A security testing method and device, electronic equipment and storage medium
Patent Information
- Application Number
- CN202211173608.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-09-26
- Publication Date
- 2026-09-29
- Estimated Expiration
- 2042-09-26
AI Technical Summary
目前,测试量的确定仅依靠功能点或者工作量进行估算,主观性影响较大,造成安全测试环节人力投入存在依据不足或者仅靠测试经理经验安排,软件系统的测试不够全面,导致软件系统存在漏洞未被检出
[0019]本发明实施例的技术方案,通过确定待测如软件项目的项目属性信息,按照预设工作量模型确定项目属性信息对应的安全测试项目参数,将安全测试项目参数填充到预设安全测试模板以生成安全测试规划,根据按照测试规划执行安全测试,实现软件系统的测试工作量的准确确定,可提高软件安全测试的全面性和效率,可增强用户的使用体验。
Smart Images

Figure CN115659347B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of computer application technology, and in particular to a security testing method, apparatus, electronic device, and storage medium. Background Technology
[0002] Security testing plays a crucial role in the entire software development lifecycle by uncovering vulnerabilities, hidden dangers, and risks in application software. The planning and execution of security tests directly impact the security of a software system. Before security testing, the testing workload needs to be determined to establish an accurate security test plan. Currently, the determination of testing workload relies solely on estimations of functional points or workload, which is highly subjective. This leads to insufficient data on manpower allocation in the security testing phase or reliance on the experience of test managers, resulting in incomplete testing and undetected vulnerabilities. There is an urgent need for a scientific and accurate method to determine testing workload to improve the comprehensiveness and efficiency of security testing. Summary of the Invention
[0003] This invention provides a security testing method, apparatus, electronic device, and storage medium to accurately determine the testing workload of a software system, improve the comprehensiveness and efficiency of software security testing, and enhance the user experience.
[0004] According to one aspect of the present invention, a security testing method is provided, wherein the method includes:
[0005] Determine the project attribute information of the software project to be tested;
[0006] The security test project parameters are determined based on the project attribute information and the preset workload model, wherein the preset workload model includes at least the mapping relationship between the project attribute information and the security test project parameters;
[0007] A security test plan is generated based on a preset security test template and the parameters of the security test items.
[0008] Perform security tests according to the security test plan.
[0009] According to another aspect of the present invention, a safety testing apparatus is provided, wherein the apparatus comprises:
[0010] The project parameter module is used to determine the project attribute information of the software project under test;
[0011] The test parameter module is used to determine the security test project parameters based on the project attribute information and the preset workload model, wherein the preset workload model includes at least the mapping relationship between the project attribute information and the security test project parameters;
[0012] The planning and determination module is used to generate a security test plan based on a preset security test template and the parameters of the security test items.
[0013] The test execution module is used to execute security tests according to the security test plan.
[0014] According to another aspect of the present invention, an electronic device is provided, the electronic device comprising:
[0015] At least one processor; and
[0016] A memory communicatively connected to the at least one processor; wherein,
[0017] The memory stores a computer program that can be executed by the at least one processor, the computer program being executed by the at least one processor to enable the at least one processor to perform the security testing method described in any embodiment of the present invention.
[0018] According to another aspect of the present invention, a computer-readable storage medium is provided, the computer-readable storage medium storing computer instructions for causing a processor to execute and implement the security testing method described in any embodiment of the present invention.
[0019] The technical solution of this invention determines the project attribute information of the software project to be tested, determines the security test project parameters corresponding to the project attribute information according to a preset workload model, fills the security test project parameters into a preset security test template to generate a security test plan, and executes security tests according to the test plan. This achieves accurate determination of the testing workload of the software system, improves the comprehensiveness and efficiency of software security testing, and enhances the user experience.
[0020] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of the present invention, nor is it intended to limit the scope of the invention. Other features of the invention will become readily apparent from the following description. Attached Figure Description
[0021] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0022] Figure 1 This is a flowchart of a security testing method provided in Embodiment 1 of the present invention;
[0023] Figure 2This is a flowchart of another security testing method provided according to Embodiment 2 of the present invention;
[0024] Figure 3 This is an example diagram of a security testing method provided according to Embodiment 3 of the present invention;
[0025] Figure 4 This is a schematic diagram of the structure of a safety testing device according to Embodiment 4 of the present invention;
[0026] Figure 5 This is a schematic diagram of the structure of an electronic device that implements the security testing method of this invention. Detailed Implementation
[0027] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.
[0028] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0029] Example 1
[0030] Figure 1 This is a flowchart illustrating a security testing method provided in Embodiment 1 of the present invention. This embodiment is applicable to security testing of software projects. The method can be executed by a security testing device, which can be implemented in hardware and / or software and can be configured in a server. Figure 1 As shown, the method includes:
[0031] Step 110: Determine the project attribute information of the software project to be tested.
[0032] The software project under test can be any software that requires security testing. It can include completed or ongoing application software. Project attribute information reflects the scale of the software project, and may include project type, business domain, and functional scale.
[0033] In this embodiment of the invention, corresponding project attribute information can be obtained for the software project under test. For example, the project type, business domain and functional scale can be extracted as project attribute information by performing text recognition on the instruction manual of the software project under test. Alternatively, the project attribute information of the software project under test can be directly input by the software developer.
[0034] Step 120: Determine the security test project parameters based on the project attribute information and the preset workload model. The preset workload model includes at least the mapping relationship between the project attribute information and the security test project parameters.
[0035] The preset workload model can be a model that determines the output parameters of a security test project through project attribute information. The preset workload model can be determined through historical security test data. Specifically, the preset workload model can be a neural network model, a support vector machine model, etc. The input of the preset workload model can be project attribute information, and the output can be security test project parameters. These security test project parameters can include parameters for performing security tests, such as the number of functional security tests, the number of non-functional security tests, the number of vulnerability scans, and the number of penetration tests.
[0036] In this embodiment of the invention, the preset workload model may include at least a mapping relationship between project attribute information and security test project parameters. This mapping relationship can be pre-generated through training with massive amounts of data. It is understood that the data used to train the mapping relationship within the preset workload model can be actual data from historical security tests. For example, it could be the specific test details and project attribute information of each security test collected after the security test was completed. Specifically, the pre-trained preset workload model can be loaded, and the project attribute information can be input into the preset workload model. The security test project parameters corresponding to the project attribute information can be determined through the mapping relationship set within the preset workload model.
[0037] Step 130: Generate a security test plan based on the preset security test template and security test item parameters.
[0038] The preset security test template can be a template file used to generate a security test plan. It can consist of one or more security test items, and the specific parameters for each test item can be blank or template values. The preset security test template can exist in text or HTML webpage format. The security test plan can be information used to assist in executing security tests, and it can include the security test content and security test cases to be executed.
[0039] In this embodiment of the invention, a pre-stored preset security test template can be extracted, and the security test project parameters generated by the preset workload model can be filled into the preset security test template. The filled preset security test template can be used as a security test plan. It is understood that there can be a correspondence between the preset security test template and the security test project parameters, and the filling can be carried out according to the correspondence.
[0040] Step 140: Perform security tests according to the security test plan.
[0041] In this embodiment of the invention, security tests can be performed according to the security test plan. For example, the device performing the security test can read the security test plan and perform the security test according to the security test plan, or the device can visualize the security test plan and the user can perform the security test according to the visualized information.
[0042] In this embodiment of the invention, by determining the project attribute information of the software project to be tested, determining the security test project parameters corresponding to the project attribute information according to a preset workload model, filling the security test project parameters into a preset security test template to generate a security test plan, and executing security tests according to the test plan, the test workload of the software system can be accurately determined, which can improve the comprehensiveness and efficiency of software security testing and enhance the user experience.
[0043] Example 2
[0044] Figure 2 This is a flowchart of another security testing method provided by Embodiment 2 of the present invention. This embodiment is a specific modification based on the above-described embodiments. See also... Figure 2 The method provided in this embodiment of the invention specifically includes the following steps:
[0045] Step 210: Collect the specification document from at least one data source according to the identification information of the software project to be tested.
[0046] The identification information can be the identifying characteristics of the software project under test. Different software projects under test may have different identification information. In some embodiments, the identification information may include the project number, project version number, software name, etc., of the software project under test. The data source can be the data source of the documentation of the software project under test, which may include development document data source or development specification data source, etc. The documentation can be a collection of information that provides a textual description of the software project under test, and may include software development documents or software specifications, etc.
[0047] In this embodiment of the invention, different data sources can be connected. The corresponding documentation files can be matched within the data sources according to the identification information of the software project under test, and the matched documentation files can be received. It is understood that different data connection methods can be used with different data sources; for example, a data queue or a data interface can be used to connect to the data source.
[0048] Step 220: Extract the project type, business domain, and function point scale parameters from the documentation as project attribute information.
[0049] In this embodiment of the invention, the project type, business domain, and function point scale parameters can be extracted from the received specification file as project attribute parameters. The project type can be information reflecting the type of the software project under test, and may include the project name or software number. The business domain can be the domain to which the business processed by the software project under test belongs, and may include finance, games, shopping, entertainment, etc. The function point scale parameter can be information about the number of function points included in the software project under test.
[0050] Step 230: Input the project type, business domain, and functional point scale parameters from the project attribute information into the mapping relationship in the preset workload model.
[0051] In this embodiment of the invention, the project type, business domain, and functional point scale parameters in the project attribute information can be used as inputs to the preset workload model. It is understood that there can be one or more mapping relationships in the preset workload model. The information such as project type, business domain, and functional point scale parameters can be input into their respective mapping relationships in the preset workload model or input together into the common mapping relationship in the preset workload model.
[0052] Step 240: Collect the output results of the mapping relationship as parameters for the security test project.
[0053] In this embodiment of the invention, the output results of the mapping relationship in the preset workload model can be monitored, and the output results of the mapping relationship can be used as parameters for security test items. In some embodiments, the security test item parameters may include the number of functional safety test points, the number of non-functional safety test points, the number of vulnerability scanning points, the number of penetration test points, etc.
[0054] Step 250: Read the template file of the preset security test template.
[0055] In this embodiment of the invention, a pre-configured template file can be read into the device, wherein the template file can be persistently stored.
[0056] Step 260: Display the preset security test template according to the template file.
[0057] Specifically, template files can be visualized as preset security test templates, making them easy for users to read. In some embodiments, users can modify the visualized preset security test templates, adding or removing security test items to improve the adaptability of the preset security test templates to the software projects under test and enhance the comprehensiveness of security testing.
[0058] Step 270: Fill the security test item parameters into the preset security test template according to the parameter type.
[0059] The parameter type can be information reflecting the data type of the security test project parameters. The parameter type can include function points, non-function point parameters, vulnerability scanning, penetration testing, etc. The value of the parameter type can be one or more of numbers, letters, or special symbols.
[0060] In this embodiment of the invention, each parameter in the preset security test template can be bound to a parameter type. For each security test item parameter, the corresponding position is found in the preset security test template, and the security test item parameter is filled into the preset security test template as a security test plan.
[0061] Step 280: Perform security tests according to the security test plan.
[0062] Step 290: Determine the actual project scale parameters for the security test, and adjust the mapping relationship within the preset workload model according to the actual project scale parameters.
[0063] The actual project scale parameter can be the actual execution situation during the security testing process, which may include the actual functional security testing situation, non-functional security testing situation, vulnerability scanning situation, penetration testing situation, and workload, etc.
[0064] In this embodiment of the invention, the actual project scale parameters during the security testing process can be statistically analyzed, and the mapping relationship in the preset workload model can be adjusted according to the actual project scale parameters to improve the accuracy of the security testing project parameter prediction.
[0065] In this embodiment of the invention, the specification documents of the software project under test are collected from various data sources using identification information. The project type, business domain, and functional point scale parameters are matched within the specification documents as project attribute information. The collected project attribute information is input into a mapping relationship within a preset workload model, and the output result is obtained as security test project parameters. A template file of a preset security test template is read and displayed as a preset security test template. The security test project parameters are filled into the preset security test template according to parameter type as a security test plan. Security tests are executed based on the security test plan. The actual project scale parameters of the security tests are statistically analyzed, and the mapping relationship within the preset workload model is adjusted according to these actual project scale parameters. This achieves accurate determination of the testing workload of the software system, improves the comprehensiveness and efficiency of software security testing, and enhances the user experience.
[0066] Furthermore, based on the above embodiments of the invention, the security testing project parameters include at least one of the following: planning phase parameters, preparation phase parameters, execution phase parameters, summary phase parameters, and workload parameters. The planning phase parameters include at least the number of security function test points, the number of non-security function test points, the number of vulnerability scanning test points, and the number of penetration testing points. The preparation phase parameters include at least one of the following: the number of security test cases, the number of non-security test cases, the number of functional interfaces, and the number of penetration scripts. The execution phase parameters include at least one of the following: the number of security test cases executed, the number of non-security test cases executed, the number of interfaces scanned, and the number of penetration scripts executed. The summary phase parameters include fixed parameter values. The workload parameters include at least one of the following: planned workload parameters, preparation workload parameters, execution workload parameters, and summary workload parameters.
[0067] In this embodiment of the invention, security testing project parameters can be divided into planning phase parameters, preparation phase parameters, execution phase parameters, summary phase parameters, and workload parameters. The planning phase parameters include at least the number of security function test points, the number of non-security function test points, the number of vulnerability scanning test points, and the number of penetration testing points. The preparation phase parameters include the number of security test cases, the number of non-security test cases, the number of functional interfaces, and the number of penetration scripts. The execution phase parameters include the number of security test cases executed, the number of non-security test cases executed, the number of interfaces scanned, the number of penetration scripts executed, as well as planning workload parameters, preparation workload parameters, execution workload parameters, and summary workload parameters.
[0068] Furthermore, based on the above embodiments of the invention, adjusting the mapping relationship within the preset workload model according to the actual workload includes:
[0069] Generate a comparison result between the actual project scale parameters and the security test project parameters of the security test plan; adjust the model parameters of the mapping relationship within the preset workload model according to the comparison result.
[0070] In this embodiment of the invention, the actual project scale parameters and safety test project parameters can be numerically compared. The model parameters in the mapping relationship are then adjusted according to the comparison results to improve the accuracy of the mapping relationship. In one embodiment, when the comparison result is greater than zero, the values of the model parameters can be reduced, making the safety test project parameters closer to the actual project scale parameters.
[0071] Example 3
[0072] Figure 3 This is an example diagram of a security testing method provided according to Embodiment 3 of the present invention. See also... Figure 3 This invention, in its embodiments, utilizes support vector machines to implement a pre-defined workload model, thereby overcoming the limitations of subjective experience values and setting reasonable types of security tests. This improves the refinement of software project management and the comprehensiveness of testing, ultimately enhancing project development efficiency. The security testing method provided by this invention specifically includes the following steps:
[0073] Step 1: Assign parameters to the support vector machine model and perform regression fitting based on the workload in previous actual security testing processes to determine the initial parameter values of the support vector machine model.
[0074] Step 2: Determine the project type of the software project to be tested, analyze the project's security requirements, estimate the security testing workload based on the initial parameter values, and conduct security testing according to the security testing workload.
[0075] Step 3: After completing the security testing of the software project, compare the actual values with the planned values and optimize and adjust the model parameters of the support vector machine model.
[0076] Step 4: Estimate the testing workload for the next software project based on the optimized and adjusted support vector machine model.
[0077] The process of determining the initial parameter values of the support vector machine model and the security testing process may include:
[0078] (1) Determine the project scale parameters based on project type, business area, and functional point scale;
[0079] (2) Fill in the values marked with “XX” in the safety test items in the table below;
[0080]
[0081]
[0082] The parameters are defined as follows:
[0083]
[0084] Wherein, the complexity parameter value 1 = x1*X1 + x2*X2 + x3*X3 + x4*X4 + i1,
[0085] The complexity parameter value 2 = y1*Y1 + y2*Y2 + y3*Y3 + y4*Y4 + i2,
[0086] The complexity parameter value 3 = z1*Z1 + z2*Z2 + z3*Z3 + z4*Z4 + i3.
[0087] (3) Determine the workload of the safety test plan based on the project size parameters determined by the support vector machine model;
[0088] (4) Allocate testing human resources according to the workload of the security testing plan, and record the actual workload of each stage during security testing.
[0089] (5) After the software project security test is completed, collect and analyze the actual workload of each stage of the security test, incorporate it into the parameter calculation model, optimize the parameters and fitting relationship according to the support vector machine data mining method, provide actual statistical data for parameter iteration, and update the calculation model regularly.
[0090] Example 4
[0091] Figure 4 This is a schematic diagram of a safety testing device according to Embodiment 4 of the present invention. Figure 4 As shown, the device includes: a project parameter module 301, a test parameter module 302, a planning determination module 303, and a test execution module 304.
[0092] Project parameter module 301 is used to determine the project attribute information of the software project under test.
[0093] The test parameter module 302 is used to determine the security test project parameters based on the project attribute information and the preset workload model, wherein the preset workload model includes at least the mapping relationship between the project attribute information and the security test project parameters.
[0094] The planning and determination module 303 is used to generate a security test plan based on a preset security test template and the security test item parameters.
[0095] The test execution module 304 is used to execute security tests according to the security test plan.
[0096] In this embodiment of the invention, the project parameter module determines the project attribute information of the software project to be tested, the test parameter module determines the security test project parameters corresponding to the project attribute information according to the preset workload model, the planning and determination module fills the security test project parameters into the preset security test template to generate a security test plan, and the test execution module executes the security test according to the test plan. This realizes the accurate determination of the test workload of the software system, which can improve the comprehensiveness and efficiency of software security testing and enhance the user experience.
[0097] Optionally, the security testing module further includes a model adjustment module, used to determine the actual project scale parameters of the security test, and adjust the mapping relationship within the preset workload model according to the actual project scale parameters.
[0098] Optionally, the project parameter module 301 includes:
[0099] The document acquisition unit is used to acquire explanatory documents from at least one data source according to the identification information of the software project under test.
[0100] The attribute extraction unit is used to extract the project type, business domain, and function point scale parameters from the specification document as the project attribute information.
[0101] Optionally, the test parameter module 302 includes:
[0102] The parameter input unit is used to input the project type, business domain, and functional point scale parameters from the project attribute information into the mapping relationship in the preset workload model.
[0103] The result output unit is used to collect the output results of the mapping relationship as parameters of the security test project.
[0104] Optionally, the security test project parameters in the test parameter module 302 include at least one of the following: planning phase parameters, preparation phase parameters, execution phase parameters, summary phase parameters, and workload parameters. The planning phase parameters include at least the number of security function test points, the number of non-security function test points, the number of vulnerability scanning test points, and the number of penetration testing points. The preparation phase parameters include at least one of the following: the number of security test cases, the number of non-security test cases, the number of functional interfaces, and the number of penetration scripts. The execution phase parameters include at least one of the following: the number of security test cases executed, the number of non-security test cases executed, the number of interfaces scanned, and the number of penetration scripts executed. The summary phase parameters include fixed parameter values. The workload parameters include at least one of the following: planned workload parameters, preparation workload parameters, execution workload parameters, and summary workload parameters.
[0105] Optionally, the planning determination module 303 includes:
[0106] The template reading unit is used to read the template file of the preset security test template.
[0107] The template display unit is used to display the preset security test template according to the template file.
[0108] The parameter filling unit is used to fill the security test item parameters into the preset security test template according to the parameter type.
[0109] Optionally, the model adjustment module is specifically used to: generate a comparison result between the actual project scale parameters and the security test project parameters of the security test plan; and adjust the model parameters of the mapping relationship within the preset workload model according to the comparison result.
[0110] The security testing device provided in the embodiments of the present invention can execute the security testing method provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the method execution.
[0111] Example 5
[0112] Figure 5 This is a schematic diagram of the structure of an electronic device implementing the security testing method of an embodiment of the present invention. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices (e.g., helmets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the invention described and / or claimed herein.
[0113] like Figure 5As shown, the electronic device 10 includes at least one processor 11 and a memory, such as a read-only memory (ROM) 12 or a random access memory (RAM) 13, communicatively connected to the at least one processor 11. The memory stores computer programs executable by the at least one processor. The processor 11 can perform various appropriate actions and processes based on the computer program stored in the ROM 12 or loaded from storage unit 18 into the RAM 13. The RAM 13 may also store various programs and data required for the operation of the electronic device 10. The processor 11, ROM 12, and RAM 13 are interconnected via a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.
[0114] Multiple components in electronic device 10 are connected to I / O interface 15, including: input unit 16, such as keyboard, mouse, etc.; output unit 17, such as various types of displays, speakers, etc.; storage unit 18, such as disk, optical disk, etc.; and communication unit 19, such as network card, modem, wireless transceiver, etc. Communication unit 19 allows electronic device 10 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.
[0115] Processor 11 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. Processor 11 performs the various methods and processes described above, such as security testing methods.
[0116] In some embodiments, the security testing method may be implemented as a computer program tangibly contained in a computer-readable storage medium, such as storage unit 18. In some embodiments, part or all of the computer program may be loaded and / or installed on electronic device 10 via ROM 12 and / or communication unit 19. When the computer program is loaded into RAM 13 and executed by processor 11, one or more steps of the security testing method described above may be performed. Alternatively, in other embodiments, processor 11 may be configured to perform the security testing method by any other suitable means (e.g., by means of firmware).
[0117] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), payload-programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.
[0118] Computer programs used to implement the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when executed by the processor, the computer programs cause the functions / operations specified in the flowcharts and / or block diagrams to be performed. The computer programs may be executed entirely on a machine, partially on a machine, or as a standalone software package, partially on a machine and partially on a remote machine, or entirely on a remote machine or server.
[0119] In the context of this invention, a computer-readable storage medium can be a tangible medium that may contain or store a computer program for use by or in conjunction with an instruction execution system, apparatus, or device. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination thereof. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.
[0120] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).
[0121] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or computing systems that include middleware components (e.g., application servers), or computing systems that include frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include local area networks (LANs), wide area networks (WANs), blockchain networks, and the Internet.
[0122] A computing system can include clients and servers. Clients and servers are generally located far apart and typically interact through communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or cloud host, which is a hosting product within the cloud computing service system to address the shortcomings of traditional physical hosts and VPS services, such as high management difficulty and weak business scalability.
[0123] It should be understood that the various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps described in this invention can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution of this invention can be achieved, and this is not limited herein.
[0124] The specific embodiments described above do not constitute a limitation on the scope of protection of this invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this invention should be included within the scope of protection of this invention.
Claims
1. A security testing method, characterized in that, include: Determine the project attribute information of the software project to be tested; The determination of the project attribute information of the software project to be tested includes: According to the identification information of the software project under test, collect the description document from at least one data source; Extract the project type, business domain, and function point scale parameters from the description document as the project attribute information; The security test project parameters are determined based on the project attribute information and the preset workload model, wherein the preset workload model includes at least the mapping relationship between the project attribute information and the security test project parameters; A security test plan is generated based on a preset security test template and the security test project parameters, wherein the security test plan includes security test content and security test cases; Perform security tests according to the security test plan; The step of determining the security test project parameters based on the project attribute information and the preset workload model includes: Input the project type, business domain, and functional point scale parameters from the project attribute information into the mapping relationship in the preset workload model; The output of the mapping relationship is collected as the parameters of the security test project. The security testing project parameters include at least one of the following: planning phase parameters, preparation phase parameters, execution phase parameters, summary phase parameters, and workload parameters. The planning phase parameters include at least the number of security function test points, the number of non-security function test points, the number of vulnerability scanning test points, and the number of penetration testing test points. The preparation phase parameters include at least one of the following: the number of security test cases, the number of non-security test cases, the number of functional interfaces, and the number of penetration scripts. The execution phase parameters include at least one of the following: the number of security test cases executed, the number of non-security test cases executed, the number of interfaces scanned, and the number of penetration scripts executed. The summary phase parameters include fixed parameter values. The workload parameters include at least one of the following: planned workload parameters, preparation workload parameters, execution workload parameters, and summary workload parameters. The generation of a security test plan based on a preset security test template and the security test item parameters includes: Read the template file of the preset security test template; The preset security test template is displayed according to the template file; The security test item parameters are filled into the preset security test template according to the parameter type. Each parameter in the preset security test template is bound to a parameter type. The corresponding position of the parameter type of each security test item parameter is found in the preset security test template, and the security test item parameter is filled into the preset security test template as a security test plan.
2. The method according to claim 1, characterized in that, Also includes: Determine the actual project scale parameters of the security test, and adjust the mapping relationship within the preset workload model according to the actual project scale parameters.
3. The method according to claim 2, characterized in that, The step of adjusting the mapping relationship within the preset workload model based on the actual project scale parameters includes: Generate a comparison result between the actual project scale parameters and the security test project parameters in the security test plan; Adjust the model parameters of the mapping relationship within the preset workload model according to the comparison results.
4. A safety testing device, characterized in that, include: The project parameter module is used to determine the project attribute information of the software project under test; The project parameter module includes: a file acquisition unit, used to acquire a description file from at least one data source according to the identification information of the software project under test; and an attribute extraction unit, used to extract project type, business domain, and function point scale parameters from the description file as the project attribute information. The test parameter module is used to determine the security test project parameters based on the project attribute information and the preset workload model, wherein the preset workload model includes at least the mapping relationship between the project attribute information and the security test project parameters; The planning and determination module is used to generate a security test plan based on a preset security test template and the security test project parameters, wherein the security test plan includes security test content and security test cases; The test execution module is used to execute security tests according to the security test plan; The test parameter module includes: The parameter input unit is used to input the project type, business domain, and functional point scale parameters from the project attribute information into the mapping relationship in the preset workload model. The result output unit is used to collect the output result of the mapping relationship as the parameter of the security test project. The security testing project parameters include at least one of the following: planning phase parameters, preparation phase parameters, execution phase parameters, summary phase parameters, and workload parameters. The planning phase parameters include at least the number of security function test points, the number of non-security function test points, the number of vulnerability scanning test points, and the number of penetration testing test points. The preparation phase parameters include at least one of the following: the number of security test cases, the number of non-security test cases, the number of functional interfaces, and the number of penetration scripts. The execution phase parameters include at least one of the following: the number of security test cases executed, the number of non-security test cases executed, the number of interfaces scanned, and the number of penetration scripts executed. The summary phase parameters include fixed parameter values. The workload parameters include at least one of the following: planned workload parameters, preparation workload parameters, execution workload parameters, and summary workload parameters. The planning determination module includes: The template reading unit is used to read the template file of the preset security test template; A template display unit is used to display the preset security test template according to the template file; The parameter filling unit is used to fill the security test item parameters into the preset security test template according to the parameter type. Each parameter to be filled in the preset security test template is bound to a parameter type. The corresponding position of the parameter type of each security test item parameter is found in the preset security test template, and the security test item parameter is filled into the preset security test template as a security test plan.
5. An electronic device, characterized in that, The electronic device includes: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that can be executed by the at least one processor, the computer program being executed by the at least one processor to enable the at least one processor to perform the security testing method according to any one of claims 1-3.
6. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions that cause a processor to execute the security testing method according to any one of claims 1-3.
Citation Information
Patent Citations
Workload determination method and device for automatic test, equipment and storage medium
CN114416583A
Automatic testing method, device and equipment and storage medium
CN114625664A