table, and scan item information, compare the scan whitelist device table with the scan item information according to the to-be-executed script, determine the to-be-scanned items, obtain the service port information and the local IP address of the to-be-scanned items, compare the device-port information correspondence table in the external device information table according to the service port information and the local IP address, to obtain target service port information, obtain a WEB service process identifier corresponding to the target service port information, obtain the path information of the WEB application service according to the WEB service process identifier, obtain the configuration file of the WEB application service according to the path information, parse the configuration file to obtain the directory path information of the WEB application service, perform a configuration file scan detection according to the path information and the directory path information, to obtain a scan result file and feedback it; a result receiving module, configured to receive the scan result file.

11. A computer-readable storage medium, storing a computer program, which when executed by a processor, causes the processor to execute the steps of the method according to any one of claims 1 to 5.

12. A computer device, including a memory and a processor, where the memory stores a computer program, which when executed by the processor, causes the processor to execute the steps of the method according to any one of claims 1 to 5.

Citation Information

Patent Citations

  • Method and system for searching for webshell with assistance of local simulation request

    CN103905422A

  • Server end scanning method based on mobile traffic

    CN107239697A