A method and system for scanning unauthorized vulnerabilities based on role account information

Through the scanning method of overprivileges vulnerability based on role account information, the matching difference calculation of sensitive word database and role module is used to solve the problems of low efficiency and weak customization function in the existing technology to detect URL overprivileges vulnerabilities, and achieve rapid and accurate detection and automated processing of overprivileges vulnerabilities.

CN115459959BActive Publication Date: 2025-05-16SHANGHAI JUSHUITAN NETWORK TECH CO LTD +2
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210983837.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-08-17
Publication Date
2025-05-16
Estimated Expiration
2042-08-17

AI Technical Summary

Technical Problem

The existing technology is inefficient, labor-intensive and cannot ensure that all URL parameters are detected when detecting URL overridden vulnerabilities. The customization function of traditional scanners is not strong and the rule base cannot be customized according to business scenarios.

Method used

The overprivileged vulnerability scanning method based on role account information, by obtaining multiple role account information in the business platform to be detected, semantic matching is performed based on the sensitive word database, the matching value of each role module is calculated, and the matching difference is calculated according to the preset role priority, and whether it is within the set threshold range is determined, and whether there is an overprivileged vulnerability.

Benefits of technology

It realizes rapid and accurate determination of overprivileged vulnerabilities. Through semantic matching and matching difference calculation, it can automatically detect and intuitively display the severity of overprivileged vulnerabilities without manual participation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115459959B_ABST
    Figure CN115459959B_ABST
Patent Text Reader

Abstract

The present invention discloses a method and system for scanning unauthorized vulnerability based on role account information, and relates to the technical field of data processing. The method comprises: semantically matching role account information based on a sensitive word database to determine a plurality of first matching values; determining a role module group according to the role corresponding to the role account information; calculating the matching value of each role module according to the plurality of first matching values; sorting the plurality of role modules according to the preset role priority; calculating the matching difference between two adjacent role modules according to the sorted plurality of role modules; for any of the matching differences, if the matching difference is within a set threshold range, outputting a first result; the first result is that there is no unauthorized vulnerability in a business platform to be detected; if the matching difference is not within a set threshold range, outputting a second result; the second result is that there is an unauthorized vulnerability in a business platform to be detected. The present invention matches and calculates based on the role account information, and realizes the rapid and accurate determination of unauthorized vulnerability.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data processing, and in particular to a method and system for scanning unauthorized vulnerabilities based on role account information. Background Art

[0002] Currently, one of the most serious business logic problems on the Internet is lax access control. Lax access control can lead to unauthorized access vulnerabilities. For example, in the Universal Resource Locator (URL) unauthorized access vulnerability, due to the design flaws of web programs, the guessability of the parameters passed in the URL can be used to change the input parameter values, which may cause horizontal unauthorized access and obtain other people's private information. URL vulnerabilities are a very harmful business logic vulnerability that can directly bypass the basic network security service defense. Unauthorized access vulnerabilities are extremely difficult to discover.

[0003] The existing detection of URL unauthorized access vulnerabilities is mainly through testers penetrating web programs and manually detecting vulnerabilities, that is, manually detecting and processing various URL parameters indiscriminately to find URL parameters that store unauthorized access vulnerabilities. This is not only inefficient and labor-intensive, but also cannot ensure that all URL parameters within the test scope are covered. The detection of traditional scanners used in unauthorized access vulnerability scanning is not flexible enough. It should be noted that unauthorized access vulnerabilities are a type of business logic vulnerability with its own special complexity. The customization function of vulnerability scanners on the market is not strong, and it is impossible to customize the rule base according to business scenarios, resulting in it never being as popular and automated as general vulnerability scanners. Summary of the invention

[0004] The purpose of the present invention is to provide a method and system for scanning unauthorized vulnerabilities based on role account information, which performs matching and calculation based on the role account information to achieve rapid and accurate determination of unauthorized vulnerabilities.

[0005] To achieve the above object, the present invention provides the following solutions:

[0006] A method for scanning for unauthorized vulnerabilities based on role account information, comprising:

[0007] Obtain multiple role account information in the business platform to be tested;

[0008] Perform semantic matching on the role account information based on a sensitive word database to determine a plurality of first matching values; the first matching value is a matching value for each of the role account information;

[0009] Determine a role module group according to the role corresponding to the role account information; the role module group includes a plurality of role modules, each of the role modules includes a plurality of role account information corresponding to the same role;

[0010] Calculating a matching value of each of the role modules according to the plurality of the first matching values;

[0011] Sorting the plurality of role modules according to preset role priorities;

[0012] Calculating the matching difference between two adjacent role modules according to the sorted multiple role modules;

[0013] For any of the matching differences, determining whether the matching difference is within a set threshold range;

[0014] If the matching difference is within the set threshold range, a first result is output; the first result is that there is no unauthorized vulnerability in the business platform to be detected;

[0015] If the matching difference is not within the set threshold range, a second result is output; the second result is that the commercial platform to be detected has an unauthorized vulnerability.

[0016] Optionally, the sensitive word database includes set sensitive words and sensitive values ​​corresponding to the set sensitive words;

[0017] The performing semantic matching on the role account information based on the sensitive word database to determine a plurality of first matching values ​​specifically includes:

[0018] Using a regular matching expression, semantically matching the set sensitive words in the sensitive word database with the role account information to match the marked sensitive words; the marked sensitive words are any of the set sensitive words;

[0019] According to the sensitivity value corresponding to the set sensitive word, the sum of the sensitivity values ​​corresponding to all the marked sensitive words is calculated to obtain a first matching value.

[0020] Optionally, calculating the matching value of each role module according to the plurality of first matching values ​​specifically includes:

[0021] Determine a first matching value corresponding to each role account information in the role module;

[0022] The first matching values ​​corresponding to the plurality of role account information are added together to determine the matching value of the role module.

[0023] Optionally, the roles corresponding to the role account information include financial, personnel, administrative and technical staff.

[0024] Optionally, the obtaining of multiple role account information in the business platform to be detected specifically includes:

[0025] Collect WEB resource information and HTTP traffic information; the WEB resource information includes the uniform resource locator URL, Header information, Method request method and Body request body; the HTTP traffic information comes from WAF equipment, RASP equipment and ISAT equipment;

[0026] According to the WEB resource information and HTTP flow information, multiple role account information in the business platform to be detected is determined.

[0027] To achieve the above object, the present invention also provides the following technical solutions:

[0028] An unauthorized vulnerability scanning system based on role account information, comprising:

[0029] The module for determining the content to be detected is used to obtain the account information of multiple roles in the business platform to be detected;

[0030] A first matching calculation module is used to perform semantic matching on the role account information based on a sensitive word database to determine a plurality of first matching values; the first matching value is a matching value for each of the role account information;

[0031] A group determination module, used to determine a role module group according to the role corresponding to the role account information; the role module group includes a plurality of role modules, each of which includes a plurality of role account information corresponding to the same role;

[0032] A second matching calculation module, used for calculating a matching value of each of the role modules according to a plurality of the first matching values;

[0033] A sorting module, used for sorting the plurality of role modules according to preset role priorities;

[0034] A matching difference calculation module, used for calculating the matching difference between two adjacent role modules according to the sorted plurality of role modules;

[0035] A judging module, used for judging, for any of the matching differences, whether the matching difference is within a set threshold range;

[0036] A first result module, configured to output a first result if the matching difference is within a set threshold range; the first result is that there is no unauthorized vulnerability in the business platform to be detected;

[0037] The second result module is used to output a second result if the matching difference is not within a set threshold range; the second result is that the commercial platform to be detected has an unauthorized vulnerability.

[0038] Optionally, the sensitive word database includes set sensitive words and sensitive values ​​corresponding to the set sensitive words;

[0039] The first matching calculation module specifically includes:

[0040] A matching submodule, for using a regular matching expression to semantically match the set sensitive words in the sensitive word database with the role account information to match the marked sensitive words; the marked sensitive words are any of the set sensitive words;

[0041] The first calculation submodule is used to calculate the sum of the sensitivity values ​​corresponding to all the marked sensitive words according to the sensitivity values ​​corresponding to the set sensitive words, so as to obtain a first matching value.

[0042] Optionally, the second matching calculation module specifically includes:

[0043] A matching value determination submodule, used to determine a first matching value corresponding to each role account information in the role module;

[0044] The second calculation submodule is used to add the first matching values ​​corresponding to the multiple role account information to determine the matching value of the role module.

[0045] Optionally, the module for determining content to be detected specifically includes:

[0046] The path resource determination submodule is used to collect WEB resource information and HTTP traffic information; the WEB resource information includes the uniform resource locator URL, Header information, Method request method and Body request body; the HTTP traffic information comes from the WAF device, RASP device and ISAT device;

[0047] The account information determination submodule is used to determine the account information of multiple roles in the business platform to be detected according to the WEB resource information and HTTP flow information.

[0048] According to the specific embodiments provided by the present invention, the present invention discloses the following technical effects:

[0049] The present invention provides a method and system for scanning unauthorized vulnerability based on role account information. Based on a sensitive word database, semantic matching is performed on multiple role account information in a business platform to be detected, and a matching value of each role account information is determined; then, the multiple role account information is divided into modules according to the roles corresponding to the role account information to obtain multiple role modules, and the matching value of each role module is calculated. Multiple role modules are sorted according to the preset role priority, so that the role modules with high authority (or high weight) are in a similar position, and then the matching difference calculation is performed on the sorted role modules in pairs, and it is judged whether the matching difference is within a set threshold range. If the matching difference is within the set threshold range, there is no unauthorized vulnerability in the business platform to be detected; if the matching difference is not within the set threshold range, it means that there is an unauthorized vulnerability in the business platform to be detected. The present invention determines the matching value of the role account information in the business platform to be detected through semantic matching, and then determines whether there is an unauthorized vulnerability through the size of the matching value, thereby realizing the rapid determination of the unauthorized vulnerability, and intuitively displays the severity of the unauthorized vulnerability through the matching difference, without manual participation in the whole process. BRIEF DESCRIPTION OF THE DRAWINGS

[0050] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative labor.

[0051] Figure 1 It is a flow chart of the unauthorized vulnerability scanning method based on role account information of the present invention;

[0052] Figure 2 It is a structural schematic diagram of the unauthorized vulnerability scanning system based on role account information of the present invention. DETAILED DESCRIPTION

[0053] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0054] In order to make the purpose, features and advantages of the present invention more obvious and easy to understand, the present invention is further described in detail below with reference to the accompanying drawings and specific embodiments.

[0055] Embodiment 1

[0056] like Figure 1 As shown, this embodiment provides a method for scanning for unauthorized vulnerabilities based on role account information, including:

[0057] Step 100, obtaining multiple role account information in the business platform to be detected. Specifically, step 100 includes:

[0058] 1) Collect WEB resource information and HTTP traffic information; the WEB resource information includes the uniform resource locator URL, Header information, Method request method and Body request body; the HTTP traffic information comes from WAF devices, RASP devices and ISAT devices.

[0059] 2) According to the WEB resource information and HTTP traffic information, multiple role account information in the business platform to be detected is determined. Different role accounts in a system have unique permissions for different functions, and the role accounts in different systems can be the same or different. Specifically, the roles corresponding to the role account information include financial, personnel, administrative and technical staff. Therefore, the role accounts in a system include ordinary financial employee accounts, financial supervisor employee accounts, personnel supervisor accounts, ordinary personnel employee accounts, and administrative supervisor accounts, etc.

[0060] The finance general account may contain text content such as amount, contract, and total, as well as corresponding numerical content, while the personnel general employee account or the administrative general employee account cannot display the above content; the finance supervisor employee account may contain text content such as the name, age, and length of service of different employees, while the finance general employee account cannot display the above content. Specifically, the permissions between different role accounts can be configured according to actual needs.

[0061] Step 200, semantically matching the role account information based on the sensitive word database to determine multiple first matching values; the first matching value is the matching value of each role account information. The sensitive word database includes set sensitive words and sensitive numerical values ​​corresponding to the set sensitive words; specifically, the set sensitive words and sensitive numerical values ​​can be set according to actual needs, and the sensitive numerical values ​​can also be set as replacement actions, for example: when matching the set sensitive words, the set sensitive words are replaced with a certain mark string or replaced with a space, etc.

[0062] Preferably, step 200 specifically includes:

[0063] 1) Using a regular matching expression, semantically matching the set sensitive words in the sensitive word database with the role account information to match the marked sensitive words; the marked sensitive words are any of the set sensitive words.

[0064] 2) According to the sensitivity value corresponding to the set sensitive word, the sum of the sensitivity values ​​corresponding to all the marked sensitive words is calculated to obtain a first matching value.

[0065] Step 300, determining a role module group according to the role corresponding to the role account information; the role module group includes a plurality of role modules, each of the role modules includes a plurality of role account information corresponding to the same role.

[0066] Step 400, calculating the matching value of each of the role modules according to the plurality of the first matching values;

[0067] Specifically, step 400 includes: determining a first matching value corresponding to each role account information in the role module; and adding the first matching values ​​corresponding to multiple role account information to determine the matching value of the role module.

[0068] Step 500: sort the multiple role modules according to preset role priorities.

[0069] Step 600: Calculate the matching difference between two adjacent role modules according to the sorted plurality of role modules.

[0070] Step 700: for any of the matching difference values, determine whether the matching difference value is within a set threshold range.

[0071] Step 800: If the matching difference is within a set threshold range, a first result is output; the first result is that there is no unauthorized vulnerability in the business platform to be detected.

[0072] Step 900: If the matching difference is not within the set threshold range, a second result is output; the second result is that the business platform to be detected has an unauthorized vulnerability.

[0073] It should be noted that a business platform contains different merchant accounts, and different merchant accounts contain accounts of different roles. According to different merchant accounts and different role accounts, multiple types of accounts can be obtained through configuration. In a specific embodiment, the multiple role account information in the business platform to be detected includes financial employee accounts, financial supervisor accounts, human resources employee accounts, human resources supervisor accounts, administrative employee accounts, and administrative supervisor accounts. The corresponding unauthorized vulnerability scanning method based on role account information includes:

[0074] 1) For each test resource, use different session identity information such as the financial employee account, financial supervisor account, human resources employee account, human resources supervisor account, administrative employee account and administrative supervisor account to construct a session request, send it to the WEB server, receive the server Response and store it, and obtain the page content corresponding to the financial employee account, financial supervisor account, human resources employee account, human resources supervisor account, administrative employee account and administrative supervisor account respectively.

[0075] 2) For the stored server Response, the staff can flexibly configure the content matching rules as needed. The rules include sensitive words in different employee accounts and different supervisor accounts, and weights are assigned to different sensitive words according to their importance in the system. Generally speaking, the more important the sensitive word is, the greater the weight assigned, that is, the larger the corresponding sensitivity value. The weight assigned to sensitive words corresponding to different roles is also different. Generally, the more important the role, the greater the weight assigned. For example, the assigned scores of financial employees and financial supervisors are larger than those of administrative supervisors and administrative employees. The sensitive word database is determined based on the sensitive words set above and the assignment of each sensitive word. In addition, the assigned values ​​​​obtained by different sensitive words can be positive or negative.

[0076] 3) According to the set sensitive words in the sensitive word database, sensitive words in the accounts of financial employees, sensitive words in the accounts of financial supervisors, sensitive words in the accounts of personnel employees, sensitive words in the accounts of personnel supervisors, sensitive words in the accounts of administrative employees, and sensitive words in the accounts of administrative supervisors are respectively filtered.

[0077] Then, calculations are performed based on the scores assigned to each sensitive word to respectively calculate the scores corresponding to the finance employee account, finance supervisor account, personnel employee account, personnel supervisor account, administrative employee account and administrative supervisor account, i.e., the first matching value.

[0078] 4) According to the roles corresponding to the above-mentioned accounts, they are divided into financial module, personnel module and administrative module, and then the matching value of each module is calculated accordingly. The matching value of the financial module = the first matching value corresponding to the financial employee account + the first matching value corresponding to the financial supervisor account, the matching value of the personnel module = the first matching value corresponding to the personnel employee account + the first matching value corresponding to the personnel supervisor account, and the matching value of the administrative module = the first matching value corresponding to the administrative employee account + the first matching value corresponding to the administrative supervisor account.

[0079] 5) In the e-commerce platform, the account priority related to the amount will generally be higher, and the corresponding sensitive word value will also be higher; followed by personnel and administration. For different platforms, the priorities of different roles may be different. In this specific embodiment, the preset role priority is set as: finance>personnel>administration. Based on this, the matching value of the financial module is subtracted from the matching value of the personnel module to calculate the matching difference between the financial module and the personnel module, and the matching value of the administrative module is subtracted from the matching value of the personnel module to calculate the matching difference between the personnel module and the administrative module.

[0080] 6) For the same resource, the response results obtained according to different session identities are different, and the corresponding scores are also different. Therefore, it is possible to determine whether the resource has an unauthorized access vulnerability based on the response results of different session identities for the same resource. Based on this, it is determined whether the matching difference between the financial module and the personnel module is within the set threshold range to obtain the first judgment result. Specifically, if the first judgment result indicates that the matching difference is within the threshold range, that is, the matching difference is higher than a certain set value, it means that there is no unauthorized vulnerability in the business platform to be tested, that is, the score of one party's authorized account is high and the score of the other party's low-authorized account is low, which can be recorded as safe. If the first judgment result indicates that the matching difference is not within the threshold range, that is, the matching difference is lower than a certain set value, it means that there is an unauthorized vulnerability in the business platform to be tested, that is, the score of one party's authorized account is similar to that of the other party's low-authorized account, which needs to be recorded as possible problems with the financial module and the personnel module, and it is necessary to combine the score to determine which module the vulnerability is specifically in.

[0081] Similarly, the matching difference between the personnel module and the administrative module is judged and processed to obtain a second judgment result.

[0082] When both the first judgment result and the second judgment result are that there is no unauthorized vulnerability, it means that the entire business platform to be tested does not have an unauthorized vulnerability; when one of the first judgment result and the second judgment result is that there is an unauthorized vulnerability, it means that the entire business platform to be tested has an unauthorized vulnerability. In addition, if three judgment results are finally obtained, if all three judgment results are that there is no unauthorized vulnerability, it means that the entire business platform to be tested does not have an unauthorized vulnerability; if any of the three judgment results is that there is an unauthorized vulnerability, it means that the entire business platform to be tested has an unauthorized vulnerability.

[0083] In actual applications, the matching value of the financial module and the matching value of the personnel module can also be added to obtain the matching sum value, and whether to perform difference calculation or sum calculation can be preset by the staff.

[0084] 7) In a specific embodiment, after the result that the detected business platform has an unauthorized vulnerability is obtained through the role module, the matching value can be further determined for the specific role account information (finance employee and financial supervisor) in the role module (finance module), specifically:

[0085] Determine the specific URL paths corresponding to the financial staff and the financial supervisor (for example, financial staff: / AA / bb / 1, financial supervisor: / AA / bb / 2), and then determine the average scores of the detection under different paths. In this embodiment, the average score of the detection under the path of / AA / bb is set to 100. If the path score of / AA / bb / 1 is lower than the average score of 100-the standard deviation of the scores of all pages under the path, it means that the judgment result is no problem; if the score is higher than the average score of 100+the standard deviation of the scores of all pages under the path, it means that the judgment result is that there is a problem. Similarly, the score under the path of / AA / bb / 2 can be judged and the result can be obtained, thereby more intelligently reflecting the difference and comparison of the scanning results under different paths (business modules).

[0086] Embodiment 2

[0087] like Figure 2 As shown, this embodiment provides an unauthorized vulnerability scanning system based on role account information, including:

[0088] The module 101 for determining the content to be detected is used to obtain the account information of multiple roles in the business platform to be detected. The module 101 for determining the content to be detected specifically includes:

[0089] The path resource determination submodule is used to collect WEB resource information and HTTP traffic information; the WEB resource information includes the uniform resource locator URL, Header header information, Method request method and Body request body; the HTTP traffic information comes from the WAF device, RASP device and ISAT device.

[0090] The account information determination submodule is used to determine the account information of multiple roles in the business platform to be detected according to the WEB resource information and HTTP flow information.

[0091] The first matching calculation module 201 is used to perform semantic matching on the role account information based on a sensitive word database to determine a plurality of first matching values; the first matching value is a matching value for each of the role account information.

[0092] The sensitive word database includes set sensitive words and sensitive values ​​corresponding to the set sensitive words; the first matching calculation module 201 specifically includes a matching submodule and a first calculation submodule.

[0093] The matching submodule is used to use a regular matching expression to semantically match the set sensitive words in the sensitive word database with the role account information to match the marked sensitive words; the marked sensitive words are any of the set sensitive words; the first calculation submodule is used to calculate the sum of the sensitive values ​​corresponding to all the marked sensitive words according to the sensitive values ​​corresponding to the set sensitive words to obtain a first matching value.

[0094] The group determination module 301 is used to determine a role module group according to the role corresponding to the role account information; the role module group includes multiple role modules, and each of the role modules includes multiple role account information corresponding to the same role.

[0095] The second matching calculation module 401 is used to calculate the matching value of each of the role modules according to the plurality of the first matching values.

[0096] The second matching calculation module 401 specifically includes:

[0097] The matching value determination submodule is used to determine the first matching value corresponding to each role account information in the role module; the second calculation submodule is used to add the first matching values ​​corresponding to multiple role account information to determine the matching value of the role module.

[0098] The sorting module 501 is used to sort the multiple role modules according to preset role priorities.

[0099] The matching difference calculation module 601 is used to calculate the matching difference between two adjacent role modules according to the sorted multiple role modules.

[0100] The judgment module 701 is used to judge whether any of the matching differences is within a set threshold range.

[0101] The first result module 801 is used to output a first result if the matching difference is within a set threshold range; the first result is that there is no unauthorized vulnerability in the business platform to be detected.

[0102] The second result module 901 is used to output a second result if the matching difference is not within a set threshold range; the second result is that the business platform to be detected has an unauthorized vulnerability.

[0103] In a practical application, the unauthorized vulnerability scanning system based on role account information in this embodiment can be set as a vulnerability scanner, and the working process of the vulnerability scanner is as follows:

[0104] First, select the resources to be scanned, and filter them according to the domain name HOST, URL keywords, and sources. Then, construct an HTTP request or replace the Cookie, Token, and SessionID information in the existing HTTP request based on the role account selected by the user. Secondly, distribute the constructed HTTP request to each scanning node, obtain the server Response content and page screenshots, and store them in the database. Furthermore, use the preset analyzer rules to replace or score the page content according to the matching mode and priority, and update the records. Finally, display the scanning task results and detection results.

[0105] Compared with the prior art, the present invention also has the following advantages:

[0106] (1) The present invention focuses on content analysis and can also intuitively display the scanning vulnerability detection results and vulnerability levels by assigning scores, thereby solving the problem that traditional scanners cannot simultaneously scan vertical and horizontal unauthorized vulnerabilities of multiple accounts.

[0107] (2) The present invention can be applied in formal or test environments, data point testing, etc. For example, a unique key record is entered in account A. If it is scanned in account B, it proves that there is an unauthorized access.

[0108] The various embodiments in this specification are described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between the various embodiments can be referenced to each other.

[0109] The principles and implementation methods of the present invention are described in this article using specific examples. The description of the above embodiments is only used to help understand the method and core idea of ​​the present invention. At the same time, for those skilled in the art, according to the idea of ​​the present invention, there will be changes in the specific implementation methods and application scope. In summary, the content of this specification should not be understood as limiting the present invention.

Claims

1. A method for scanning unauthorized vulnerabilities based on role account information, characterized in that: The unauthorized vulnerability scanning method comprises: Obtain multiple role account information in the business platform to be tested; Perform semantic matching on the role account information based on a sensitive word database to determine a plurality of first matching values; the first matching value is a matching value for each of the role account information; Determine a role module group according to the role corresponding to the role account information; the role module group includes a plurality of role modules, each of the role modules includes a plurality of role account information corresponding to the same role; Calculating a matching value of each of the role modules according to the plurality of the first matching values; Sorting the plurality of role modules according to preset role priorities; Calculating the matching difference between two adjacent role modules according to the sorted plurality of role modules; For any of the matching differences, determining whether the matching difference is within a set threshold range; If the matching difference is within the set threshold range, a first result is output; the first result is that there is no unauthorized vulnerability in the business platform to be detected; If the matching difference is not within the set threshold range, a second result is output; the second result is that the commercial platform to be detected has an unauthorized vulnerability.

2. The unauthorized vulnerability scanning method based on role account information according to claim 1 is characterized in that: The sensitive word database includes set sensitive words and sensitive values ​​corresponding to the set sensitive words; The performing semantic matching on the role account information based on the sensitive word database to determine a plurality of first matching values ​​specifically includes: Using a regular matching expression, semantically matching the set sensitive words in the sensitive word database with the role account information to match the marked sensitive words; the marked sensitive words are any of the set sensitive words; According to the sensitivity value corresponding to the set sensitive word, the sum of the sensitivity values ​​corresponding to all the marked sensitive words is calculated to obtain a first matching value.

3. The unauthorized vulnerability scanning method based on role account information according to claim 1 is characterized in that: The step of calculating the matching value of each role module according to the plurality of the first matching values ​​specifically includes: Determine a first matching value corresponding to each role account information in the role module; The first matching values ​​corresponding to the plurality of role account information are added together to determine the matching value of the role module.

4. The unauthorized vulnerability scanning method based on role account information according to claim 1 is characterized in that: The roles corresponding to the role account information include financial, human resources, administrative and technical staff.

5. The unauthorized vulnerability scanning method based on role account information according to claim 1 is characterized in that: The obtaining of multiple role account information in the business platform to be detected specifically includes: Collect WEB resource information and HTTP traffic information; the WEB resource information includes the uniform resource locator URL, Header information, Method request method and Body request body; the HTTP traffic information comes from WAF equipment, RASP equipment and ISAT equipment; According to the WEB resource information and HTTP flow information, multiple role account information in the business platform to be detected is determined.

6. An unauthorized vulnerability scanning system based on role account information, characterized in that: The unauthorized vulnerability scanning system based on role account information includes: The module for determining the content to be detected is used to obtain the account information of multiple roles in the business platform to be detected; A first matching calculation module is used to perform semantic matching on the role account information based on a sensitive word database to determine a plurality of first matching values; the first matching value is a matching value for each of the role account information; A group determination module, used to determine a role module group according to the role corresponding to the role account information; the role module group includes a plurality of role modules, each of which includes a plurality of role account information corresponding to the same role; A second matching calculation module, used for calculating a matching value of each of the role modules according to a plurality of the first matching values; A sorting module, used for sorting the plurality of role modules according to preset role priorities; A matching difference calculation module, used for calculating the matching difference between two adjacent role modules according to the sorted plurality of role modules; A judging module, used for judging, for any of the matching differences, whether the matching difference is within a set threshold range; A first result module, configured to output a first result if the matching difference is within a set threshold range; the first result is that there is no unauthorized vulnerability in the business platform to be detected; The second result module is used to output a second result if the matching difference is not within a set threshold range; the second result is that the commercial platform to be detected has an unauthorized vulnerability.

7. The unauthorized vulnerability scanning system based on role account information according to claim 6 is characterized in that: The sensitive word database includes set sensitive words and sensitive values ​​corresponding to the set sensitive words; The first matching calculation module specifically includes: A matching submodule, for using a regular matching expression to semantically match the set sensitive words in the sensitive word database with the role account information to match the marked sensitive words; the marked sensitive words are any of the set sensitive words; The first calculation submodule is used to calculate the sum of the sensitivity values ​​corresponding to all the marked sensitive words according to the sensitivity values ​​corresponding to the set sensitive words, so as to obtain a first matching value.

8. The unauthorized vulnerability scanning system based on role account information according to claim 6 is characterized in that: The second matching calculation module specifically includes: A matching value determination submodule, used to determine a first matching value corresponding to each role account information in the role module; The second calculation submodule is used to add the first matching values ​​corresponding to the multiple role account information to determine the matching value of the role module.

9. The unauthorized vulnerability scanning system based on role account information according to claim 6 is characterized in that: The module for determining the content to be detected specifically includes: The path resource determination submodule is used to collect WEB resource information and HTTP traffic information; the WEB resource information includes the uniform resource locator URL, Header information, Method request method and Body request body; the HTTP traffic information comes from the WAF device, RASP device and ISAT device; The account information determination submodule is used to determine the account information of multiple roles in the business platform to be detected according to the WEB resource information and HTTP flow information.

Citation Information

Patent Citations

  • Out-of-authority vulnerability detection method and device, computer equipment and medium

    CN111683047A

  • Unauthorized vulnerability detection method, device, storage medium and computer equipment

    CN112115475A