Vulnerability testing method, device, computer equipment and storage medium

By cutting and analyzing the source code and tracking the engine, combined with semantic and syntactic analysis, the problem of traditional WEB application security testing being unable to accurately locate vulnerabilities is solved, dynamic tracking and positioning of vulnerabilities is achieved, and code quality and the efficiency of vulnerability verification are improved.

CN114036526BActive Publication Date: 2025-09-05GUANGZHOU POWER SUPPLY BUREAU GUANGDONG POWER GRID CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111290262.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-11-02
Publication Date
2025-09-05
Estimated Expiration
2041-11-02

AI Technical Summary

Technical Problem

Traditional WEB application security testing technology cannot accurately locate vulnerabilities and is difficult to apply to different types of agents, resulting in high R&D costs and limited application scenarios.

Method used

By obtaining the source code and cutting it into token files, using the analysis engine to track the input interface, tracking the variable transfer process forward and backward, combining semantic and grammatical analysis, determining the logical relationship between the vulnerability location and the network address path, and generating a vulnerability test report.

Benefits of technology

It realizes dynamic tracking and backtracing of source code vulnerabilities, improves code quality, helps black box testers locate vulnerability entrances, and improves the effectiveness of vulnerability verification testing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114036526B_ABST
    Figure CN114036526B_ABST
Patent Text Reader

Abstract

The present application relates to a vulnerability testing method, device, computer equipment and storage medium. The method obtains the source code to be tested, and cuts the source code according to preset rules to obtain a token file, and then uses an analysis engine to track the token file to determine the input interface of the source code, and then performs a backtracking check of the variable tracking process by forward and reverse tracing the variables associated with the input interface of the source code, finds vulnerabilities in the transmission process, and performs semantic analysis and grammatical analysis on the code to obtain a syntax tree; traverses the syntax tree and combines the vulnerabilities in the variable transmission process found by forward and reverse tracing the variables associated with the input interface of each code, and determines the logical relationship between the network address path corresponding to the vulnerability after the source code is compiled by the system and the vulnerability position in the source code. Better display the relationship between the source code and the system code level, better serve testers to reproduce and retest existing vulnerabilities, and effectively improve the code quality of programmers.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of application security testing, and in particular to a vulnerability testing method, apparatus, computer equipment, and storage medium. Background Art

[0002] In order to discover vulnerabilities and defects in software applications and ensure the security of WEB applications before and after delivery, it is necessary to use security testing technology to proactively identify architectural weaknesses and vulnerabilities in WEB applications (applications that can be accessed via the WEB) to prevent the corresponding applications from being exploited by hackers and illegal personnel, causing security hazards.

[0003] After years of development, web application security testing technologies such as SAST, DAST, and IAST have emerged. However, during implementation, the inventors discovered that traditional web application security testing technologies often suffer from the defect of being unable to determine the specific location of vulnerabilities. Furthermore, those that can detect vulnerability locations are difficult to apply to different types of agents, resulting in high R&D costs and limited application scenarios. Summary of the Invention

[0004] Based on this, it is necessary to provide a vulnerability testing method, device, computer equipment and storage medium that can dynamically track and trace vulnerabilities and discover vulnerabilities in response to the above technical problems.

[0005] In one aspect, a vulnerability testing method is provided, comprising:

[0006] Obtain the source code to be tested and cut the source code into token files according to preset rules;

[0007] Using an analysis engine to trace the token file to determine the input interface of the source code;

[0008] By forward and reverse tracing the variables associated with the input interface of the source code, a backtracking check of the variable tracing process is performed to find loopholes in the variable transfer process;

[0009] Perform semantic analysis and grammatical analysis on the source code to obtain the corresponding syntax tree;

[0010] Traverse the syntax tree and combine forward and reverse tracing of variables associated with the input interface of each code to find vulnerabilities in the variable passing process, and determine the logical relationship between the network address path corresponding to the vulnerability after the source code is compiled by the system and the vulnerability location in the source code.

[0011] In one embodiment, the steps of finding vulnerabilities in the variable transfer process by forward and reverse tracing variables associated with input interfaces of various codes include:

[0012] Trace the variables associated with the input interface forward and backward to identify vulnerabilities in the variable transmission process by checking for code logic vulnerabilities during the variable transmission process, and / or checking whether the variables are passed to high-risk functions, and / or checking the parameters of sensitive functions.

[0013] In one embodiment, the token file is a token list, and the steps of obtaining the source code to be detected and segmenting the source code according to preset rules to obtain the token file include:

[0014] The source code is split according to the preset rules to obtain multiple tokens;

[0015] Cut each token of the source code into a list to form a token list.

[0016] In one embodiment, the step of segmenting the source code according to a preset rule to obtain a plurality of tokens includes:

[0017] Remove content from the source code that does not affect the semantics of the code;

[0018] The source code is cut line by line to remove the content that does not affect the semantics of the code, and each line of code is converted into the corresponding token.

[0019] In one embodiment, the step of using an analysis engine to track a token file to determine an input interface of a source code includes:

[0020] The analysis engine is used to compare the token file through forward and reverse tracing to determine that the external access interface corresponding to the token file that receives external input parameters is the input interface of the source code.

[0021] In one embodiment, the vulnerability testing method further includes:

[0022] Generate and send a vulnerability test report based on the logical relationship between the network address path corresponding to the vulnerability after the source code is compiled by the system and the vulnerability location in the source code.

[0023] On the other hand, a vulnerability testing device is also provided, comprising:

[0024] The token file acquisition module is used to obtain the source code to be detected and cut the source code according to the preset rules to obtain the token file;

[0025] A source code input interface determination module is used to track the token file using an analysis engine to determine the input interface of the source code;

[0026] A vulnerability search module is used to perform a backtracking check of the variable tracking process by tracing the variables associated with the input interface of the source code in a forward and reverse manner, and to find vulnerabilities in the variable transmission process;

[0027] Syntax tree acquisition module, used to perform semantic analysis and syntactic analysis on the source code to obtain the corresponding syntax tree;

[0028] The vulnerability path and location relationship determination module is used to traverse the syntax tree and combine forward and reverse tracing of variables associated with the input interface of each code to find vulnerabilities in the variable transfer process, and determine the logical relationship between the network address path corresponding to the vulnerability after the source code is compiled by the system and the vulnerability location in the source code.

[0029] In one embodiment, the vulnerability search module includes:

[0030] A backtracking query unit is used to track the variables associated with the input interface in forward and reverse directions, and to determine the vulnerabilities in the variable transmission process by checking whether there are code logic vulnerabilities in the variable transmission process, and / or checking whether the variable is passed to a high-risk function, and / or checking the parameters of a sensitive function.

[0031] A computer device includes a memory and a processor. The memory stores a computer program. When the processor executes the computer program, the steps of the vulnerability testing method are implemented.

[0032] A computer-readable storage medium stores a computer program, which implements the steps of the vulnerability testing method when executed by a processor.

[0033] The above vulnerability testing method, apparatus, computer equipment, and storage medium have at least the following beneficial effects:

[0034] Among them, the vulnerability testing method obtains the source code to be tested, and cuts the source code according to preset rules to obtain a token file. The token file is tracked by an analysis engine to determine the input interface of the source code, and further by forward and reverse tracing the variables associated with the input interface of the source code, vulnerabilities in the variable transfer process are found. White box testing technology can be used to discover vulnerabilities, and further semantic analysis and grammatical analysis of the source code are performed to obtain the corresponding syntax tree. By traversing the syntax tree and combining forward and reverse tracing of the variables associated with the input interface of each code to find the vulnerabilities in the variable transfer process, the logical relationship between the network address path corresponding to the vulnerability after the source code is compiled by the system and the vulnerability location in the source code is determined. This better demonstrates the relationship between the source code and the system code level, better serves testers to reproduce and retest existing vulnerabilities, and effectively improves the quality of programmers' code. Dynamic tracking and backtracing can be achieved, and the vulnerability entry location can be discovered, thereby more effectively helping black box testers to carry out targeted vulnerability verification testing. BRIEF DESCRIPTION OF THE DRAWINGS

[0035] Figure 1A diagram of an application environment of a vulnerability testing method in one embodiment;

[0036] Figure 2 1 is a flow chart of a vulnerability testing method according to an embodiment;

[0037] Figure 3 1 is a flow chart of a vulnerability testing method according to an embodiment;

[0038] Figure 4 is a structural block diagram of a vulnerability testing device in one embodiment;

[0039] Figure 5 FIG. 1 is a diagram showing the internal structure of a computer device in one embodiment. DETAILED DESCRIPTION

[0040] In order to make the purpose, technical solutions and advantages of this application more clear, the following further describes this application in detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not intended to limit this application.

[0041] The security vulnerability detection method provided by this application can be applied to Figure 1 In the application environment shown, terminal 102 communicates with server 104 via a network. Server 104 obtains the source code of the web application on terminal 102 and, based on the following security vulnerability detection method, performs vulnerability detection on the source code of the web application. It can also generate a vulnerability detection report for the user to review, thereby providing a strong guarantee for the security of the web application. Terminal 102 can be, but is not limited to, various personal computers, laptops, smartphones, tablet computers, and portable wearable devices. Server 104 can be implemented as an independent server or a server cluster consisting of multiple servers.

[0042] Currently, the commonly used WEB application security testing technologies in the industry are mainly divided into three categories: SAST, DAST and IAST.

[0043] Among them, SAST (Static Application Security Testing) usually analyzes the syntax, structure, process, interface, etc. of the application source code or binary files during the coding stage to discover security vulnerabilities in the program code. It is mainly a white box code audit technology in the development stage.

[0044] DAST (Dynamic Application Security Testing) is a technology that analyzes the dynamic operating status of an application during the testing or operation phase. It is primarily a black-box vulnerability scanning technology used in the operational phase. It simulates hacker behavior to dynamically attack the application, analyzes the application's response, and thereby determines whether the web application is vulnerable to attack.

[0045] IAST (Interactive Application Security Testing) collects and monitors the function execution and data transmission process of WEB applications during runtime by deploying agent probes, traffic agents / VPNs (virtual private networks), or host system software on the server side. It also interacts with the scanner side in real time to efficiently and accurately identify security defects and vulnerabilities. It can also accurately determine the code file, line number, function, and parameters where the vulnerability is located.

[0046] However, SAST has a high false positive rate, requiring more time to eliminate false positives than to fix vulnerabilities. Not only must SAST tools distinguish between different development languages, but they must also support the web application frameworks used. If the SAST tool doesn't support an application's development language and framework, testing will be hampered.

[0047] However, the DAST testing method can have a certain impact on business testing, as dirty data from security testing can contaminate business testing data. Furthermore, vulnerabilities discovered by DAST will locate the URL (network address) of the vulnerability, but it cannot pinpoint the specific line of code or the cause of the vulnerability. Therefore, vulnerability location and cause analysis require specialized personnel.

[0048] The main problem with IAST is that web applications developed in different languages ​​require different types of agents. In particular, the technical difficulty and investment in developing passive IAST are extremely huge. It does not have crawler technology and does not actively replay data packets. Therefore, it cannot detect web applications that do not have agents installed. IAST is not applicable to scenarios that require remote vulnerability scanning.

[0049] In order to solve the above problems, in one embodiment, Figure 2 As shown, a vulnerability testing method is provided, the method comprising:

[0050] S100: Obtain source code to be tested and segment it according to preset rules to generate token files. The preset rules can be custom source code segmentation rules, such as line-by-line segmentation or segmentation based on carriage returns. In one embodiment, line-by-line segmentation can be used to segment the source code. Token files are tokens, which serve as credentials for establishing communication between the front-end and back-end. They can be a one-dimensional array or a table file.

[0051] S200: Utilize an analysis engine to track the token file to determine the input interface of the source code.

[0052] The analysis engine uses forward and reverse tracing to compare token files and find out which token files are receiving external parameters, that is, receiving parameters from the external input interface, so as to find the input of the source code. The tracking rules and configuration information management can be configured on the analysis engine side, or the analysis engine configuration file can be configured. The analysis engine can track the source code through the external access interface to determine the input interface of the source code. The specific implementation of tracking token files can utilize the analyzer in the analysis engine. The analyzer can perform conventional analysis, data / control flow analysis and advanced analysis. The analysis engine can also monitor the source code transmission process and generate system logs based on the analysis results for storage, which is convenient for users to query logs. To facilitate the tracking of token files, the analysis engine can store code and intermediate data, and can also store test results.

[0053] S300: Search for vulnerabilities in the variable transfer process by tracing variables associated with the source code's input interface forward and backward. Variables associated with the source code's input interface are those that can control the behavior of the point where the input interface is located. After finding the input interface, the variable transfer process can be tracked to determine if there are any security vulnerabilities. For example, white-box testing can be used to detect vulnerabilities. By tracing back to the original origin of the variable, the source of the variable can be determined, as well as the other variables that affect the variable. If these variables are externally controllable, the code corresponding to the variable can be considered vulnerable.

[0054] S500: Perform semantic analysis and syntactic analysis on the source code to obtain the corresponding syntax tree (AST, Abstract Syntax Tree). During the conversion process, each source code corresponds to an AST file, which can be a file in XML format. Each line of the source code can be converted into a node in the AST file, which is convenient for subsequent line-by-line detection. During the semantic and pre-analysis process, the vulnerability detection program is set at the trigger point of the source code, that is, the above-mentioned node, to determine the specific location of the vulnerability. Semantic analysis can be the process of scanning the character stream that constitutes the source code and segmenting it according to the word segmentation rules during the process of reading the source code. Syntactic analysis can be the process of combining grammatical phrases based on word segmentation.

[0055] S600: Traverse the syntax tree and combine the forward and reverse tracking of the variables associated with the input interface of each code to find the vulnerabilities in the variable transfer process, and determine the logical relationship between the network address (URL, Uniform Resource Locator) path corresponding to the vulnerability after the source code is compiled by the system and the vulnerability location in the source code.

[0056] Specifically, this vulnerability testing method obtains the source code to be tested and cuts the source code according to preset rules to obtain a token file. The token file is tracked by an analysis engine to determine the input interface of the source code. The variables associated with the input interface of the source code are further traced forward and backward to find vulnerabilities in the variable transfer process. White-box testing technology can be used to discover vulnerabilities, and the source code can be further semantically and syntactically analyzed to obtain the corresponding syntax tree. By traversing the syntax tree and combining forward and backward tracing of the variables associated with the input interface of each code to find vulnerabilities in the variable transfer process, the logical relationship between the network address path corresponding to the vulnerability after the source code is compiled by the system and the vulnerability location in the source code is determined. This better demonstrates the relationship between the source code and the system code level, better serves testers in reproducing and retesting existing vulnerabilities, and effectively improves the quality of programmers' code. Dynamic tracking and backtracing can be achieved to discover the vulnerability entry location, thereby more effectively helping black-box testers carry out targeted vulnerability verification testing.

[0057] The vulnerability testing method provided in the embodiment of the present application is different from the traditional SAST white-box code audit, which cannot be associated with the vulnerability entry location of the actual system and thus cannot inform the black-box tester of the potential problem input points. The vulnerability testing method can use the vulnerabilities discovered by the white-box code audit and the above-mentioned dynamic variable tracking and backtracing to discover the vulnerability entry location, which can effectively assist the black-box tester in conducting targeted vulnerability verification testing.

[0058] In one embodiment, step S300 of finding vulnerabilities in the variable transfer process by forward and reverse tracing variables associated with input interfaces of various codes includes:

[0059] Trace the variables associated with the input interface forward and backward to identify vulnerabilities in the variable transmission process by checking for code logic vulnerabilities during the variable transmission process, and / or checking whether the variables are passed to high-risk functions, and / or checking the parameters of sensitive functions.

[0060] Vulnerabilities can be discovered by tracking variables and examining whether there are logical vulnerabilities in the code during variable transfer, such as business logic vulnerabilities caused by coding errors, and whether variables are passed to high-risk or sensitive functions. Specifically, this can be achieved by converting the front-end language code (such as Java or C / C++ source code) into an intermediate code by calling a development language editor or interpreter. The call relationships, execution environment, and context within the source code can then be analyzed to identify security issues associated with the use of unsafe functions (high-level or sensitive functions) and methods within the program. This can also be used to track, record, and analyze security issues arising from data transfer within the program, including security issues associated with executing instructions at specific times and states within the program. It can also analyze sensitive information and configuration gaps in project configuration files, such as missing permissions. Security issues within the program's context and structure can be analyzed to identify vulnerabilities. High-risk functions in this context refer to high-risk functions within the specific language code being used, such as in_array(), filter_var(), class_exists(), strpos, mail, escapeshellcmd, escapeshellarg, preg_replace, and preg_replace in PHP. Sensitive functions refer to high-risk functions that are found in the code based on the actual source code content. The number of sensitive functions can be greater than or equal to the above-mentioned high-risk functions. Since it is based on the actual code situation, it can more comprehensively detect vulnerabilities in the source code transmission process.

[0061] When checking high-risk functions and sensitive functions as mentioned above, token verification can be used to determine whether there are vulnerabilities in the source code. For example, a baseline token (baseline token) with the source code is configured, and then the baseline token is compared with the target token (the actual corresponding token during the source code transmission process), the difference value is calculated, and the token information is recorded to provide a basis for vulnerability detection.

[0062] In one embodiment, Figure 3 As shown, the token file is a token list. Step S100 of obtaining the source code to be detected and cutting the source code according to preset rules to obtain the token file includes:

[0063] S110: The source code is segmented according to preset rules to obtain multiple tokens. The preset rules can be pre-configured, for example, segmenting the code line by line or segmenting the code sentence by sentence, for example, using a carriage return character as the end mark for a sentence. Each segmented portion of the code is converted into a symbolic representation, which is then referred to as a token.

[0064] S120: Cut each token of the source code into a list to form a token list. The token list can also be understood as a one-dimensional array, depending on the configured storage method, and finally generates the above-mentioned token file (token file).

[0065] In order to further improve the efficiency of vulnerability testing, in one embodiment, step S110 of obtaining multiple tokens after segmenting the source code according to a preset rule includes:

[0066] Remove content from the source code that does not affect the semantics of the code. Content that does not affect the semantics of the code is removed, such as whitespace and comments.

[0067] The source code is segmented line by line, removing any content that does not affect the semantics of the code, and each line of code is converted into a corresponding token. Since whitespace and other parts that are not useful for semantic analysis are excluded, the efficiency of code segmentation is improved. The efficiency of subsequent semantic and syntactic analysis of the segmented code is also further improved, thereby improving the overall efficiency of vulnerability testing.

[0068] In one embodiment, the step S200 of using an analysis engine to track a token file to determine an input interface of a source code includes:

[0069] The analysis engine is used to compare the token file through forward and reverse tracing to determine that the external access interface corresponding to the token file that receives external input parameters is the input interface of the source code.

[0070] In one embodiment, Figure 3 As shown, the vulnerability testing method also includes:

[0071] S700: Generate and send a vulnerability test report based on the logical relationship between the network address path corresponding to the vulnerability after the source code is compiled by the system and the vulnerability location in the source code. The vulnerability test report content may include the distribution of defects in the source code and the URL path from the code vulnerability to the system mutation. This provides a way to locate and track problems in the code, uncover potential security risks in the system, and prevent information security issues that may arise after the system goes online due to code defects. The vulnerability test report can be sent to the terminal used by the engineer, such as a laptop, mobile phone, or tablet. During the transmission process to the terminal, data encryption is used to enhance data transmission security.

[0072] It should be understood that although Figure 2-3 The steps in the flowchart are shown in sequence as indicated by the arrows, but these steps are not necessarily executed in the order indicated by the arrows. Unless otherwise specified in this document, there is no strict order restriction for the execution of these steps, and these steps can be executed in other orders. In addition, Figure 2-3 At least part of the steps may include multiple steps or multiple stages. These steps or stages are not necessarily performed at the same time, but can be performed at different times. The order of execution of these steps or stages is not necessarily one by one, but can be performed in turn or alternately with other steps or at least part of the steps or stages in other steps.

[0073] On the other hand, a vulnerability testing device is also provided. Figure 4 As shown, the device includes:

[0074] The token file acquisition module 100 is used to obtain the source code to be detected and cut the source code according to the preset rules to obtain the token file;

[0075] A source code input interface determination module 200 is configured to track the token file using an analysis engine to determine the input interface of the source code;

[0076] The vulnerability search module 300 is used to perform a backtracking check of the variable tracking process by tracing the variables associated with the input interface of the source code in a forward and reverse manner, and to find vulnerabilities in the variable transfer process;

[0077] Syntax tree acquisition module 500, used to perform semantic analysis and syntactic analysis on the source code to obtain the corresponding syntax tree;

[0078] The vulnerability path and location relationship determination module 600 is used to traverse the syntax tree and combine the vulnerabilities found in the variable transfer process by forward and reverse tracing the variables associated with the input interface of each code to determine the logical relationship between the network address path corresponding to the vulnerability after the source code is compiled by the system and the vulnerability location in the source code.

[0079] In one embodiment, the vulnerability search module 300 includes:

[0080] The backtracking query unit is used to track the variables associated with the input interface in both forward and reverse directions, and to determine the vulnerabilities in the variable transmission process by checking whether there are code logic vulnerabilities in the variable transmission process, and / or checking whether the variable is passed to a high-risk function, and / or checking the parameters of the sensitive function.

[0081] In one embodiment, Figure 4 As shown, the token file is a token list, and the token file acquisition module 100 includes:

[0082] A source code segmentation unit 110 is configured to segment the source code according to a preset rule to obtain a plurality of tokens;

[0083] The list generating unit 120 is configured to cut each token of the source code into a list to form a token list.

[0084] In one embodiment, the source code segmentation unit 110 includes:

[0085] The irrelevant information removal unit is used to remove content in the source code that does not affect the semantics of the code; for example, whitespace characters, comments, and other parts that do not affect the semantics of the code.

[0086] The line-by-line cutting unit is a token conversion unit, which is used to cut the source code line by line to remove the content that does not affect the semantics of the code, and convert each line of code into a corresponding token.

[0087] In one embodiment, the source code input interface determination module 200 includes:

[0088] The source code input confirmation unit is used to use the analysis engine to compare the token file through forward and reverse tracking to determine that the external access interface corresponding to the token file that receives external input parameters is the input interface of the source code.

[0089] In one embodiment, Figure 4 As shown, the vulnerability testing device also includes:

[0090] The vulnerability test report generating module 700 generates and sends a vulnerability test report according to the logical relationship between the network address path corresponding to the vulnerability after the source code is compiled by the system and the vulnerability position in the source code.

[0091] The specific definition of the vulnerability testing device can be found in the definition of the vulnerability testing method above and will not be repeated here. Each module in the vulnerability testing device described above may be implemented in whole or in part through software, hardware, or a combination thereof. Each of the modules described above may be embedded in or independent of a processor in a computer device in hardware form, or may be stored in a memory in the computer device in software form, so that the processor can call and execute the corresponding operations of each module.

[0092] In one embodiment, a computer device is provided. The computer device may be a server, and its internal structure diagram may be as follows: Figure 5 As shown. The computer device includes a processor, a memory, and a network interface connected via a system bus. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and computer program in the non-volatile storage medium. The database of the computer device is used to store data such as preset rules. The network interface of the computer device is used to communicate with an external terminal via a network connection. When the computer program is executed by the processor, a vulnerability testing method is implemented.

[0093] Those skilled in the art will understand that Figure 5 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than shown in the figure, or combine certain components, or have a different component arrangement.

[0094] In one embodiment, a computer device is provided, including a memory and a processor, wherein a computer program is stored in the memory, and when the processor executes the computer program, the following steps are implemented:

[0095] S100: Obtain the source code to be detected, and cut the source code according to preset rules to obtain a token file. The preset rules can be custom source code cutting rules, such as line-by-line cutting or cutting with carriage return symbols. In one embodiment, the line-by-line cutting rule can be selected to cut the source code.

[0096] S200: Utilize an analysis engine to track the token file to determine the input interface of the source code.

[0097] S300: Find vulnerabilities in the variable transfer process by tracing variables associated with the input interface of the source code in both forward and reverse directions;

[0098] S500: Perform semantic analysis and grammatical analysis on the source code to obtain a corresponding syntax tree;

[0099] S600: Traversing the syntax tree and combining forward and backward tracing of variables associated with the input interface of each code to find vulnerabilities in the variable transfer process, determine the logical relationship between the network address path corresponding to the vulnerability after the source code is compiled by the system and the vulnerability location in the source code.

[0100] In one embodiment, when the processor executes the computer program, the processor further implements the following steps:

[0101] Trace the variables associated with the input interface forward and backward to identify vulnerabilities in the variable transmission process by checking for code logic vulnerabilities during the variable transmission process, and / or checking whether the variables are passed to high-risk functions, and / or checking the parameters of sensitive functions.

[0102] In one embodiment, when the processor executes the computer program, the processor further implements the following steps:

[0103] S110: Splitting the source code according to preset rules to obtain multiple tokens;

[0104] S120: Cut each token of the source code into a list to form a token list.

[0105] In one embodiment, when the processor executes the computer program, the processor further implements the following steps:

[0106] Remove content from the source code that does not affect the semantics of the code;

[0107] The source code is cut line by line to remove the content that does not affect the semantics of the code, and each line of code is converted into the corresponding token.

[0108] In one embodiment, when the processor executes the computer program, the processor further implements the following steps:

[0109] The analysis engine is used to compare the token file through forward and reverse tracing to determine that the external access interface corresponding to the token file that receives external input parameters is the input interface of the source code.

[0110] In one embodiment, when the processor executes the computer program, the processor further implements the following steps:

[0111] S700: Generate and send a vulnerability test report based on the logical relationship between the network address path corresponding to the vulnerability after the source code is compiled by the system and the vulnerability position in the source code.

[0112] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the following steps are implemented:

[0113] S100: Obtain the source code to be detected, and cut the source code according to preset rules to obtain a token file. The preset rules can be custom source code cutting rules, such as line-by-line cutting or cutting with carriage return symbols. In one embodiment, the line-by-line cutting rule can be selected to cut the source code.

[0114] S200: Utilize an analysis engine to track the token file to determine the input interface of the source code.

[0115] S300: Find vulnerabilities in the variable transfer process by tracing variables associated with the input interface of the source code in both forward and reverse directions;

[0116] S500: Perform semantic analysis and grammatical analysis on the source code to obtain a corresponding syntax tree;

[0117] S600: Traversing the syntax tree and combining forward and backward tracing of variables associated with the input interface of each code to find vulnerabilities in the variable transfer process, determine the logical relationship between the network address path corresponding to the vulnerability after the source code is compiled by the system and the vulnerability location in the source code.

[0118] Those skilled in the art will appreciate that all or part of the processes in the above-mentioned embodiment methods can be implemented by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to memory, storage, database or other media used in the embodiments provided in this application may include at least one of non-volatile and volatile memory. Non-volatile memory may include read-only memory (ROM), magnetic tape, floppy disk, flash memory or optical memory, etc. Volatile memory may include random access memory (RAM) or external cache memory. As an illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM).

[0119] The technical features of the above embodiments can be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0120] The above-described embodiments merely represent several implementation methods of the present application. While the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the present invention. It should be noted that a person skilled in the art could make various modifications and improvements without departing from the spirit of the present application, all of which fall within the scope of protection of the present application. Therefore, the scope of protection of the present patent application shall be determined by the appended claims.

Claims

1. A vulnerability testing method, characterized in that: The method comprises: Obtain the source code to be detected, and cut the source code into token files according to preset rules; Tracking the token file using an analysis engine to determine an input interface of the source code; By forward and reverse tracing the variables associated with the input interface of the source code, a backtracking check of the variable tracing process is performed to find loopholes in the variable transfer process; Performing semantic analysis and grammatical analysis on the source code to obtain a corresponding syntax tree; Traversing the syntax tree and combining forward and reverse tracing of variables associated with input interfaces of each code to find vulnerabilities in the variable transfer process, determining a logical relationship between a network address path corresponding to the vulnerability after the source code is compiled by the system and a location of the vulnerability in the source code; The token file is a token list. The steps of obtaining the source code to be detected and cutting the source code according to preset rules to obtain the token file include: Cutting the source code according to preset rules to obtain multiple tokens; Cutting each of the tokens of the source code into a list to form the token list; The step of obtaining a plurality of tokens by cutting the source code according to a preset rule comprises: Remove the content in the source code that does not affect the semantics of the code; The source code is cut line by line to remove the content that does not affect the semantics of the code, and each line of code is converted into the corresponding token.

2. The method according to claim 1, characterized in that The step of performing a backtracking check of the variable tracking process by forward and reverse tracing the variables associated with the input interface of the source code to find vulnerabilities in the variable transfer process includes: Track the variables associated with the input interface forward and backward, and determine the vulnerabilities in the variable transmission process by checking whether there are code logic vulnerabilities in the variable transmission process, and / or checking whether the variable is passed to a high-risk function, and / or checking the parameters of a sensitive function.

3. The method according to claim 1, characterized in that The step of using an analysis engine to track the token file to determine the input interface of the source code includes: The analysis engine is used to compare the token file through forward and reverse tracing to determine that the external access interface corresponding to the token file for receiving external input parameters is the input interface of the source code.

4. The method according to any one of claims 1 to 3, characterized in that Also includes: A vulnerability test report is generated and sent according to the logical relationship between the network address path corresponding to the vulnerability after the source code is compiled by the system and the vulnerability position in the source code.

5. A vulnerability testing device, characterized in that: The device comprises: A token file acquisition module is used to obtain the source code to be detected and cut the source code into token files according to preset rules; a source code input interface determination module, configured to track the token file using an analysis engine to determine the input interface of the source code; A vulnerability search module is used to perform a backtracking check of the variable tracking process by tracing the variables associated with the input interface of the source code in a forward and reverse manner, and to find vulnerabilities in the variable transmission process; A syntax tree acquisition module is used to perform semantic analysis and syntax analysis on the source code to obtain a corresponding syntax tree; a vulnerability path and location relationship determination module, configured to traverse the syntax tree and, in combination with forward and reverse tracing of variables associated with input interfaces of each code, find vulnerabilities in the variable transfer process, and determine a logical relationship between a network address path corresponding to the vulnerability after the source code is compiled by the system and the vulnerability location in the source code; The token file is a token list. The steps of obtaining the source code to be detected and cutting the source code according to preset rules to obtain the token file include: Cutting the source code according to preset rules to obtain multiple tokens; Cutting each of the tokens of the source code into a list to form the token list; The step of obtaining a plurality of tokens by cutting the source code according to a preset rule comprises: Remove the content in the source code that does not affect the semantics of the code; The source code is cut line by line to remove the content that does not affect the semantics of the code, and each line of code is converted into the corresponding token.

6. The device according to claim 5, characterized in that The vulnerability search module includes: A backtracking query unit is used to track the variables associated with the input interface in forward and reverse directions, and to determine the vulnerabilities in the variable transmission process by checking whether there are code logic vulnerabilities in the variable transmission process, and / or checking whether the variable is passed to a high-risk function, and / or checking the parameters of a sensitive function.

7. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the vulnerability testing method according to any one of claims 1 to 4 are implemented.

8. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the vulnerability testing method according to any one of claims 1 to 4 are implemented.

Citation Information

Patent Citations

  • Method and device for detecting security flaws of source files

    CN102955914A

  • Detecting method and device for vulnerabilities

    CN104462981A