Vulnerability detection method, system, electronic device and storage medium
By sending test data to modify the state of the object under test and monitoring its anomalies, the problem of multi-protocol collaborative communication vulnerability detection in the existing technology is solved, and efficient vulnerability detection of multi-protocol collaborative communication is achieved.
Patent Information
- Application Number
- CN202211509344.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-11-29
- Publication Date
- 2025-09-23
- Estimated Expiration
- 2042-11-29
AI Technical Summary
It is difficult to effectively detect vulnerabilities in software and hardware devices during multi-protocol collaborative communication with existing technologies, especially it is difficult to discover potential vulnerabilities when collaborative communication is performed between different communication protocols.
By sending test data to the object under test based on the first communication protocol, modifying its status, and using the second communication protocol to send related business processing requests, the operation anomalies of the object under test are monitored to detect whether there are vulnerabilities in its multi-protocol collaborative communication.
It can efficiently detect vulnerabilities of the tested object during multi-protocol collaborative communication, improve the coverage and accuracy of vulnerability detection, and is suitable for multi-protocol collaborative communication scenarios.
Smart Images

Figure CN115941305B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of information security technology, and in particular to a vulnerability detection method, system, electronic device, and storage medium. Background Art
[0002] With the rapid development of network technology, the network security of hardware and software devices, such as application software and embedded devices, has received increasing attention. When focusing on the network security of these hardware and software devices, they can often be used as test objects, allowing testing to detect vulnerabilities hidden in the test objects. Therefore, corresponding vulnerability detection methods are needed. Summary of the Invention
[0003] The purpose of the embodiments of the present application is to provide a vulnerability detection method, system, electronic device and storage medium for detecting whether there is a vulnerability hidden in the object being tested.
[0004] A first aspect of an embodiment of the present application provides a vulnerability detection method, comprising:
[0005] Sending test data to the object under test based on a first communication protocol, wherein the test data is used to modify the state of the object under test;
[0006] Based on the second communication protocol, an associated business processing request associated with the modified state of the object under test is sent to the object under test, so as to detect whether there is a vulnerability when the object under test communicates collaboratively according to the first communication protocol and the second communication protocol through the processing of the associated business requested by the associated business processing request.
[0007] In one embodiment, the method further includes:
[0008] The seed file is mutated according to a preset mutation strategy to generate the test data.
[0009] In one embodiment, sending test data to the object under test based on the first communication protocol specifically includes:
[0010] Encapsulating the test data using a first communication protocol;
[0011] The encapsulated test data is sent to the object under test through a transmission channel corresponding to the first communication protocol.
[0012] In one embodiment, the test data is used to modify the accessible state of the target file in the tested object; and
[0013] Sending, to the measured object based on the second communication protocol, an associated service processing request associated with the modified state of the measured object, specifically includes:
[0014] An access request for the target file access service is sent to the measured object based on the second communication protocol.
[0015] In one embodiment, the test data is used to modify the operation permission status of the target file in the tested object; and
[0016] Sending, to the measured object based on the second communication protocol, an associated service processing request associated with the modified state of the measured object, specifically includes:
[0017] An operation request for the target file operation service is sent to the measured object based on the second communication protocol.
[0018] In one embodiment, the test data includes a test file; and the test data is used to modify the storage state of the tested object by storing the test file in the tested object; and,
[0019] Sending, to the measured object based on the second communication protocol, an associated service processing request associated with the modified state of the measured object, specifically includes:
[0020] A parsing request and / or an access request for the test file is sent to the object under test based on a second communication protocol.
[0021] In one embodiment, during the processing of the associated business, the method further includes:
[0022] By monitoring whether the object under test operates abnormally, it is detected whether there is a vulnerability when the object under test communicates in collaboration according to the first communication protocol and the second communication protocol. If it is monitored that the object under test operates abnormally, there is a vulnerability when the first communication protocol and the second communication protocol communicate in collaboration.
[0023] In one embodiment, there are multiple first communication protocols; and
[0024] Sending test data to the object under test based on the first communication protocol specifically includes:
[0025] Test data are sent to the object under test in sequence based on each first communication protocol, wherein each test data is used to modify the state of the object under test in sequence.
[0026] In one embodiment, the method further includes:
[0027] Two communication protocols are selected from three or more communication protocols multiple times, and the two communication protocols selected each time are used as the first communication protocol and the second communication protocol respectively.
[0028] A second aspect of an embodiment of the present application provides a vulnerability detection system, including:
[0029] a fuzzy test mutation module, which sends test data to the object under test based on a first communication protocol, wherein the test data is used to modify the state of the object under test;
[0030] The continuous operation module sends an associated business processing request associated with the modified state of the measured object to the measured object based on the second communication protocol, so as to detect whether there is a vulnerability when the measured object communicates collaboratively according to the first communication protocol and the second communication protocol through the processing of the associated business requested by the associated business processing request.
[0031] A third aspect of the embodiments of the present application provides an electronic device, including:
[0032] processor;
[0033] A memory for storing processor-executable instructions; wherein the processor is configured to execute the method described in any one of the first aspects above.
[0034] A fourth aspect of the embodiments of the present application provides a computer-readable storage medium, wherein the storage medium stores a computer program, and the computer program can be executed by a processor to complete any method described in the first aspect.
[0035] The vulnerability detection method provided in the embodiment of the present application first sends test data to the object under test based on a first communication protocol, thereby modifying the state of the object under test, and then sends an associated business processing request associated with the modified state of the object under test to the object under test based on a second communication protocol. In this way, the associated business processing request sent by the second communication protocol prompts the processing of the associated business. Since the associated business is associated with the modified state of the object under test, and the state modification of the object under test is based on the test data sent by the first communication protocol, it is possible to detect whether there is a vulnerability when the object under test communicates collaboratively according to the first communication protocol and the second communication protocol through the processing of the associated business. BRIEF DESCRIPTION OF THE DRAWINGS
[0036] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following is a brief introduction to the drawings required for use in the embodiments of the present application. It should be understood that the following drawings only show certain embodiments of the present application and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other relevant drawings can be obtained based on these drawings without creative work.
[0037] Figure 1 A flowchart of a vulnerability detection method provided in one embodiment of the present application;
[0038] Figure 2 A schematic diagram of the structure of a vulnerability detection system provided in one embodiment of the present application;
[0039] Figure 3 Provided in accordance with an embodiment of the present application, a schematic diagram of the interaction between a vulnerability detection device and an object under test when detecting the object under test using the vulnerability detection method provided in an embodiment of the present application;
[0040] Figure 4 A schematic diagram of the structure of an electronic device provided in one embodiment of the present application. DETAILED DESCRIPTION
[0041] The technical solutions in the embodiments of the present application will be described below in conjunction with the accompanying drawings. In the description of the present application, the terms "first", "second", etc. are only used to distinguish the description and cannot be understood as indicating or implying relative importance or sequence.
[0042] As mentioned above, software and hardware devices can usually be used as the objects under test, so that vulnerabilities hidden in the objects under test can be detected through testing. Therefore, it is necessary to provide corresponding vulnerability detection methods.
[0043] Based on this, the present application provides a vulnerability detection method, such as Figure 1 The specific flow chart of the method is shown, and the method includes the following steps:
[0044] Step S11: Sending test data to the object under test based on the first communication protocol.
[0045] The object under test may be application software or hardware such as an embedded device, and the type of the object under test is not limited here.
[0046] In addition, the test data can be used to modify the state of the object under test, including modifying the accessible state, operating authority state, storage state, etc. of the target file in the object under test. For example, the test data is used to modify the accessible state of the target file from inaccessible to accessible, or from accessible to inaccessible; for another example, the test data is used to modify the operating authority state of the target file from inoperable to operable, or from operable to inoperable; for another example, the test data can carry a test file, and in this case, the test data is used to receive and store the test file through the object under test to modify the storage state of the object under test (the storage state is modified from not storing the test file to storing the test file). The target file can be any file in the object under test, or it can be a specified file in the object under test, such as specifying the test file as the target file.
[0047] In addition, the test data can be used to modify the state of the object under test, and can also include modifying the operating parameters in the object under test, thereby modifying the operating state of the object under test, including modifying the exit time point, startup time point, software operation mode (background or foreground operation), etc. in the object under test.
[0048] It should be noted that the method may further include obtaining test data before step S31. The test data may generally be generated by mutation of a seed file, for example, by mutating the seed file according to a preset mutation strategy, thereby generating the test data. The preset mutation strategy is generally formulated according to the test objective of the fuzz test. For example, if the test objective of the fuzz test is to detect the robustness of the object under test, the preset mutation strategy formulated may be to replace part of the content in the seed file (the content of the method field) with a string of preset length, such as 256-byte characters, 512-byte characters, etc.
[0049] Therefore, as for the specific methods of obtaining test data, the first method can be to mutate the seed file according to a preset mutation strategy to generate the test data; the second method can also be to obtain the test data from a test database. For example, the first method can be used to pre-generate multiple test data, and assign a unique identifier to each test data respectively, and then the generated multiple test data are stored in the test database. In this way, the unique identifier of the test data to be obtained can be used to query the test database to obtain the corresponding test data.
[0050] In addition, the seed file can be a script file for network fuzz testing, such as Peach's test file. The seed file formats of different fuzz testing tools (such as BooFuzz, KitterFuzzer, etc.) are different, and the corresponding seed files can be generated based on XML, python scripts or other custom files. Usually, multiple seed files can be generated in advance and assigned corresponding file identifiers (such as file name, generation time, etc.), and then the seed files are stored in the seed file library; when needed, the corresponding seed file can be obtained from the seed file library according to the file identifier, and then the seed file can be mutated according to the preset mutation strategy to generate test data.
[0051] Regarding the specific method of sending test data to the object under test based on the first communication protocol in the above step S11, the test data can be first encapsulated using the first communication protocol, and then the encapsulated test data is sent to the object under test through the transmission channel corresponding to the first communication protocol.
[0052] Among them, the first communication protocol can be any one or more of FTP, HTTP, TCP, UDP, CAN, Ethernet, Bluetooth, AO / DO and other communication protocols. For example, the first communication protocol can be the FTP communication protocol, and the first communication protocol can be the HTTP communication protocol, and the first communication protocol can be the FTP communication protocol and the HTTP communication protocol, etc.
[0053] The communication mode between the transmission channel and the object under test may include TCP communication (Transmission Control Protocol) through a TCP transmission channel, UDP communication (User Datagram Protocol) through a UDP transmission channel, Ethernet communication through an Ethernet transmission channel, BlueTooth communication through a BlueTooth transmission channel, CAN communication (bus gateway communication) through a CAN transmission channel, AO / DO communication through an AO / DO transmission channel, serial port communication through a serial port transmission channel, USB communication (Universal Serial Bus) through a USB transmission channel, or ZigBee communication through a ZigBee transmission channel.
[0054] Therefore, when sending encapsulated test data to the object under test through a transmission channel, the transmission channel needs to be a transmission channel corresponding to the first communication protocol. For example, if the first communication protocol can be an FTP communication protocol, an HTTP communication protocol, or a TCP communication protocol, then the transmission channel can be a TCP transmission channel; if the first communication protocol can be BlueTooth, then the transmission channel can be a BlueTooth transmission channel.
[0055] Encapsulation is a fundamental concept in computer networks. Here, we use the TCP-based application protocol to encapsulate test payloads as an example. For the COTP protocol described in the XML file above (COTP is a protocol defined by the OSI 7-layer protocol and sits above TCP), the encapsulation process consists of three parts: Part 1: TCP and lower-layer protocol content, which is encapsulated by calling operating system functions using a TCP socket; Part 2: Encapsulation of the application layer above TCP, which uses operators to calculate the test data fields and then concatenates the hexadecimal values of each field; Part 3: Concatenating the contents of Parts 1 and 2 to obtain a complete data packet, namely the encapsulated test data.
[0056] Step S12: sending, to the measured object based on the second communication protocol, an associated service processing request associated with the modified state of the measured object.
[0057] In step S12, by sending an associated service processing request, the associated service requested by the associated service processing request is processed to detect whether there is a vulnerability when the object under test communicates collaboratively according to the first communication protocol and the second communication protocol.
[0058] Among them, in the above-mentioned step S11, test data is sent to the object under test based on the first communication protocol, thereby modifying the state of the object under test, and then in the step S12, an associated business processing request associated with the modified state of the object under test is further sent to the object under test based on the second communication protocol. In this way, the associated business processing request sent by the second communication protocol prompts the processing of the associated business. Since the associated business is associated with the modified state of the object under test, and the state modification of the object under test is based on the test data sent by the first communication protocol, it is possible to detect whether there is a vulnerability when the object under test communicates collaboratively according to the first communication protocol and the second communication protocol through the processing of the associated business.
[0059] The second communication protocol is a communication protocol different from the first communication protocol, and the second communication protocol may be any one or more of FTP, HTTP, TCP, UDP, CAN, Ethernet, Bluetooth, AO / DO, etc. For example, the first communication protocol may be the FTP communication protocol, and the second communication protocol may be the HTTP communication protocol; or the first communication protocol may be the TCP communication protocol, and the second communication protocol may be the UDP communication protocol.
[0060] As mentioned above, the test data can be used to modify the state of the object under test, including modifying the accessibility state, operation permission state, storage state, etc. of the target file in the object under test.
[0061] For example, the test data is used to modify the accessible state of the target file from inaccessible to accessible, or from accessible to inaccessible; in this case, the associated business associated with the modified state of the tested object in step S12 may be an access business for the target file, and the associated business processing request may be an access request, that is, step S12 may specifically be sending an access request for the target file access business to the tested object based on the second communication protocol. In this case, since the test data is used to modify the accessible state of the target file in the tested object, and the test data is sent based on the first communication protocol, and the access request is sent based on the second communication protocol, it is possible to detect whether there are vulnerabilities when the tested object communicates collaboratively according to the first communication protocol and the second communication protocol based on the processing of the target file access business.
[0062] For another example, the test data is used to modify the operating permission status of the target file from inoperable to operable, or from operable to inoperable; in this case, the associated business associated with the modified state of the tested object in step S12 can be an operating business for the target file, and the associated business processing request can be an operation request, that is, step S12 can specifically be sending an operation request for the target file operating business to the tested object based on the second communication protocol. Since the test data is used to modify the operating permission status of the target file in the tested object, and the test data is sent based on the first communication protocol, and the access request is sent based on the second communication protocol, it is possible to detect whether there are vulnerabilities when the tested object communicates collaboratively according to the first communication protocol and the second communication protocol based on the processing of the target file operating business.
[0063] For another example, the test data may carry a test file, and in this case, the test data is used to receive and store the test file through the object under test to modify the storage state of the object under test. At this time, the associated business associated with the modified state of the object under test in step S12 may be a parsing and / or access business for the test file, and the associated business processing request may be a corresponding parsing request and / or access request, that is, step S12 may specifically be sending a parsing request and / or access request for the test file to the object under test based on the second communication protocol. Since the test data carries the test file, the object under test stores the test file, and the test data is sent based on the first communication protocol, and the access request is sent based on the second communication protocol. Therefore, it is possible to detect whether there is a vulnerability when the object under test communicates collaboratively according to the first communication protocol and the second communication protocol based on the processing of the target file operation business.
[0064] In actual applications, during the processing of related services, the object under test can be monitored, such as monitoring whether the object under test is running abnormally, so as to detect whether there are loopholes in the collaborative communication between the first communication protocol and the second communication protocol by monitoring whether the object under test is running abnormally. For example, if the object under test is monitored to be running abnormally, it means that there are loopholes in the collaborative communication between the first communication protocol and the second communication protocol; of course, if the object under test is still not monitored to be running abnormally after a period of time, it can be said that there are no loopholes in the collaborative communication between the first communication protocol and the second communication protocol. Among them, the abnormal operation of the object under test may include abnormal communication port of the object under test, downtime, unreasonable business exit, blue screen, indicator light alarm, etc.
[0065] In actual applications, there are many ways to monitor the object under test. For example, the operating status of the object under test can be determined by monitoring the communication port to achieve the monitoring; the monitoring can also be achieved by sending a request to the object under test to request the object under test to feedback its own operating status; of course, other monitoring methods can also be used.
[0066] The monitoring is achieved by sending a request to the measured object to request feedback on its own operating status. The request sent can be an ARP (Address Resolution Protocol) request, a Ping request, a URL request, a Modbus address request, AO / DO point information, etc. The monitoring is achieved by monitoring the operating status of the measured object by monitoring the corresponding port, for example, a TCP / UDP port can be monitored.
[0067] In addition, when a vulnerability is detected in the collaborative communication between the first communication protocol and the second communication protocol of the tested object, an early warning can usually be issued, such as sending an early warning message to relevant personnel via email, instant messaging, etc.
[0068] It should be further explained that other vulnerability detection methods can usually be used when conducting vulnerability detection, such as Method 1: By optimizing the test cases, the optimized test cases are used for detection, such as first using the adversarial network to generate a model, and then using the model to generate a test case, and then using the test case to detect vulnerabilities; Method 3: Optimizing the test process, for example, combining all field attributes and attribute values in the communication protocol to obtain mutation values, and then replacing the original values of each field mutation value in turn to perform targeted fuzz testing on the protocol to be tested; Method 3: Performing fuzz testing on a certain communication protocol to detect vulnerabilities when the object under test communicates according to the communication protocol, such as security testing of game protocols.
[0069] However, in these three methods, it is difficult to detect vulnerabilities in the multi-protocol collaborative communication of the object under test, and thus it is difficult to dig out vulnerabilities in the multi-protocol collaborative communication. In actual applications, the object under test usually involves the collaborative communication of multiple protocols, and some vulnerabilities usually only exist in the process of multi-protocol collaborative communication. Therefore, there is an actual demand for vulnerability detection in the collaborative communication of multiple protocols. Based on this, the method provided in the embodiment of the present application can be used to detect whether there are vulnerabilities in the object under test when it communicates collaboratively according to the first communication protocol and the second communication protocol, and thus is applied to vulnerability detection in the collaborative communication of multiple protocols.
[0070] It should be noted that the first communication protocol mentioned above can be any one or more of FTP, HTTP, TCP, UDP, CAN, Ethernet, Bluetooth, AO / DO, and the like, and the second communication protocol is a communication protocol different from the first communication protocol. Therefore, this method can be applied to detecting whether there are vulnerabilities when two different communication protocols communicate in coordination. For example, if the first communication protocol is the FTP communication protocol and the second communication protocol is the HTTP communication protocol, then this method can be used to detect whether there are vulnerabilities when the FTP communication protocol and the HTTP communication protocol communicate in coordination. For another example, if the first communication protocol is the TCP communication protocol and the second communication protocol is the UDP communication protocol, then this method can be used to detect whether there are vulnerabilities when the TCP communication protocol and the UDP communication protocol communicate in coordination.
[0071] In addition, the method provided in the embodiments of the present application can also be used to detect vulnerabilities in the collaborative communication of three or more different communication protocols. The first method is to select two communication protocols from three or more communication protocols multiple times, and use the two communication protocols selected each time as the first communication protocol and the second communication protocol respectively, and then use the method provided in the embodiments of the present application to detect whether there are vulnerabilities when the first communication protocol and the second communication protocol communicate in a collaborative manner.
[0072] For example, two different communication protocols can be selected from the three or more different communication protocols first, and then the two different communication protocols can be used as the first communication protocol and the second communication protocol respectively, and then the method provided in the embodiment of the present application can be used for testing to detect whether there are loopholes in the collaborative communication between the two selected different communication protocols; then two different communication protocols can be reselected from the three or more different communication protocols, and the two reselected different communication protocols can be used as the first communication protocol and the second communication protocol respectively, and then the method provided in the embodiment of the present application can be used for testing. In this way, by reselecting two different communication protocols multiple times and executing the method provided in the embodiment of the present application, it is possible to detect loopholes in the collaborative communication between the three or more different communication protocols, and then evaluate the loopholes in the collaborative communication between the three or more different communication protocols.
[0073] For example, if there are no loopholes when two of the three or more different communication protocols communicate in coordination with each other, then it is determined that there are no loopholes when the three or more different communication protocols communicate in coordination; or, if there are loopholes when two of the three or more different communication protocols communicate in coordination with each other, then it is determined that there are loopholes when the three or more different communication protocols communicate in coordination.
[0074] Of course, when using the method provided in the embodiment of the present application to detect vulnerabilities in the collaborative communication of three or more different communication protocols, the second method is: to use one of the three or more different communication protocols as the second communication protocol, and the remaining communication protocols as the first communication protocol.
[0075] At this time, there are multiple first communication protocols (i.e., there are multiple first communication protocols). Therefore, for the above-mentioned step S11, test data can be sent to the object under test in sequence based on each first communication protocol, and each test data is used to modify the state of the object under test in sequence. At this time, since the object under test has received multiple test data in sequence, and each test data is used to modify the state of the object under test, the state of the object under test is continuously modified. For example, the multiple first communication protocols can be the first communication protocol 1, the first communication protocol 2...communication protocol n. At this time, in this step S11, test data can be sent to the object under test based on the first communication protocol 1, so that the state of the object under test is modified from state 0 to state 1, and then test data can be sent to the object under test based on the first communication protocol 2, so that the state of the object under test is modified from state 1 to state 2, and then test data can be sent to the object under test based on the first communication protocol 3, so that the state of the object under test is modified from state 2 to state 3... and then test data can be sent to the object under test based on the first communication protocol n, so that the state of the object under test is modified from state n-1 to state n.
[0076] Accordingly, in step S12, an associated service processing request associated with the modified state of the tested object is sent to the tested object based on the second communication protocol. For example, in the above example, if the modified state of the tested object is state n, an associated service processing request associated with state n can be sent to the tested object based on the second communication protocol. At this time, since test data was sent sequentially based on each of the first communication protocols in step S11, after step S12, through the processing of associated services, it is possible to detect whether there are vulnerabilities when the tested object communicates in coordination with the second communication protocol according to multiple first communication protocols.
[0077] In actual applications, any of the above two methods can be selected to perform vulnerability detection on three or more different communication protocols. Among them, the first method requires selecting two communication protocols multiple times and performing detection. Therefore, when there are few vulnerabilities in the collaborative communication between these communication protocols (for example, no vulnerabilities), the efficiency is low. When there are many vulnerabilities, the efficiency is relatively high because the vulnerabilities can be accurately located (that is, which communication protocols have vulnerabilities in the collaborative communication). The second method mentioned above is efficient when there are few or even no vulnerabilities in the collaborative communication between these communication protocols. However, when there are many vulnerabilities, the efficiency is relatively low because it is difficult to accurately locate the vulnerabilities. Therefore, you can make a choice based on the actual situation.
[0078] Based on the same inventive concept as the vulnerability detection method provided in the embodiment of the present application, the embodiment of the present application can also provide a vulnerability detection system. Figure 2 FIG. 2 is a schematic diagram showing a specific structure of the vulnerability detection system. The vulnerability detection system 20 may include: a fuzzy test mutation module 201, a continuous operation module 202, a transmission channel module 203, a monitoring module 204, a configuration module 205, and a scheduling module 206, wherein:
[0079] The fuzzy test mutation module 201 sends test data to the object under test based on the first communication protocol, wherein the test data is used to modify the state of the object under test;
[0080] The continuous operation module 202 sends an associated business processing request associated with the modified state of the measured object to the measured object based on the second communication protocol, so as to detect whether there is a vulnerability when the measured object communicates collaboratively according to the first communication protocol and the second communication protocol through the processing of the associated business requested by the associated business processing request.
[0081] Therefore, the vulnerability detection system 20 provided in the embodiment of the present application is adopted. Since the vulnerability detection system 20 adopts the same inventive concept as the vulnerability detection method provided in the embodiment of the present application, on the premise that the method can solve the technical problem, the vulnerability detection system 20 can also solve the technical problem, and no further details will be given here.
[0082] In addition, in actual applications, the technical effects achieved by combining the vulnerability detection system 20 with specific hardware equipment are also within the scope of protection of this application, such as using a distributed structure to deploy different modules in the vulnerability detection system 20 at different nodes, thereby improving efficiency.
[0083] In practical applications, the fuzzy test mutation module 201 may include a fuzzy test mutation subunit, which is used to mutate the seed file according to a preset mutation strategy to generate the test data.
[0084] The fuzzy test mutation module 201 may also include an encapsulation subunit and a sending subunit, wherein: the encapsulation subunit is used to encapsulate the test data using the first communication protocol; the sending subunit is used to send the encapsulated test data to the object under test through the transmission channel corresponding to the first communication protocol.
[0085] It should be noted that in the vulnerability detection system 20, the transmission channel can be set as an independent module ( Figure 2 The transmission channel module 203 shown in the figure) enables other modules in the vulnerability detection system 20 to use the transmission channel module 203 to communicate with the object under test in parallel, achieving a flexible configuration effect. In the transmission channel module 203, multiple submodules can be set according to different communication modes, including a TCP submodule ( Figure 2 TCP), UDP submodule ( Figure 2 UDP in), Ethernet submodule ( Figure 2 Ethernet), Bluetooth submodule ( Figure 2 BlueTooth in), CAN submodule ( Figure 2 CAN), AO / DO submodule ( Figure 2 AO / DO in ), serial port sub-module, USB sub-module and ZigBee sub-module, etc.
[0086] In actual applications, test data can be used to modify the accessible status of the target file in the object under test; and the continuous operation module 202 can specifically include a request to send a first sub-unit, which is used to send an access request for the target file access service to the object under test based on the second communication protocol.
[0087] The test data can also be used to modify the operation permission status of the target file in the object under test; and the continuous operation module 202 can specifically include a request to send a second sub-unit, which is used to send an operation request for the target file operation business to the object under test based on a second communication protocol.
[0088] The test data includes a test file; and the test data is used to modify the storage status of the object under test by storing the test file through the object under test; and the continuous operation module 202 can specifically include a request to send a third sub-unit, which is used to send a parsing request and / or access request for the test file to the object under test based on a second communication protocol.
[0089] In actual applications, the vulnerability detection system 20 may also include a monitoring module 204, which is used to detect whether there is a vulnerability in the collaborative communication between the first communication protocol and the second communication protocol by monitoring whether the object under test is running abnormally during the processing of the related business. If it is monitored that the object under test is running abnormally, there is a vulnerability in the collaborative communication between the first communication protocol and the second communication protocol.
[0090] There are multiple first communication protocols; and sending test data to the object under test based on the first communication protocol can specifically include: sending test data to the object under test in sequence based on each first communication protocol, wherein each test data is used to modify the state of the object under test in sequence.
[0091] The device 20 may further include a selection module for selecting two communication protocols from three or more communication protocols multiple times, and using the two communication protocols selected each time as the first communication protocol and the second communication protocol respectively.
[0092] The configuration module 205 can be used to configure relevant parameters in the continuous operation module 202, so as to determine when and how the fuzzy test mutation module 201 and the continuous operation module 202 send test data and related business processing requests to the object under test.
[0093] The configuration module 205 can also be used to configure relevant parameters in the test load generation module to determine a specific preset mutation strategy; the configuration module 205 can also be used to configure relevant parameters in the fuzzy test mutation module 201 to pre-configure the interaction method and communication method between the fuzzy test mutation module 201 and the object under test.
[0094] The configuration module 205 can also be used to configure relevant parameters in the monitoring module 204, so as to determine the monitoring mode of the monitoring module 204 and the communication mode with the object under test.
[0095] The scheduling module 206 is used to schedule other modules in the vulnerability detection system 20, including scheduling the fuzzy test mutation module 201 to send test data to the object under test, scheduling the continuous operation module 202 to send related business processing requests to the object under test, etc.
[0096] It should be noted that the vulnerability detection system 20 can be set on a dedicated device for vulnerability detection (referred to as a vulnerability detection device), and then the vulnerability detection device is used to detect the object being tested. Figure 3 The diagram shows an interaction diagram of the vulnerability detection device 31 during the detection of the detected object using the method provided in the embodiment of the present application, which includes the following steps:
[0097] Step S1: The vulnerability detection device 31 sends test data to the object under test 32 based on the first communication protocol.
[0098] Step S2: The tested object 32 modifies its state according to the test data.
[0099] Step S3: The vulnerability detection device 31 sends an associated service processing request associated with the modified state of the detected object to the detected object 32 based on the second communication protocol.
[0100] Step S4: the measured object 32 processes the associated service according to the associated service processing request.
[0101] Step S5: During the processing of the associated services, the vulnerability detection device 31 monitors whether the object under test 32 operates abnormally.
[0102] In this step S5, the vulnerability detection device 31 detects whether there is a vulnerability in the object under test 32 when it communicates in collaboration according to the first communication protocol and the second communication protocol by monitoring whether the object under test 32 operates abnormally. For example, if it is monitored that the object under test 32 operates abnormally, it means that there is a vulnerability in the collaborative communication between the first communication protocol and the second communication protocol.
[0103] Obviously, the interaction between the vulnerability detection device 31 and the object under test 32 can also be used to solve the problems of the prior art, which will not be described in detail here.
[0104] Based on the same inventive concept as the embodiment of the present application, Figure 4 As shown, this embodiment further provides an electronic device 40, which includes: at least one processor 41 and a memory 42, Figure 4In the embodiment, a processor 41 and a memory 42 may be connected via a bus. The memory 42 stores instructions that can be executed by the processor 41. The instructions are executed by the processor 41 so that the electronic device 40 can execute all or part of the process of the method in the embodiment of the present application.
[0105] The electronic device 40 may be a dedicated device for vulnerability detection, or may be a laptop computer, a desktop computer, a server or a server cluster composed of the same.
[0106] An embodiment of the present invention further provides a computer-readable storage medium storing a computer program that can be executed by a processor to complete all or part of the process of the method in the above embodiment. The storage medium can be a magnetic disk, an optical disk, a read-only memory (ROM), a random access memory (RAM), a flash memory, a hard disk drive (HDD), or a solid-state drive (SSD). The storage medium can also include a combination of the above types of memory.
[0107] Although the embodiments of the present invention have been described with reference to the accompanying drawings, those skilled in the art may make various modifications and variations without departing from the spirit and scope of the present invention. Such modifications and variations are all within the scope defined by the appended claims.
Claims
1. A vulnerability detection method, characterized in that: include: Sending test data to the object under test based on a first communication protocol, wherein the test data is used to modify the state of the object under test; Sending, based on the second communication protocol, an associated business processing request associated with the modified state of the measured object to the measured object, so as to detect whether there is a vulnerability when the measured object communicates collaboratively according to the first communication protocol and the second communication protocol by processing the associated business requested by the associated business processing request; The processing of the associated service requested by the associated service processing request to detect whether there is a vulnerability when the tested object communicates collaboratively according to the first communication protocol and the second communication protocol includes: During the processing of the associated business, the object under test is monitored for abnormal operation to detect whether there is a vulnerability in the collaborative communication between the first communication protocol and the second communication protocol; if the object under test is monitored to be abnormal, it is determined that there is a vulnerability in the collaborative communication between the first communication protocol and the second communication protocol; if the object under test is not monitored to be abnormal operation after a period of time, it is determined that there is no vulnerability in the collaborative communication between the first communication protocol and the second communication protocol.
2. The method according to claim 1, characterized in that The method further comprises: The seed file is mutated according to a preset mutation strategy to generate the test data.
3. The method according to claim 2, characterized in that Sending test data to the object under test based on the first communication protocol specifically includes: Encapsulating the test data using a first communication protocol; The encapsulated test data is sent to the object under test through a transmission channel corresponding to the first communication protocol.
4. The method according to claim 1, wherein The test data is used to modify the accessible state of the target file in the tested object; as well as, Sending, to the measured object based on the second communication protocol, an associated service processing request associated with the modified state of the measured object, specifically includes: An access request for the target file access service is sent to the measured object based on the second communication protocol.
5. The method according to claim 1, wherein The test data is used to modify the operation permission status of the target file in the tested object; and Sending, to the measured object based on the second communication protocol, an associated service processing request associated with the modified state of the measured object, specifically includes: An operation request for the target file operation service is sent to the measured object based on the second communication protocol.
6. The method according to claim 1, wherein The test data includes a test file; and the test data is used to modify the storage state of the tested object by storing the test file in the tested object; as well as, Sending, to the measured object based on the second communication protocol, an associated service processing request associated with the modified state of the measured object, specifically includes: A parsing request and / or an access request for the test file is sent to the object under test based on a second communication protocol.
7. The method according to claim 1, characterized in that There are multiple first communication protocols; and Sending test data to the object under test based on the first communication protocol specifically includes: Test data are sent to the object under test in sequence based on each first communication protocol, wherein each test data is used to modify the state of the object under test in sequence.
8. The method according to claim 1, characterized in that The method further comprises: Two communication protocols are selected from three or more communication protocols multiple times, and the two communication protocols selected each time are used as the first communication protocol and the second communication protocol respectively.
9. A vulnerability detection system, characterized in that: include: A fuzzy test mutation module sends test data to the object under test based on a first communication protocol, wherein the test data is used to modify the state of the object under test; a continuous operation module that sends, to the measured object based on the second communication protocol, an associated business processing request associated with the modified state of the measured object, so as to detect whether there is a vulnerability when the measured object communicates collaboratively according to the first communication protocol and the second communication protocol by processing the associated business requested by the associated business processing request; The processing of the associated service requested by the associated service processing request to detect whether there is a vulnerability when the tested object communicates collaboratively according to the first communication protocol and the second communication protocol includes: During the processing of the associated business, the object under test is monitored for abnormal operation to detect whether there is a vulnerability in the collaborative communication between the first communication protocol and the second communication protocol; if the object under test is monitored to be abnormal, it is determined that there is a vulnerability in the collaborative communication between the first communication protocol and the second communication protocol; if the object under test is not monitored to be abnormal operation after a period of time, it is determined that there is no vulnerability in the collaborative communication between the first communication protocol and the second communication protocol.
10. An electronic device, characterized in that: include: processor; A memory for storing processor-executable instructions; wherein the processor is configured to perform the method according to any one of claims 1 to 8.
11. A computer-readable storage medium, characterized in that The storage medium stores a computer program, and the computer program can be executed by a processor to implement the method according to any one of claims 1 to 8.
Citation Information
Patent Citations
Reconfigurable Message-Delivery Preconditions for Delivering Attacks to Analyze the Security of Networked Systems
US20080072322A1