Horizontal privilege escalation detection method and device

By receiving user requests, capturing packets to identify the overprivileged interface and performing orchestration process, the problem of preventing anti-replay and anti-tampering reinforcement systems in the prior art is solved, and the rapid and accurate level overprivileged detection of the encryption system is achieved.

CN115460014BActive Publication Date: 2025-07-11CCB FINTECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211176940.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-09-26
Publication Date
2025-07-11
Estimated Expiration
2042-09-26

AI Technical Summary

Technical Problem

The existing level of overprivileged detection methods cannot effectively deal with application systems that have been replayed and anti-tampered and reinforcing, as well as encrypted application systems, resulting in inaccurate test results or inability to identify overprivileged interfaces.

Method used

By receiving user requests, capturing packets to obtain business data, identifying unauthorized interfaces, using anti-playback, anti-tampering and anti-parameter encrypted orchestration nodes for process orchestration, realizing automated testing and obtaining test results.

Benefits of technology

An application system that can effectively detect anti-playback and anti-tampering reinforcement, and a system that should be partially or fully encrypted by messages, achieving fast and accurate horizontal overright detection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115460014B_ABST
    Figure CN115460014B_ABST
Patent Text Reader

Abstract

The present invention discloses a horizontal privilege escalation detection method and device, which are applied to the technical fields of network security and automated testing. The method includes: receiving a service request initiated by a user at the client of the system under test; obtaining service data captured for the system under test based on packet capture parameters; identifying a privilege escalation interface from the service data based on the eigenvalue of the privilege escalation parameter, where the privilege escalation interface includes a privilege escalation parameter; performing process choreography on the combined order of pre-configured choreography nodes involved in the privilege escalation interface to obtain a choreographed process, where the choreography nodes include a replay prevention and tampering prevention choreography node and a parameter encryption choreography node; performing automated testing based on the choreographed process and horizontal privilege escalation vulnerability confirmation parameters to obtain a test result, where the test result includes the identified privilege escalation interface. The present invention can achieve horizontal privilege escalation detection, especially for application systems that have been fortified against replay and tampering or encrypted application systems, and has good detection effects.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical fields of network security and automated testing, and particularly to a horizontal privilege escalation detection method and device. Background Art

[0002] This section aims to provide background or context for the embodiments of the present invention described in the claims. The descriptions herein are not admitted to be prior art merely because they are included in this section.

[0003] With the rapid development of the Internet, the types of applications are increasing, and the coverage of user groups is gradually expanding. At the same time, network security problems occur frequently, and among them, the privilege escalation problem ranks first in network security problems. Therefore, after the system is developed, sufficient security testing should be carried out, but manual testing has problems such as high labor costs, long time consumption, and omission of test cases.

[0004] Currently, there are a small number of automated horizontal privilege escalation testing solutions, but these solutions have the following problems:

[0005] (1) Unable to handle application systems that have adopted anti-replay and anti-tampering measures: that is, the existing methods do not recognize the pre-logic of the headers or parameters in the request message, and the test cases cannot pass the anti-replay and anti-tampering verification and thus become ineffective. Before the front-end sends a request to the back-end, it may perform pre-processing on some fields or parameters of the request header, such as adding a timestamp field or a signature field.

[0006] (2) Unable to handle application systems that have adopted partial or full encryption of the message: that is, the existing methods do not recognize the situation where some fields or all fields in the request message are encrypted for transmission. Therefore, for the case of two-way encryption of the communication message, pre-encryption and post-encryption processing are required. Simply modifying the privilege escalation fields will surely cause an error in the back-end and ultimately affect the correctness of the execution result of the horizontal privilege escalation test case. Even some application systems also encrypt the returned message. Without the corresponding decryption arrangement, the correct privilege escalation parameters cannot be recognized. Summary of the Invention

[0007] Embodiments of the present invention provide a horizontal privilege escalation detection method to achieve horizontal privilege escalation detection, especially for application systems that have been fortified with anti-replay and anti-tampering measures or encrypted application systems, with good detection effects. The method includes:

[0008] Receiving a service request initiated by a user at the client of the system under test;

[0009] Obtaining service data captured from the system under test based on the packet capture parameters;

[0010] Identifying a privilege escalation interface from the service data based on the privilege escalation parameter eigenvalue, where the privilege escalation interface includes privilege escalation parameters;

[0011] Perform process choreography on the combined order of pre-configured choreography nodes involved in the unauthorized interface to obtain a choreography process. The choreography nodes include a replay prevention and tampering prevention choreography node and a parameter encryption choreography node;

[0012] Based on the choreography process and horizontal privilege escalation vulnerability confirmation parameters, perform automated testing to obtain test results. The test results include the identified unauthorized interfaces.

[0013] An embodiment of the present invention further provides a horizontal privilege escalation detection device for implementing horizontal privilege escalation detection, especially for application systems that have been fortified against replay and tampering, with good detection effects. The device includes:

[0014] A service request receiving module for receiving service requests initiated by users at the client of the system under test;

[0015] A packet capture module for obtaining service data captured from the system under test based on packet capture parameters;

[0016] An unauthorized interface identification module for identifying unauthorized interfaces from the service data based on unauthorized parameter feature values. The unauthorized interfaces include unauthorized parameters;

[0017] A choreography module for performing process choreography on the combined order of pre-configured choreography nodes involved in the unauthorized interface to obtain a choreography process. The choreography nodes include a replay prevention and tampering prevention choreography node and a parameter encryption choreography node;

[0018] An automated testing module for performing automated testing based on the choreography process and horizontal privilege escalation vulnerability confirmation parameters to obtain test results. The test results include the identified unauthorized interfaces.

[0019] An embodiment of the present invention further provides a computer device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, the above-mentioned horizontal privilege escalation detection method is implemented.

[0020] An embodiment of the present invention further provides a computer-readable storage medium storing a computer program, and when the computer program is executed by a processor, the above-mentioned horizontal privilege escalation detection method is implemented.

[0021] An embodiment of the present invention further provides a computer program product, including a computer program, and when the computer program is executed by a processor, the above-mentioned horizontal privilege escalation detection method is implemented.

[0022] In an embodiment of the present invention, a service request initiated by a user at a client of a system under test is received; based on packet capture parameters, service data for packet capture of the system under test is obtained; based on an overprivilege parameter eigenvalue, an overprivilege interface is identified from the service data, and the overprivilege interface includes overprivilege parameters; the combined order of preconfigured orchestration nodes related to the overprivilege interface is flow-orchestrated to obtain an orchestration process, and the orchestration nodes include a replay prevention and tamper prevention orchestration node and a parameter encryption orchestration node; based on the orchestration process and horizontal overprivilege vulnerability confirmation parameters, automated testing is performed to obtain a test result, and the test result includes the determined overprivilege interface. Compared with the prior art, the combined order of preconfigured orchestration nodes related to the overprivilege interface can be flow-orchestrated to obtain an orchestration process, and the orchestration nodes include a replay prevention and tamper prevention orchestration node and a parameter encryption orchestration node. Therefore, it can cope with application systems that have adopted replay prevention and tamper prevention, and application systems that have adopted partial or full encryption of message packets; in addition, due to the orchestration, automated testing can be achieved, the test result can be obtained quickly, and the detection effect is good. BRIEF DESCRIPTION OF THE DRAWINGS

[0023] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the following drawings are only some embodiments of the present invention, and those of ordinary skill in the art can also obtain other drawings based on these drawings without creative efforts. In the drawings:

[0024] Figure 1 is the flow of the horizontal overprivilege detection method in the embodiment of the present invention Figure 1 ;

[0025] Figure 2 is the flow of the horizontal overprivilege detection method in the embodiment of the present invention Figure 2 ;

[0026] Figure 3 is the flow of the horizontal overprivilege detection method in the embodiment of the present invention Figure 3 ;

[0027] Figure 4 is the flow of the horizontal overprivilege detection method in the embodiment of the present invention Figure 4 ;

[0028] Figure 5 is the flow of the horizontal overprivilege detection method in the embodiment of the present invention Figure 5 ;

[0029] Figure 6 is the schematic diagram of the horizontal overprivilege detection device in the embodiment of the present invention Figure 1 ;

[0030] Figure 7 Schematic diagram of the horizontal privilege escalation detection device in the embodiments of the present invention Figure 2 ;

[0031] Figure 8 Schematic diagram of the horizontal privilege escalation detection device in the embodiments of the present invention Figure 3 ;

[0032] Figure 9 Schematic diagram of the horizontal privilege escalation detection device in the embodiments of the present invention Figure 4 ;

[0033] Figure 10 Schematic diagram of the horizontal privilege escalation detection device in the embodiments of the present invention Figure 5 ;

[0034] Figure 11 Schematic diagram of the computer device in the embodiments of the present invention. Detailed implementation manners

[0035] To make the objectives, technical solutions and advantages of the embodiments of the present invention clearer and more understandable, the embodiments of the present invention will be further described in detail below with reference to the accompanying drawings. Herein, the illustrative embodiments of the present invention and their descriptions are used to explain the present invention, but not to limit the present invention.

[0036] First, the terms related to the present invention will be explained.

[0037] Network request: It refers to the call request sent from the browser side to the server side, which has the same meaning as interface call.

[0038] Privilege escalation: In an application system, different users have different permissions, and the resources that users with different permissions can access are also different. When a user can access resources that originally do not belong to himself / herself, privilege escalation occurs. Privilege escalation is divided into horizontal privilege escalation and vertical privilege escalation. The present invention is directed to horizontal privilege escalation.

[0039] Horizontal privilege escalation: It means that users with the same permissions can access each other's resources by escalating privileges.

[0040] Application layer packet capture: Network request capture is performed by setting up a proxy. When a user accesses background resources through a browser, all network requests of the browser are captured. Various data initiated by the request can be viewed in the captured request packet, such as the URI of the request, the headers and parameters of the request, and the headers and parameters of the response.

[0041] Packet capture parameters: When performing application layer packet capture, all network requests can be captured by default. In order to perform targeted capture, packet capture parameters can be set to capture only specific requests. The packet capture parameters include setting the domain name, URI, request method (such as GET and POST), etc.

[0042] Penetration testing: A testing method that simulates real attacks on application systems to detect security vulnerabilities in information systems, uses the vulnerabilities to break through the security control mechanism of the information system, and then evaluates the actual security risks faced by the information system. Horizontal privilege escalation testing is an important part of penetration testing work.

[0043] Replay attack: A replay attack is a secondary request. That is, the attacker captures the HTTP message of the request through packet capture, and then copies or modifies the HTTP request header and request body and sends it to the server again. That is, the server processes two requests, first processes the normal HTTP request, and then processes the exactly same or tampered parameter HTTP request sent by the attacker.

[0044] Replay prevention: Prevent replay attacks to a certain extent or increase the difficulty of replay attacks through technical means.

[0045] Tamper prevention: After the attacker tampers with the captured HTTP request message, a replay attack can be carried out to obtain sensitive data of the system. Tamper prevention and replay prevention often complement each other. Tamper prevention means preventing replay attacks to a certain extent or increasing the difficulty of replay attacks through technical means.

[0046] Orchestration engine: During the horizontal privilege escalation testing process, it is necessary to modify the parameters with privilege escalation and then initiate a simulated replay attack after processing according to the processing logic of the front end for the message. There are various implementation methods and processes for the processing logic of the front end for the message. The work of the orchestration engine is to identify, maintain, and implement these logics to facilitate simulated replay attacks and achieve automated horizontal privilege escalation testing. Based on the packet capture results at the application layer, the orchestration engine automatically analyzes the privilege escalation parameters, identifies the requests and processing logics that need to be orchestrated, and automatically generates global orchestration, proprietary orchestration, and process orchestration after manual review.

[0047] Global orchestration: Refers to the orchestration applicable to all requests.

[0048] Proprietary orchestration: Refers to the orchestration applicable to specified partial requests.

[0049] Process orchestration: After modifying the privilege escalation parameters for the captured network requests, it is necessary to orchestrate the processing process and process the request URI, headers, and request body. The processing processes of different requests are different and need to be orchestrated.

[0050] Figure 1 For the process of the horizontal privilege escalation detection method in the embodiments of the present invention Figure 1 , including:

[0051] Step 101, receiving a service request initiated by a user at the client of the system under test;

[0052] Step 102: Obtain the service data captured for the system under test based on the packet capture parameters;

[0053] Step 103: Identify the privilege escalation interfaces from the service data based on the privilege escalation parameter eigenvalues, where the privilege escalation interfaces include privilege escalation parameters;

[0054] Step 104: Perform process choreography on the combined order of the pre-configured choreography nodes involved in the privilege escalation interfaces to obtain a choreography process, where the choreography nodes include anti-replay and anti-tampering choreography nodes, and parameter encryption choreography nodes;

[0055] Step 105: Perform automated testing based on the choreography process and horizontal privilege escalation vulnerability confirmation parameters to obtain a test result, where the test result includes the identified privilege escalation interfaces.

[0056] In an embodiment of the present invention, a service request initiated by a user at the client of the system under test is received; the service data captured for the system under test is obtained based on the packet capture parameters; the privilege escalation interfaces are identified from the service data based on the privilege escalation parameter eigenvalues, where the privilege escalation interfaces include privilege escalation parameters; the combined order of the pre-configured choreography nodes involved in the privilege escalation interfaces is choreographed to obtain a choreography process, where the choreography nodes include anti-replay and anti-tampering choreography nodes, and parameter encryption choreography nodes; automated testing is performed based on the choreography process and horizontal privilege escalation vulnerability confirmation parameters to obtain a test result, where the test result includes the identified privilege escalation interfaces. Compared with the prior art, the combined order of the pre-configured choreography nodes involved in the privilege escalation interfaces can be choreographed to obtain a choreography process, where the choreography nodes include anti-replay and anti-tampering choreography nodes, and parameter encryption choreography nodes. Therefore, it can cope with application systems that have adopted anti-replay and anti-tampering measures, and application systems that have adopted partial or full encryption of message parts; in addition, due to the choreography, automated testing can be realized, and the test result can be obtained quickly, and the detection effect is good.

[0057] Figure 2 This is the flow of the horizontal privilege escalation detection method in an embodiment of the present invention Figure 2 In one embodiment, before receiving the service request initiated by the user at the client of the system under test, it further includes:

[0058] Step 201: Initialize the system under test after loading the packet capture parameters, horizontal privilege escalation vulnerability confirmation parameters, privilege escalation parameter eigenvalues, pre-configured choreography nodes, and encryption components into the system under test.

[0059] Assume that the tester creates a new test project, names this test project horizon_test_pro, and then automatically runs this method to initialize the system under test.

[0060] The purpose of setting the packet capture parameters is to accurately capture the requests that need to be concerned about horizontal privilege escalation, filter out useless requests, and avoid interference. The packet capture parameters include:

[0061] (1) The domain name to be captured, such as http: / / example.com;

[0062] (2) The type of business request to be captured (divided into GET and POST);

[0063] (3) The suffix of the business request to be captured, such as "byId", "byPhoneNo".

[0064] The eigenvalue of the privilege escalation parameter, such as feature strings with identity identification like "id", "num", "no", "phone", "mobile", "number", etc. Whether to distinguish between uppercase and lowercase when identifying the privilege escalation parameter can be set. The tested system will automatically identify the privilege escalation parameter in the request based on the privilege escalation parameter.

[0065] The encryption component can adopt various encodings. For example, base64 encoding, DES encryption algorithm, Md5 encryption algorithm, Sha1 signature algorithm.

[0066] The pre-configured orchestration nodes include two major categories. The first category is the commonly used global orchestration nodes, and the second category is the custom orchestration nodes. The custom orchestration nodes are the orchestration nodes that can be tested and reused. The following will introduce them separately.

[0067] (1) All orchestration nodes

[0068] (a) Replay prevention and tampering prevention orchestration nodes:

[0069] The replay prevention and tampering prevention orchestration nodes are the orchestration nodes abstracted from some common reinforcement methods of the tested systems. This orchestration node consists of a series of nodes. The replay prevention and tampering prevention orchestration nodes include: adding a timestamp node, adding a random number node, and adding a message signature field. Each orchestration node can belong to different parts of the HTTP business request when processing, such as the URI, request header, and request body. Based on these orchestration nodes, relevant orchestration processes can be generated subsequently. For example, see Table 1: For the following business request, it is necessary to add a timestamp X-TS in the URI, add a random number X-Random in the URI, and add a message front field Signature in the request header. Therefore, the above orchestration nodes can be used. If these fields are not added in the replayed business request, the business request cannot execute the business code due to failure to pass the legality check, that is, the test case is invalid.

[0070] Table 1

[0071]

[0072]

[0073] (b) Parameter encryption orchestration node:

[0074] There are two types. The first type, the ordinary parameter encryption orchestration node encrypts a certain parameter in the service request message. Usually, in horizontal privilege escalation testing, it encrypts and orchestrates the escalated parameter. For example, in an interface for querying user orders, the front end encrypts the user ID parameter instead of directly passing the user ID.

[0075] The second type, the parameter full - encryption orchestration node, is an orchestration node that encrypts all parameters. Usually, it includes two types: symmetric encryption and asymmetric encryption, and the orchestration process may also include a node for pulling the secret key. For example, in an interface for querying user management, three fields, namely organization ID, user name, and user ID, need to be passed in. In some systems under test, these parameters are encrypted as a whole before being passed in. At this time, a parameter full - encryption processing logic needs to be added.

[0076] (2) Customized orchestration node:

[0077] The customized orchestration node is the one saved by the tester last time. The tester can customize the orchestration at different positions (URI, header, request body) of the service request according to different orchestration nodes to deal with different systems under test. Since different systems under test adopt different logics when implementing interfaces, the tester can save the orchestration logic of a certain system under test for reuse in testing business systems with the same processing logic. For example, for the attendance management system and the outsourced personnel management system, when preventing tampering and replay, both use timestamps and random numbers in the URI and combine with the Signature field in the request header. At the same time, both use parameter full - encryption in encryption. Then, this orchestration logic can be saved and reused in testing the attendance system and the outsourced personnel management system.

[0078] After setting relevant parameters or characteristic values, replay the request after modifying the escalated parameter, and then compare the difference characteristics of the response messages before and after to confirm whether there is a horizontal privilege escalation vulnerability. Therefore, it is necessary to define horizontal privilege escalation vulnerability confirmation parameters, including:

[0079] (1) The lengths returned before and after are the same;

[0080] (2) The status code of the second return is 200;

[0081] (3) The length of the second return is greater than a certain threshold;

[0082] (4) The data format of the second return is the same as the first one, such as both being a JSON string in a certain format.

[0083] Figure 3 This is the process of the horizontal privilege escalation detection method in the embodiments of the present invention. Figure 3 In one embodiment, before receiving a service request initiated by a user at the client of the system under test, the following steps are further included:

[0084] Step 301: Start the application layer of the system under test for packet capture.

[0085] After receiving the service request initiated by the user at the client of the system under test (step 101), receive the service data captured by the application layer for the system under test.

[0086] The tester enables packet capture at the application layer and then uses the functions of the system under test on the browser side. Try to click on all service function points as much as possible to capture all service requests that the user can use.

[0087] In step 103, based on the privilege escalation parameter eigenvalue, identify the privilege escalation interfaces from the service data, where the privilege escalation interfaces include privilege escalation parameters;

[0088] Identifying the privilege escalation interfaces includes two cases:

[0089] The first case is automatic identification;

[0090] After the packet capture is completed, identify the real privilege escalation parameters according to the privilege escalation parameter characteristics and mark the identification results. For example, when identifying the user ID field, check whether there are fields such as userId, userNo, and userNumber in the service request path (URI), in the request header (header), and in the request body (body). Similar privilege escalation parameter characteristics include "id", "num", "no", "phone", "mobile", "number", etc. After identifying the privilege escalation parameters, the interfaces containing the privilege escalation parameters are identified as privilege escalation interfaces.

[0091] The second case is manual identification;

[0092] In addition to the possibly identified privilege escalation interfaces through automatic identification, manual intervention is also required to supplement the network requests that have not been identified. This is because the definition of the parameter fields in the URI and request body of the service request depends on the development specifications. In cases where the development is partially non-standard or there are spelling mistakes resulting in a mismatch between the field names and the privilege escalation parameter characteristics, manual supplementary identification can be carried out.

[0093] In step 104, perform process choreography on the combined order of the pre-configured choreography nodes involved in the privilege escalation interfaces to obtain a choreography process, where the choreography nodes include anti-replay and anti-tampering choreography nodes, and parameter encryption choreography nodes;

[0094] An orchestration engine can be adopted. After identifying all suspected unauthorized interfaces and corresponding unauthorized parameters, a process orchestration is performed by arranging the combination order of pre-configured orchestration nodes involved in the unauthorized interfaces to obtain an orchestration process. For example, when it is necessary to perform a horizontal privilege escalation test on the attendance opening function in the attendance management system, and the previously identified unauthorized parameter is the staff ID (staffId), the replay prevention and tamper prevention orchestration nodes can be default set. That is, when automatically initiating a test interface call, the replay prevention and tamper prevention orchestration nodes add a timestamp, a random number, and a signature field to the specified position. For tests that cannot be completed with all orchestration nodes, it is necessary to manually define its custom orchestration nodes. The principle is similar to that of the global orchestration nodes, and finally an orchestration process is obtained.

[0095] In step 105, based on the orchestration process and the horizontal privilege escalation vulnerability confirmation parameters, an automated test is performed to obtain a test result, and the test result includes the determined unauthorized interface.

[0096] After each interface returns a message, it is possible to check whether there is a horizontal privilege escalation vulnerability according to the confirmation parameters for the existence of the horizontal privilege escalation vulnerability and output the result in real time.

[0097] For example, the interface for querying attendance information in the attendance management system is as shown in Table 2 below. It can be seen that this interface requires replay prevention and tamper prevention orchestration nodes. The request body is the DES encryption of the content {"user_id":"qqq","query_type":"03",}. Therefore, during the automated test, the user_id field is automatically modified to the unauthorized parameter value. For example, after changing qqq to qqx, the determined orchestration process is to first execute the parameter encryption orchestration node, and then execute the replay prevention and tamper prevention orchestration nodes. After forming the orchestration process, execute this orchestration process to initiate an actual network request. When judging the test result, compare the horizontal privilege escalation vulnerability confirmation parameters. For full testing, the unauthorized parameters can be modified and traversed more.

[0098] Table 2

[0099]

[0100] Figure 4 The process of the horizontal privilege escalation detection method in the embodiments of the present invention Figure 4 , in one embodiment, the method further includes:

[0101] Step 401: Traverse and test all unauthorized interfaces determined after testing. For example, if the mobile phone number is an 11-digit number, attempt to generate all possible mobile phone numbers for horizontal privilege escalation brute force. After the traversal is completed, the results are output in real time. An attacker uses the horizontal privilege escalation vulnerability to perform traversal operations, that is, automatically generate all possible IDs according to the rules of the unauthorized parameters, and then try them one by one, which can more comprehensively reflect the problems of the horizontal privilege escalation vulnerability.

[0102] Figure 5 This is the flow of the horizontal privilege escalation detection method in the embodiments of the present invention Figure 5 In one embodiment, the method further includes:

[0103] Step 501: Generate a test report based on the test results; store the test report for retesting.

[0104] In addition, after discovering a vulnerability, the vulnerability should be rectified, and after rectification, a round of retesting is also required, which makes the overall closed loop of the horizontal privilege escalation vulnerability test.

[0105] In summary, the method proposed in the embodiments of the present invention has the following beneficial effects:

[0106] (1) It is possible to perform process choreography on the combined order of pre-configured choreography nodes involved in the unauthorized interface to obtain a choreography process. The choreography nodes include a replay prevention and tamper prevention choreography node and a parameter encryption choreography node. Therefore, it can cope with application systems that have adopted replay prevention and tamper prevention, and application systems that have adopted partial or full encryption of messages.

[0107] (2) Due to the choreography, automated testing can be achieved, and test results can be obtained quickly, with good detection effects.

[0108] (3) An attacker can use the horizontal privilege escalation vulnerability to perform traversal operations, that is, automatically generate all possible IDs according to the rules of the unauthorized parameters, and then try them one by one. This situation can more comprehensively reflect the problems of the horizontal privilege escalation vulnerability.

[0109] The embodiments of the present invention also propose a horizontal privilege escalation detection device, the principle of which is similar to the horizontal privilege escalation detection method and will not be elaborated here.

[0110] Figure 6 This is the schematic diagram of the horizontal privilege escalation detection device in the embodiments of the present invention Figure 1 including:

[0111] A service request receiving module 601, configured to receive a service request initiated by a user at the client of the system under test;

[0112] A packet capture module 602, configured to obtain service data for packet capture of the system under test based on packet capture parameters;

[0113] An unauthorized interface identification module 603, configured to identify an unauthorized interface from the service data based on unauthorized parameter feature values, where the unauthorized interface includes unauthorized parameters;

[0114] An orchestration module 604, configured to perform process orchestration on the combined order of pre-configured orchestration nodes involved in the unauthorized interface to obtain an orchestration process, where the orchestration nodes include a replay prevention and tampering prevention orchestration node and a parameter encryption orchestration node;

[0115] An automated testing module 605, configured to perform automated testing based on the orchestration process and horizontal privilege escalation vulnerability confirmation parameters to obtain a test result, where the test result includes the identified unauthorized interface.

[0116] Figure 7 This is a schematic diagram of the horizontal privilege escalation detection device in an embodiment of the present invention Figure 2 In one embodiment, the device further includes an initialization module 701, configured to:

[0117] Before receiving a service request initiated by a user at the client of the system under test, load packet capture parameters, horizontal privilege escalation vulnerability confirmation parameters, unauthorized parameter feature values, pre-configured orchestration nodes, and encryption components into the system under test, and then initialize the system under test.

[0118] In one embodiment, the packet capture parameters include the domain name to be captured, the type of service request to be captured, and the suffix of the service request to be captured.

[0119] In one embodiment, the orchestration node further includes a custom orchestration node, and the custom orchestration node is an orchestration node that can be tested and reused.

[0120] Figure 8 This is a schematic diagram of the horizontal privilege escalation detection device in an embodiment of the present invention Figure 3 In one embodiment, the device further includes an application layer startup module 801, configured to:

[0121] Before receiving a service request initiated by a user at the client of the system under test, start the application layer of the system under test to perform packet capture;

[0122] The packet capture module is specifically configured to: after receiving a service request initiated by a user at the client of the system under test, receive the service data captured by the application layer for the system under test.

[0123] Figure 9 This is a schematic diagram of the horizontal privilege escalation detection device in an embodiment of the present invention Figure 4 In one embodiment, the device further includes a traversal testing module 901, configured to:

[0124] Perform traversal testing on all the identified unauthorized interfaces after testing.

[0125] Figure 10 Schematic diagram of the horizontal privilege escalation detection device in the embodiments of the present invention Figure 5 In one embodiment, the device further includes a test report generation module 1001, which is configured to:

[0126] Generate a test report based on the test results;

[0127] Store the test report for retesting.

[0128] In summary, the device proposed in the embodiments of the present invention has the following beneficial effects:

[0129] (1) It is possible to perform process choreography on the combined order of pre-configured choreography nodes involved in the privilege escalation interface to obtain a choreography process. The choreography nodes include a replay prevention and tampering prevention choreography node and a parameter encryption choreography node. Therefore, it can cope with application systems that have adopted replay prevention and tampering prevention, and application systems that have adopted partial or full encryption of messages.

[0130] (2) Due to the choreography, automated testing can be achieved, and test results can be obtained quickly, with good detection effects.

[0131] (3) An attacker can use the horizontal privilege escalation vulnerability to perform traversal operations, that is, automatically generate all possible IDs according to the rules of privilege escalation parameters, and then try them one by one. This situation can more comprehensively reflect the problem of horizontal privilege escalation vulnerabilities.

[0132] The embodiments of the present invention also provide a computer device Figure 11 Schematic diagram of the computer device in the embodiments of the present invention. The computer device 1100 includes a memory 1110, a processor 1120, and a computer program 1130 stored in the memory 1110 and executable on the processor 1120. When the processor 1120 executes the computer program 1130, the above-mentioned horizontal privilege escalation detection method is implemented.

[0133] The embodiments of the present invention also provide a computer-readable storage medium. The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the above-mentioned horizontal privilege escalation detection method is implemented.

[0134] The embodiments of the present invention also provide a computer program product. The computer program product includes a computer program, and when the computer program is executed by a processor, the above-mentioned horizontal privilege escalation detection method is implemented.

[0135] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, a system, or a computer program product. Therefore, the present invention can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memory, CD-ROM, optical memory, etc.) that contain computer-usable program code.

[0136] The present invention is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to embodiments of the present invention. It should be understood that each flow and / or block in the flowchart and / or block diagram, as well as the combination of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing devices generate means for implementing the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0137] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory generate a manufactured article including instruction means that implement the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0138] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operation steps are performed on the computer or other programmable device to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0139] The specific embodiments described above further elaborate on the objectives, technical solutions, and beneficial effects of the present invention. It should be understood that the above are only specific embodiments of the present invention and are not used to limit the protection scope of the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present invention should be included in the protection scope of the present invention.

Claims

1. A horizontal privilege escalation detection method, characterized in that, It includes: Receiving a service request initiated by a user at the client of the system under test; Obtaining service data captured for the system under test based on packet capture parameters; the packet capture parameters include the domain name to be captured, the type of service request to be captured, and the suffix of the service request to be captured; After identifying the privilege escalation parameter based on the privilege escalation parameter eigenvalue, identifying the interface containing the privilege escalation parameter as a privilege escalation interface; Performing process orchestration on the combined order of pre-configured orchestration nodes involved in the privilege escalation interface to obtain an orchestration process, where the orchestration nodes include a replay prevention and tampering prevention orchestration node and a parameter encryption orchestration node; Performing automated testing based on the orchestration process and horizontal privilege escalation vulnerability confirmation parameters to obtain a test result, where the test result includes the identified privilege escalation interfaces; The horizontal privilege escalation vulnerability confirmation parameters include that the lengths returned in the first and second times are the same, the status code returned in the second time is a preset value, the length returned in the second time is greater than a threshold, and the data format returned in the second time is the same as the first time.

2. The method according to claim 1, wherein Before receiving the service request initiated by the user at the client of the system under test, it further includes: Initializing the system under test after loading the packet capture parameters, horizontal privilege escalation vulnerability confirmation parameters, privilege escalation parameter eigenvalue, pre-configured orchestration nodes, and encryption components into the system under test.

3. The method according to claim 1, characterized in that, The orchestration nodes further include custom orchestration nodes, and the custom orchestration nodes are orchestration nodes that can be reused for testing.

4. The method according to claim 1, characterized in that, Before receiving the service request initiated by the user at the client of the system under test, it further includes: Starting the application layer of the system under test for packet capture; After receiving the service request initiated by the user at the client of the system under test, receiving the service data captured for the system under test by the application layer.

5. The method according to claim 1, wherein It further includes: Performing traversal testing on all the identified privilege escalation interfaces after testing.

6. The method according to claim 1, characterized in that, It further includes: Generating a test report based on the test result; Storing the test report for retesting.

7. A horizontal privilege escalation detection device, characterized in that, It includes: A service request receiving module for receiving a service request initiated by a user at the client of the system under test; A packet capture module for obtaining service data captured for the system under test based on packet capture parameters; the packet capture parameters include the domain name to be captured, the type of service request to be captured, and the suffix of the service request to be captured; A privilege escalation interface identification module for identifying privilege escalation interfaces from the service data based on the privilege escalation parameter eigenvalue, where the privilege escalation interfaces contain privilege escalation parameters; An orchestration module for performing process orchestration on the combined order of pre-configured orchestration nodes involved in the privilege escalation interface to obtain an orchestration process, where the orchestration nodes include a replay prevention and tampering prevention orchestration node and a parameter encryption orchestration node; An automated testing module for performing automated testing based on the orchestration process and horizontal privilege escalation vulnerability confirmation parameters to obtain a test result, where the test result includes the identified privilege escalation interfaces; The horizontal privilege escalation vulnerability confirmation parameters include that the lengths returned in the first and second times are the same, the status code returned in the second time is a preset value, the length returned in the second time is greater than a threshold, and the data format returned in the second time is the same as the first time.

8. The device according to claim 7, characterized in that, It further includes an initialization module for: Before receiving a service request initiated by a user at the client of the system under test, load packet capture parameters, horizontal privilege escalation vulnerability confirmation parameters, privilege escalation parameter eigenvalues, pre-configured orchestration nodes, and encryption components in the system under test, and then initialize the system under test.

9. The device according to claim 7, characterized in that, The orchestration node further includes a custom orchestration node, and the custom orchestration node is an orchestration node that can be reused for testing.

10. The device according to claim 7, characterized in that, It further includes an application layer startup module for: Before receiving a service request initiated by a user at the client of the system under test, start the application layer of the system under test to perform packet capture; The packet capture module is specifically used for: after receiving a service request initiated by a user at the client of the system under test, receive the service data captured by the application layer for the system under test.

11. The device according to claim 7, characterized in that, It further includes a traversal test module for: Obtain all the privilege escalation interfaces determined after testing and perform traversal testing.

12. The device according to claim 7, characterized in that, It further includes a test report generation module for: Generate a test report based on the test results; Store the test report for re-testing.

13. A computer device, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the method according to any one of claims 1 to 5.

14. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, it implements the method according to any one of claims 1 to 5.

15. A computer program product, characterized in that, The computer program product includes a computer program, and when the computer program is executed by a processor, it implements the method according to any one of claims 1 to 5.

Citation Information

Patent Citations

  • Method and device for detecting horizontal unauthorized vulnerability and electronic equipment

    CN111125713A

  • Unauthorized vulnerability detection method and device, equipment and storage medium

    CN112765611A