A method, device, medium and electronic device for identifying web vulnerabilities

CN115906095BActive Publication Date: 2026-09-25BEIJING TOPSEC NETWORK SECURITY TECH +2
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202211449701.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-18
Publication Date
2026-09-25
Estimated Expiration
2042-11-18

AI Technical Summary

Technical Problem

前者适合工作时间长的开发人员,对新手开发人员和安全人员不是很友好,虽然结果准确,但是耗费时间长,如果在多个web项目的情况下,人工审计显然不是最好的方式;后者使用工具审计,对开发人员和安全人员都比较友好,但是存在误报率高,不准确的缺陷

Benefits of technology

[0008]本申请的一些实施例通过提供多种规则库提升技术方案的通用性。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115906095B_ABST
    Figure CN115906095B_ABST
Patent Text Reader

Abstract

Embodiments of the present application provide a method, device, medium and electronic equipment for identifying web vulnerabilities, the method comprising: selecting a target rule library according to attribute information of a web project to be identified, wherein the target rule library comprises defense function keywords and dangerous functions corresponding to a plurality of vulnerabilities respectively; constructing a defense library according to the defense function keywords in the target rule library; and performing vulnerability scanning on the web project to be identified according to the defense library and the dangerous functions, to obtain a vulnerability scanning result. Through the embodiments of the present application, the security vulnerabilities in the web source code can be found, and the technical problems of high false positive rate and inaccuracy of existing tool audits are significantly reduced, and the accuracy of vulnerability identification is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of vulnerability identification, and more specifically, the embodiments of this application relate to a method, apparatus, medium, and electronic device for identifying vulnerabilities in web projects. Background Technology

[0002] Web vulnerabilities refer to flaws in a website's program, which may be caused by oversights by the code writer. Common web vulnerabilities include SQL injection, XSS vulnerabilities, and file upload vulnerabilities. Dangerous functions are functions that can cause web vulnerabilities.

[0003] Code auditing is a form of source code analysis aimed at discovering program errors, security vulnerabilities, and violations of programming standards. Currently, there are two main methods for code auditing: manual auditing and tool-based auditing. The former is suitable for experienced developers but is not very user-friendly for novice developers and security personnel. While the results are accurate, it is time-consuming, and manual auditing is clearly not the best approach for multiple web projects. The latter, tool-based auditing, is more user-friendly for both developers and security personnel, but it suffers from a high false positive rate and inaccuracies. Summary of the Invention

[0004] The purpose of this application is to provide a method, apparatus, medium, and electronic device for identifying web vulnerabilities. Through the embodiments of this application, security vulnerabilities in Web source code can be discovered, significantly reducing the technical problems of high false alarm rate and inaccuracy in existing auditing tools, and improving the accuracy of vulnerability identification.

[0005] In a first aspect, embodiments of this application provide a method for identifying web vulnerabilities. The method includes: selecting a target rule base based on attribute information of a web project to be identified, wherein the target rule base includes defense function keywords and dangerous functions corresponding to various vulnerabilities; constructing a defense library based on the defense function keywords in the target rule base; and performing vulnerability scanning on the web project to be identified based on the defense library and the dangerous functions to obtain vulnerability scanning results.

[0006] Some embodiments of this application perform vulnerability scanning on web projects based on defense libraries and dangerous functions to obtain vulnerability scanning results, which can effectively reduce the false positive rate of web vulnerabilities.

[0007] In some embodiments, selecting a target rule base based on the attribute information of the web project to be identified includes: selecting the target rule base from multiple rule bases based on the programming language used by the web project to be identified, wherein one rule base corresponds to one programming language, and each rule base includes defense function keywords and dangerous functions corresponding to various vulnerabilities.

[0008] Some embodiments of this application enhance the versatility of the technical solution by providing multiple rule bases.

[0009] In some embodiments, constructing a defense library based on defense function keywords in the target rule base includes: filtering defense functions that match the defense function keywords from the web project to be identified to obtain target defense functions; obtaining a method for calling the target defense function to obtain multiple defense rules; and obtaining the defense library based on the multiple defense rules.

[0010] Some embodiments of this application provide a method for obtaining a defense rule base, through which the defense rules in the defense base can reduce the false identification rate of vulnerabilities.

[0011] In some embodiments, obtaining the defense library based on the multiple defense rules includes: identifying a first type of defense rule from the multiple defense rules to obtain multiple target defense rules, wherein the first type of defense rule belongs to the defense rules that cannot block hacker access; deleting the multiple target defense rules from the multiple defense rules to obtain the defense library.

[0012] Some embodiments of this application record and delete rules with weak defenses from the database, organize and reorganize strict defense strategies, and re-integrate them into a defense rule database. This reduces the amount of data in the rule database, improves the defense security of the remaining defense rules, and thus improves the accuracy of vulnerability identification for web projects to be identified.

[0013] In some embodiments, the step of identifying a first type of defense rule from the plurality of defense rules to obtain a plurality of target defense rules includes: providing the plurality of defense rules; and receiving input information to obtain the plurality of target defense rules.

[0014] Some embodiments of this application obtain target defense rules through human intervention, thereby improving the quality of the defense rules obtained as matching objects and thus improving the accuracy of the obtained vulnerability judgment results.

[0015] In some embodiments, the step of filtering out defense functions that match the defense function keywords from the web project to be identified to obtain target defense functions includes: performing regular expression matching on each defense function keyword in the target rule base with the web project to be identified to obtain the row number of the defense function keyword in the web project to be identified, and taking the successfully matched defense function as a target defense function; repeating the above operation by decrementing the row number by one until the entire web project to be identified is matched to obtain all target defense functions.

[0016] Some embodiments of this application provide an iterative method for obtaining all target defense functions.

[0017] In some embodiments, the step of performing vulnerability scanning on the web project to be identified based on the defense library and the dangerous functions to obtain vulnerability scanning results includes: obtaining the methods, classes, or interfaces of dangerous functions called by the web project to be identified based on the dangerous functions to obtain an initial vulnerability set; and obtaining vulnerability scanning results by at least deleting the methods, classes, or interfaces in the initial vulnerability set that simultaneously call defense rules in the defense library.

[0018] Some embodiments of this application use dangerous functions and defense rules to match a certain object, ensuring that the obtained vulnerability is a real vulnerability and effectively reducing the false positive rate.

[0019] In some embodiments, obtaining the method, class, or interface of the dangerous function called by the web project to be identified based on the dangerous function, and obtaining the initial vulnerability set, includes: matching the dangerous function with the web project to be identified, and using the successfully matched methods, classes, or interfaces included in the web project to be identified as the initial vulnerability set.

[0020] Some embodiments of this application obtain vulnerability elements in the initial vulnerability set through a matching method.

[0021] In some embodiments, the step of deleting methods, classes, or interfaces that simultaneously invoke defense rules in the defense library from the initial vulnerability set includes: matching elements in the initial vulnerability set with the defense library, and marking successfully matched methods, classes, or interfaces as normal; and deleting elements marked as normal from the initial vulnerability set.

[0022] Some embodiments of this application identify falsely identified vulnerabilities by matching them with defense rules in a defense library and removing these vulnerabilities from the initial vulnerability set, thereby improving the accuracy of vulnerability identification and preventing false alarms.

[0023] In some embodiments, obtaining vulnerability scanning results by deleting methods, classes, or interfaces that simultaneously invoke defense rules in the defense library from the initial vulnerability set includes: obtaining a candidate vulnerability set by deleting methods, classes, or interfaces that simultaneously invoke defense rules in the defense library from the initial vulnerability set; and re-scanning the elements in the candidate vulnerability set to obtain the vulnerability scanning results.

[0024] Some embodiments of this application further correct vulnerabilities obtained after matching with the defense library to reduce the false positive rate.

[0025] In some embodiments, the vulnerability scan results include: dangerous methods, dangerous classes, or dangerous interfaces.

[0026] The vulnerability scanning results provided in some embodiments of this application include dangerous methods, dangerous classes, and dangerous interfaces identified from the web project to be identified.

[0027] In some embodiments, the vulnerability scan results include: dangerous methods, dangerous classes, dangerous interfaces, and vulnerability types, wherein the vulnerability type is determined by the dangerous function.

[0028] The vulnerability scanning results provided in some embodiments of this application include dangerous methods, dangerous classes, dangerous interfaces, and vulnerability types corresponding to various vulnerabilities identified from the web project to be identified.

[0029] Secondly, some embodiments of this application provide an apparatus for identifying web vulnerabilities. The apparatus includes: a target rule base acquisition module configured to select a target rule base based on attribute information of the web project to be identified, wherein the target rule base includes defense function keywords and dangerous functions corresponding to various vulnerabilities; a defense library acquisition module configured to construct a defense library based on the defense function keywords in the target rule base; and a vulnerability result acquisition module configured to perform vulnerability scanning on the web project to be identified based on the defense library and the dangerous functions to obtain vulnerability scanning results.

[0030] Thirdly, some embodiments of this application provide a computer storage medium having a computer program stored thereon, which, when executed by a processor, can implement the method described in any embodiment of the first aspect.

[0031] Fourthly, some embodiments of this application provide an electronic device including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor, when executing the program, can implement the method as described in any embodiment of the first aspect. Attached Figure Description

[0032] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings used in the embodiments of this application will be briefly introduced below. It should be understood that the following drawings only show some embodiments of this application and should not be regarded as a limitation of the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.

[0033] Figure 1 A system architecture diagram for identifying web vulnerabilities provided in this application embodiment;

[0034] Figure 2 This is one of the flowcharts of a method for identifying web vulnerabilities provided in an embodiment of this application;

[0035] Figure 3 This is the second flowchart of a method for identifying web vulnerabilities provided in an embodiment of this application;

[0036] Figure 4 This is the third flowchart of the method for identifying web vulnerabilities provided in the embodiments of this application;

[0037] Figure 5 This is the fourth flowchart of the method for identifying web vulnerabilities provided in the embodiments of this application;

[0038] Figure 6 A block diagram illustrating the composition of an apparatus for identifying web vulnerabilities provided in an embodiment of this application;

[0039] Figure 7 This application provides a schematic diagram of the electronic device composition in its embodiments. Detailed Implementation

[0040] The technical solutions in the embodiments of this application will now be described with reference to the accompanying drawings.

[0041] It should be noted that similar reference numerals and letters in the following figures indicate similar items; therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures. Furthermore, in the description of this application, terms such as "first," "second," etc., are used only to distinguish descriptions and should not be construed as indicating or implying relative importance.

[0042] The embodiments of this application use regular expressions to match dangerous functions, iteratively call dangerous functions, methods, interfaces and classes during the vulnerability scanning process. During the iteration process, if a defense rule in the defense library is matched, the vulnerability message will be excluded from the vulnerability list. If no match is found, the vulnerability result will be output to reduce the false positive rate. This is a secondary optimization of the entire task.

[0043] Please refer to Figure 1 , Figure 1 The system for identifying web vulnerabilities provided in this application includes a terminal device 100 and a server 200. The terminal device 100 generates a web project to be identified, and then sends the web project to be identified to the server 200 so that the server can identify the vulnerabilities present therein and obtain vulnerability scanning results.

[0044] The following is combined Figure 2 This paper exemplifies a method for identifying web vulnerabilities performed by server 200.

[0045] like Figure 2 As shown in the figure, this application provides a method for identifying web vulnerabilities, the method including:

[0046] S101, Select a target rule base based on the attribute information of the web project to be identified, wherein the target rule base includes defense function keywords and dangerous functions corresponding to various vulnerabilities.

[0047] In some embodiments of this application, step S101 includes, for example, selecting the target rule base from multiple rule bases based on the programming language used by the web project to be identified. Each rule base corresponds to a programming language, and each rule base includes defense function keywords and dangerous functions corresponding to various vulnerabilities. Some embodiments of this application enhance the versatility of the technical solution by providing multiple rule bases.

[0048] For example, in some embodiments of this application, step S101 exemplarily includes: reading the content of a web project and selecting different rule bases based on the language of the web project. Each rule base contains two parts: one part is defense function keywords used to defend against vulnerabilities, and the other part is dangerous functions and their corresponding keywords.

[0049] S102, construct a defense library based on the defense function keywords in the target rule library.

[0050] In some embodiments of this application, S102 includes, for example,: filtering defense functions matching the keywords of the defense function from the web project to be identified, to obtain target defense functions; obtaining a method for calling the target defense function to obtain multiple defense rules; and obtaining the defense library based on the multiple defense rules. For example, in some embodiments of this application, the multiple defense rules are directly combined to obtain the defense library, which includes: defense rules that can be bypassed by hackers; defense rules that cannot be bypassed; and useless code (e.g., comments). In some embodiments of this application, the initial defense library obtained by combination is filtered by manual intervention to filter out strategies that can be bypassed by hackers, and these strategies are deleted, and the remaining defense rules are combined to form the defense library. That is to say, some embodiments of this application provide a method for obtaining a defense rule library, through which the defense rules in the defense library can reduce the false identification rate of vulnerabilities.

[0051] To further improve the defensive performance of the obtained defense rules, in some embodiments of this application, S120 includes obtaining the defense library based on the multiple defense rules, which includes: identifying a first type of defense rule from the multiple defense rules to obtain multiple target defense rules, wherein the first type of defense rule belongs to the defense rules that cannot block hacker access; deleting the multiple target defense rules from the multiple defense rules to obtain the defense library.

[0052] In other words, some embodiments of this application record and delete rules with weak defenses (e.g., defense rules that hackers can bypass, i.e., first-type defense rules) from the database, organize and reorganize strict defense strategies, and re-integrate them into a defense rule database. While reducing the amount of data in the rule database, the defense security of the remaining defense rules is improved, thereby improving the accuracy of vulnerability identification for the web projects to be identified.

[0053] To further improve the defensive performance of the obtained defense rules, the target defense rules can be screened through manual intervention. For example, in some embodiments of this application, S102, which involves identifying a first type of defense rule from the multiple defense rules to obtain multiple target defense rules, includes: providing the multiple defense rules (e.g., displaying the multiple defense rules to a user); and receiving input information to obtain the multiple target defense rules (e.g., the user selecting multiple target defense rules from the multiple defense rules). In other words, some embodiments of this application utilize manual intervention to obtain target defense rules, thereby improving the quality of the defense rules obtained as matching objects and thus improving the accuracy of the obtained vulnerability judgment results.

[0054] It should be noted that some embodiments of this application may also select multiple target defense rules from the multiple defense rules according to the attributes of the first type of defense rules.

[0055] To ensure that as many target defense functions as possible are identified, some embodiments of this application provide a method for iterative processing by row. For example, in some embodiments of this application, the process of filtering defense functions that match the defense function keywords from the web project to be identified in step S102 to obtain target defense functions includes: performing regular expression matching on each defense function keyword in the target rule base with the web project to be identified to obtain the row number of the defense function keyword in the web project to be identified, and taking the successfully matched defense function as a target defense function; repeating the above operation by decrementing the row number by one until the entire web project to be identified is matched to obtain all target defense functions.

[0056] It should be noted that those skilled in the art can set the iteration method according to actual needs, and may not follow the iteration method of row-based units. The embodiments of this application do not limit the unit of iteration.

[0057] For example, in some embodiments of this application, S102 may include: matching the defense function keywords of the selected vulnerability defense in the selected rule base using regular expressions to determine the location of the defense function in the web project to be identified; then iterating to find the method in the web project to be identified that calls the defense function—here collectively referred to as the defense rule; and assembling all the defense rules into a library. Through manual analysis of the defense rule library, rules with weak defense are recorded and deleted from the library (i.e., identifying and deleting the first type of defense rule), while strict defense strategies are organized and reassembled into a defense library.

[0058] It should be noted that after the defense rules in the defense library obtained by S102 are sent to the vulnerability scanning module, the defense rules in the web project are then manually checked for security flaws, and the defense rules without security risks are used as the defense rules in the defense library.

[0059] S103, Perform vulnerability scanning on the web project to be identified based on the defense library and the dangerous functions to obtain vulnerability scanning results.

[0060] Unlike related technologies that rely solely on keywords corresponding to dangerous functions for vulnerability identification, the embodiments of this application employ a secondary matching method to improve the accuracy of vulnerability identification, enabling the identification of more precise vulnerabilities. Specifically, the embodiments of this application use a defense library and dangerous functions to jointly match the web project to be identified. Methods, classes, and interfaces that successfully match dangerous functions and defense rules are recorded as safe, inactive vulnerabilities. For example, in some embodiments of this application, S103 includes:

[0061] The first step is to obtain the methods, classes, or interfaces of the dangerous functions called by the web project to be identified, based on the dangerous functions, to obtain an initial set of vulnerabilities.

[0062] For example, in some embodiments of this application, the first step typically includes: matching the dangerous function with the web project to be identified, and using the successfully matched methods, classes, or interfaces included in the web project to be identified as the initial vulnerability set. Some embodiments of this application obtain each vulnerability element in the initial vulnerability set through a matching method.

[0063] The second step is to obtain vulnerability scanning results by deleting at least the methods, classes, or interfaces that simultaneously call the defense rules in the defense library from the initial vulnerability set.

[0064] For example, in some embodiments of this application, the second step may include: matching elements in the initial vulnerability set with the defense library, and marking the successfully matched methods, classes or interfaces as normal; and deleting the elements marked as normal from the initial vulnerability set.

[0065] In other words, some embodiments of this application ensure that the identified vulnerabilities are genuine by matching dangerous functions with defense rules against a specific object, effectively reducing the false positive rate. Some embodiments of this application identify incorrectly identified vulnerabilities by matching them with defense rules in a defense library and remove these vulnerabilities from the initial vulnerability set, thereby improving the accuracy of vulnerability identification and preventing false positives.

[0066] For example, in some embodiments of this application, the second step typically includes: obtaining a candidate vulnerability set by deleting methods, classes, or interfaces that simultaneously call defense rules in the defense library from the initial vulnerability set; and re-scanning the elements in the candidate vulnerability set to obtain the vulnerability scan result. Some embodiments of this application also further refine the vulnerabilities obtained after matching with the defense library to reduce the false positive rate. In other words, some embodiments of this application perform vulnerability scanning on web projects based on the defense library and dangerous functions to obtain vulnerability scan results, which can effectively reduce the false positive rate of web vulnerabilities.

[0067] For example, in some embodiments of this application, S103 includes: matching the web project to be identified with dangerous functions in the target rule base, determining the location of the dangerous functions in the web project to be identified, and iterating to identify the methods, classes, or interfaces that use the dangerous functions—collectively referred to here as dangerous methods, dangerous classes, and dangerous interfaces. If a dangerous method, dangerous class, or dangerous interface calls a defense rule in the defense library during the iteration process, then the dangerous method, dangerous class, or dangerous interface is classified as a normal method, normal class, or normal interface. Afterwards, all dangerous methods, dangerous classes, and dangerous interfaces are compiled into a table and output to obtain the vulnerability scan results. Some embodiments of this application reduce the false positive rate by excluding normal methods, normal classes, and normal interfaces, and allow security personnel to determine whether a web project has vulnerabilities by returning dangerous methods, dangerous classes, and dangerous interfaces.

[0068] It should be noted that, in some embodiments of this application, the vulnerability scanning results include: dangerous methods, dangerous classes, or dangerous interfaces. In some embodiments of this application, the vulnerability scanning results include: dangerous methods, dangerous classes, dangerous interfaces, and vulnerability types, wherein the vulnerability type is determined by the hazard function. That is, the vulnerability scanning results provided by some embodiments of this application include dangerous methods, dangerous classes, and dangerous interfaces identified from the web project to be identified. The vulnerability scanning results provided by some embodiments of this application include dangerous methods, dangerous classes, dangerous interfaces, and vulnerability types corresponding to various vulnerabilities identified from the web project to be identified.

[0069] The following is combined Figures 3-5 The present application provides exemplary methods for identifying web vulnerabilities through some embodiments.

[0070] pass Figure 3 The method can achieve the following technical objectives: (1) In order to support multiple languages, some embodiments of this application use different language rule bases for matching source code in different languages, supporting language diversification. (2) In order to reduce the false positive rate of web vulnerabilities, some embodiments of this application use an iterative algorithm based on regular expression matching of dangerous functions to iteratively match the methods, classes, interfaces that use dangerous functions with the defense rule base. If there are methods that use defense rules in the defense base among the methods, classes, and interfaces that use dangerous functions, then the result is excluded; otherwise, the identification result is output as the identified vulnerability. (3) In addition, the defense base of some embodiments of this application is mainly built by tool scanning and supplemented by manual analysis, which means that the strategies corresponding to the defense rules in the web project can be manually analyzed. Whether the defense rules are strict determines whether a web vulnerability can be bypassed, exploited by hackers, and cause property loss.

[0071] like Figure 3 As shown, some embodiments of this application provide a method for identifying web vulnerabilities, including:

[0072] S201, Task Creation and Editing

[0073] The task creation and editing module mainly handles the preparatory work for creating scanning tasks, such as... Figure 4 The example content created and edited for the task shown includes the following five categories of information:

[0074] First, create a task name.

[0075] Second, edit the language used by the project (i.e., the web project). The language used by the web project is used to select the target rule base corresponding to a certain language from multiple rule bases.

[0076] Third, remarks information (i.e., web project remarks information), such as: testing time, personnel in charge of the project, and personnel who tested the project.

[0077] Fourth, the types of vulnerabilities that need to be returned (i.e., setting the types of vulnerabilities that need to be returned).

[0078] Fifth, enter the project to be scanned (i.e., the web project) to prepare for task creation.

[0079] For example, creating a task in the task creation and editing module involves selecting the rule base required for the web project, inputting the web project information, creating a task name, filling in task remarks, and setting the type of vulnerability to be returned. The web project input primarily involves specifying the location of the web project on the computer. This information is used to facilitate loading the web project. The task name is designed for ease of memorization and to label the web project. Remarks are used to add additional information. The returned vulnerability type can be selected based on the type of vulnerability.

[0080] It should be noted that the rule base mainly consists of two parts: one part is defense function keywords, which facilitates the matching of defense rules for web projects, and then the defense rules are analyzed manually; the other part is dangerous functions for common vulnerabilities, which facilitates the matching of dangerous methods, dangerous interfaces, dangerous classes, and the classification of vulnerability types based on dangerous functions.

[0081] S202, Project Loading

[0082] The purpose of the web project loading module is to read the entire contents of the web project files, making it easier for users to read the source code and audit it online.

[0083] S203, Defense Scan

[0084] The role of the defense scanning module is to use regular expressions combined with defense function keywords in the rule base to match defense functions in the web project to be identified, and to use an iterative method to iterate out the methods that call the defense functions to obtain the defense rules.

[0085] For example, in some embodiments of this application, S203 includes: after the project is loaded, the system enters the defense scanning module. Each defense function keyword in the rule base is matched with the web project to be identified using regular expressions to obtain the line number of the defense function keyword in the web project file. The system iterates upwards by decrementing the line number by one, calling the methods of the defense function keyword—collectively referred to as defense rules—and then sends them to the defense database creation module. The above operation is repeated until the entire web project to be identified is matched.

[0086] S204, Building a Defense Library

[0087] The defense library creation module receives the defense rules returned by the defense scanning module, organizes them into a library, and then outputs the defense library. Users analyze the defenses. If the user adjusts the defense library, the organized defense library is sent to the vulnerability scanning module; otherwise, the defense rule library is sent directly to the vulnerability scanning module.

[0088] For example, such as Figure 5 As shown, S204 includes, for example,: S301, anti-defense scanning, i.e., scanning the web item to be identified (e.g., line-by-line scanning). S302, using regular expressions to scan for defense functions in the item. S303, using an iterative method to find the methods that use the defense functions. That is, through... Figure 5 The method can use regular expressions to match defense function keywords with the web items to be identified, and obtain defense rules.

[0089] It should be noted that in some embodiments of this application, the matched defense rules also need to be deleted to improve their defensive capabilities. For example, in some embodiments of this application, target defense rules are obtained through manual analysis, and these rules are then deleted to obtain the defense library. The reason for this is that if only regular expression matching is used, all defense rules obtained include the following three types: defense rules that can be bypassed by hackers (belonging to the first type of defense rules, i.e., target defense rules), defense rules that cannot be bypassed, and useless code (e.g., comments). Therefore, in order to further identify defense rules with better defensive performance from these defense rules, some embodiments of this application can use manual analysis or automatic analysis to filter out target defense rules, and delete these target defense rules from the multiple defense rules obtained by regular expression matching. The deleted defense rules are then used as the defense rules in the defense library. In other words, the embodiments of this application also consider identifying and deleting defense rules that do not meet the requirements when constructing the rule library.

[0090] In other words, in some embodiments of this application, all defense rules passed to the defense library creation module are compiled into a single defense library. The defense library creation module then outputs the defense library, which the user can analyze. Unreasonable defense rules are recorded and deleted from the defense rule library. Reasonable defense strategies (those that perfectly defend against vulnerabilities and cannot be bypassed, i.e., strategies not belonging to the first category of defense rules) are compiled and re-integrated into a single defense library. The advantages of this approach are: First, it analyzes the defense strategies in the web project to be identified, upgrades unreasonable defense rules, and reduces security risks associated with defense rules. Second, it reduces the load on the vulnerability scanning module. Finally, the compiled defense library is transmitted to the vulnerability scanning module.

[0091] S205, Vulnerability Scanning

[0092] Vulnerability scanning is performed on the web project to be identified based on the defense rules and dangerous functions of the defense library.

[0093] For example, in some embodiments of this application, the vulnerability scanning module corresponding to S205 functions uses regular expressions to match dangerous functions and iteratively calls the methods and interfaces of those dangerous functions. During the iteration process, regular expressions are used to match the vulnerability information with a defense library. If a match is found, the vulnerability information is excluded to reduce the false positive rate. This process continues until all dangerous functions in the web application have been processed, and then all output security vulnerabilities are forwarded to the vulnerability output module.

[0094] For example, in some embodiments of this application, the vulnerability scanning module used to execute S205, after receiving the defense library, performs regular expression matching on the keywords of each dangerous function in the rule base against the web project to be identified, obtains the line number of the dangerous function keyword in the web project file, and iterates upwards by decrementing the line number to call the dangerous function keyword's method—the dangerous method; obtains the line number of the dangerous method in the web project file, and iterates upwards by decrementing the line number to call the class of the dangerous method—the dangerous class; similarly, dangerous interfaces are obtained using this iterative method. During iteration, if the dangerous method, dangerous class, or dangerous interface contains rules that call the defense library, the dangerous method, dangerous class, or dangerous interface is converted into a safe method, safe class, or safe method to reduce the false positive rate. Finally, the dangerous method, dangerous class, and dangerous interface are sent to the result output module as the final vulnerability scanning result.

[0095] S206, Vulnerability Result Output

[0096] Output all vulnerabilities identified after the vulnerability scanning steps of S205.

[0097] For example, the result output module is responsible for outputting a vulnerability report based on the results of the vulnerability scanning module, with dangerous methods, dangerous classes, and dangerous interfaces as the first-level directory and vulnerability types as the second-level directory.

[0098] In other words, after receiving all the dangerous methods, dangerous classes, and dangerous interfaces sent by the vulnerability scanning module, the result output module corresponding to S206 classifies all dangerous methods, dangerous classes, and dangerous interfaces into vulnerability categories according to the dangerous functions in the rule base. Finally, the results are output with dangerous methods, dangerous classes, and dangerous interfaces as the first-level directory and vulnerability types as the second-level directory, which is the vulnerability scanning result.

[0099] Based on the above examples, it is not difficult to see that some embodiments of this application have at least the following technical advantages:

[0100] 1. Supports multiple languages, allowing you to select different rule bases based on different languages.

[0101] 2. It can analyze the defense strategy of web projects, locate the position of defense functions in web projects based on defense function keywords and regular expressions in the rule base, iterate to generate defense rules, and organize all defense rules into a defense rule base to facilitate security personnel to analyze the defense rules in web projects and find security vulnerabilities in the defense rules.

[0102] 3. Low false positive rate: Regular expressions are used to match dangerous functions. Based on the dangerous functions, the methods and interfaces of the dangerous functions are iteratively called. During the iteration process, regular expression matching is performed with the defense library. If a match is found in the defense library, the vulnerability information is excluded, thereby reducing the false positive rate.

[0103] Please refer to Figure 6 , Figure 6 The present application illustrates an apparatus for identifying web vulnerabilities, and it should be understood that this apparatus is similar to the one described above. Figure 2 Corresponding to the method embodiments, it can execute the various steps involved in the above method embodiments. The specific functions of the device can be found in the description above. To avoid repetition, detailed descriptions are appropriately omitted here. The device includes at least one software function module that can be stored in the memory or embedded in the device's operating system in the form of software or firmware. The device for identifying web vulnerabilities includes: a target rule base acquisition module 101, a defense base acquisition module 102, and a vulnerability result acquisition module 103.

[0104] The target rule base acquisition module is configured to select a target rule base based on the attribute information of the web project to be identified. The target rule base includes defense function keywords and dangerous functions corresponding to various vulnerabilities.

[0105] The defense library acquisition module is configured to construct a defense library based on the defense function keywords in the target rule library.

[0106] The vulnerability result acquisition module is configured to perform vulnerability scanning on the web project to be identified based on the defense library and the dangerous functions, and obtain vulnerability scanning results.

[0107] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working process of the device described above can be referred to the corresponding process in the aforementioned method, and will not be elaborated further here.

[0108] Some embodiments of this application provide a computer storage medium having a computer program stored thereon, which, when executed by a processor, can implement the method described in any of the embodiments of the above-described method for identifying web vulnerabilities.

[0109] like Figure 7 As shown, some embodiments of this application provide an electronic device 500, which exemplarily includes a memory 510, a processor 520, and a computer program stored on the memory 510 and executable on the processor 520. When the processor 520 reads and executes the program via a bus 530, it can implement the methods described in any of the embodiments of the above-described method for identifying web vulnerabilities.

[0110] Processor 520 can process digital signals and can include various computing architectures. For example, it can be a complex instruction set computer architecture, a reduced instruction set computer architecture, or an architecture that implements multiple instruction set combinations. In some examples, processor 520 can be a microprocessor.

[0111] The memory 510 can be used to store instructions executed by the processor 520 or data related to the execution of instructions. These instructions and / or data may include code used to implement some or all of the functions of one or more modules described in the embodiments of this application. The processor 520 of the embodiments of this disclosure can be used to execute the instructions in the memory 510 to implement… Figure 2 The method shown. Memory 510 includes dynamic random access memory, static random access memory, flash memory, optical memory, or other memory well known to those skilled in the art.

[0112] In the several embodiments provided in this application, it should be understood that the disclosed apparatus and methods can also be implemented in other ways. The apparatus embodiments described above are merely illustrative. For example, the flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of apparatus, methods, and computer program products according to various embodiments of this application. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than those marked in the drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram and / or flowchart, and combinations of blocks in block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or action, or using a combination of dedicated hardware and computer instructions.

[0113] In addition, the functional modules in the various embodiments of this application can be integrated together to form an independent part, or each module can exist independently, or two or more modules can be integrated to form an independent part.

[0114] If the aforementioned functions are implemented as software functional modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0115] The above description is merely an embodiment of this application and is not intended to limit the scope of protection of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of protection of this application. It should be noted that similar reference numerals and letters in the following figures indicate similar items; therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures.

[0116] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

[0117] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

Claims

1. A method for identifying web vulnerabilities, characterized in that, The method includes: The target rule base is selected based on the attribute information of the web project to be identified, wherein the target rule base includes defense function keywords and dangerous functions corresponding to various vulnerabilities; Construct a defense library based on the defense function keywords in the target rule base; Based on the defense library and the dangerous functions, a vulnerability scan is performed on the web project to be identified to obtain the vulnerability scan results; The step of constructing a defense library based on the defense function keywords in the target rule base includes: The target defense function is obtained by filtering out defense functions that match the keywords of the defense function from the web projects to be identified; The method for invoking the target defense function yields multiple defense rules; The defense library is obtained based on the aforementioned multiple defense rules; The step of performing vulnerability scanning on the web project to be identified based on the defense library and the dangerous functions to obtain vulnerability scanning results includes: Based on the dangerous functions, obtain the methods, classes, or interfaces of the dangerous functions called by the web project to be identified, and obtain an initial set of vulnerabilities; At least by deleting the methods, classes, or interfaces that simultaneously call the defense rules in the defense library from the initial vulnerability set, the vulnerability scan results can be obtained; The method, class, or interface for obtaining dangerous functions called by the web project to be identified based on the dangerous functions, to obtain an initial vulnerability set, includes: The dangerous function is matched with the web project to be identified, and the methods, classes or interfaces of the web project to be identified that are successfully matched are used as the initial vulnerability set. The step of deleting methods, classes, or interfaces from the initial vulnerability set that simultaneously invoke defense rules in the defense library includes: Match the elements in the initial vulnerability set with the defense library, and mark the successfully matched methods, classes or interfaces as normal; Remove elements marked as normal from the initial vulnerability set; The process of obtaining vulnerability scan results by deleting at least the methods, classes, or interfaces that simultaneously invoke defense rules in the defense library from the initial vulnerability set includes: A candidate vulnerability set is obtained by deleting methods, classes, or interfaces that simultaneously call defense rules in the defense library from the initial vulnerability set; The vulnerability scan results are obtained by scanning the elements in the candidate vulnerability set again.

2. The method as described in claim 1, characterized in that, The step of selecting the target rule base based on the attribute information of the web project to be identified includes: The target rule base is selected from multiple rule bases based on the programming language used by the web project to be identified. Each rule base corresponds to a programming language, and each rule base includes defense function keywords and dangerous functions corresponding to various vulnerabilities.

3. The method as described in claim 1, characterized in that, The defense database obtained based on the multiple defense rules includes: From the multiple defense rules, a first type of defense rule is identified, resulting in multiple target defense rules. Among these, the first type of defense rule is a defense rule that cannot block hacker access. The defense library is obtained by deleting the target defense rules from the multiple defense rules.

4. The method as described in claim 3, characterized in that, The process of identifying the first type of defense rules from the multiple defense rules to obtain multiple target defense rules includes: Provide the aforementioned multiple defense rules; The multiple target defense rules are obtained by receiving input information.

5. The method as described in claim 3, characterized in that, The step of filtering out defense functions that match the keywords of the defense function from the web projects to be identified, to obtain the target defense function, includes: Each defense function keyword in the target rule base is matched with the web project to be identified using regular expressions to obtain the row number of the defense function keyword in the web project to be identified, and the defense function that successfully matches is taken as a target defense function. Repeat the above operation by decreasing the row number by one until all the web items to be identified are matched to obtain all target defense functions.

6. The method as described in claim 1, characterized in that, The vulnerability scan results include: dangerous methods, dangerous classes, or dangerous interfaces.

7. The method as described in claim 1, characterized in that, The vulnerability scan results include: dangerous methods, dangerous classes, dangerous interfaces, and vulnerability types, wherein the vulnerability type is determined by the dangerous function.

8. An apparatus for identifying web vulnerabilities, characterized in that, The device includes: The target rule base acquisition module is configured to select a target rule base based on the attribute information of the web project to be identified, wherein the target rule base includes defense function keywords and dangerous functions corresponding to various vulnerabilities; The defense library acquisition module is configured to construct a defense library based on the defense function keywords in the target rule library; The vulnerability result acquisition module is configured to perform vulnerability scanning on the web project to be identified based on the defense library and the dangerous functions, and obtain vulnerability scanning results. The defense library acquisition module is specifically used for: The target defense function is obtained by filtering out defense functions that match the keywords of the defense function from the web projects to be identified; The method for invoking the target defense function yields multiple defense rules; The defense library is obtained based on the aforementioned multiple defense rules; The vulnerability result acquisition module is specifically used for: Based on the dangerous functions, obtain the methods, classes, or interfaces of the dangerous functions called by the web project to be identified, and obtain an initial set of vulnerabilities; At least by deleting the methods, classes, or interfaces that simultaneously call the defense rules in the defense library from the initial vulnerability set, the vulnerability scan results can be obtained; The method, class, or interface for obtaining dangerous functions called by the web project to be identified based on the dangerous functions, to obtain an initial vulnerability set, includes: The dangerous function is matched with the web project to be identified, and the methods, classes or interfaces of the web project to be identified that are successfully matched are used as the initial vulnerability set. The step of deleting methods, classes, or interfaces from the initial vulnerability set that simultaneously invoke defense rules in the defense library includes: Match the elements in the initial vulnerability set with the defense library, and mark the successfully matched methods, classes or interfaces as normal; Remove elements marked as normal from the initial vulnerability set; The process of obtaining vulnerability scan results by deleting at least the methods, classes, or interfaces that simultaneously invoke defense rules in the defense library from the initial vulnerability set includes: A candidate vulnerability set is obtained by deleting methods, classes, or interfaces that simultaneously call defense rules in the defense library from the initial vulnerability set; The vulnerability scan results are obtained by scanning the elements in the candidate vulnerability set again.

9. A computer storage medium having a computer program stored thereon, characterized in that, When the program is executed by a processor, it can implement the method described in any one of claims 1-7.

10. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein, When the processor executes the program, it can implement the method described in any one of claims 1-7.

Citation Information

Patent Citations

  • Code auditing method and device, electronic equipment and medium

    CN111666218A