Security Testing Method and Device for Application, Storage Medium and Electronic Device
By receiving target instructions of target objects and obtaining instrumentation methods, the biometric function of the APP is tested for security, which solves the problem of difficulty in testing the message encryption function in the APP in the prior art, and achieves timely discovery of security vulnerabilities and improving testing efficiency.
Patent Information
- Application Number
- CN202111496574.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-08
- Publication Date
- 2025-06-03
- Estimated Expiration
- 2041-12-08
AI Technical Summary
The prior art is difficult to perform security testing on the biometric function of message encryption in APP, making it difficult for testers to discover security vulnerabilities in APP.
By receiving the target instructions of the target object, obtain the selected instrumentation method, and conduct security testing of the application's biometric function according to the instrumentation method, including instrumentation and analysis of encryption and decryption functions or authentication functions.
It realizes security testing of the biometric function of packet encryption in the APP, can promptly discover security vulnerabilities in the application, and improves the efficiency and accuracy of security testing.
Smart Images

Figure CN114238982B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of information security technology. Specifically, it relates to a security testing method and device for an application program, a storage medium, and an electronic device. Background Art
[0002] With the large-scale application and promotion of biometric authentication in the Internet market, the security performance of biometric authentication services has become the main security issue faced by APPs of various manufacturers. Among them, the face recognition authentication service is a typical representative of biometric authentication services. Since most manufacturers adopt the face recognition authentication method of front-end authentication + back-end verification, hackers and lawbreakers can bypass the back-end server verification and cause the loss of customer face information by decrypting data packets and replacing packets. In response to such risks, the traditional approach is to have security testers test and verify the business security through penetration testing before the business development is completed, and verify the security of the business server by simulating hacker attacks.
[0003] However, with the development of technology, in related technologies, some APPs use packet encryption means to protect the security of face recognition authentication information, but using such methods cannot avoid hackers and lawbreakers from identifying and tampering with the packets. Although such methods have achieved a certain degree of security protection for back-end server verification, over time and with the continuous development of encryption and decryption technologies, the limitations of such methods have gradually emerged. The specific limitations are as follows: hackers can obtain the encryption key of the face recognition parameters in the APP through reverse means; since the face recognition authentication function is also stored in the front end, hackers can bypass the front-end authentication link by tampering with the local data file and tampering with the face recognition authentication function; moreover, since the APP is encrypted during the development stage, security testers cannot test the face recognition authentication service function through traditional penetration testing means, so there will be a situation where even if there are vulnerabilities in the APP, security testers cannot discover them.
[0004] In view of the problem in related technologies that it is difficult to perform security testing on the biometric function with encrypted packets in an APP, resulting in difficulty for testers to discover security vulnerabilities in the APP, no effective solution has been proposed yet. Summary of the Invention
[0005] The main purpose of the present application is to provide a security testing method and device for an application program, a storage medium, and an electronic device, so as to solve the problem in related technologies that it is difficult to perform security testing on the biometric function with encrypted packets in an APP, resulting in difficulty for testers to discover security vulnerabilities in the APP.
[0006] To achieve the above object, according to one aspect of the present application, a security testing method for an application program is provided. The method includes: receiving a target instruction of a target object and responding to the target instruction, where the target instruction is used to indicate a security test of the biometric function of the application program; obtaining the instrumentation method selected by the target object, where the instrumentation method is one of the following: instrumenting the encryption and decryption functions of biometrics, instrumenting the authentication function of biometrics; and performing a security test on the biometric function of the application program according to the selected instrumentation method to determine the security performance of the biometric function of the application program.
[0007] Further, performing a security test on the biometric function of the application program according to the selected instrumentation method to determine the security performance of the biometric function of the application program includes: when the selected instrumentation method is to instrument the encryption and decryption functions of biometrics, obtaining a first target message based on processing of a first message; receiving first response information returned by a target server in response to the first target message, analyzing the first response information to obtain an analysis result; and determining the security performance of the biometric function of the application program based on the analysis result.
[0008] Further, when the selected instrumentation method is to instrument the encryption and decryption functions of biometrics, obtaining a first target message based on processing of a first message includes: obtaining the first message; performing decryption processing on the first message to obtain a decrypted first message; combining a test payload with the decrypted first message to generate a second message; and performing encryption processing on the second message to obtain the first target message.
[0009] Further, performing decryption processing on the first message to obtain a decrypted first message includes: performing reverse analysis on the application program through the first message to obtain first target information of a target function corresponding to the first message, where the first target information is at least one of the following: category information of the target function, call format information of the target function, and parameter format information of the target function; and inserting a target program into the application program according to the first target information to obtain the decrypted first message.
[0010] Further, receiving first response information returned by a target server in response to the first target message, analyzing the first response information to obtain an analysis result includes: parsing the first target message by the target server to obtain a first target image; comparing the first target image with an image pre-stored in the target server to obtain a comparison result; using the comparison result as the first response information, and analyzing the first response information to obtain the analysis result.
[0011] Further, according to the selected instrumentation method, perform a security test on the biometric function of the application program, and determine the security performance of the biometric function of the application program, including: when the selected instrumentation method is to instrument the authentication function of biometrics, based on processing the parameters of the authentication function, obtain a second target message; receive second response information returned by the target server in response to the second target message, analyze the second response information, and obtain an analysis result; based on the analysis result, determine the security performance of the biometric function of the application program.
[0012] Further, when the selected instrumentation method is to instrument the authentication function of biometrics, based on processing the parameters of the authentication function, obtaining a second target message includes: analyzing the authentication function to obtain second target information of the authentication function, where the second target information is at least one of the following: the parameter passing information of the authentication function and the return result information of the authentication function; according to the second target information, replace the parameters of the authentication function to obtain the replaced parameters; process the replaced parameters to obtain the second target message.
[0013] Further, receiving second response information returned by the target server in response to the second target message, analyzing the second response information, and obtaining an analysis result includes: parsing the second target message by the target server to obtain a second target image; comparing the second target image with the image pre-stored in the target server to obtain a comparison result; using the comparison result as the second response information, analyzing the second response information, and obtaining the analysis result.
[0014] Further, based on the analysis result, determining the security performance of the biometric function of the application program includes: when the analysis result indicates that the first target image or the second target image is the same as the image pre-stored in the target server, there is a security vulnerability in the biometric function of the application program; when the analysis result indicates that the first target image or the second target image is different from the image pre-stored in the target server, there is no security vulnerability in the biometric function of the application program.
[0015] To achieve the above object, according to another aspect of the present application, a security testing device for an application is provided. The device includes: a first processing unit, configured to receive a target instruction of a target object and respond to the target instruction, where the target instruction is used to indicate a security test of the biometric function of the application; a first obtaining unit, configured to obtain the instrumentation method selected by the target object, where the instrumentation method is one of the following: instrumenting the encryption and decryption functions of biometrics, instrumenting the authentication function of biometrics; a first testing unit, configured to perform a security test on the biometric function of the application according to the selected instrumentation method, and determine the security performance of the biometric function of the application.
[0016] Further, the first testing unit includes: a first processing subunit, configured to, when the selected instrumentation method is to instrument the encryption and decryption functions of biometrics, obtain a first target message based on processing of a first message; a second processing subunit, configured to receive first response information returned by the target server in response to the first target message, and analyze the first response information to obtain an analysis result; a first determining subunit, configured to determine the security performance of the biometric function of the application based on the analysis result.
[0017] Further, the first processing subunit includes: a first obtaining module, configured to obtain the first message; a first processing module, configured to perform decryption processing on the first message to obtain a decrypted first message; a first generating module, configured to combine a test payload with the decrypted first message to generate a second message; a second processing module, configured to perform encryption processing on the second message to obtain the first target message.
[0018] Further, the second processing module includes: a first processing sub-module, configured to perform reverse analysis on the application through the first message to obtain first target information of a target function corresponding to the first message, where the first target information is at least one of the following: category information of the target function, call format information of the target function, and parameter format information of the target function; a first inserting sub-module, configured to insert a target program into the application according to the first target information to obtain the decrypted first message.
[0019] Further, the second processing subunit includes: a first parsing module, configured to parse the first target message through the target server to obtain a first target image; a first comparing module, configured to compare the first target image with an image pre-stored in the target server to obtain a comparison result; a first analyzing module, configured to use the comparison result as the first response information, and analyze the first response information to obtain the analysis result.
[0020] Further, the first test unit includes: a third processing subunit, configured to, when the selected instrumentation method is to instrument the authentication function of biometric recognition, obtain a second target message based on processing the parameters of the authentication function; a fourth processing subunit, configured to receive second response information returned by the target server in response to the second target message, and analyze the second response information to obtain an analysis result; and a second determination subunit, configured to determine the security performance of the biometric recognition function of the application program based on the analysis result.
[0021] Further, the third processing subunit includes: a second analysis module, configured to analyze the authentication function to obtain second target information of the authentication function, where the second target information is at least one of the following: parameter passing information of the authentication function and return result information of the authentication function; a first replacement module, configured to replace the parameters of the authentication function according to the second target information to obtain the replaced parameters; and a third processing module, configured to process the replaced parameters to obtain the second target message.
[0022] Further, the fourth processing subunit includes: a second parsing module, configured to parse the second target message through the target server to obtain a second target image; a second comparison module, configured to compare the second target image with an image pre-stored in the target server to obtain a comparison result; and a third analysis module, configured to use the comparison result as the second response information, and analyze the second response information to obtain the analysis result.
[0023] Further, the first determination subunit or the second determination subunit includes: a fourth processing module, configured to, when the analysis result indicates that the first target image or the second target image is the same as the image pre-stored in the target server, there is a security vulnerability in the biometric recognition function of the application program; and a fifth processing module, configured to, when the analysis result indicates that the first target image or the second target image is different from the image pre-stored in the target server, there is no security vulnerability in the biometric recognition function of the application program.
[0024] To achieve the above object, according to another aspect of the present application, there is provided a computer-readable storage medium, where the storage medium includes a stored program, and the program executes the security testing method of the application program described in any one of the above.
[0025] To achieve the above object, according to another aspect of the present application, there is provided a processor, where the processor is used to run a program, and the program executes the security testing method of the application program described in any one of the above when running.
[0026] To achieve the above object, according to another aspect of the present application, there is provided an electronic device, which includes one or more processors and a memory for storing one or more programs. When the one or more programs are executed by the one or more processors, the one or more processors implement the security testing method of the application program described in any one of the above.
[0027] Through the present application, the following steps are adopted: receiving a target instruction of a target object and responding to the target instruction, where the target instruction is used to indicate a security test of the biometric function of an application program; obtaining the instrumentation method selected by the target object, where the instrumentation method is one of the following: instrumenting the encryption and decryption functions of biometrics, instrumenting the authentication functions of biometrics; and based on the selected instrumentation method, performing a security test on the biometric function of the application program to determine the security performance of the biometric function of the application program, solving the problem in the related art that it is difficult to perform a security test on the biometric function of message encryption in an APP, resulting in difficulty for testers to discover security vulnerabilities in the APP. By receiving and responding to the target instruction of the target object and performing a security test on the biometric function of the application program according to the instrumentation method selected by the target object, the security performance of the biometric function of the application program is determined, so that a security test can be performed on the biometric function of message encryption in the APP, and further achieving the effect that when there are security vulnerabilities in the APP, testers can discover them in time. Description of the Drawings
[0028] The drawings constituting a part of the present application are used to provide a further understanding of the present application. The schematic embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation to the present application. In the drawings:
[0029] Figure 1 is a flowchart of the security testing method of the application program provided by the embodiment of the present application;
[0030] Figure 2 is a schematic diagram of the security testing system of the application program provided by the embodiment of the present application;
[0031] Figure 3 is a schematic diagram of an optional security testing method of the application program provided by the embodiment of the present application;
[0032] Figure 4 is a schematic diagram of the security testing subsystem of the application program provided by the embodiment of the present application;
[0033] Figure 5 is a schematic diagram of the instrumentation subsystem of the application program provided by the embodiment of the present application;
[0034] Figure 6 is a schematic diagram of a security testing device for an application program provided according to an embodiment of the present application;
[0035] Figure 7 is a schematic diagram of an electronic device provided according to an embodiment of the present application. Detailed implementation manners
[0036] It should be noted that, without conflict, the embodiments in the present application and the features in the embodiments may be combined with each other. The present application will be described in detail below with reference to the drawings and in conjunction with the embodiments.
[0037] In order to enable those skilled in the art to better understand the solution of the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.
[0038] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above drawings are used to distinguish similar objects, and do not necessarily need to be used to describe a specific order or sequence. It should be understood that such used data can be interchanged under appropriate circumstances for the embodiments of the present application described herein. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0039] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for display, data for analysis, etc.) involved in the present disclosure are all information and data that have been authorized by the user or fully authorized by all parties.
[0040] The present invention will be described below in conjunction with preferred implementation steps. Figure 1 is a flowchart of a security testing method for an application program provided according to an embodiment of the present application. As Figure 1 shown, the method includes the following steps:
[0041] Step S1001, receiving a target instruction of a target object and responding to the target instruction, where the target instruction is used to indicate a security test for the biometric function of the application program.
[0042] For example,Figure 2 The APP testing device in Figure 2 is for business security testers and is software or a device (including but not limited to mobile phones, tablets, emulators, etc.) dedicated to accessing the background server of the APP to be tested. Before conducting security testing, security testers need to establish a security testing system as shown in
[0043] Step S1002: Obtain the instrumentation method selected by the target object, where the instrumentation method is one of the following: instrumenting the encryption and decryption functions of biometric identification, or instrumenting the authentication function of biometric identification.
[0044] Based on the instruction issued by the security tester, determine whether the instrumentation method for the security testing of the biometric identification function this time is to instrument the encryption and decryption functions of biometric identification, or to instrument the authentication function of biometric identification, or both of the above instrumentation methods exist during the security testing of the biometric identification function this time.
[0045] Step S1003: According to the selected instrumentation method, conduct security testing on the biometric identification function of the application program to determine the security performance of the biometric identification function of the application program.
[0046] After determining the instrumentation method for the security testing of the biometric identification function this time, conduct security testing on the biometric identification function of the application program according to the instrumentation method, so as to determine the security performance of the biometric identification function of the application program.
[0047] Through the above steps S1001 to S1003, by receiving and responding to the target instruction of the target object and based on the instrumentation method selected by the target object, conduct security testing on the biometric identification function of the application program, so as to determine the security performance of the biometric identification function of the application program, and thus achieve the effect of security testing on the biometric identification function of message encryption in the APP.
[0048] Optionally, in the security testing method of the application program provided in the embodiments of the present application, according to the selected instrumentation method, the biometric function of the application program is subjected to security testing, and determining the security performance of the biometric function of the application program includes: when the selected instrumentation method is to instrument the encryption and decryption functions of biometrics, based on processing the first message, a first target message is obtained; receiving the first response information returned by the target server in response to the first target message, analyzing the first response information, and obtaining an analysis result; based on the analysis result, determining the security performance of the biometric function of the application program.
[0049] For example, when the selected instrumentation method is to instrument the encryption and decryption functions of biometrics, the network transmission module in the security testing subsystem intercepts the data transmission ciphertext between the APP test device and the server, and processes this ciphertext to obtain the target message. Then the target message is sent to the application server under test, and subsequently, the response of the application background server under test to each test message is observed to detect whether there are security vulnerabilities. Finally, after the test is completed, the vulnerabilities of the application system are summarized and sorted out to generate a security test report.
[0050] Through the above solution, it is possible to conveniently implement the security testing of the biometric function of message encryption in the APP. In addition, applying such a testing method does not require modifying the original development process, is transparent to developers, and does not require developers to make additional modifications or add branches to the APP source code. While there is no increase in development costs, the testing efficiency is guaranteed; the application scope of such a testing method is not limited to a certain single encryption method, and is applicable to various encryption algorithms such as symmetric, asymmetric, international standards, and national cryptography standards; applying such a testing method can achieve a comprehensive penetration testing effect, and can cover various penetration tests based on message tampering and replay.
[0051] Optionally, in the security testing method of the application program provided in the embodiments of the present application, when the selected instrumentation method is to instrument the encryption and decryption functions of biometrics, based on processing the first message, obtaining the first target message includes: obtaining the first message; performing decryption processing on the first message to obtain the decrypted first message; combining the test payload with the decrypted first message to generate a second message; performing encryption processing on the second message to obtain the first target message.
[0052] For example, after the network transmission module of the security test subsystem intercepts the ciphertext of the data transmission between the APP test device and the server, it is sent to the stub coordination module-slave of the stub subsystem through the stub coordination module-master of the security test subsystem, and enters the processing flow of the stub subsystem; the stub subsystem decrypts the ciphertext to obtain the decrypted plaintext; the decrypted plaintext service message is sent to the test payload generation module of the security test subsystem through the stub coordination module-slave and the stub coordination module-master. The test payload generation module uses means such as machine learning and predefined rules to automatically generate attack payloads for the plaintext service message. The test scenarios cover a series of security-related attack techniques including XSS, SQL injection, privilege escalation, command execution, replay, etc. After the generated test payload is combined with the plaintext message, it is sent to the stub subsystem again through the stub coordination module-master for encryption processing to obtain the first target message.
[0053] In summary, by decrypting and encrypting the ciphertext, the encrypted message can be obtained conveniently, so that the biometric function can be security tested using the encrypted message.
[0054] Optionally, in the security test method of the application program provided in the embodiment of the present application, decrypting the first message to obtain the decrypted first message includes: performing reverse analysis on the application program through the first message to obtain the first target information of the target function corresponding to the first message, where the first target information is at least one of the following: the category information of the target function, the call format information of the target function, and the parameter format information of the target function; inserting the target program into the application program according to the first target information to obtain the decrypted first message.
[0055] The ciphertext is sent to the stub coordination module-slave through the stub coordination module-master and enters the processing flow of the stub subsystem; the stub coordination module-slave passes the ciphertext to the analysis module in the stub subsystem. The analysis module analyzes the APP program. Through reverse means, it obtains the smali, java, native and other codes of the APP, and combines information such as field names to automatically judge the information such as the class to which the encryption and decryption functions need to be called, the call format, and the parameter format, and passes it to the code stub module together with the ciphertext; according to the results of the analysis module, the code stub module injects binary code and calls the corresponding decryption function in the APP to decrypt the ciphertext.
[0056] In summary, by using the analysis results of the ciphertext by the analysis module, the decryption of the ciphertext by the stub module can be realized, and the ciphertext service message can be restored to the plaintext, so that the security test payload can be generated using the decrypted plaintext.
[0057] Optionally, in the security testing method of the application provided in the embodiments of the present application, receiving the first response information returned by the target server in response to the first target message, and analyzing the first response information, the analysis result includes: parsing the first target message by the target server to obtain the first target image; comparing the first target image with the images pre-stored in the target server to obtain a comparison result; using the comparison result as the first response information, and analyzing the first response information to obtain the analysis result.
[0058] For example, the encrypted test payload is sent to the application server under test via the network transmission module; the application server under test parses the ciphertext generated by encrypting the plaintext test payload message to obtain the corresponding picture; comparing this picture with the pictures pre-stored in the application server under test, so as to obtain the analysis result.
[0059] In summary, by comparing the picture obtained after parsing the message with the pictures pre-stored in the server and analyzing the comparison result, the analysis result can be obtained.
[0060] Optionally, in the security testing method of the application provided in the embodiments of the present application, according to the selected instrumentation method, performing security testing on the biometric function of the application to determine the security performance of the biometric function of the application includes: when the selected instrumentation method is to instrument the authentication function of biometrics, based on processing the parameters of the authentication function, obtaining a second target message; receiving the second response information returned by the target server in response to the second target message, analyzing the second response information, and obtaining the analysis result; determining the security performance of the biometric function of the application based on the analysis result.
[0061] For example, when the selected instrumentation method is to instrument the authentication function of biometrics, the instrumentation subsystem processes the parameters of the authentication function to obtain the target message. Then the target message is sent to the application server under test, and then observe the response of the application server under test to each test message to detect whether there are security vulnerabilities. Finally, after the test is completed, summarize and organize the vulnerabilities of the application system to generate a security test report.
[0062] Through the above solution, it is possible to conveniently implement security testing on the biometric function of message encryption in the APP and generate a security test report, so as to determine whether there are security vulnerabilities in the biometric function of the application.
[0063] Optionally, in the security testing method of the application program provided in the embodiments of the present application, when the selected instrumentation method is to instrument the biometric authentication function, based on processing the parameters of the authentication function, obtaining the second target message includes: analyzing the authentication function to obtain the second target information of the authentication function, where the second target information is at least one of the following: the parameter passing information of the authentication function and the return result information of the authentication function; according to the second target information, replacing the parameters of the authentication function to obtain the replaced parameters; processing the replaced parameters to obtain the second target message.
[0064] The analysis module in the instrumentation subsystem analyzes and locates the face recognition authentication function, checks information such as the parameter passing and return result of the face recognition authentication function; according to this information, the instrumentation module replaces the parameters of the face recognition function, and then the APP test device processes the replaced parameters to obtain the message.
[0065] In summary, by replacing the parameters of the authentication function to obtain the replaced parameters, the security test of the biometric function can be performed using the message after processing the replaced parameters.
[0066] Optionally, in the security testing method of the application program provided in the embodiments of the present application, receiving the second response information returned by the target server in response to the second target message, analyzing the second response information, and obtaining the analysis result includes: parsing the second target message by the target server to obtain the second target image; comparing the second target image with the image pre-stored in the target server to obtain the comparison result; using the comparison result as the second response information and analyzing the second response information to obtain the analysis result.
[0067] For example, the message obtained by processing the replaced parameters by the APP test device is sent to the application server under test via the network transmission module; the application server under test parses the message to obtain the corresponding picture, replaces the picture of the face information transmitted to the background server with the preset attack photo, and compares the preset attack photo with the image pre-stored in the application server under test to obtain the analysis result.
[0068] In summary, by comparing the preset attack photo with the image pre-stored in the application server under test and analyzing the comparison result, the analysis result can be obtained.
[0069] Optionally, in the security testing method of the application program provided in the embodiments of the present application, determining the security performance of the biometric function of the application program based on the analysis result includes: when the analysis result indicates that the first target image or the second target image is the same as the image pre-stored in the target server, there is a security vulnerability in the biometric function of the application program; when the analysis result indicates that the first target image or the second target image is different from the image pre-stored in the target server, there is no security vulnerability in the biometric function of the application program.
[0070] For example, the test result analysis module of the security testing subsystem determines whether there is a vulnerability according to the result returned by the application server and saves the result. If the picture received by the server is the same as the pre-stored picture, it can be determined that there is a security vulnerability in the biometric function of the application program. If the picture received by the server is different from the pre-stored picture, it can be determined that there is no security vulnerability in the biometric function of the application program.
[0071] In summary, by analyzing the result returned by the server, it can be determined whether there is a security vulnerability in the biometric function of the application program, so as to achieve the effect of security testing on the biometric function.
[0072] Schematic diagram of an optional security testing method for an application program, as Figure 3 shown. Before conducting security testing, security testers need to establish a security testing system, deploy a stub subsystem on the APP testing device, and deploy a security testing subsystem on the PC-side testing device. Then, the security testers make settings on the APP testing device, that is, the security testers issue an instruction to enter the biometric function module. Then, the APP testing device responds to this instruction and enters the biometric function module; the APP testing device determines the stubbing method for the security testing of the biometric function according to the instruction issued by the security tester; after determining the stubbing method for the security testing of the biometric function this time, the security testing of the biometric function of the application program is carried out according to the stubbing method, so as to determine the security performance of the biometric function of the application program. In addition, as Figure 4As shown in the figure, the security test subsystem includes a network transmission module 201, an instrumentation cooperation module - master 202, a test payload generation module 203, and a test result analysis module 204. Among them, the network transmission module 201 is responsible for intercepting the communication data between the APP and the server, and sending the adjusted test message to the application server and receiving the return result; the instrumentation cooperation module - master 202 is responsible for cooperating with the instrumentation subsystem 103 in the client, and forging and calling the encryption and decryption functions of the APP locally in the form of executing custom code through instrumentation, for decrypting the encrypted message and encrypting the test message. That is, when the network transmission module 201 intercepts the ciphertext service message, the 202 module is responsible for linking the 103 module to call the local decryption function of the APP to decrypt the message. When the 203 transmits the plaintext test service message, the 202 module is responsible for linking the 103 module to call the local encryption function of the APP to encrypt the message; the test payload generation module 203 automatically generates security test payloads according to the service message, realizes including judging the attack scenarios faced by the message, and completes the automatic generation of a series of security test payloads such as XSS, SQL injection, privilege escalation, command execution, etc., and combines them with the original message; after receiving the response of the application server to the test message, the test result analysis module 204 analyzes the response information in combination with the test payload situation generated and used in 203, judges whether there are security vulnerabilities in the 104 server, stores and classifies the problems identified as vulnerabilities, and generates a security test report after the test. As Figure 5 As shown in the figure, the instrumentation subsystem includes an instrumentation cooperation module 301, an analysis module 302, and a code instrumentation module 303. Among them, the instrumentation cooperation module - slave 301 works together with the instrumentation cooperation module 202 in the security test system 102. The 301 is responsible for receiving the task calls initiated by the 202, feedback results, etc. When receiving a call request from the 202, it forwards the relevant data content to the 302 for analysis and processing. When the 303 completes encryption, the result is returned to the 102 through the 301; the analysis module 302 obtains the smali, java, native and other codes of the APP through reverse means by analyzing the APP text, and automatically judges the class, call format, parameter format, etc. of the encryption and decryption functions and face authentication functions that need to be called in combination with the field names and other contents, and sends the relevant information to the 303 for processing; the main function of the code instrumentation module 303 is to instrument the APP with custom code inserted. The code instrumentation module 303 can achieve the effect of calling any function by inserting its own binary into the content of the target APP. Combining the function information obtained by the analysis of the 302, it realizes the tampering and calling of the encryption, decryption functions and face authentication functions, including restoring the ciphertext service message to plaintext, encrypting the plaintext test payload message into ciphertext, or tampering the verification photo uploaded to the background into a preset attack bypass photo.
[0073] In summary, the security testing method for an application provided by the embodiments of the present application receives a target instruction of a target object and responds to the target instruction, where the target instruction is used to indicate to perform a security test on the biometric function of the application; determine the instrumentation method, where the instrumentation method is one of the following: instrument the encryption and decryption functions of biometrics, instrument the authentication function of biometrics; obtain the instrumentation method selected by the target object, perform a security test on the biometric function of the application, and determine the security performance of the biometric function of the application, solving the problem in the related art that it is difficult to perform a security test on the biometric function with message encryption in an APP, resulting in testers being difficult to discover security vulnerabilities in the APP. By receiving and responding to the target instruction of the target object and performing a security test on the biometric function of the application according to the instrumentation method selected by the target object, the security performance of the biometric function of the application is determined, so that a security test can be performed on the biometric function with message encryption in the APP, and further achieving the effect that when there are security vulnerabilities in the APP, testers can discover them in time.
[0074] It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.
[0075] The embodiments of the present application also provide a security testing device for an application. It should be noted that the security testing device for an application in the embodiments of the present application can be used to execute the security testing method for an application provided by the embodiments of the present application. The following introduces the security testing device for an application provided by the embodiments of the present application.
[0076] Figure 6 is a schematic diagram of the security testing device for an application according to the embodiments of the present application. As Figure 6 shown, the device includes: a first processing unit 601, a first obtaining unit 602, and a first testing unit 603.
[0077] Specifically, the first processing unit 601 is configured to receive a target instruction of a target object and respond to the target instruction, where the target instruction is used to indicate to perform a security test on the biometric function of the application;
[0078] The first obtaining unit 602 is configured to obtain the instrumentation method selected by the target object, where the instrumentation method is one of the following: instrument the encryption and decryption functions of biometrics, instrument the authentication function of biometrics;
[0079] The first test unit 603 is used to perform a security test on the biometric function of the application program according to the selected instrumentation method, and determine the security performance of the biometric function of the application program.
[0080] In summary, the security test device for the application program provided by the embodiment of the present application receives a target instruction of a target object through the first processing unit 601 and responds to the target instruction, where the target instruction is used to indicate performing a security test on the biometric function of the application program; the first acquisition unit 602 acquires the instrumentation method selected by the target object, where the instrumentation method is one of the following: instrumenting the encryption and decryption functions of biometrics, instrumenting the authentication function of biometrics; the first test unit 603 performs a security test on the biometric function of the application program according to the selected instrumentation method, and determines the security performance of the biometric function of the application program, solving the problem in the related art that it is difficult to perform a security test on the biometric function with message encryption in the APP, resulting in difficulty for testers to discover security vulnerabilities in the APP. By receiving and responding to the target instruction of the target object and performing a security test on the biometric function of the application program according to the instrumentation method selected by the target object, the security performance of the biometric function of the application program is determined, so that a security test can be performed on the biometric function with message encryption in the APP, and further achieving the effect that when there are security vulnerabilities in the APP, testers can discover them in time.
[0081] Optionally, in the security test device for the application program provided by the embodiment of the present application, the first test unit includes: a first processing subunit, configured to, when the selected instrumentation method is to instrument the encryption and decryption functions of biometrics, obtain a first target message based on processing the first message; a second processing subunit, configured to receive the first response information returned by the target server in response to the first target message, analyze the first response information, and obtain an analysis result; a first determination subunit, configured to determine the security performance of the biometric function of the application program based on the analysis result.
[0082] Optionally, in the security test device for the application program provided by the embodiment of the present application, the first processing subunit includes: a first acquisition module, configured to acquire the first message; a first processing module, configured to perform decryption processing on the first message to obtain the decrypted first message; a first generation module, configured to combine the test payload with the decrypted first message to generate a second message; a second processing module, configured to perform encryption processing on the second message to obtain the first target message.
[0083] Optionally, in the security testing device for an application provided in the embodiments of the present application, the second processing module includes: a first processing sub-module, configured to perform reverse analysis on the application through a first message to obtain first target information of a target function corresponding to the first message, where the first target information is at least one of the following: category information of the target function, call format information of the target function, and parameter format information of the target function; a first insertion sub-module, configured to insert a target program into the application according to the first target information to obtain a decrypted first message.
[0084] Optionally, in the security testing device for an application provided in the embodiments of the present application, the second processing sub-unit includes: a first parsing module, configured to parse a first target message through a target server to obtain a first target image; a first comparison module, configured to compare the first target image with an image pre-stored in the target server to obtain a comparison result; a first analysis module, configured to use the comparison result as a first response message and analyze the first response message to obtain an analysis result.
[0085] Optionally, in the security testing device for an application provided in the embodiments of the present application, the first testing unit includes: a third processing sub-unit, configured to, when the selected instrumentation method is to instrument an authentication function for biometric identification, process the parameters of the authentication function to obtain a second target message; a fourth processing sub-unit, configured to receive a second response message returned by the target server in response to the second target message, analyze the second response message to obtain an analysis result; a second determination sub-unit, configured to determine the security performance of the biometric identification function of the application based on the analysis result.
[0086] Optionally, in the security testing device for an application provided in the embodiments of the present application, the third processing sub-unit includes: a second analysis module, configured to analyze an authentication function to obtain second target information of the authentication function, where the second target information is at least one of the following: parameter passing information of the authentication function and return result information of the authentication function; a first replacement module, configured to replace the parameters of the authentication function according to the second target information to obtain replaced parameters; a third processing module, configured to process the replaced parameters to obtain a second target message.
[0087] Optionally, in the security testing device for an application provided in the embodiments of the present application, the fourth processing sub-unit includes: a second parsing module, configured to parse the second target message through a target server to obtain a second target image; a second comparison module, configured to compare the second target image with an image pre-stored in the target server to obtain a comparison result; a third analysis module, configured to use the comparison result as a second response message and analyze the second response message to obtain an analysis result.
[0088] Optionally, in the security testing device for an application provided in the embodiments of the present application, the first determination subunit or the second determination subunit includes: a fourth processing module, configured to determine that there is a security vulnerability in the biometric function of the application when the analysis result indicates that the first target image or the second target image is the same as the image pre-stored in the target server; a fifth processing module, configured to determine that there is no security vulnerability in the biometric function of the application when the analysis result indicates that the first target image or the second target image is different from the image pre-stored in the target server.
[0089] The security testing device for the application includes a processor and a memory. The above-mentioned first processing unit 601, first acquisition unit 602, first testing unit 603, etc. are all stored in the memory as program units, and the processor executes the above-mentioned program units stored in the memory to implement corresponding functions.
[0090] The processor contains a kernel, and the kernel retrieves the corresponding program unit from the memory. One or more kernels can be set, and the security of the biometric function for encrypting messages in the APP is tested by adjusting the kernel parameters.
[0091] The memory may include non-permanent memory in a computer-readable medium, in the form of random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash memory (flash RAM), and the memory includes at least one storage chip.
[0092] The embodiments of the present invention provide a storage medium, on which a program is stored, and when the program is executed by a processor, the security testing method for the application is implemented.
[0093] The embodiments of the present invention provide a processor, and the processor is used to run a program, wherein when the program runs, the security testing method for the application is executed.
[0094] As Figure 7 shown, the embodiments of the present invention provide an electronic device, which includes a processor, a memory, and a program stored on the memory and executable on the processor. When the processor executes the program, the following steps are implemented: receiving a target instruction of a target object and responding to the target instruction, where the target instruction is used to indicate a security test for the biometric function of an application; obtaining a staking method selected by the target object, where the staking method is one of the following: staking on the encryption and decryption functions of biometrics, staking on the authentication function of biometrics; according to the selected staking method, performing a security test on the biometric function of the application to determine the security performance of the biometric function of the application.
[0095] When the processor executes the program, the following steps are also implemented: When the selected instrumentation method is to instrument the encryption and decryption functions of biometric recognition, based on the processing of the first message, a first target message is obtained; The first response information returned by the target server in response to the first target message is received, and the first response information is analyzed to obtain an analysis result; Based on the analysis result, the security performance of the biometric recognition function of the application program is determined.
[0096] When the processor executes the program, the following steps are also implemented: The first message is obtained; The first message is decrypted to obtain the decrypted first message; The test payload is combined with the decrypted first message to generate a second message; The second message is encrypted to obtain the first target message.
[0097] When the processor executes the program, the following steps are also implemented: Decrypting the first message to obtain the decrypted first message includes: performing reverse analysis on the application program through the first message to obtain first target information of the target function corresponding to the first message, where the first target information is at least one of the following: the category information of the target function, the call format information of the target function, and the parameter format information of the target function; According to the first target information, a target program is inserted into the application program to obtain the decrypted first message.
[0098] When the processor executes the program, the following steps are also implemented: Receiving the first response information returned by the target server in response to the first target message, and analyzing the first response information to obtain an analysis result includes: parsing the first target message by the target server to obtain a first target image; Comparing the first target image with the image pre-stored in the target server to obtain a comparison result; Using the comparison result as the first response information, and analyzing the first response information to obtain the analysis result.
[0099] When the processor executes the program, the following steps are also implemented: According to the selected instrumentation method, performing a security test on the biometric recognition function of the application program, and determining the security performance of the biometric recognition function of the application program includes: When the selected instrumentation method is to instrument the authentication function of biometric recognition, based on the processing of the parameters of the authentication function, a second target message is obtained; Receiving the second response information returned by the target server in response to the second target message, and analyzing the second response information to obtain an analysis result; Based on the analysis result, the security performance of the biometric recognition function of the application program is determined.
[0100] When the processor executes the program, the following steps are also implemented: When the selected instrumentation method is to instrument the authentication function of biometric recognition, based on processing the parameters of the authentication function, a second target message is obtained, including: analyzing the authentication function to obtain second target information of the authentication function, where the second target information is at least one of the following: parameter passing information of the authentication function and return result information of the authentication function; replacing the parameters of the authentication function according to the second target information to obtain the replaced parameters; processing the replaced parameters to obtain the second target message.
[0101] When the processor executes the program, the following steps are also implemented: receiving second response information returned by the target server in response to the second target message, and analyzing the second response information to obtain an analysis result, including: parsing the second target message by the target server to obtain a second target image; comparing the second target image with an image pre-stored in the target server to obtain a comparison result; using the comparison result as the second response information and analyzing the second response information to obtain the analysis result.
[0102] When the processor executes the program, the following steps are also implemented: determining the security performance of the biometric recognition function of the application program based on the analysis result, including: when the analysis result indicates that the first target image or the second target image is the same as the image pre-stored in the target server, there is a security vulnerability in the biometric recognition function of the application program; when the analysis result indicates that the first target image or the second target image is different from the image pre-stored in the target server, there is no security vulnerability in the biometric recognition function of the application program. The device in this article can be a server, a PC, a PAD, a mobile phone, etc.
[0103] The present application also provides a computer program product, which, when executed on a data processing device, is adapted to execute a program initialized with the following method steps: receiving a target instruction of a target object and responding to the target instruction, where the target instruction is used to indicate a security test on the biometric recognition function of an application program; obtaining the instrumentation method selected by the target object, where the instrumentation method is one of the following: instrumenting the encryption and decryption functions of biometric recognition, instrumenting the authentication function of biometric recognition; performing a security test on the biometric recognition function of the application program according to the selected instrumentation method to determine the security performance of the biometric recognition function of the application program.
[0104] When executed on a data processing device, it is also suitable for executing a program initialized with the following method steps: According to the selected instrumentation method, perform a security test on the biometric function of the application program, and determine the security performance of the biometric function of the application program, including: when the selected instrumentation method is to instrument the encryption and decryption functions of biometrics, based on the processing of the first message, obtain a first target message; receive the first response information returned by the target server in response to the first target message, analyze the first response information, and obtain an analysis result; based on the analysis result, determine the security performance of the biometric function of the application program.
[0105] When executed on a data processing device, it is also suitable for executing a program initialized with the following method steps: when the selected instrumentation method is to instrument the encryption and decryption functions of biometrics, based on the processing of the first message, obtaining a first target message includes: obtaining the first message; performing decryption processing on the first message to obtain the decrypted first message; combining the test payload with the decrypted first message to generate a second message; performing encryption processing on the second message to obtain the first target message.
[0106] When executed on a data processing device, it is also suitable for executing a program initialized with the following method steps: performing decryption processing on the first message to obtain the decrypted first message includes: performing reverse analysis on the application program through the first message to obtain first target information of the target function corresponding to the first message, where the first target information is at least one of the following: the category information of the target function, the call format information of the target function, and the parameter format information of the target function; inserting a target program into the application program according to the first target information to obtain the decrypted first message.
[0107] When executed on a data processing device, it is also suitable for executing a program initialized with the following method steps: receiving the first response information returned by the target server in response to the first target message, analyzing the first response information, and obtaining an analysis result includes: parsing the first target message by the target server to obtain a first target image; comparing the first target image with the image pre-stored in the target server to obtain a comparison result; using the comparison result as the first response information, analyzing the first response information, and obtaining the analysis result.
[0108] When executed on a data processing device, it is also suitable for executing a program initialized with the following method steps: According to the selected instrumentation method, perform a security test on the biometric function of the application program, and determine the security performance of the biometric function of the application program, including: when the selected instrumentation method is to instrument the authentication function of biometrics, based on processing the parameters of the authentication function, obtain a second target message; receive second response information returned by the target server in response to the second target message, analyze the second response information, and obtain an analysis result; based on the analysis result, determine the security performance of the biometric function of the application program.
[0109] When executed on a data processing device, it is also suitable for executing a program initialized with the following method steps: when the selected instrumentation method is to instrument the authentication function of biometrics, based on processing the parameters of the authentication function, obtaining a second target message includes: analyzing the authentication function to obtain second target information of the authentication function, where the second target information is at least one of the following: the parameter passing information of the authentication function and the return result information of the authentication function; according to the second target information, replace the parameters of the authentication function to obtain the replaced parameters; process the replaced parameters to obtain the second target message.
[0110] When executed on a data processing device, it is also suitable for executing a program initialized with the following method steps: receiving second response information returned by the target server in response to the second target message, analyzing the second response information, and obtaining an analysis result includes: parsing the second target message by the target server to obtain a second target image; comparing the second target image with an image pre-stored in the target server to obtain a comparison result; using the comparison result as the second response information, analyzing the second response information, and obtaining the analysis result.
[0111] When executed on a data processing device, it is also suitable for executing a program initialized with the following method steps: based on the analysis result, determining the security performance of the biometric function of the application program includes: when the analysis result indicates that the first target image or the second target image is the same as the image pre-stored in the target server, there is a security vulnerability in the biometric function of the application program; when the analysis result indicates that the first target image or the second target image is not the same as the image pre-stored in the target server, there is no security vulnerability in the biometric function of the application program.
[0112] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memory, CD-ROM, optical memory, etc.) that contain computer-usable program code.
[0113] The present application is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to the embodiments of the present application. It should be understood that each flow and / or block in the flowchart and / or block diagram, as well as the combination of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate means for implementing the functions specified in Figure 1 one or more of the flows Figure 1 or multiple flows and / or blocks
[0114] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured article including instruction means, and the instruction means implements the functions specified in Figure 1 one or more of the flows Figure 1 or multiple flows and / or blocks
[0115] These computer program instructions can also be loaded onto a computer or other programmable data processing device, so that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in Figure 1 one or more of the flows Figure 1 or multiple flows and / or blocks
[0116] In a typical configuration, a computing device includes one or more processors (CPUs), an input / output interface, a network interface, and a memory.
[0117] The memory may include non-permanent memory in a computer-readable medium, in the form of random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash memory (flash RAM). The memory is an example of a computer-readable medium.
[0118] Computer readable media include permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. Information can be computer readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic tape magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer readable media does not include temporary computer readable media (transitory media), such as modulated data signals and carrier waves.
[0119] It should also be noted that the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, commodity or device. In the absence of more restrictions, the elements defined by the sentence "comprises a ..." do not exclude the existence of other identical elements in the process, method, commodity or device including the elements.
[0120] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems or computer program products. Therefore, the present application may adopt the form of a complete hardware embodiment, a complete software embodiment or an embodiment in combination with software and hardware. Moreover, the present application may adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.
[0121] The above are only embodiments of the present application and are not intended to limit the present application. For those skilled in the art, the present application may have various changes and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application should be included within the scope of the claims of the present application.
Claims
1. A security testing method for an application program, characterized in that, it includes: Receiving a target instruction of a target object and responding to the target instruction, where the target instruction is used to indicate to perform a security test on the biometric function of the application program; Obtaining the instrumentation method selected by the target object, where the instrumentation method is one of the following: instrumenting the encryption and decryption functions of biometrics, instrumenting the authentication function of biometrics; According to the selected instrumentation method, performing a security test on the biometric function of the application program to determine the security performance of the biometric function of the application program; According to the selected instrumentation method, performing a security test on the biometric function of the application program to determine the security performance of the biometric function of the application program includes: When the selected instrumentation method is to instrument the encryption and decryption functions of biometrics, based on processing the first message, obtaining a first target message; Receiving the first response information returned by the target server in response to the first target message, analyzing the first response information to obtain an analysis result; Based on the analysis result, determining the security performance of the biometric function of the application program; or, When the selected instrumentation method is to instrument the authentication function of biometrics, based on processing the parameters of the authentication function, obtaining a second target message; Receiving the second response information returned by the target server in response to the second target message, analyzing the second response information to obtain an analysis result; Based on the analysis result, determining the security performance of the biometric function of the application program.
2. The method according to claim 1, characterized in that, When the selected instrumentation method is to instrument the encryption and decryption functions of biometrics, based on processing the first message, obtaining a first target message includes: Obtaining the first message; Performing decryption processing on the first message to obtain a decrypted first message; Combining the test payload with the decrypted first message to generate a second message; Performing encryption processing on the second message to obtain the first target message.
3. The method according to claim 2, characterized in that, Performing decryption processing on the first message to obtain a decrypted first message includes: Performing reverse analysis on the application program through the first message to obtain first target information of the target function corresponding to the first message, where the first target information is at least one of the following: the category information of the target function, the call format information of the target function, and the parameter format information of the target function; Inserting a target program into the application program according to the first target information to obtain the decrypted first message.
4. The method according to claim 1, characterized in that, Receiving the first response information returned by the target server in response to the first target message, analyzing the first response information to obtain an analysis result includes: Parsing the first target message through the target server to obtain a first target image; Compare the first target image with the images pre-stored in the target server to obtain a comparison result; Use the comparison result as the first response information, and analyze the first response information to obtain the analysis result.
5. The method according to claim 1, wherein, when the selected instrumentation method is to instrument the authentication function of biometric recognition, based on processing the parameters of the authentication function, the second target message obtained includes: Analyze the authentication function to obtain second target information of the authentication function, where the second target information is at least one of the following: the parameter passing information of the authentication function and the return result information of the authentication function; Replace the parameters of the authentication function according to the second target information to obtain the replaced parameters; Process the replaced parameters to obtain the second target message.
6. The method according to claim 1, wherein, Receive the second response information returned by the target server in response to the second target message, and analyze the second response information to obtain the analysis result including: Parse the second target message through the target server to obtain a second target image; Compare the second target image with the images pre-stored in the target server to obtain a comparison result; Use the comparison result as the second response information, and analyze the second response information to obtain the analysis result.
7. The method according to any one of claims 4 or 6, wherein, Determining the security performance of the biometric recognition function of the application program based on the analysis result includes: When the analysis result indicates that the first target image or the second target image is the same as the images pre-stored in the target server, there is a security vulnerability in the biometric recognition function of the application program; When the analysis result indicates that the first target image or the second target image is different from the images pre-stored in the target server, there is no security vulnerability in the biometric recognition function of the application program.
8. A security testing device for an application program, wherein, comprising: A first processing unit, configured to receive a target instruction of a target object and respond to the target instruction, where the target instruction is used to indicate a security test of the biometric recognition function of the application program; A first acquisition unit, configured to acquire the instrumentation method selected by the target object, where the instrumentation method is one of the following: instrumenting the encryption and decryption functions of biometric recognition, instrumenting the authentication function of biometric recognition; A first testing unit, configured to perform a security test on the biometric recognition function of the application program according to the selected instrumentation method, and determine the security performance of the biometric recognition function of the application program; Among them, the first test unit includes: a first processing subunit, configured to, when the selected instrumentation method is to instrument the encryption and decryption functions of biometric identification, obtain a first target message based on processing the first message; a second processing subunit, configured to receive first response information returned by the target server in response to the first target message, analyze the first response information, and obtain an analysis result; a first determination subunit, configured to determine the security performance of the biometric identification function of the application program based on the analysis result The first test unit includes: a third processing subunit, configured to, when the selected instrumentation method is to instrument the authentication function of biometric identification, obtain a second target message based on processing the parameters of the authentication function; a fourth processing subunit, configured to receive second response information returned by the target server in response to the second target message, analyze the second response information, and obtain an analysis result; a second determination subunit, configured to determine the security performance of the biometric identification function of the application program based on the analysis result.
9. A computer-readable storage medium, characterized in that the storage medium includes a stored program, wherein the program executes the security test method of the application program according to any one of claims 1 to 7.
10. An electronic device, characterized in that it includes one or more processors and a memory, the memory is used to store one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors implement the security test method of the application program according to any one of claims 1 to 7.
Citation Information
Patent Citations
Vulnerability analysis method, device, terminal and storage medium
CN107040553A
A method of mining and analyzing information security vulnerabilities
CN109002721A