A vulnerability retest method, terminal, electronic device and storage medium
By storing the system state and test command sequence before the vulnerability occurred in the terminal, the system state is restored and targeted retesting is performed, which solves the problem of low vulnerability retesting efficiency in the existing technology and achieves efficient and accurate vulnerability repair confirmation.
Patent Information
- Application Number
- CN202111406242.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-11-24
- Publication Date
- 2025-12-12
- Estimated Expiration
- 2041-11-24
AI Technical Summary
Existing technologies have low efficiency in retesting vulnerabilities, especially in mobile operating systems, where a large number of terminals need to be used repeatedly for random testing to discover and confirm the status of vulnerability fixes.
By pre-storing the system state and test command sequence before the vulnerability occurred in the terminal, the system state is restored to the state closest to the moment the vulnerability occurred, and some test command sequences are used for targeted retesting, thereby improving the efficiency and accuracy of retesting.
It improves the efficiency and accuracy of vulnerability retesting, reduces the number of repeated tests and the amount of terminal devices used, and speeds up the confirmation of vulnerability remediation.
Smart Images

Figure CN114064502B_ABST
Abstract
Description
[0001] Embodiments of the present application relate to the technical field of testing, and in particular, to a vulnerability retest method, a terminal, an electronic device, and a storage medium.
[0002] Currently, an automatic testing tool is usually used to test possible vulnerabilities in a mobile operating system, for example, a Monkey testing tool is used to automatically test an Android system. Since the test instructions used in the Monkey testing process are random, in order to find some vulnerabilities in the Android system that have a small probability of occurrence, a large number of terminals each running the Monkey testing tool are usually used for testing. If a vulnerability occurs, the testing process stops, and a developer fixes the vulnerability. In order to determine whether the vulnerability is successfully fixed, the prior art often repeats the above testing process to retest the vulnerability, resulting in low retest efficiency.
[0003] Embodiments of the present application provide a vulnerability retest method, a terminal, an electronic device, and a storage medium, which can improve the testing efficiency when retesting a vulnerability after debugging in the prior art.
[0004] In a first aspect, embodiments of the present application provide a vulnerability retest method. The method is applied to a terminal running a preset mobile operating system. The terminal pre-stores system states S i at each preset time T i before a vulnerability occurs in a pre-test process of the preset mobile operating system and all test instruction sequences used. The system state is used to indicate a foreground application, at least one background application, and a corresponding start order of the terminal at each preset time Ti, i is a positive integer not less than 1, and n is a positive integer. The method comprises the following steps.
[0005] When a retest instruction for the vulnerability in the preset mobile operating system in the terminal after debugging is detected, the terminal queries a first target system state S n corresponding to the preset time T n before the vulnerability occurs in the pre-test process, and controls the preset mobile operating system to be in the first target system state S n .
[0006] The terminal retests the vulnerability by using a first target test instruction sequence in the all test instruction sequences after the preset time T n .
[0007] In the embodiments of the present application, the terminal stores the system state S i of each preset time T i before a vulnerability appears in a pre-test process and all test instruction sequences used, when it is necessary to retest the debugged vulnerability in the terminal, the terminal can restore its system state to the first target system state S n corresponding to the preset time T n , that is, the terminal restores its system state to the system state closest to the time before the vulnerability appears, and then uses the part of the test sequence after the preset time T n in the above-mentioned all test instruction sequences to retest the vulnerability, so as to determine whether the vulnerability is repaired. In this method, the vulnerability is retested based on the system state closest to the time when the vulnerability appears and the part of the test instruction sequence in the pre-test process, so that the retest process is more targeted, thereby improving the retest efficiency.
[0008] Optionally, if no exception occurs when the vulnerability is retested based on the first target test instruction sequence, the method further includes:
[0009] The terminal queries the second target system state S n-m corresponding to the preset time T n-m before the vulnerability appears in the pre-test process, and controls the preset mobile operating system to be in the second target system state S n-m , m is a positive integer not less than 1 and not greater than n-1;
[0010] The terminal retests the vulnerability using the second target test instruction sequence after the preset time T n-m in the all test instruction sequences, wherein the second target test instruction sequence includes the first target test instruction sequence.
[0011] In the embodiments of the present application, when no exception occurs when the vulnerability is retested based on the first target test instruction sequence, the terminal can restore its system state to the second target system state S n-m corresponding to the preset time T n-m before the vulnerability appears, and retest the vulnerability based on the second target test instruction sequence after the preset time T n-m in the all test instruction sequences, thereby improving the accuracy of retest.
[0012] Optionally, before detecting the retest instruction for the debugged vulnerability in the preset mobile operating system in the terminal, the method further includes:
[0013] When a preliminary test command is detected targeting the preset mobile operating system in the terminal, the terminal performs the preliminary test on the preset mobile operating system based on the automated testing tool of the preset mobile operating system it is running, and saves the preset time points T before the vulnerability appears during the preliminary test. i The corresponding system state S of the preset mobile operating system i And all the test instructions used.
[0014] In this embodiment of the application, when the terminal performs a pre-testing process based on automated testing tools, it can save the preset time T of its own system before the vulnerability appears during the pre-testing process. i The corresponding system state S i And all the test instruction sequences used, so that targeted retesting can be carried out later.
[0015] Optionally, save the preset time points T before the vulnerability occurs during the pre-testing process. i The corresponding preset mobile operating system S i The system status includes:
[0016] The terminal stores data at various preset times T before the vulnerability occurs during the pre-testing process. i The at least one active window and its corresponding arrangement order are used. Different active windows are used to represent the display interface of the application that is currently in the startup state, and the arrangement order of different active windows is used to represent the startup order of the applications that are currently in the startup state.
[0017] In this embodiment, different active windows can represent the interfaces corresponding to applications in the startup state, and the arrangement order of different active windows can represent the startup order of various applications in the startup state. Therefore, the terminal can save each preset time T. i At least one active window and its corresponding arrangement order are used to record each preset time T. i The corresponding system state S i .
[0018] Optionally, the terminal queries a preset time T before the vulnerability occurs during the pre-testing process. n The corresponding first target system state S n And control the preset mobile operating system to be in the first target system state S. n include:
[0019] The terminal queries the preset time T before the vulnerability occurs during the pre-test process. ncorresponding at least one target activity window and corresponding arrangement order;
[0020] The terminal displays the preset time T n corresponding foreground application and background application.
[0021] In the embodiment, the terminal can query the preset time T n corresponding at least one target activity window and corresponding arrangement order, and then display the preset time T n corresponding foreground application and background application, so that the system state of the terminal can be conveniently restored to the first target system state S n .
[0022] In a second aspect, the embodiment provides a terminal, wherein the terminal runs a preset mobile operating system, and the terminal pre-stores system states S i of the preset mobile operating system at each preset time T i before a vulnerability appears in a pre-test process and all test instruction sequences used, the system state is used to indicate a foreground application, at least one background application and corresponding start order started by the terminal at each preset time T i i is a positive integer not less than 1, and n is a positive integer, and the terminal comprises:
[0023] A processing unit, when detecting a retest instruction for the vulnerability in the preset mobile operating system in the terminal, is configured to query a first target system state S n corresponding to the preset time T n before the vulnerability appears in the pre-test process, and control the preset mobile operating system to be in the first target system state S n .
[0024] A retest unit, configured to retest the vulnerability by using a first target test instruction sequence after the preset time T n in the all test instruction sequences.
[0025] Optionally, if no exception occurs when the vulnerability is retested based on the first target test instruction sequence, the processing unit is further configured to:
[0026] query a second target system state S n-m corresponding to the preset time T n-mand control the preset mobile operating system to be in the second target system state S n-m m is a positive integer not less than 1 and not greater than n-1;
[0027] The retest unit is further configured to:
[0028] The retest unit is further configured to: n-m The retest unit is further configured to:
[0029] Optionally, the terminal further comprises:
[0030] The retest unit is further configured to: i The retest unit is further configured to: i The retest unit is further configured to:
[0031] Optionally, the retest unit comprises:
[0032] The retest unit is further configured to:
[0033] Optionally, the processing unit is specifically configured to:
[0034] The retest unit is further configured to: n The retest unit is further configured to:
[0035] The retest unit is further configured to: n The retest unit is further configured to:
[0036] In a third aspect, an electronic device is provided, the terminal comprising a processor and a memory, the processor being configured to implement the steps of the method according to any of the embodiments of the first aspect when executing a computer program stored in the memory.
[0037] In a fourth aspect, an embodiment of the present application provides a computer readable storage medium, which stores a computer program, and the computer program is executed by a processor to implement the steps of the method according to any one of the embodiments of the first aspect.
[0038] It should be understood that the second to fourth aspects of the embodiments of the present application are consistent with the technical solution of the first aspect of the embodiments of the present application, and the beneficial effects obtained by each aspect and the corresponding feasible implementation manner are similar, which will not be described again. BRIEF DESCRIPTION OF DRAWINGS
[0039] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings needed in the embodiments will be briefly introduced as follows. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor.
[0040] Figure 1 A flowchart of a vulnerability retest method provided by an embodiment of the present application;
[0041] Figure 2 A schematic diagram of the system state corresponding to each preset time and the test instruction sequence used between each preset time pre-stored by an embodiment of the present application;
[0042] Figure 3 A structural schematic diagram of a terminal provided by an embodiment of the present application;
[0043] Figure 4 A structural schematic diagram of an electronic device provided by an embodiment of the present application. DETAILED DESCRIPTION
[0044] In order to better understand the technical solutions of the present application, the embodiments of the present application will be described in detail below with reference to the drawings.
[0045] It should be clear that the described embodiments are only some embodiments of the present application, not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor are within the scope of protection of the present application.
[0046] The terms used in the embodiments of the present application are only for the purpose of describing the specific embodiments, and are not intended to limit the present application. The singular forms "a", "an" and "the" used in the embodiments of the present application and the appended claims are also intended to include the plural forms, unless the context clearly indicates otherwise.
[0047] The inventors of the present application have found that after a mobile operating system is developed, the mobile operating system running on a terminal can be tested for vulnerabilities based on an automated testing tool. For example, the Monkey testing tool can be used to automatically test an Android system for vulnerabilities. Since the sequence of test instructions used in the Monkey testing process is random, in order to find some vulnerabilities in the Android system that have a small probability of occurrence, it is often necessary to use hundreds of terminal devices to test the same version of the mobile operating system. When the above version of the mobile operating system is detected to have a vulnerability, the developer will debug the detected vulnerability. In order to confirm that the vulnerability has been modified, the above testing process needs to be repeated to retest the vulnerability, i.e., using the random test instruction sequence generated by the Monkey testing tool to retest the mobile operating system running on the hundreds of terminal devices.
[0048] As can be seen from the above, when the vulnerability is debugged by the developer and the repair of the vulnerability needs to be retested, the retesting efficiency is low.
[0049] In view of this, the embodiments of the present application provide a retesting method for a vulnerability. In the method, the vulnerability is retested based on the system state that has appeared in the pre-testing process and is closest to the time when the vulnerability appears and part of the test instruction sequence, so that the retesting process is more targeted, thereby improving the retesting efficiency.
[0050] The technical solutions provided by the embodiments of the present application will be described below with reference to the accompanying drawings. Please refer to Figure 1 The embodiments of the present application provide a retesting method for a vulnerability. The method is applied to a terminal, which can be a smart phone, a tablet computer, a desktop computer, or a smart wearable device, etc. The type of the terminal is not particularly limited here. The terminal runs a preset mobile operating system, such as an Android system or an IOS system. The type of the mobile operating system running on the terminal is not particularly limited here. The flow of the method is described as follows:
[0051] Step 101: When a retesting instruction for a vulnerability in the preset mobile operating system in the terminal that has been debugged is detected, the terminal queries a first target system state S n corresponding to a preset time T n before the vulnerability appears in the pre-testing process, and controls the preset mobile operating system to be in the first target system state S n .
[0052] Taking a random automated test based on a Monkey test tool as an example, a working mechanism thereof is to send a pseudo-random user event stream (such as a key input, a touch screen input, a gesture input, etc.) to a mobile operating system, so as to implement stress testing on an application being developed. Here, the object to be tested can be an operating system or a certain software or certain software, which is not particularly limited here.
[0053] Since the test instruction sequence output by the Monkey test tool is random, it means that the test instruction sequence used and the system state of the mobile operating system in the terminal are not the same for different test processes of the same terminal. It should be understood that the current system state of the mobile operating system can be considered as the foreground application started at the current time, at least one background application and the corresponding start order.
[0054] Therefore, in the embodiment of the present application, for the vulnerability appearing in the pre-test process, after the developer debugs the vulnerability, in order to quickly confirm whether the vulnerability has been successfully repaired by the developer, the test instruction sequence used and triggering the vulnerability appearing in the pre-test process can be used to retest the vulnerability. Before that, the system state of the mobile operating system in the terminal needs to be restored to the system state at a certain time before the vulnerability appears.
[0055] As a possible implementation, the terminal can pre-store the system state S i and all test instruction sequences used at each preset time T i before the vulnerability appears in the pre-test process of the preset mobile operating system. Here, i is a positive integer less than or equal to n and not less than 1, and n is a positive integer. For example, referring to Figure 2 , the terminal pre-stores the system state S1-S6 at the preset time T1-T6 before the vulnerability appears and all test instruction sequences (test instruction sequences 1-6) used.
[0056] The terminal can detect whether there is a retest instruction for the preset mobile operating system, for example, the terminal can establish a communication connection with another terminal in the developer mode, and the other terminal has a driver that can manage the terminal, and then the other terminal sends the retest instruction to the terminal. Of course, the retest instruction can also be sent to the terminal in other ways, which is not particularly limited here.
[0057] When detecting the retest instruction for the vulnerability in the preset mobile operating system in the terminal after debugging, the terminal can query the first target system state S n corresponding to the preset time T n before the vulnerability appears in the pre-test process. Here, the first target system state S nThe system state closest to the time before the vulnerability occurs can be considered as the system state pre-stored in the terminal. The terminal queries the first target system state S n Afterwards, the terminal can control the preset mobile system running in the terminal to be in the first target system state S n , i.e., the preset mobile operating system running in the terminal is restored to the system state closest to the time before the vulnerability occurs.
[0058] For example, please continue to refer to Figure 2 When the terminal detects the retest instruction, the terminal can query the first target system state S6 closest to the time when the vulnerability occurs from the pre-stored system states S1-S6 corresponding to the preset time T1-T6 before the vulnerability occurs, and control the preset mobile operating system in the terminal to be in the first target system state S6.
[0059] The following will describe in detail how to pre-test the preset mobile operating system running in the terminal.
[0060] In the embodiment of the application, when the preliminary test instruction for the preset mobile operating system in the terminal is detected, the terminal pre-tests the preset mobile operating system based on the pre-installed automated test tool. The automated test tool can be the one provided by the preset mobile operating system or a third-party test tool, which is not particularly limited here. In the above pre-test process, a plurality of preset times T i are set, and at each preset time T i , the terminal saves the current system state S i and the test instruction sequence used in the above process, until the preset mobile operating system has a vulnerability, and the pre-test process is automatically stopped.
[0061] For example, please continue to refer to Figure 2 In the pre-test process, the system state S1 corresponding to the time T1 can be considered as the initial system state of the preset mobile operating system, and on the basis of the system state S1, the system state S2 is obtained at the preset time T2 by applying the test instruction sequence 1; on the basis of the system state S2, the system state S3 is obtained at the preset time T3 by applying the test instruction sequence 2; on the basis of the system state S3, the system state S4 is obtained at the preset time T4 by applying the test instruction sequence 3; on the basis of the system state S4, the system state S5 is obtained at the preset time T5 by applying the test instruction sequence 4; on the basis of the system state S5, the system state S6 is obtained at the preset time T6 by applying the test instruction sequence 5; and on the basis of the system state S6, the test instruction sequence 6 is applied, and a vulnerability occurs, and the pre-test process is stopped.
[0062] In the pre-test process, the terminal can save the system states S1-S6 corresponding to the preset time T1-T6 respectively, and the test instruction sequences 1-6.
[0063] In some embodiments, considering that the terminal is in different system states S i , the corresponding display interfaces of different applications or different display interfaces of the same application are displayed, and different display interfaces actually correspond to different Activity windows, i.e., when a certain Activity window is invoked, it indicates that the content in the Activity window is about to be displayed or has been displayed. Therefore, in the embodiments of the present application, the use traces of different Activity windows can be saved to indirectly save the system states S i corresponding to the preset time T i .
[0064] As a possible implementation, the terminal can save at least one Activity window used at each preset time T i before the vulnerability occurs in the pre-test process and the corresponding arrangement order. It should be understood that different Activity windows correspond to the display interfaces of applications in the startup state, and the arrangement order between different Activity windows represents the startup order between the applications in the startup state or the startup order of different display interfaces of the same application.
[0065] For example, continuing to refer to Figure 2 , for the preset time T1-T6 before the vulnerability occurs, the terminal can save at least one Activity window used at each preset time and the corresponding arrangement order. Taking the preset time T6 as an example, when the terminal is in the preset time T6, the application in the foreground in the preset mobile operating system is Douyin (Douyin is currently the foreground application, but in terms of startup order, Douyin can be considered to be the last to be started), the applications in the background are WeChat and Gaode Map (WeChat and Gaode Map are currently background applications, but in terms of startup order, WeChat and Gaode Map can be considered to be started before Douyin), and WeChat is started before Gaode Map. Therefore, the terminal can save the Activity windows corresponding to Douyin, WeChat, and Gaode Map respectively, and the arrangement order between the above three Activity windows, i.e., the Activity window of WeChat is arranged in the front, followed by the Activity window of Gaode Map, and finally the Activity window of Douyin.
[0066] The following describes in detail how the terminal controls the preset mobile operating system of the terminal to be in the first target system state S n .
[0067] In the pre-test process, the terminal saves the preset time T ncorresponding at least one target activity window and the corresponding arrangement order, so that when it is needed to restore the preset mobile operating system in the terminal to the first target system state S n , the terminal can query the corresponding at least one target activity window and the corresponding arrangement order at the preset time T n , and then based on the at least one target activity window and the corresponding arrangement order, display the corresponding foreground application and background application at the preset time T n , that is, restore to the first target system state S n .
[0068] Please continue to see Figure 2 , if at the preset time T6 in the pre-test process, the terminal saves the activity window corresponding to Douyin, WeChat and Gaode map respectively, and the arrangement order between the above three activity windows, that is, the activity window of WeChat is arranged in the front, followed by the activity window of Gaode map, and finally the activity window of Douyin, then before the preset mobile system in the terminal is needed to be retested, the system state of the preset mobile operating system in the terminal can be restored to the first target system state S6 based on the activity window corresponding to Douyin, WeChat and Gaode map respectively, and the arrangement order between the above three activity windows. That is, when the terminal is in the first target system state S6, Douyin is the foreground application, WeChat and Gaode map are the background applications, and WeChat is started before Gaode map.
[0069] Step 102: The terminal uses the first target test instruction sequence after the preset time T n in the whole test instruction sequence to retest the vulnerability.
[0070] In the embodiment of the application, when the preset mobile operating system in the terminal is in the first target state, the used test instruction sequence can be used for targeted retesting, thereby improving the retesting efficiency.
[0071] As a possible implementation, when the preset mobile operating system in the terminal is in the first target system state S n , the terminal can use the first target test instruction sequence after the preset time T n in the whole test instruction sequence to retest the vulnerability.
[0072] Please continue to see Figure 2 , when the preset mobile operating system in the terminal is in the first target system state S6, the terminal can use the first target test instruction sequence (i.e. test instruction sequence 6) to retest the vulnerability.
[0073] In some embodiments, considering that the preset mobile operating system in the terminal has a vulnerability at a certain time, the vulnerability is not only related to the system state closest to the vulnerability and the test instruction sequence, but also related to the system states at multiple preset times before the vulnerability and the test instruction sequences used. Therefore, in the embodiments of the present application, in order to more accurately evaluate whether the vulnerability successfully repaired by the developer, the preset mobile operating system in the terminal can be restored to a system state at a time interval further away from the vulnerability, and more test instruction sequences used can be used for retesting.
[0074] As a possible implementation, when the terminal determines that no exception occurs in retesting the vulnerability based on the first target test sequence, the terminal can also query the system state S n-m corresponding to the preset time T n-m before the vulnerability in the previous test process. It should be understood that here m is a positive integer not less than 1 and not greater than n-1. Then, the terminal can control the preset mobile operating system to be in the second target system state, and how to control the preset mobile operating system to be in the second target system state can refer to the specific scheme of restoring the preset mobile operating system to the first target system state in the above, which will not be described here.
[0075] After the terminal restores the preset mobile operating system in the terminal to the second target system state S n-m corresponding to the preset time T n-m after the vulnerability, the terminal can retest the vulnerability using the second target test instruction sequence in the entire test instruction sequence after the preset time T n-m . It should be understood that the second target test instruction sequence includes the first target test instruction sequence.
[0076] For example, please continue to refer to Figure 2When the terminal determines that no exception occurs in the retest of the vulnerability based on the first target test sequence (test instruction sequence 6), the terminal can restore the preset mobile operating system thereof to the second target system state S5 corresponding to the preset time T5, and then perform retest by using the second target test sequence (test instruction sequence 5 and test instruction sequence 6); by analogy, the terminal can restore the preset mobile operating system thereof to the second target system state S4 corresponding to the preset time T4, and then perform retest by using the second target test sequence (test instruction sequence 4, test instruction sequence 5 and test instruction sequence 6); the terminal can restore the preset mobile operating system thereof to the second target system state S3 corresponding to the preset time T3, and then perform retest by using the second target test sequence (test instruction sequence 3, test instruction sequence 4, test instruction sequence 5 and test instruction sequence 6); the terminal can restore the preset mobile operating system thereof to the second target system state S2 corresponding to the preset time T2, and then perform retest by using the second target test sequence (test instruction sequence 2, test instruction sequence 3, test instruction sequence 4, test instruction sequence 5 and test instruction sequence 6); the terminal can restore the preset mobile operating system thereof to the second target system state S1 corresponding to the preset time T1, and then perform retest by using the second target test sequence (test instruction sequence 1, test instruction sequence 2, test instruction sequence 3, test instruction sequence 4, test instruction sequence 5 and test instruction sequence 6). It should be understood that when the vulnerability occurs again in any of the above retest processes, the retest process stops.
[0077] Please refer to Figure 3 , based on the same inventive concept, the embodiment of the present application provides a terminal, the terminal runs a preset mobile operating system, and the terminal pre-stores system states S i of each preset time T i before the occurrence of a vulnerability in a preset mobile operating system pre-test process and all test instruction sequences used, the system state is used to indicate a foreground application, at least one background application and a corresponding start order started by the terminal at each preset time T i , i is a positive integer not less than 1, n is a positive integer, the terminal comprises a processing unit 201 and a retest unit 202.
[0078] The processing unit 201, when detecting a retest instruction for a debugged vulnerability in the preset mobile operating system in the terminal, is used to query a first target system state S n corresponding to a preset time T n before the occurrence of a vulnerability in a preset test process, and control the preset mobile operating system to be in the first target system state S n .
[0079] The retest unit 202 is configured to retest the vulnerability by using a second target test instruction sequence after the preset time T n The first target test instruction sequence is used to retest the vulnerability.
[0080] Optionally, if no exception occurs when the first target test instruction sequence is used to retest the vulnerability, the processing unit 201 is further configured to:
[0081] query the at least one target active window and the corresponding arrangement order corresponding to the preset time T n-m corresponding to the second target system state S n-m and control the preset mobile operating system to be in the second target system state S n-m m is a positive integer not less than 1 and not greater than n-1;
[0082] The retest unit 202 is further configured to:
[0083] retest the vulnerability by using a second target test instruction sequence after the preset time T n-m The second target test instruction sequence includes the first target test instruction sequence.
[0084] Optionally, the terminal further includes:
[0085] The preliminary test unit is configured to perform preliminary testing on the preset mobile operating system based on the pre-installed automated testing tool when a preliminary test instruction for the preset mobile operating system in the terminal is detected, and save the system state S i of the preset mobile operating system corresponding to each preset time T i before the vulnerability occurs in the preliminary testing process and all test instructions used.
[0086] Optionally, the preliminary test unit includes:
[0087] The saving subunit is configured to save at least one active window used and the corresponding arrangement order at each preset time T n before the vulnerability occurs in the preliminary testing process, different active windows are used to represent the display interface corresponding to the application currently in the startup state, and the arrangement order between different active windows is used to represent the startup order between the applications currently in the startup state.
[0088] Optionally, the processing unit 201 is specifically configured to:
[0089] query the at least one target active window and the corresponding arrangement order corresponding to the preset time T n before the vulnerability occurs in the preliminary testing process;
[0090] display the preset time T nThe corresponding front-end and back-end applications.
[0091] Please see Figure 4 Based on the same inventive concept, embodiments of this application also provide an electronic device 100, which may include at least one processor for executing a computer program stored in a memory to implement the functions provided in embodiments of this application. Figure 1 The steps of the vulnerability retesting method shown are as follows.
[0092] Optionally, the processor mentioned above may be a central processing unit, a specific ASIC, or one or more integrated circuits used to control program execution.
[0093] Optionally, the electronic device 100 may further include a memory connected to at least one processor. The memory may include ROM, RAM, and disk storage. The memory stores data required for processor operation, i.e., it stores instructions executable by at least one processor. The at least one processor executes instructions stored in the memory to perform tasks such as... Figure 1 The method is shown. The number of memories can be one or more.
[0094] The physical devices corresponding to both the processing unit 201 and the retesting unit 202 can be the aforementioned processors. This electronic device can be used to execute... Figure 1 The method provided in the illustrated embodiment. Therefore, regarding the functions that each functional module in this electronic device can achieve, please refer to... Figure 1 The corresponding descriptions in the illustrated embodiments will not be repeated here.
[0095] The aforementioned electronic device 100 can be a smart electronic device such as a smartphone or tablet computer. This embodiment does not limit the form of the aforementioned electronic device.
[0096] Instance-like, Figure 4 A schematic diagram of the structure of electronic device 100 is shown, taking a smartphone as an example. Figure 4As shown, the electronic device 100 can include a processor 110, an external memory interface 120, an internal memory 121, a universal serial bus (USB) interface 130, a charging management module 140, a power management module 141, a battery 142, an antenna 1, an antenna 2, a mobile communication module 150, a wireless communication module 160, an audio module 170, a speaker 170A, a receiver 170B, a microphone 170C, a headset jack 170D, a sensor module 180, a key 190, a motor 191, an indicator 192, a camera 193, a display screen 194, and a subscriber identification module (SIM) card interface 195, etc.
[0097] It can be understood that the structure shown in the embodiments of the present application does not constitute a specific limitation on the electronic device 100. In other embodiments of the present application, the electronic device 100 can include more or fewer components than shown, or combine certain components, or split certain components, or different arrangement of components. The components shown can be implemented in hardware, software, or a combination of software and hardware.
[0098] The processor 110 can include one or more processing units, for example: the processor 110 can include an application processor (AP), a modem processor, a graphics processing unit (GPU), an image signal processor (ISP), a controller, a video codec, a digital signal processor (DSP), a baseband processor, and / or a neural-network processing unit (NPU), etc. Among them, different processing units can be independent devices, or can be integrated in one or more processors.
[0099] The controller can generate operation control signals according to instruction operation codes and timing signals, and complete the control of fetching instructions and executing instructions.
[0100] The memory in the processor 110 can also be provided for storing instructions and data. In some embodiments, the memory in the processor 110 is a cache memory. The memory can save instructions or data that the processor 110 has just used or repeatedly uses. If the processor 110 needs to use the instructions or data again, it can be directly called from the memory. Avoiding repeated access, reducing the waiting time of the processor 110, thus improving the efficiency of the system.
[0101] In some embodiments, the processor 110 can include one or more interfaces. The interfaces can include an inter-integrated circuit (I2C) interface, an inter-integrated circuit sound (I2S) interface, a pulse code modulation (PCM) interface, a universal asynchronous receiver / transmitter (UART) interface, a mobile industry processor interface (MIPI), a general-purpose input / output (GPIO) interface, a subscriber identity module (SIM) interface, and / or a universal serial bus (USB) interface, among others.
[0102] The charging management module 140 is configured to receive charging input from a charger.
[0103] The power management module 141 is configured to connect the battery 142 with the processor 110 and the charging management module 140.
[0104] In some embodiments, the antenna 1 and the mobile communication module 150 of the electronic device 100 are coupled, and the antenna 2 and the wireless communication module 160 are coupled, so that the electronic device 100 can communicate with a network and other devices through wireless communication technology. The wireless communication technology can include global system for mobile communications (GSM), general packet radio service (GPRS), code division multiple access (CDMA), wideband code division multiple access (WCDMA), time-division code division multiple access (TD-SCDMA), long term evolution (LTE), BT, GNSS, WLAN, NFC, FM, and / or IR technology, etc. The GNSS can include a global positioning system (GPS), a global navigation satellite system (GLONASS), a beidu navigation satellite system (BDS), a quasi-zenith satellite system (QZSS), and / or a satellite based augmentation systems (SBAS).
[0105] The electronic device 100 implements a display function through a GPU, a display screen 194, an application processor, etc.
[0106] The display screen 194 is configured to display images, videos, etc. The display screen 194 includes a display panel.
[0107] The ISP is configured to process data fed back by the camera 193.
[0108] The camera 193 is configured to capture still images or videos.
[0109] The digital signal processor is configured to process digital signals, which can include processing digital image signals, and processing other digital signals. For example, when the electronic device 100 selects a frequency point, the digital signal processor is configured to perform Fourier transform on frequency point energy, etc.
[0110] A video codec is used to compress or decompress digital video. The electronic device 100 can support one or more video codecs. In this way, the electronic device 100 can play or record video in multiple encoding formats, such as moving picture experts group (MPEG) 1, MPEG 2, MPEG 3, MPEG 4, and so on.
[0111] The external memory interface 120 can be used to connect an external memory card, such as a Micro SD card, to extend the storage capacity of the electronic device 100. The external memory card communicates with the processor 110 through the external memory interface 120 to implement a data storage function. For example, files such as music, video, and so on are saved in the external memory card.
[0112] The internal memory 121 can be used to store computer executable program code, which includes instructions. The internal memory 121 can include a program storage area and a data storage area. The program storage area can store an operating system, at least one application required for a function (such as a sound playing function, an image playing function, and so on), and the like. The data storage area can store data created during use of the electronic device 100 (such as audio data, a phonebook, and so on), and the like. In addition, the internal memory 121 can include a high-speed random access memory, and can also include a nonvolatile memory, such as at least one magnetic disk storage device, a flash memory device, a universal flash storage (UFS), and the like. The processor 110 executes various function applications and data processing of the electronic device 100 by running instructions stored in the internal memory 121 and / or instructions stored in a memory disposed in the processor.
[0113] The electronic device 100 can implement an audio function through an audio module 170, a speaker 170A, a receiver 170B, a microphone 170C, an earphone interface 170D, an application processor, and the like. For example, music playing, recording, and the like.
[0114] The audio module 170 is used to convert digital audio information into an analog audio signal output, and is also used to convert an analog audio input into a digital audio signal.
[0115] The speaker 170A, also referred to as a “loudspeaker”, is used to convert an audio electrical signal into a sound signal.
[0116] The receiver 170B, also referred to as a “earpiece”, is used to convert an audio electrical signal into a sound signal.
[0117] The microphone 170C, also referred to as a “microphone”, “sound transducer”, is used to convert a sound signal into an electrical signal.
[0118] The earphone interface 170D is used to connect a wired earphone. The earphone interface 170D can be a USB interface 130, or a 3.5mm open mobile terminal platform (OMTP) standard interface, or a cellular telecommunications industry association of the USA (CTIA) standard interface.
[0119] The keys 190 include a power-on key, a volume key, and the like.
[0120] The motor 191 can generate a vibration prompt.
[0121] The indicator 192 can be an indicator light, which can be used to indicate a charging state, a power change, or a message, a missed call, a notification, and the like.
[0122] The SIM card interface 195 is used to connect a SIM card. In some embodiments, the electronic device 100 uses an eSIM, i.e., an embedded SIM card. The eSIM card can be embedded in the electronic device 100 and cannot be separated from the electronic device 100.
[0123] Embodiments of the present application also provide a computer storage medium, wherein the computer storage medium stores computer instructions, when the computer instructions run on a computer, the computer executes the method as Figure 1 described above.
[0124] The above only describes the preferred embodiments of the present application and is not intended to limit the present application. Any modification, equivalent replacement, improvement, and the like made within the spirit and principle of the present application shall be included in the protection scope of the present application.
Claims
1. A method for retesting vulnerabilities, characterized in that, This is applied to a terminal running a preset mobile operating system, wherein the terminal pre-stores preset time points T during the pre-testing process of the preset mobile operating system before a vulnerability occurs. i System status S i and all test instruction sequences used, the system state S i Including the terminal at the corresponding preset time T i At least one active window and its corresponding arrangement order are used, with different active windows representing the preset time T. i The display interface corresponding to the application in the current running state, and the arrangement order of different active windows are used to represent the preset time T. i The startup order among applications currently in the startup state, where i is less than or equal to n, i is a positive integer not less than 1, and n is a positive integer, the method includes: When a retest instruction is detected targeting the debugged vulnerability in the preset mobile operating system on the terminal, the terminal queries a preset time T before the vulnerability occurred during the pre-test process. n The corresponding first target system state S n And control the preset mobile operating system to be in the first target system state S. n The first target system state S n Including according to the preset time T n The foreground and background applications launched by at least one target active window and their corresponding arrangement order; The terminal utilizes the sequence of all test commands located at the preset time T. n The subsequent first target test instruction sequence retests the vulnerability.
2. The method according to claim 1, characterized in that, If no anomalies are found when the vulnerability is retested based on the first target test instruction sequence, the method further includes: The terminal queries the preset time T before the vulnerability occurs during the pre-test process. n-m The corresponding second target system state S n-m And control the preset mobile operating system to be in the second target system state S. n-m m is a positive integer not less than 1 and not greater than n-1; The terminal utilizes the sequence of all test commands located at the preset time T. n-m The vulnerability is then retested using a second target test instruction sequence, which includes the first target test instruction sequence.
3. The method according to claim 1, characterized in that, Before detecting a retest instruction targeting a debugged vulnerability in the preset mobile operating system on the terminal, the method further includes: When a preliminary test command is detected targeting the preset mobile operating system in the terminal, the terminal performs the preliminary test on the preset mobile operating system based on a pre-installed automated testing tool, and saves the preset time points T before the vulnerability appears during the preliminary test. i The corresponding system state S of the preset mobile operating system i And all the test instructions used.
4. The method according to claim 3, characterized in that, Save each preset time T before the vulnerability occurs during the pre-testing process. i The corresponding preset mobile operating system S i The system status includes: The terminal stores data at various preset times T before the vulnerability occurs during the pre-testing process. i The at least one active window and its corresponding arrangement order are used. Different active windows are used to represent the display interface of the application that is currently in the startup state, and the arrangement order of different active windows is used to represent the startup order of the applications that are currently in the startup state.
5. The method according to claim 4, characterized in that, The terminal queries the preset time T before the vulnerability occurs during the pre-test process. n The corresponding first target system state S n And control the preset mobile operating system to be in the first target system state S. n include: The terminal queries the preset time T before the vulnerability occurs during the pre-test process. n At least one target active window and its corresponding arrangement order; The terminal displays the preset time T based on the at least one target active window and its arrangement order. n The corresponding front-end and back-end applications.
6. A terminal, characterized in that, The terminal runs a preset mobile operating system, and the terminal pre-stores preset time points T during the pre-testing process of the preset mobile operating system before a vulnerability occurs. i System status S i and all test instruction sequences used, the system state S i Including the terminal at the corresponding preset time T i At least one active window and its corresponding arrangement order are used, with different active windows representing the preset time T. i The display interface corresponding to the application in the current running state, and the arrangement order of different active windows are used to represent the preset time T. i The startup order among applications currently in the startup state, where i is less than or equal to n, i is a positive integer not less than 1, and n is a positive integer. The terminal includes: The processing unit, upon detecting a retest instruction targeting a debugged vulnerability in the preset mobile operating system on the terminal, queries a preset time T before the vulnerability appeared during the pre-testing process. n The corresponding first target system state S n And control the preset mobile operating system to be in the first target system state S. n The first target system state S n Including according to the preset time T n The foreground and background applications launched by at least one target active window and their corresponding arrangement order; The retest unit is used to utilize the test instructions located at the preset time T from the entire sequence of test instructions. n The subsequent first target test instruction sequence retests the vulnerability.
7. The terminal according to claim 6, characterized in that, If no anomalies are found when the vulnerability is retested based on the first target test instruction sequence, the processing unit is further configured to: Query the preset time T before the vulnerability occurs during the pre-test process. n-m The corresponding second target system state S n-m And control the preset mobile operating system to be in the second target system state S. n-m m is a positive integer not less than 1 and not greater than n-1; The retesting unit is also used for: Using the sequence of all test instructions located at the preset time T n-m The vulnerability is then retested using a second target test instruction sequence, which includes the first target test instruction sequence.
8. The terminal according to claim 6, characterized in that, The terminal also includes: The initial testing unit, upon detecting an initial testing instruction targeting the preset mobile operating system in the terminal, performs the preliminary test on the preset mobile operating system based on pre-installed automated testing tools, and saves the preset time points T before the vulnerability occurs during the preliminary test. i The corresponding system state S of the preset mobile operating system i And all the test instructions used.
9. The terminal according to claim 8, characterized in that, The initial measurement unit includes: The storage subunit is used to store at least one active window and its corresponding arrangement order used at each preset time Ti before the vulnerability occurs during the pre-test process. Different active windows are used to represent the display interface corresponding to the application currently in the startup state, and the arrangement order between different active windows is used to represent the startup order between the applications currently in the startup state.
10. The terminal according to claim 9, characterized in that, The processing unit is specifically used for: Query the preset time T before the vulnerability occurs during the pre-test process. n At least one target active window and its corresponding arrangement order; Based on the at least one target activity window and its arrangement order, the preset time T is displayed. n The corresponding front-end and back-end applications.
11. An electronic device, characterized in that, The electronic device includes at least one processor and a memory connected to the at least one processor, the at least one processor being configured to implement the steps of the method as described in any one of claims 1-5 when executing a computer program stored in the memory.
12. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method as described in any one of claims 1-5.
Citation Information
Patent Citations
Microcontroller application software debugging method
CN105786688A
Testing method and device of memory
CN108122596A