Target object inspection method and apparatus

By generating initial test cases and their weight information for the target object, and combining practical testing and vulnerability detection, the problem of bias in the test results of network security products is solved, and an accurate and comprehensive evaluation of network security products is achieved.

CN116010270BActive Publication Date: 2026-02-10ZHEJIANG E COMMERCE BANK CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211735352.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-30
Publication Date
2026-02-10
Estimated Expiration
2042-12-30

AI Technical Summary

Technical Problem

In existing technologies, the testing methods for cybersecurity products lack specificity, leading to discrepancies in the test results of the same product under different user scenarios. This makes it impossible to objectively measure its true defense capabilities and security level. Furthermore, traditional test cases are not applicable to highly customized self-developed products and lack comprehensive coverage.

Method used

By generating initial test cases and their weight information for the target object, and combining practical testing and vulnerability detection, the effective interception rate and security assessment results are calculated to form a comprehensive target testing result.

Benefits of technology

It enables accurate and comprehensive testing of cybersecurity products, objectively assessing their defense capabilities and security in different scenarios. It is applicable to highly customized self-developed products and covers the product's own security assessment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116010270B_ABST
    Figure CN116010270B_ABST
Patent Text Reader

Abstract

The embodiment of the present specification provides a target object testing method and device, wherein the target object testing method comprises: in response to an object testing instruction for a target object, determining an initial test case corresponding to the target object and weight information corresponding to the initial test case; performing a security test on the initial test case according to the target object, and determining a target test case that successfully tests from the initial test case; determining a first testing result of the target object according to the initial test case, the target test case and the weight information corresponding to the target test case, and performing a vulnerability test on the target object to obtain a second testing result of the target object; determining a target testing result of the target object according to the first testing result and the second testing result; and through the combination of the weight information of the test case and the test on the target object itself, more accurate and comprehensive testing on the target object is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments in this specification relate to the field of computer technology, and in particular to a method for inspecting target objects. Background Technology

[0002] Currently, the evaluation of cybersecurity products often involves using standardized test cases to calculate accuracy and recall rates based on whether the product is defending or not, thereby determining the product's defensive capabilities.

[0003] However, the same cybersecurity product may have different performance for different users. If the cybersecurity product is still tested using the same test cases, the test results will inevitably be biased.

[0004] Therefore, it is of great importance to know how to accurately test cybersecurity products. Summary of the Invention

[0005] In view of this, embodiments of this specification provide a method for inspecting target objects. One or more embodiments of this specification also relate to a target object inspection apparatus, a computing device, a computer-readable storage medium, and a computer program, to address the technical deficiencies existing in the prior art.

[0006] According to a first aspect of the embodiments of this specification, a target object inspection method is provided, comprising:

[0007] In response to an object inspection instruction for a target object, an initial test case corresponding to the target object and weight information corresponding to the initial test case are determined, wherein the target object is one of the objects to be inspected;

[0008] Security tests are performed on the initial test cases based on the target object, and target test cases that have been successfully tested are determined from the initial test cases;

[0009] Based on the initial test case, the target test case, and the weight information corresponding to the target test case, the first inspection result of the target object is determined, and the target object is subjected to vulnerability inspection to obtain the second inspection result of the target object.

[0010] Based on the first test result and the second test result, the target test result of the target object is determined.

[0011] According to a second aspect of the embodiments of this specification, a target object inspection apparatus is provided, comprising:

[0012] The first determining module is configured to, in response to an object verification instruction for a target object, determine the initial test case corresponding to the target object and the weight information corresponding to the initial test case.

[0013] The testing module is configured to perform security testing on the initial test cases based on the target object, and to determine the target test cases that have been successfully tested from the initial test cases;

[0014] The verification module is configured to determine the first verification result of the target object based on the initial test case, the target test case, and the weight information corresponding to the target test case, and to perform vulnerability verification on the target object to obtain the second verification result of the target object.

[0015] The second determining module is configured to determine the target inspection result of the target object based on the first inspection result and the second inspection result.

[0016] According to a third aspect of the embodiments of this specification, a computing device is provided, comprising:

[0017] Memory and processor;

[0018] The memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions, which, when executed by the processor, implement the steps of the target object inspection method described above.

[0019] According to a fourth aspect of the embodiments of this specification, a computer-readable storage medium is provided that stores computer-executable instructions, which, when executed by a processor, implement the steps of the target object inspection method described above.

[0020] According to a fifth aspect of the embodiments of this specification, a computer program is provided, wherein when the computer program is executed in a computer, it causes the computer to perform the steps of the target object inspection method described above.

[0021] An embodiment of this specification provides a target object verification method, which, in response to an object verification instruction for a target object, determines an initial test case corresponding to the target object and weight information corresponding to the initial test case, wherein the target object is one of the objects to be verified; performs security testing on the initial test cases based on the target object, and determines a target test case that has successfully passed the test from the initial test cases; determines a first verification result of the target object based on the initial test cases, the target test cases, and the weight information corresponding to the target test cases, and performs vulnerability verification on the target object to obtain a second verification result of the target object; and determines a target verification result of the target object based on the first verification result and the second verification result.

[0022] Specifically, by determining the initial test cases and weight information of the target object to be tested, and by determining the target test cases that have successfully passed the security test based on the target object, the corresponding first inspection result is determined based on the initial test cases, the target test cases, and the weight information of the target test cases. Then, combined with the second inspection result determined by vulnerability detection of the target product itself, the target inspection result for the target object is determined. By combining the weight information of the test cases and the inspection of the target object itself, a more accurate inspection of the target object is achieved. Attached Figure Description

[0023] Figure 1 This is a schematic diagram of a scenario for a target object inspection method provided in one embodiment of this specification;

[0024] Figure 2 This is a flowchart of a target object inspection method provided in one embodiment of this specification;

[0025] Figure 3 This is a flowchart illustrating the processing procedure of a target object inspection method provided in one embodiment of this specification;

[0026] Figure 4 This is a schematic diagram of the processing procedure of a target object inspection method provided in one embodiment of this specification;

[0027] Figure 5 This is a schematic diagram of the structure of a target object inspection device provided in one embodiment of this specification;

[0028] Figure 6 This is a structural block diagram of a computing device provided in one embodiment of this specification. Detailed Implementation

[0029] Many specific details are set forth in the following description to provide a full understanding of this specification. However, this specification can be implemented in many other ways than those described herein, and those skilled in the art can make similar extensions without departing from the spirit of this specification. Therefore, this specification is not limited to the specific implementations disclosed below.

[0030] The terminology used in one or more embodiments of this specification is for the purpose of describing particular embodiments only and is not intended to be limiting of the one or more embodiments of this specification. The singular forms “a,” “described,” and “the” as used in one or more embodiments of this specification and the appended claims are also intended to include the plural forms unless the context clearly indicates otherwise. It should also be understood that the term “and / or” as used in one or more embodiments of this specification refers to and includes any or all possible combinations of one or more associated listed items.

[0031] It should be understood that although the terms first, second, etc., may be used to describe various information in one or more embodiments of this specification, such information should not be limited to these terms. These terms are only used to distinguish information of the same type from one another. For example, first may also be referred to as second without departing from the scope of one or more embodiments of this specification, and similarly, second may also be referred to as first. Depending on the context, the word "if" as used herein may be interpreted as "when," "when," or "in response to a determination."

[0032] First, the terms and concepts used in one or more embodiments of this specification will be explained.

[0033] Network security products refer to various software products and related hardware / software products used to ensure the system and information security of various user networks and to enable the normal operation of systems. As a crucial carrier of security capabilities in enterprise information security construction, network security products provide strong security guarantees for enterprise network information security.

[0034] Real-world testing: Test the target's capabilities by simulating real attacks.

[0035] Test cases are descriptions of testing tasks for a specific software product, reflecting the test plan, methods, techniques, and strategies. They include test objectives, test environment, input data, test steps, expected results, and test scripts, ultimately forming a document.

[0036] Currently, there is no mature testing methodology for cybersecurity products. Because the same security product offers varying defensive capabilities against different security vendors, it cannot be measured using standardized test cases. Security confrontations occur daily; different testing methods for the same product have varying applicability and attack costs; furthermore, the development levels of various cybersecurity products differ. Therefore, a universal method is currently lacking to solve the problem of scientifically testing and measuring cybersecurity products.

[0037] In existing solutions, specific test cases are created, data packets are constructed and sent to network security products for testing, and accuracy and recall are calculated based on whether defense is provided or not.

[0038] However, the above solutions have the following problems: 1. Conventional network security products are not applicable to highly customized self-developed network security products. Within enterprises, unlike conventional commercial network security products, self-developed network security products are often highly customized, such as WAFs (Web Application Firewalls) used only for emergency response. In this case, traditional test cases cannot be used to measure the product's capabilities; 2. Each network security product's test cases have a certain scope of application and varying levels of difficulty, making it impossible to objectively measure the true security level; 3. Test cases created using traditional methods are relatively fixed, while security attacks occur constantly. Due to this limitation, the coverage of test cases is often insufficient; 4. Traditional methods only consider the capabilities of network security products and do not cover the verification and evaluation of the product's own security.

[0039] To address the aforementioned technical problems, embodiments of this specification provide a target object inspection method. These embodiments also relate to a target object inspection device, a computing device, and a computer-readable storage medium, which will be described in detail in the following embodiments.

[0040] See Figure 1 , Figure 1 The illustration shows a scenario diagram of a target object inspection method according to an embodiment of this specification, which specifically includes the following:

[0041] like Figure 1 As shown, Figure 1 It includes a client 102 and a server 104. The client 102 includes, but is not limited to, desktop computers, laptops, tablets, mobile phones, etc.; the server 104 can be understood as a cloud server and a physical server, etc.

[0042] For ease of understanding, in the embodiments of this specification, the client 102 is a laptop computer, the server 104 is a physical server, and the target object is a network security product. Based on the target object inspection method, the inspection process of the network security product is described in detail.

[0043] In specific implementation, client 102 sends a product inspection instruction for network security products to server 104. The client 102 can send the product inspection instruction to server 104 based on certain inspection requirements or conditions, or it can send the product inspection instruction for network security products to server 104 when the preset period is met. According to the product inspection instruction, the client 102 obtains the initial test cases corresponding to the network security products and the weight information corresponding to the initial test cases from the preset relationship correspondence table.

[0044] In one implementation, the initial test cases corresponding to the network security product and the weight information corresponding to the initial test cases can be pre-generated test cases based on the defense capabilities emphasized by the network security product before product testing, and the weight information of the test cases can be set according to the application difficulty and other conditions corresponding to the test cases. The generated test cases and the correspondence between the test cases and the network security products can be stored in a preset correspondence table.

[0045] After obtaining the initial test cases, the network security product performs interception tests on the initial test cases. Based on whether the network security product intercepts the initial test cases or not, the initial test cases that the network security product fails to intercept are identified from the initial test cases and designated as target test cases.

[0046] Based on the number of initial test cases, target test cases, and the weight information corresponding to the target test cases, the effective interception rate of the network security product is calculated using a preset calculation method. That is, the percentage of initial test cases successfully intercepted by the network security product to the total number of initial test cases.

[0047] At the same time, the security of the network security product itself is tested according to the preset vulnerability testing method, and the security of the network security product itself is used as an important evaluation item in the practical test to obtain the security assessment result of the network security product; combined with the security assessment result and the effective interception rate, the target test result of the network security product is determined, and the target test result is fed back to the client 102.

[0048] Specifically, by determining the initial test cases and weight information of the target object to be tested, and by determining the target test cases that have successfully passed the security test based on the target object, the corresponding first inspection result is determined based on the initial test cases, the target test cases, and the weight information of the target test cases. Then, combined with the second inspection result determined by vulnerability detection of the target product itself, the target inspection result for the target object is determined. By combining the weight information of the test cases and the inspection of the target object itself, a more accurate inspection of the target object is achieved.

[0049] See Figure 2 , Figure 2 A flowchart of a target object inspection method according to an embodiment of this specification is shown, which specifically includes the following steps.

[0050] Step 202: In response to the object inspection instruction for the target object, determine the initial test case corresponding to the target object and the weight information corresponding to the initial test case, wherein the target object is one of the objects to be inspected.

[0051] In this context, the object to be inspected can be understood as any object that needs to be inspected in any scenario; while the target object can be understood as one of the objects that needs to be inspected in any scenario, such as network security products like firewalls, security management devices, and security routers. For ease of understanding, the following embodiments will all use the network security product as the target object for detailed description.

[0052] An object inspection instruction can be understood as an inspection instruction sent by any third-party platform or third-party personnel targeting a target object, or an inspection instruction targeting a target object triggered at a certain period, such as triggering an inspection instruction targeting a target object once a month. In practical applications, there can be various ways to trigger an object inspection instruction, such as an object inspection instruction triggered by any third-party platform or third-party personnel by clicking a certain control, or an object inspection instruction that is automatically triggered at a preset time period as described above. The specific settings depend on the actual application, and the embodiments in this specification do not impose any limitations on this.

[0053] Initial test cases can be understood as test cases generated based on parameters such as the performance of the target object. For example, if the performance of the target object focuses on network emergency repair, then test cases simulating attacks on network emergency modifications can be set.

[0054] Weighting information can be understood as the importance of performance settings for the target object; for example, if the target object has outstanding performance in aspect a, the test cases should be set to have higher weighting information in aspect a.

[0055] Specifically, in response to an object inspection instruction for a target object, determining the initial test case corresponding to the target object and the weight information corresponding to the initial test case can be understood as: receiving an object inspection instruction issued by any third-party platform or any third-party personnel for any target object among the objects to be inspected, and obtaining the initial test case corresponding to the target object and the weight information corresponding to the initial test case based on the correspondence between the target object, the initial test case, and the weight information.

[0056] In practice, before testing the target objects, it is necessary to pre-create test cases for each target object based on the performance focus of each target object. This will allow for more targeted testing of different target objects in the future. The specific implementation method is as follows:

[0057] The response to the object inspection instruction for the target object also includes:

[0058] Based on the first object and its performance, generate a first test case corresponding to the first object, wherein the first object is one of at least two objects to be tested;

[0059] Based on the first test case and the preset test conditions, the weight information corresponding to the first test case is determined, wherein the preset test conditions are the conditions that the at least two first test cases need to meet when performing security testing on the first object;

[0060] The first object, the first test case, and the weight information of the first test case are stored in a preset relationship correspondence table.

[0061] The relationship mapping table can be understood as a table that stores the object to be tested, the corresponding test cases for the object to be tested, the weight information of the test cases, and the correspondence between them. It should be noted that the storage method of the above data is not limited to tables; it can also be in the form of configuration files, etc., and can be set according to the actual application. This manual does not limit this.

[0062] Preset test conditions can be understood as the conditions that the first test case needs to meet when performing security testing on the first object. For example, the preset test conditions can be connected to an internal network, have certain configuration content, etc.

[0063] The performance of the first object can be understood as the capabilities that the first object possesses, or the capabilities it emphasizes. For example, the performance of the first object can be capabilities that emphasize emergency response or capabilities that emphasize anti-interference.

[0064] Specifically, based on the first object, one of the objects to be tested, and the capabilities that the first object emphasizes, test cases corresponding to the capabilities that the first object emphasizes are generated according to a preset generation method. Based on the generated first test cases and the preset test conditions that the first test cases need to meet when they are tested, the weight information corresponding to the first test cases is determined. Then, the determined first object, the first test cases, and the weight information of the first test cases are stored in a preset relationship correspondence table.

[0065] In one implementation, when setting the weight information of the first test case based on the first test case and the corresponding preset test conditions, the weight information can be set lower based on the difficulty of achieving the preset test conditions that the first test case needs to meet when performing security testing on the first object. That is, if the preset test conditions that the first test case needs to meet when performing security testing on the first object are difficult to achieve, the weight information corresponding to the first test case can be set lower. Alternatively, the weight information of the first test case can be determined based on scenarios such as the scope of use of the first test case. That is, if it is determined that the probability of the first test case being reused is low, the weight information of the first test case can be set lower. Setting lower weight information for some test cases with more complex usage conditions makes the subsequent calculation of the effective interception rate of the target object based on the weight information more objective and comprehensive, and avoids the impact of some difficult-to-implement test cases on the overall evaluation of the target object.

[0066] In practical applications, there may be situations where a test case requires two preset test conditions to be met simultaneously before security testing can proceed. For example, it may require logging into the internal network and confirming that the target object has data 'a' configured before security testing can be performed. In such cases, it is necessary to pre-determine the weight information based on these two preset test conditions, and then determine the weight information of this test case based on these two preset test conditions. This allows for a more accurate determination of the test case weight information, further improving the accuracy of subsequent testing results. The specific implementation method is as follows:

[0067] The step of determining the weight information corresponding to the first test case based on the first test case and preset test conditions includes:

[0068] If it is determined that the first test case corresponds to at least two preset test conditions, the applicability of the first test case is determined based on the at least two preset test conditions;

[0069] According to the applicability, set the weight information corresponding to the first preset test condition, wherein the first preset test condition is one of the at least two preset test conditions;

[0070] The weight information of the first test case is determined based on the weight information of the first preset test conditions.

[0071] In this context, applicability can be understood as the degree to which the preset test conditions can be achieved. For example, if the preset test condition is logging into an internal network, it can be determined that the implementation of this test case is relatively difficult and not applicable to most test scenarios, thus the applicability of this test case is low.

[0072] Specifically, when determining that the first test case needs to meet at least two preset test conditions when performing security testing on the object under test, the applicability of the first test case is determined based on the difficulty of its use in performing security testing on the object under test, etc., based on the applicability of the first preset test case. Weight information corresponding to one of the first test conditions in the at least two test cases is set based on the applicability of the first preset test case. Then, the weight information of the first test case is determined based on the weight information of the first preset test condition. Subsequently, weight information is set for other test conditions in the at least two test cases based on the applicability of the first test case, thus determining the final weight information of the first test case. By setting the weight information for each preset test condition corresponding to each test case based on factors such as the usage scenarios and applicable scope of the multiple preset test conditions corresponding to each test case, and then determining the weight information of the corresponding test case based on the weight information of multiple preset test conditions, the determination of the test case weight information is more comprehensive.

[0073] For example, the first test case a needs to simultaneously satisfy the corresponding preset test condition b1 (login to the internal network) and the preset test condition b2 (the version of the object under test is 1.0). It is determined that preset test condition b1 is difficult to achieve, while preset test condition b2 is relatively easy to achieve. Therefore, the applicability of the first test case is determined based on the degree of implementation of b1 and b2. Based on this applicability, the weight information corresponding to test condition b1 is set to 0.1, and the weight information corresponding to test condition b2 is set to 0.6. Thus, the weight information of the first test case a is determined to be 0.1 multiplied by 0.6, resulting in 0.06.

[0074] Furthermore, after storing the identified target objects, test cases, test case weight information, and their corresponding relationships in a preset relationship mapping table, the system can quickly retrieve the corresponding test cases and weight information for the target object upon receiving an object verification instruction for that target object. The specific implementation method is as follows:

[0075] The step of determining the initial test cases corresponding to the target object and the weight information corresponding to the initial test cases includes:

[0076] Based on the target object, obtain the initial test case corresponding to the target object and the weight information corresponding to the initial test case from the preset relationship correspondence table.

[0077] Specifically, based on the correspondence between the target object and the initial test cases and weight information, the initial test cases corresponding to the target object and the weight information corresponding to the initial test cases are obtained from the preset correspondence table, thereby accelerating the acquisition rate of the test cases and weight information corresponding to the target object.

[0078] The target object verification method provided in this specification, in response to an object verification instruction for a specific target object, obtains the initial test cases and weight information corresponding to the target object from a pre-configured relational mapping table, providing a basis for the subsequent determination of target test cases and the first verification result, and further accelerating the determination of the target verification result.

[0079] Step 204: Perform security testing on the initial test cases based on the target object, and determine the target test cases that have been successfully tested from the initial test cases.

[0080] Security testing can be understood as testing the performance of a target object through practical verification based on initial test cases.

[0081] Target test cases can be understood as initial test cases that are tested in practice against the target object to achieve a successful attack.

[0082] Specifically, security testing is performed on the initial test cases based on the target object, and the target test cases that have been successfully tested are determined from the initial test cases. This can be understood as: using the initial test cases to test the capabilities of the target object in a way that simulates a real attack, and then determining the initial test cases that have been successfully attacked from the initial test cases, and determining the initial test cases as the target test cases.

[0083] In one embodiment, the practical verification method for the initial test case can be to send a data packet and determine whether the expected result is obtained, thereby determining whether the initial test case has been successfully attacked; that is, if the initial test case sent to the target object is to obtain data a from the target object, and the test result is determined to be obtaining data a, then the initial test case is determined to have been successfully attacked.

[0084] Furthermore, to verify whether the initial test case was successful, it can also be determined whether the initial test case was intercepted by the target object. Using multiple verification methods makes identifying the target test case from the initial test case more accurate. The specific implementation method is as follows:

[0085] The step of performing security testing on the initial test cases based on the target object, and determining the target test cases that have successfully passed the test from the initial test cases, includes:

[0086] The initial test cases are intercepted and tested based on the target object to obtain test results.

[0087] Based on the test results, the initial test cases that failed to be intercepted by the target object are identified from the initial test cases and used as target test cases.

[0088] Interception testing can be understood as testing that intercepts the initial test cases based on the target object.

[0089] Specifically, based on the target object, the initial test cases corresponding to the target object are intercepted and tested to obtain the test results corresponding to the target object. Based on the test results, the initial test cases that failed to be intercepted by the target object are identified as target test cases. That is, by checking whether the expected data is found in the test results, it is determined whether the initial test case was intercepted. If it is determined that the initial test case was not intercepted by the target object, the attack on the initial test case is considered successful, and the initial test case is identified as the target test case. This achieves accurate acquisition of target test cases and provides a basis for subsequent calculation of the effective interception rate.

[0090] The target object verification method provided in this specification performs security checks on initial test cases using the target object, and then determines the target test cases that have been successfully tested from the initial test cases based on the test results. Furthermore, it can determine from the target test cases in which aspects the target object has problems, and at the same time, it provides a basis for determining the subsequent first test results, further accelerating the determination of the target object's target verification results.

[0091] Step 206: Based on the initial test case, the target test case, and the weight information corresponding to the target test case, determine the first verification result of the target object, and perform vulnerability verification on the target object to obtain the second verification result of the target object.

[0092] The first test result can be understood as the effective interception rate of the target object against the corresponding test cases; the second test result can be understood as the score result of the security detection of the target object itself.

[0093] Specifically, based on the initial test cases, the target test cases, and the weight information corresponding to the target test cases, a first verification result for the target object is determined, and a vulnerability verification is performed on the target object to obtain a second verification result for the target object: based on the number of initial test cases, the target test cases, and the weight information corresponding to the target test cases, the effective interception rate corresponding to the target object is calculated, and the effective interception rate is determined as the first verification result for the target object; and a vulnerability verification is performed on the target object itself according to a preset vulnerability verification method to determine whether the target object itself has security issues, and the security verification result for the target object itself is determined as the second verification result for the target object.

[0094] When determining the results of the first test, in order to more accurately determine the capabilities of the target object in different aspects and further determine the effective interception rate corresponding to the target object, it is necessary to combine the target test cases and the weight information corresponding to the target test cases to calculate the effective interception rate. The specific implementation method is as follows:

[0095] The step of determining the first test result of the target object based on the initial test case, the target test case, and the weight information corresponding to the target test case includes:

[0096] The target test metric value is determined based on the target test case and the weight information corresponding to the target test case;

[0097] Based on the number of initial test cases and the target test metric value, the test interception information of the target object is determined as the first verification result of the target object.

[0098] Among them, test interception information can be understood as information that the target object intercepts in response to test cases.

[0099] Specifically, calculations are performed based on each target test case and its corresponding weight information, and the sum of the calculation results is determined as the target test metric value. Then, based on the number of initial test cases and the target test metric value, the proportion of the target test cases in the initial test cases is determined, thereby determining the test interception information of the target object. This serves as the first verification result of the target object, enabling a more accurate determination of the target object's capabilities in different aspects. This facilitates subsequent optimization or repair operations based on the verification results.

[0100] In practical applications, the target test metric value is determined by multiplying each target test case with its corresponding weight information and summing the product results of each target test case. Then, the effective interception rate, i.e., the first test result, is determined by the difference between the number of initial test cases and the target test metric value, and the proportion of the initial test case data information.

[0101] For example, taking an initial number of test cases as 10, and target test cases including test case a, test case b, and test case c, with test case a having a weight of 0.7, test case b having a weight of 0.3, and test case c having a weight of 0.1, the calculation of the effective interception rate is explained as follows: The target test metric value is obtained by multiplying test case a by 0.7, test case b by 0.3, and test case c by 0.1. The difference between the initial number of test cases (10) and the target test metric value (1.1) is 8.9. The ratio of this difference (8.9) to the initial number of test cases (10), which is 0.89, is determined as the effective interception rate of the target object.

[0102] To improve the comprehensiveness of target object verification, a pre-defined vulnerability verification method can be used to perform vulnerability verification on the target object itself, and a security assessment can be conducted on the vulnerability verification results. Based on the assessment results, a second verification result for the target object is determined. By verifying and assessing the security of the target object itself, comprehensiveness of target object verification is achieved. The specific implementation method is as follows:

[0103] The step of performing vulnerability verification on the target object to obtain a second verification result for the target object includes:

[0104] The target object is subjected to vulnerability detection according to a preset vulnerability detection method to obtain vulnerability information of the target object;

[0105] A security assessment is performed on the vulnerability information to obtain the security assessment result, which serves as the second verification result for the target object.

[0106] Vulnerability detection can be understood as the detection of vulnerabilities before they are exploited; for example, vulnerability detection methods can be security scanning technology to detect whether a system has published security vulnerabilities; or through source code scanning, disassembly scanning, environment error injection, etc., to determine whether the target object has vulnerabilities that have not yet been discovered.

[0107] Vulnerability information can be understood as information such as which vulnerabilities exist in the target object and the number of such vulnerabilities.

[0108] Specifically, the target object is subjected to vulnerability detection according to the preset vulnerability detection method to identify the vulnerability information existing in the target object. The vulnerability information existing in the target object is then subjected to security assessment to determine its threat level. Based on the threat level of the existing vulnerabilities, a score is assigned to obtain the security assessment result, which serves as the second verification result of the target object.

[0109] In one embodiment, the vulnerability can be assessed and scored based on the basic metric dimension, time metric dimension, and environmental metric dimension. For example, if the attack path of the vulnerability is a remote attack, the threat level is high and a higher score is set. If the vulnerability is a physical attack, it is easier to be intercepted by the target object and the threat level is low, so a lower score is set. Finally, the security assessment result of the target object having a vulnerability is determined based on the scoring result.

[0110] In practical applications, when conducting security assessments and scoring based on vulnerability information, general vulnerability assessment methods can be referenced for the corresponding security assessment and scoring.

[0111] The target object verification method provided in the embodiments of this specification calculates the first verification result corresponding to the target object based on the initial test case, the target test case, and the weight information corresponding to the target test case, and performs vulnerability detection on the target object itself. Considering the comprehensiveness of the verification of the target object, it achieves accurate verification of the capabilities of the target object.

[0112] Step 208: Determine the target inspection result of the target object based on the first inspection result and the second inspection result.

[0113] Specifically, determining the target inspection result of the target object based on the first inspection result and the second inspection result can be understood as: combining and displaying the first inspection result and the second inspection result, and using the combined first inspection result and the second inspection result as the target inspection result of the target object.

[0114] In practical applications, due to the frequent occurrence of network countermeasures, in order to ensure the comprehensiveness of the target object's verification and avoid the problem of the target object being unable to intercept network countermeasures, resulting in losses, it is necessary to periodically obtain updated test cases and then save the updated test cases to a relational mapping table to ensure the effectiveness of subsequent test cases obtained from the relational mapping table. The specific implementation method is as follows:

[0115] After storing the first object, the first test case, and the weight information of the first test case into a preset relational mapping table, the method further includes:

[0116] If a preset time period is met, updated test cases for the first object are obtained from a third-party platform.

[0117] Based on the updated test cases and the preset test conditions, determine the weight information corresponding to the updated test cases;

[0118] The first object, the updated test case, and the weight information of the updated test case are stored in the preset relationship correspondence table.

[0119] In this context, a third-party platform can be understood as any open platform that stores network countermeasures technologies or test cases.

[0120] Specifically, using a certain time period as a cycle, such as one month or three months, once a time period is determined, updated test cases for the first object are obtained from any third-party platform. Based on the updated test cases and the preset test conditions that the updated test cases need to meet when performing security checks on the first object, the weight information corresponding to the updated test cases is determined. The first object, the updated test cases, the weight information of the updated test cases, and their corresponding relationships are stored in a preset relationship table. By continuously improving the existing test management, the comprehensiveness and timeliness of the test cases are ensured.

[0121] The target object verification method provided in this specification determines the target verification result corresponding to the target object by obtaining the first verification result and the second verification result, and then determines the capability of the target object based on the target verification result, further determining the target object's interception capability against test cases, and ensuring the effectiveness of test case acquisition by periodically updating test cases.

[0122] An embodiment of this specification provides a target object verification method, which, in response to an object verification instruction for a target object, determines an initial test case corresponding to the target object and weight information corresponding to the initial test case, wherein the target object is one of the objects to be verified; performs security testing on the initial test cases based on the target object, and determines a target test case that has successfully passed the test from the initial test cases; determines a first verification result of the target object based on the initial test cases, the target test cases, and the weight information corresponding to the target test cases, and performs vulnerability verification on the target object to obtain a second verification result of the target object; and determines a target verification result of the target object based on the first verification result and the second verification result.

[0123] Specifically, by determining the initial test cases and weight information of the target object to be tested, and by determining the target test cases that have successfully passed the security test based on the target object, the corresponding first inspection result is determined based on the initial test cases, the target test cases, and the weight information of the target test cases. Then, combined with the second inspection result determined by vulnerability detection of the target product itself, the target inspection result for the target object is determined. By combining the weight information of the test cases and the inspection of the target object itself, a more accurate inspection of the target object is achieved.

[0124] The following is in conjunction with the appendix Figure 3 , Figure 3 The present specification shows a flowchart of a target object inspection method according to an embodiment, which includes the following steps.

[0125] Step 302: Receive the product inspection instruction for the network security product, and determine the initial test cases and weight information corresponding to the initial test cases from the preset relationship correspondence table.

[0126] Among these, network security products can be understood as the aforementioned target objects; product inspection instructions can be understood as the aforementioned object inspection instructions.

[0127] In one embodiment, before conducting product testing on a network security product, test cases need to be generated based on the product's defensive capabilities, and weight information for each test case is set according to its applicability (i.e., testing difficulty). This generates test cases tailored to the specific capabilities of each network security product, facilitating more targeted security testing of the product. The network security product, test cases, and their corresponding weight information, along with their interrelationships, are stored in a pre-defined mapping table. This allows for direct retrieval of the corresponding test cases and weight information from the pre-defined mapping table when a product testing instruction for a network security product is received.

[0128] Step 304: Based on the network security product, perform interception tests on the initial test cases, and identify the target test cases from the initial test cases that failed to intercept.

[0129] Specifically, based on the initial test cases, the network security product is tested for bypass in a practical manner to determine whether the network security product will block the initial test cases, and further determine the defense capabilities of the network security product. At the same time, based on whether the network security product blocks the test cases, the initial test cases that are not blocked by the network security product are identified from the initial test cases and designated as target test cases.

[0130] Step 306: Determine the effective interception rate of the network security product based on the initial test cases, the target test cases, and the weight information corresponding to the target test cases.

[0131] Specifically, the difference between the sum of the products of each target test case and its corresponding weight information and the initial test cases is calculated to determine the interception information of the network security product. Then, based on the proportion of the interception information in the total number of initial test cases, the effective interception rate of the network security product is determined.

[0132] Step 308: Perform vulnerability detection on the network security products according to the preset vulnerability detection method, and obtain the corresponding security assessment results of the network security products.

[0133] In one implementation, the backend information and interface information corresponding to the network security product can be examined according to a preset vulnerability inspection method, thereby determining the security of the backend information and interface information corresponding to the network security product, and conducting a security assessment of the backend information and interface information of the network security product to determine the security assessment result corresponding to the network security product.

[0134] In one alternative implementation, when assessing security vulnerabilities caused or introduced by the network security product itself, the vulnerability rating of CVSS 3.0 can be referenced.

[0135] Step 310: Determine the target inspection results of the network security products based on the effective interception rate of the network security products and the security assessment results.

[0136] Step 312: If the preset time period is met, obtain test cases for network security products from any third-party platform and store them in the preset relationship mapping table.

[0137] The specific implementation of steps 302-312 above is consistent with the specific implementation of the target object verification method in the above embodiment, and will not be discussed in detail here. For details, please refer to the audio processing method in the above embodiment.

[0138] The target object verification method provided in the embodiments of this specification adopts new evaluation rules and changes the scope of application of the evaluation to solve the problem of insufficient applicability of traditional network security product test cases; it solves the problem of insufficient accuracy of traditional network security product test cases by introducing a weighted scoring mechanism; it solves the problem of insufficient comprehensiveness of traditional network security product test cases by periodically following up on the latest network security product technologies and continuously enriching the existing test case set (i.e., the preset relationship correspondence table); and it solves the problem of insufficient coverage of traditional network security products by introducing the network security product's own verification process.

[0139] See Figure 4 , Figure 4 This specification illustrates a schematic diagram of the processing procedure of a target object inspection method according to an embodiment of the present specification, which specifically includes the following contents.

[0140] First, an evaluation system is established for the capabilities emphasized by network security products. This system sets different weights for the capabilities emphasized by the network security products to provide a more objective evaluation. Based on this evaluation system, corresponding test cases are generated. The network security products are then subjected to real-world simulations using these test cases. The effectiveness of the network security products in intercepting the test cases is determined, and the effective interception rate of the network security products is obtained.

[0141] While conducting practical tests, the security of the network security product itself can be evaluated based on the preset vulnerability testing methods. The security of the network security product itself can be used as an important evaluation item in practical tests to make up for the security risks introduced by the network security product itself and obtain the corresponding security evaluation results of the network security product.

[0142] By combining the effective interception rate of cybersecurity products with security assessment results, the final test results of cybersecurity products can be obtained. These test results can then be used to optimize or repair the cybersecurity products.

[0143] Furthermore, to ensure the comprehensiveness of test cases, corresponding network countermeasures technologies can be obtained from any third-party platform by periodically updating test cases, generating corresponding updated test cases, and storing the correspondence between the updated test cases and network security products. Subsequently, corresponding practical tests can be conducted based on the updated test cases to ensure the comprehensiveness of the test cases.

[0144] The target object verification method provided in the embodiments of this specification adopts new evaluation rules and changes the scope of application of the evaluation to solve the problem of insufficient applicability of traditional network security product test cases; it solves the problem of insufficient accuracy of traditional network security product test cases by introducing a weighted scoring mechanism; it solves the problem of insufficient comprehensiveness of traditional network security product test cases by periodically following up on the latest network security product technologies and continuously enriching the existing test case set (i.e., the preset relationship correspondence table); and it solves the problem of insufficient coverage of traditional network security products by introducing the network security product's own verification process.

[0145] Corresponding to the above method embodiments, this specification also provides embodiments of a target object inspection device. Figure 5 A schematic diagram of a target object inspection device according to one embodiment of this specification is shown. Figure 5 As shown, the device includes:

[0146] The first determining module 502 is configured to determine, in response to an object verification instruction for a target object, an initial test case corresponding to the target object and weight information corresponding to the initial test case.

[0147] Test module 504 is configured to perform security testing on the initial test cases based on the target object, and determine the target test cases that have been successfully tested from the initial test cases;

[0148] The verification module 506 is configured to determine the first verification result of the target object based on the initial test case, the target test case and the weight information corresponding to the target test case, and to perform vulnerability verification on the target object to obtain the second verification result of the target object.

[0149] The second determining module 508 is configured to determine the target inspection result of the target object based on the first inspection result and the second inspection result.

[0150] Optionally, the device further includes:

[0151] The configuration module is configured as follows:

[0152] Based on the first object and its performance, generate a first test case corresponding to the first object, wherein the first object is one of at least two objects to be tested;

[0153] Based on the first test case and the preset test conditions, the weight information corresponding to the first test case is determined, wherein the preset test conditions are the conditions that the at least two first test cases need to meet when performing security testing on the first object;

[0154] The first object, the first test case, and the weight information of the first test case are stored in a preset relationship correspondence table.

[0155] Optionally, the configuration module is further configured to:

[0156] Based on the target object, obtain the initial test case corresponding to the target object and the weight information corresponding to the initial test case from the preset relationship correspondence table.

[0157] Optionally, the configuration module is further configured to:

[0158] If it is determined that the first test case corresponds to at least two preset test conditions, the applicability of the first test case is determined based on the at least two preset test conditions;

[0159] According to the applicability, set the weight information corresponding to the first preset test condition, wherein the first preset test condition is one of the at least two preset test conditions;

[0160] The weight information of the first test case is determined based on the weight information of the first preset test conditions.

[0161] Optionally, the device further includes:

[0162] The update module is configured as follows:

[0163] If a preset time period is met, updated test cases for the first object are obtained from a third-party platform.

[0164] Based on the updated test cases and the preset test conditions, determine the weight information corresponding to the updated test cases;

[0165] The first object, the updated test case, and the weight information of the updated test case are stored in the preset relationship correspondence table.

[0166] Optionally, the test module 504 is further configured to:

[0167] The initial test cases are intercepted and tested based on the target object to obtain test results.

[0168] Based on the test results, the initial test cases that failed to be intercepted by the target object are identified from the initial test cases and used as target test cases.

[0169] Optionally, the inspection module 506 is further configured to:

[0170] The target test metric value is determined based on the target test case and the weight information corresponding to the target test case;

[0171] Based on the number of initial test cases and the target test metric value, the test interception information of the target object is determined as the first verification result of the target object.

[0172] Optionally, the inspection module 508 is further configured to:

[0173] The target object is subjected to vulnerability detection according to a preset vulnerability detection method to obtain vulnerability information of the target object;

[0174] A security assessment is performed on the vulnerability information to obtain the security assessment result, which serves as the second verification result for the target object.

[0175] An embodiment of this specification provides a target object verification device that, in response to an object verification command for a target object, determines an initial test case corresponding to the target object and weight information corresponding to the initial test case, wherein the target object is one of the objects to be verified; performs security testing on the initial test cases based on the target object, and determines a target test case that has successfully passed the test from the initial test cases; determines a first verification result of the target object based on the initial test cases, the target test cases, and the weight information corresponding to the target test cases, and performs vulnerability verification on the target object to obtain a second verification result of the target object; and determines a target verification result of the target object based on the first verification result and the second verification result.

[0176] Specifically, by determining the initial test cases and weight information of the target object to be tested, and by determining the target test cases that have successfully passed the security test based on the target object, the corresponding first inspection result is determined based on the initial test cases, the target test cases, and the weight information of the target test cases. Then, combined with the second inspection result determined by vulnerability detection of the target product itself, the target inspection result for the target object is determined. By combining the weight information of the test cases and the inspection of the target object itself, a more accurate inspection of the target object is achieved.

[0177] The above is a schematic scheme of a target object inspection device according to this embodiment. It should be noted that the technical solution of this target object inspection device and the technical solution of the target object inspection method described above belong to the same concept. For details not described in detail in the technical solution of the target object inspection device, please refer to the description of the technical solution of the target object inspection method described above.

[0178] Figure 6 A structural block diagram of a computing device 600 according to one embodiment of this specification is shown. The components of the computing device 600 include, but are not limited to, a memory 610 and a processor 620. The processor 620 is connected to the memory 610 via a bus 630, and a database 650 is used to store data.

[0179] The computing device 600 also includes an access device 640, which enables the computing device 600 to communicate via one or more networks 660. Examples of these networks include Public Switched Telephone Network (PSTN), Local Area Network (LAN), Wide Area Network (WAN), Personal Area Network (PAN), or combinations of communication networks such as the Internet. The access device 640 may include one or more of any type of wired or wireless network interface (e.g., a network interface card (NIC)), such as an IEEE 802.11 Wireless Local Area Network (WLAN) wireless interface, a Wi-MAX (Worldwide Interoperability for Microwave Access) interface, an Ethernet interface, a Universal Serial Bus (USB) interface, a cellular network interface, a Bluetooth interface, or a Near Field Communication (NFC) interface.

[0180] In one embodiment of this specification, the above-described components of the computing device 600 and Figure 6 Other components, not shown, can also be connected to each other, for example, via a bus. It should be understood that... Figure 6 The block diagram of the computing device shown is for illustrative purposes only and is not intended to limit the scope of this specification. Those skilled in the art can add or replace other components as needed.

[0181] The computing device 600 can be any type of stationary or mobile computing device, including mobile computers or mobile computing devices (e.g., tablet computers, personal digital assistants, laptop computers, notebook computers, netbooks, etc.), mobile phones (e.g., smartphones), wearable computing devices (e.g., smartwatches, smart glasses, etc.) or other types of mobile devices, or stationary computing devices such as desktop computers or personal computers (PCs). The computing device 600 can also be a mobile or stationary server.

[0182] The processor 620 is configured to execute the following computer-executable instructions, which, when executed by the processor, implement the steps of the aforementioned data processing method. The above is an illustrative scheme of a computing device according to this embodiment. It should be noted that the technical solution of this computing device and the technical solution of the aforementioned target object inspection method belong to the same concept. Details not described in detail in the technical solution of the computing device can be found in the description of the technical solution of the aforementioned target object inspection method.

[0183] An embodiment of this specification also provides a computer-readable storage medium storing computer-executable instructions that, when executed by a processor, implement the steps of the target object inspection method described above.

[0184] The above is an illustrative scheme of a computer-readable storage medium according to this embodiment. It should be noted that the technical solution of this storage medium and the technical solution of the target object inspection method described above belong to the same concept. For details not described in detail in the technical solution of the storage medium, please refer to the description of the technical solution of the target object inspection method described above.

[0185] An embodiment of this specification also provides a computer program, wherein when the computer program is executed in a computer, it causes the computer to perform the steps of the target object inspection method described above.

[0186] The above is an illustrative example of a computer program according to this embodiment. It should be noted that the technical solution of this computer program and the technical solution of the target object inspection method described above belong to the same concept. Details not described in detail in the computer program's technical solution can be found in the description of the technical solution of the target object inspection method described above.

[0187] The foregoing has described specific embodiments of this specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims may be performed in a different order than that shown in the embodiments and may still achieve the desired result. Furthermore, the processes depicted in the drawings do not necessarily require the specific or sequential order shown to achieve the desired result. In some embodiments, multitasking and parallel processing are possible or may be advantageous.

[0188] The computer instructions include computer program code, which may be in the form of source code, object code, executable file, or some intermediate form. The computer-readable medium may include: any entity or device capable of carrying the computer program code, recording media, USB flash drive, portable hard drive, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signals, telecommunication signals, and software distribution media, etc. It should be noted that the content included in the computer-readable medium may be appropriately added to or subtracted according to the requirements of legislation and patent practice in the jurisdiction. For example, in some jurisdictions, according to legislation and patent practice, computer-readable media may not include electrical carrier signals and telecommunication signals.

[0189] It should be noted that, for the sake of simplicity, the foregoing method embodiments are all described as a series of actions. However, those skilled in the art should understand that the embodiments in this specification are not limited to the described order of actions, because according to the embodiments in this specification, some steps can be performed in other orders or simultaneously. Furthermore, those skilled in the art should also understand that the embodiments described in this specification are all preferred embodiments, and the actions and modules involved are not necessarily essential to the embodiments in this specification.

[0190] In the above embodiments, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments.

[0191] The preferred embodiments disclosed above are merely illustrative of this specification. The optional embodiments do not exhaustively describe all details, nor do they limit the invention to the specific implementations described. Clearly, many modifications and variations can be made based on the embodiments described herein. These embodiments are selected and specifically described in this specification to better explain the principles and practical applications of the embodiments, thereby enabling those skilled in the art to better understand and utilize this specification. This specification is limited only by the claims and their full scope and equivalents.

Claims

1. A method for detecting a target object, comprising: In response to an object inspection instruction for a target object, an initial test case corresponding to the target object and weight information corresponding to the initial test case are determined, wherein the target object is one of the objects to be inspected; Security tests are performed on the initial test cases based on the target object, and target test cases that have been successfully tested are determined from the initial test cases; Determining the first inspection result of the target object based on the initial test case, the target test case, and the weight information corresponding to the target test case includes: determining the target test indicator value based on the target test case and the weight information corresponding to the target test case; and determining the test interception information of the target object based on the quantity information of the initial test case and the target test indicator value, as the first inspection result of the target object. The target object is then subjected to vulnerability testing to obtain a second test result for the target object. Based on the first test result and the second test result, the target test result of the target object is determined.

2. The target object inspection method according to claim 1, further comprising, before responding to the object inspection instruction for the target object: Based on the first object and its performance, generate a first test case corresponding to the first object, wherein the first object is one of at least two objects to be tested; Based on the first test case and the preset test conditions, the weight information corresponding to the first test case is determined, wherein the preset test conditions are the conditions that the at least two first test cases need to meet when performing security testing on the first object; The first object, the first test case, and the weight information of the first test case are stored in a preset relationship correspondence table.

3. The target object verification method according to claim 2, wherein determining the initial test case corresponding to the target object and the weight information corresponding to the initial test case includes: Based on the target object, obtain the initial test case corresponding to the target object and the weight information corresponding to the initial test case from the preset relationship correspondence table.

4. The target object verification method according to claim 2, wherein determining the weight information corresponding to the first test case based on the first test case and preset test conditions includes: If it is determined that the first test case corresponds to at least two preset test conditions, the applicability of the first test case is determined based on the at least two preset test conditions; According to the applicability, weight information corresponding to the first preset test condition is set, wherein the first preset test condition is one of the at least two preset test conditions; The weight information of the first test case is determined based on the weight information of the first preset test conditions.

5. The target object verification method according to claim 2, after storing the first object, the first test case, and the weight information of the first test case into a preset relational mapping table, further includes: If a preset time period is met, updated test cases for the first object are obtained from a third-party platform. Based on the updated test cases and the preset test conditions, determine the weight information corresponding to the updated test cases; The first object, the updated test case, and the weight information of the updated test case are stored in the preset relationship correspondence table.

6. The target object verification method according to claim 1, wherein performing security testing on the initial test cases based on the target object, and determining the target test cases that have successfully passed the test from the initial test cases, comprises: The initial test cases are intercepted and tested based on the target object to obtain test results. Based on the test results, the initial test cases that failed to be intercepted by the target object are identified from the initial test cases and used as target test cases.

7. The target object inspection method according to claim 1, wherein performing vulnerability inspection on the target object to obtain a second inspection result of the target object includes: The target object is subjected to vulnerability detection according to a preset vulnerability detection method to obtain vulnerability information of the target object; A security assessment is performed on the vulnerability information to obtain the security assessment result, which serves as the second verification result for the target object.

8. A target object inspection device, comprising: The first determining module is configured to, in response to an object verification instruction for a target object, determine the initial test case corresponding to the target object and the weight information corresponding to the initial test case. The testing module is configured to perform security testing on the initial test cases based on the target object, and to determine the target test cases that have been successfully tested from the initial test cases; The verification module is configured to determine the first verification result of the target object based on the initial test case, the target test case, and the weight information corresponding to the target test case, and to perform vulnerability verification on the target object to obtain the second verification result of the target object. The verification module is further configured to determine the target test index value based on the target test case and the weight information corresponding to the target test case; Based on the number of initial test cases and the target test metric value, the test interception information of the target object is determined as the first verification result of the target object; The second determining module is configured to determine the target inspection result of the target object based on the first inspection result and the second inspection result.

9. A computing device, comprising: Memory and processor; The memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions, which, when executed by the processor, implement the steps of the target object inspection method according to any one of claims 1 to 7.

10. A computer-readable storage medium storing computer-executable instructions that, when executed by a processor, implement the steps of the target object inspection method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Test case recommendation method and device and electronic equipment

    CN112416778A

  • Method and device for testing application system

    CN113468053A