Safe injection automation method, device, electronic device and storage medium
By implementing a safe injection automation method in the C/S architecture information management system, including positioning controls, starting SQL tracking tools, generating and entering SQL injection statements, analyzing data flow identification risks, the problem of manual injection in the existing technology is solved, and automatic security testing is realized, which improves the testing efficiency and quality.
Patent Information
- Application Number
- CN202011245538.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-11-10
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2040-11-10
AI Technical Summary
In the prior art, the safe injection monitoring of C/S architecture can only be done manually, resulting in large labor consumption and inability to analyze results in real time, and lack of automated monitoring technology.
Provides a secure injection automation method for information management systems based on C/S architecture. Through positioning system controls, starts the SQL tracking tool, enters the generated SQL injection statement, closes the tracking tool, and analyzes the data flow according to preset rules to identify injection risks.
It realizes automated security testing of C/S architecture information management system, without manual intervention, can feedback security results in real time, greatly save test labor costs, and improve test efficiency and quality.
Smart Images

Figure CN114461512B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of data security, and particularly relates to a security injection automation method, device, electronic device, and storage medium. Background Art
[0002] The general idea of security testing for the C / S (client / server) architecture is as follows: requirements analysis > test case design > test case maintenance > test case execution > result analysis. The test case execution and result analysis in the above process are generally done manually. Currently, common security testing tools include Appscan and Burpsuit, etc., which are mainly based on the B / S (browser / server) architecture. In the information management system with the C / S architecture, due to the large number of input boxes, the threat of information leakage to social security, and the fact that test case execution and result analysis consume a lot of time and lack timeliness, it is necessary to implement automated test case execution and real-time reporting of security results.
[0003] The current automated security injection monitoring technology for information management systems based on the C / S architecture cannot perform real-time result analysis and requires manual intervention to implement monitoring. Moreover, the existing security monitoring technology for security injection monitoring of the C / S architecture can only be in the manual injection mode at present. Due to the complexity and large quantity of system controls, manual injection is very labor-consuming.
[0004] Generally speaking, the current automated security injection monitoring technology for information management systems with the C / S architecture is lacking. Therefore, it is necessary to develop a technology for automated security injection monitoring of information management systems based on the C / S architecture. Summary of the Invention
[0005] The technical problem to be solved by the present invention is to overcome the defects in the prior art that the security injection monitoring for the C / S architecture can only be in the manual injection mode at present. Due to the complexity and large quantity of system controls, manual injection is very labor-consuming, and real-time result analysis cannot be performed, and manual intervention is required to implement monitoring. The present invention provides a security injection automation method, device, electronic device, and storage medium.
[0006] The present invention solves the above technical problem through the following technical solutions:
[0007] The present invention provides a security injection automation method for an information management system based on the C / S architecture. The security injection automation method includes:
[0008] When a trigger condition is satisfied, the following steps are executed:
[0009] Locate the controls of the information management system;
[0010] Start an SQL (Structured Query Language) tracing tool, and the SQL tracing tool is used to trace the database to view the data flow;
[0011] Input an SQL injection statement, which is generated according to the value received by the control;
[0012] Close the SQL tracing tool;
[0013] Analyze the injection risk of the data stream according to a preset rule and obtain an analysis result.
[0014] Preferably, the preset rule includes:
[0015] If the SQL injection statement includes a preset high-risk SQL statement, the obtained analysis result is a high-risk injection risk;
[0016] And / or, if data belonging to preset sensitive information is transmitted in plaintext, the obtained analysis result is a high-risk injection risk.
[0017] Preferably, the controls of the location information management system specifically include:
[0018] Locate the Windows standard controls of the information management system by using autoit (a software for automated operations in Windows GUI (Graphical User Interface)), and locate the Windows non-standard controls of the information management system by using RanorexStudio (a GUI automated testing tool);
[0019] Or, locate the standard and non-standard controls of the information management system by using RanorexStudio.
[0020] Preferably, the triggering condition includes timed triggering;
[0021] And / or, the security injection automation method further includes sending the analysis result to a preset email box by email;
[0022] And / or, the SQL tracing tool is an SQL Profiler tracker.
[0023] The present invention also provides a security injection automation device for an information management system based on a C / S architecture. The security injection automation device includes: a triggering module, a location module, a tracing module, an input module, and an analysis module;
[0024] The triggering module is used to call the location module when a triggering condition is satisfied; the location module is used to locate the controls of the information management system, and then call the tracing module to start an SQL tracing tool, and the SQL tracing tool is used to trace the database to view the data stream;
[0025] The tracking module calls the input module after starting the SQL tracking tool; the input module is used to input an SQL injection statement, which is generated according to the value received by the control, and then calls the tracking module to close the SQL tracking tool;
[0026] After closing the SQL tracking tool, the tracking module calls the analysis module, which is used to analyze the injection risk of the data stream according to preset rules and obtain an analysis result.
[0027] Preferably, the preset rules include:
[0028] If the SQL injection statement includes a preset high-risk SQL statement, the obtained analysis result is a high-risk injection risk;
[0029] And / or, if data belonging to preset sensitive information is transmitted in plain text, the obtained analysis result is a high-risk injection risk.
[0030] Preferably, the positioning module is specifically used for:
[0031] Using autoit to locate the Windows standard controls of the information management system, and using RanorexStudio to locate the Windows non-standard controls of the information management system;
[0032] Or, using RanorexStudio to locate the standard controls and non-standard controls of the information management system.
[0033] Preferably, the triggering condition includes timed triggering;
[0034] And / or, the security injection automation device further includes a notification module, which is used to send the analysis result to a preset email box by email;
[0035] And / or, the SQL tracking tool is an SQL Profiler tracker.
[0036] The present invention also provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor, wherein when the processor executes the program, it implements the security injection automation method of the information management system based on the C / S architecture as described above.
[0037] The present invention also provides a computer-readable storage medium, on which a computer program is stored, wherein when the program is executed by a processor, it implements the steps of the security injection automation method of the information management system based on the C / S architecture as described above.
[0038] On the basis of conforming to the common knowledge in the art, the above preferred conditions can be combined arbitrarily to obtain various preferred embodiments of the present invention.
[0039] The positive and progressive effects of the present invention are as follows: The present invention can achieve automated testing in the field of security testing of C / S architecture information management systems. Even if the system controls are complex and large in quantity, no manual intervention is required, and automated monitoring and tracking are completed, improving the efficiency and quality of automated security testing. Brief Description of the Drawings
[0040] Figure 1 It is a flowchart of a security injection automation method for an information management system based on C / S architecture according to Embodiment 1 of the present invention;
[0041] Figure 2 It is a schematic block diagram of a security injection automation device for an information management system based on C / S architecture according to Embodiment 2 of the present invention;
[0042] Figure 3 It is a schematic structural diagram of an electronic device according to Embodiment 3 of the present invention. Detailed Embodiments
[0043] The present invention will be further described below by way of embodiments, but the present invention is not limited to the scope of the described embodiments.
[0044] Embodiment 1
[0045] Figure 1 A security injection automation method for an information management system based on C / S architecture in this embodiment is shown. Among them, the information management system can be any information management system for applications, such as an information management system for personnel file management, an information management system for library book borrowing, etc. The security injection automation method includes:
[0046] When the trigger condition is met, the trigger condition can be timed trigger, and the following steps are executed:
[0047] Step 11: Locate the controls of the information management system. If the information management system is designed based on the Windows system, the controls can be divided into Windows standard controls and Windows non-standard controls. The location of Windows standard controls is relatively simple and can be achieved by using autoit. The location of Windows non-standard controls is more complex and can be achieved by using RanorexStudio; of course, RanorexStudio can also be used to locate both the standard controls and non-standard controls of the information management system at the same time.
[0048] Step 12: Start the SQL tracing tool, which is used to trace the data flow for viewing the database. In this embodiment, the SQL tracing tool is the SQL Profiler tracer. Of course, other tools that can achieve tracing the data flow for viewing the database are also applicable to this method.
[0049] Step 13: Input the SQL injection statement, which is generated based on the value received by the control. The value received by the control can be understood as being generated by the user's operations on the control (which may be input, selection, etc.), and through these operations, it is code-converted into an SQL injection statement. These SQL injection statements may be secure SQL statements or SQL statements that concatenate insecure SQL statements.
[0050] Step 14: Close the SQL tracing tool.
[0051] Step 15: Analyze the injection risk for the data flow according to the preset rules and obtain the analysis result. Among them, the preset rules may include:
[0052] If the SQL injection statement includes a preset high-risk SQL statement, the obtained analysis result is a high-risk injection risk. A high-risk SQL statement refers to an SQL statement with a high-risk injection risk. This high-risk SQL statement is very likely to bypass the application security measures and insert malicious SQL code into the database query, enabling the attacker to fully control the database server and seriously threatening the database security. The following lists some possible high-risk SQL statements for reference:
[0053] Daily query:
[0054] ‘or 1 like ‘1
[0055] 1' HAVING 1=1 --
[0056] 1' GROUP BY CPOE_BRSYK.EMRXH HAVING 1=1 --
[0057] 1' AND 1 > (SELECT TOP 1 HZXM FROM CPOE_BRSYK) --
[0058] 1' ORDER BY 13
[0059] Based on time delay:
[0060] kobe' and sleep(5)--
[0061] kobe' and if((substr(database(),1,1))='a',sleep(5),null)--
[0062] kobe' and if((substr(database(),1,1))='p',sleep(5),null)--
[0063] Brute-force cracking of table names and column names:
[0064] kobe' and exists(select * from aa)--
[0065] The preset rules may further include:
[0066] If data belonging to preset sensitive information is transmitted in plaintext, the obtained analysis result is a high-risk injection risk. The sensitive information may include information such as usernames and passwords. If this information is not encrypted during data transmission, it is very likely to lead to information leakage and malicious eavesdropping, so it also has a high-risk injection risk.
[0067] Step 16: Send the analysis result to a preset email address via email. The preset email address can be set according to actual needs, such as the email address of a security administrator or a system maintenance personnel or other email addresses.
[0068] The method of this embodiment uses security injection automated monitoring technology to automate the security testing of information systems with a C / S architecture and provide real-time feedback on the results, without manual intervention, greatly saving the testing labor cost.
[0069] Embodiment 2
[0070] Figure 2 Shows a security injection automation device for an information management system based on a C / S architecture. Among them, the information management system can be any information management system for applications, such as an information management system for personnel file management, an information management system for library book borrowing, etc. The security injection automation device includes: a trigger module 21, a positioning module 22, a tracking module 23, an input module 24, an analysis module 25, and a notification module 26.
[0071] The trigger module 21 is used to call the positioning module 22 when a trigger condition is met. The trigger condition may be a timed trigger.
[0072] The positioning module 22 is used to locate the controls of the information management system, and then call the tracking module 23 to start the SQL tracking tool, which is used to track the data stream by viewing the database. If the information management system is designed based on the Windows system, the controls can be divided into Windows standard controls and Windows non-standard controls. The positioning of Windows standard controls is relatively simple and can be achieved by using autoit. The positioning of Windows non-standard controls is more complex and can be achieved by using RanorexStudio. Of course, RanorexStudio can also be used to locate both the standard controls and non-standard controls of the information management system at the same time.
[0073] After starting the SQL tracking tool, the tracking module 23 calls the input module 24; the input module 24 is used to input SQL injection statements, which are generated according to the values received by the controls, and then call the tracking module 23 to close the SQL tracking tool. In this embodiment, the SQL tracking tool is the SQL Profiler tracker. Of course, other tools that can implement tracking the data stream by viewing the database are also applicable to this device.
[0074] After closing the SQL tracking tool, the tracking module 23 calls the analysis module 25, which is used to analyze the injection risk of the data stream according to preset rules and obtain an analysis result, and then call the notification module 26. Among them, the preset rules include:
[0075] If the SQL injection statement includes a preset high-risk SQL statement, the obtained analysis result is a high-risk injection risk. Among them, a high-risk SQL statement refers to a SQL statement with a high-risk injection risk. This high-risk SQL statement is very likely to bypass the application security measures and insert malicious SQL code into the database query, enabling the attacker to completely control the database server and seriously threatening the database security;
[0076] And / or, if the data belonging to the preset sensitive information is transmitted in plain text, the obtained analysis result is a high-risk injection risk. Among them, the sensitive information may include information such as user names and passwords. If this information is not encrypted during data transmission, it is very likely to lead to information leakage and be maliciously monitored. Therefore, it also has a high-risk injection risk.
[0077] The notification module 26 is used to send the analysis result to a preset email box by email. The preset email box can be set according to actual needs, such as being set as the email box of the security management personnel or the system maintenance personnel or other email boxes.
[0078] The device of this embodiment uses security injection automation monitoring technology to automate the execution and provide real-time feedback on the results of the information system security test with a C / S architecture, without manual intervention, greatly saving the test labor cost.
[0079] Embodiment 3
[0080] Figure 3 FIG. 3 is a schematic structural diagram of an electronic device provided in Embodiment 3 of the present invention. The electronic device includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the program, the method of Embodiment 1 is implemented. Figure 3 The displayed electronic device 40 is merely an example and should not impose any limitation on the functions and usage scope of the embodiments of the present invention.
[0081] As Figure 3 shown, the electronic device 40 may be presented in the form of a general-purpose computing device, for example, it may be a server device. The components of the electronic device 40 may include, but are not limited to: at least one of the above-mentioned processors 41, at least one of the above-mentioned memories 42, and a bus 43 connecting different system components (including the memory 42 and the processor 41).
[0082] The bus 43 includes a data bus, an address bus, and a control bus.
[0083] The memory 42 may include volatile memory, such as a random access memory (RAM) 421 and / or a cache memory 422, and may further include a read-only memory (ROM) 423.
[0084] The memory 42 may further include a program / utilities 425 having a set (at least one) of program modules 424. Such program modules 424 include, but are not limited to: an operating system, one or more application programs, other program modules, and program data. Each or some combination of these examples may include an implementation of a network environment.
[0085] The processor 41 executes various functional applications and data processing by running the computer program stored in the memory 42, such as the method provided in Embodiment 1 of the present invention.
[0086] The electronic device 40 may also communicate with one or more external devices 44 (such as a keyboard, a pointing device, etc.). Such communication may be performed through an input / output (I / O) interface 45. And, the model-generated electronic device 40 may also communicate with one or more networks (such as a local area network (LAN), a wide area network (WAN), and / or a public network, such as the Internet) through a network adapter 46. As Figure 3As shown, network adapter 46 communicates with other modules of the electronic device 40 that generates the model via bus 43. It should be understood that although not shown in the figure, other hardware and / or software modules may be used in conjunction with the electronic device 40 that generates the model, including but not limited to: microcode, device drivers, redundant processors, external disk drive arrays, RAID (redundant array of independent disks) systems, tape drives, and data backup storage systems, etc.
[0087] It should be noted that although several units / modules or sub-units / modules of the electronic device are mentioned in the above detailed description, this division is merely exemplary and not mandatory. In fact, according to the embodiments of the present invention, the features and functions of two or more of the above-described units / modules may be embodied in one unit / modules. Conversely, the features and functions of one unit / modules described above may be further divided and embodied by multiple units / modules.
[0088] Embodiment 4
[0089] This embodiment provides a computer-readable storage medium on which a computer program is stored, and when the program is executed by a processor, the steps of the method provided in Embodiment 1 are implemented.
[0090] Among them, the more specific computer-readable storage medium that can be adopted may include but not limited to: portable disks, hard disks, random access memories, read-only memories, erasable programmable read-only memories, optical storage devices, magnetic storage devices, or any suitable combination of the above.
[0091] In a possible implementation manner, the present invention can also be implemented in the form of a program product, which includes program code. When the program product runs on a terminal device, the program code is used to cause the terminal device to execute the steps in the method described in Embodiment 1.
[0092] Among them, the program code for executing the present invention can be written in any combination of one or more programming languages. The program code can be executed entirely on the user device, partially on the user device, executed as an independent software package, partially on the user device and partially on a remote device, or entirely on a remote device.
[0093] Although the specific implementation manners of the present invention have been described above, those skilled in the art should understand that these are only examples, and the protection scope of the present invention is defined by the appended claims. Without departing from the principles and essence of the present invention, those skilled in the art can make various changes or modifications to these implementation manners, but these changes and modifications all fall within the protection scope of the present invention.
Claims
1. A security injection automation method for an information management system based on the C / S architecture, characterized in that, the security injection automation method includes: when the trigger condition is satisfied, perform the following steps: Locate the controls of the information management system; Start an SQL tracing tool, which is used to trace the database to view the data flow; Input an SQL injection statement, which is generated according to the value received by the control; Close the SQL tracing tool; Analyze the injection risk based on a preset rule for the data flow and obtain an analysis result; wherein, the trigger condition includes timed triggering.
2. The security injection automation method according to claim 1, characterized in that, the preset rule includes: If the SQL injection statement includes a preset high-risk SQL statement, the obtained analysis result is a high-risk injection risk; and / or, if data belonging to preset sensitive information is transmitted in plain text, the obtained analysis result is a high-risk injection risk.
3. The security injection automation method according to claim 1, characterized in that, Locating the controls of the information management system specifically includes: Using autoit to locate the Windows standardized controls of the information management system, and using RanorexStudio to locate the Windows non-standardized controls of the information management system; Or, using RanorexStudio to locate the standardized and non-standardized controls of the information management system.
4. The security injection automation method according to claim 1, characterized in that, the security injection automation method further includes sending the analysis result to a preset email via email; and / or, the SQL tracing tool is an SQL Profiler tracer.
5. A security injection automation device for an information management system based on the C / S architecture, characterized in that, the security injection automation device includes: a trigger module, a location module, a tracing module, an input module, and an analysis module; The trigger module is used to call the location module when the trigger condition is satisfied; the location module is used to locate the controls of the information management system, and then call the tracing module to start an SQL tracing tool, which is used to trace the database to view the data flow; The tracing module calls the input module after starting the SQL tracing tool; the input module is used to input an SQL injection statement, which is generated according to the value received by the control, and then call the tracing module to close the SQL tracing tool; The tracing module calls the analysis module after closing the SQL tracing tool, and the analysis module is used to analyze the injection risk based on a preset rule for the data flow and obtain an analysis result; wherein, the trigger condition includes timed triggering.
6. The security injection automation device according to claim 5, characterized in that, the preset rule includes: If the SQL injection statement includes a preset high-risk SQL statement, the obtained analysis result is a high-risk injection risk; And / or, if the data belonging to the preset sensitive information is transmitted in plain text, the obtained analysis result is a high-risk injection risk.
7. The security injection automation device according to claim 5, characterized in that the positioning module is specifically configured to: Use autoit to locate the Windows standard controls of the information management system, and use RanorexStudio to locate the Windows non-standard controls of the information management system; Or, use RanorexStudio to locate the standard and non-standard controls of the information management system.
8. The security injection automation device according to claim 5, characterized in that the security injection automation device further includes a notification module, and the notification module is configured to send the analysis result to a preset email box by email; And / or, the SQL tracing tool is a SQL Profiler tracer.
9. An electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that when the processor executes the program, it implements the security injection automation method for the information management system based on the C / S architecture according to any one of claims 1 to 4.
10. A computer-readable storage medium, on which a computer program is stored, characterized in that when the program is executed by a processor, it implements the steps of the security injection automation method for the information management system based on the C / S architecture according to any one of claims 1 to 4.
Citation Information
Patent Citations
SQL injection attack protection method based on machine learning
CN107566363A