RBAC-Based Web Application Security Access Control Vulnerability Detection Method and System
Through dynamic and static hybrid modeling and attack vector simulation, a multi-attribute site map model is built, which solves the authentication bypass attack problem in web application access control vulnerability detection and achieves the security of web applications.
Patent Information
- Application Number
- CN202310062030.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-01-17
- Publication Date
- 2025-07-29
- Estimated Expiration
- 2043-01-17
AI Technical Summary
The access control mechanism of existing web applications is flawed, resulting in authentication bypass attacks, user privacy leaks, and unauthorized attackers can access sensitive information, becoming a serious security threat.
Through dynamic and static hybrid modeling, combining permission verification and database identity information, a multi-attribute site map model is built, user operations are simulated, attack vectors are generated, web application response is evaluated, and vulnerability detection is realized.
Effectively detect vertical and horizontal overprivileges vulnerabilities, ensure the correctness of user access rights, improve the security of web applications, and reduce the risk of authentication bypass attacks.
Smart Images

Figure CN116094808B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security technology, and particularly to an access control vulnerability detection method and system for Web application security based on the RBAC model. Background Art
[0002] In today's social life, with the increasing popularity of computers, web network application programs have become more and more popular and common. Since Web application programs allow users to log in to any computer to access websites and obtain their own information and data, Web application programs have become attractive targets for attackers who want to steal other users' data or resources. Web application programs usually solve this problem through access control. Access control is to provide a set of methods to organize, identify, and manage all the data in the system, and then provide a simple and unique interface for the server to call. Generally speaking, it means that the access control mechanism authenticates the users who want to access the program and ensures that the users are granted appropriate permissions. In theory, this mechanism should ensure that unauthorized attackers cannot damage the application program. Unfortunately, many web application programs do not follow these seemingly simple permission verification steps, or the steps in access control are not perfect enough. Each web application program usually deploys its own authentication and access control framework. If there are any defects in its authentication system, an authentication bypass attack may occur, allowing attackers to be verified as valid users without presenting user credentials, and then the privacy of users is leaked. Therefore, access control vulnerabilities are considered to be one of the most serious security threats faced by today's web application programs in managing sensitive information, and three of the top ten web application security risks can be attributed to the defective access control in web applications. Summary of the Invention
[0003] In order to overcome the deficiencies of the prior art, the present invention performs fine-grained modeling on the program through a dynamic and static hybrid method, combines permission verification with the identity information in the database entries, analyzes the expected behaviors of different roles and users, constructs a multi-attribute site map model by simulating user operations to track and collect response information, deduces the access control policy of the program, and realizes vulnerability detection by constructing three types of attack vectors to simulate vulnerability attacks and evaluate the responses of Web application programs.
[0004] To achieve the above object, the solution adopted by the present invention is as follows:
[0005] An access control vulnerability detection method for Web application security based on the RBAC model, which includes the following steps:
[0006] Step 1: Obtain the basic data in the Web application program database;
[0007] Obtain the basic data in the database of a Web application (a global, dynamically interactive, cross-platform distributed graphic information system based on hypertext and HTTP), where the basic data consists of a start link node SN, the account password information PL logged in by the user, and the local file directory SC of the program source code;
[0008] Step 2: Process the basic data, construct a dynamic node connection graph and a static link jump graph, and merge them to form a site map model;
[0009] Step 21: Based on the dynamic analysis method, when the specific composition of the application is unknown, regard the application as a black box system, simulate all expected operations of the user by designing a prototype, and construct a dynamic node connection graph of the black box system;
[0010] Form a page node set N0 from the user resource page links accessed by the user's expected operations, form an edge set E0 from the access and being accessed relationships between the page nodes formed by the user resource page links, and form an edge weight set W from the session information, user, and role information passed between the page nodes. Construct a multi-role based dynamic framework graph model G0 as follows:
[0011]
[0012] In the formula: G0 represents the dynamic node connection graph; E0 represents the edge set formed by the access and being accessed relationships between the page nodes formed by the user resource page links; W represents the edge weight set formed by the session information, user, and role information passed between the page nodes; N0 represents the page node set formed by the user resource page links, denoted as UP0, which contains n resource nodes a, where nodes a1 to a k represents the same node obtained in dynamic analysis and static analysis, and node a k to a n represents the different nodes obtained in dynamic analysis and static analysis; <a i , a j > represents an edge formed by nodes a i and a j ; w l represents the weight of the l-th edge; n represents the total number of resource nodes; k represents the split point number of the same and different nodes of the resources; i and j respectively represent the first edge number and the second edge number of the resource nodes;
[0013] Step 22: Based on the static analysis method, regard the application as a white box system, analyze the page jump situations involved in the source code, and construct a static link jump graph;
[0014] Analyze the source code of the Web application to obtain the source code directory structure of the Web application and the directory hierarchy where the pages are located, and complete the links in the static code; during static analysis, the pages are identified as individual nodes, and these nodes are similar page nodes. Therefore, the status of the nodes and the complex relationships of the edges in UP0 are more than those in UP0′. Therefore, static analysis pays more attention to the relationship between UP0′ and the FP nodes. Finally, the static page connection graph is constructed as follows:
[0015]
[0016] In the formula: G1 represents the static link jump graph; N1 represents the set of page nodes obtained by static analysis, including the resource page node UP and the function page node FP; E1 represents the set of edges formed by the call and being called between the set of resource page nodes UP and the set of function nodes FP; UP1 represents the set of resource pages obtained during static analysis; UP'0 represents that there are overlapping nodes between some UP nodes obtained by static analysis and those obtained by dynamic analysis; <a p ,b q > represents an edge formed by nodes a p and b q ; bm represents the m-th node b; n′ represents the total number of nodes a p ; m represents the total number of nodes b q .
[0017] Step 23: Based on the KM maximum matching algorithm (Kuhn-Munkres algorithm, used to find the maximum weight matching under perfect matching) and the union-find set algorithm (used to process queries and merges of elements in mutually disjoint sets), merge the dynamic node connection graph G0 obtained in Step 21 and the static link jump graph G1 obtained in Step 22 to establish a user-based site map model;
[0018] Step 3: Mine the access control policies Gr of different users in the site map model;
[0019] Step 4: Violate the access control policy to generate attack vectors for the Web application;
[0020] Based on the multi-attribute cross-recombination method, reorganize the access logic between the accessed user and the accessed resource to achieve vulnerability intrusion; based on the membership relationship between roles and the resource pages that can be accessed, force different types of role users to access resource pages mutually to construct vulnerability attack vectors; generate a refined attack vector based on the ordered correspondence relationship between roles and resources, as shown in the following formula:
[0021] Φatts = {<r s ,u v >→{N,E,<r z ,u w>}|u v ,u w ∈U; r s ,r z ∈R, v ≠ w};
[0022] Where: Φatts represents the set of attack vectors; r s represents the first role, and s takes values in [0, 1, 2]; u v represents the first user; <r s ,u v > indicates that the access subject of the attack is u with the role of r s role; N represents the set of nodes of the site map G; E represents the edge relationship set of the site map G; r v represents the second role, and z takes values in [0, 1, 2]; u z represents the second user, where v ≠ w means u w is different users; U represents the set of users; R represents the set of roles; {N, E, <r v ,u w >} indicates that the accessed resource is all nodes N and edge relationships E of u with the role of r z ,u w > user; z role; w user;
[0023] Step 5: Complete the access control vulnerability detection of the Web application;
[0024] Based on the correct access control policy in Step 3 and the set of attack vectors in Step 4, access the program according to the policies of the above two steps, and perform fuzzy matching on the obtained response results based on the response parameters and response content to detect whether there is an access control vulnerability and establish a vulnerability detection rule; if the results match, it indicates the existence of a vulnerability and a report is made.
[0025] Preferably, the start link node SN, the account password information PL for user login, and the local file directory SC of the program source code in Step 1 are as follows:
[0026] The start link node SN and the account password information PL for user login are used as the start entry point for simulating user behavior in the dynamic analysis stage, so that the program can automatically simulate the user login operation;
[0027] The local file directory SC of the program source code is used as the start entry point for constructing the connection between pages in the static analysis stage, so that the program can perform in-depth access based on the existing locations.
[0028] Preferably, the dynamic analysis method in step 21 can simulate all expected operations of users by itself and adapt to the dynamic changes of the program, truly record the execution process of the program, and at the same time characterize the dynamic changes of the pages based on roles and users in the program; performing dynamic access to the program in a role-based manner helps to directly identify and obtain the access paths and access permissions of different roles.
[0029] Preferably, the static analysis method in step 22, based on the system analysis of the program source code pages, can comprehensively characterize all resource page sets in the program and the relationships between pages; by analyzing the connection relationships between pages, it can effectively identify sensitive operations corresponding to resource pages and avoid the situation of missing program access control policies.
[0030] Preferably, merging the dynamic node connection graph G0 obtained in step 21 and the static link jump graph G1 obtained in step 22 in step 23 can reflect the real execution behavior of the program, improve the page coverage rate of the program without increasing the consumption of system analysis, and comprehensively characterize the relationships between program resource pages; at the same time, based on the analysis of roles in the RBAC (role-based-access-control) model, obtain the permission access constraint conditions based on roles and users, and can directly determine the relationships between roles, users and resource permissions during the model construction process.
[0031] Preferably, the site map model integration based on users needs to be carried out in step 23 for establishing the site map model based on users, specifically:
[0032] The site map model integration includes node merging and edge merging; the edge merging follows the node movement, simplifies the problem to the UP integration and FP addition problems during the node merging process, uses a to represent the set of UP nodes, and b to represent the set of FP nodes;
[0033] Step 231: UP node integration, complete the unification of nodes with the same name and supplement the missing nodes with different names;
[0034] First, complete the unification of nodes with the same name; for the UP nodes with the same name existing in G0 and the static link jump graph G1 obtained in step 22, to ensure the comprehensiveness of the model to obtain nodes, use as many nodes as possible. When there are nodes with the same name, only retain their child nodes; by comparing the similarity of node links, determine the nodes with the same name in G0 and G1, stipulate that the nodes obtained by dynamic analysis are child nodes, and the nodes obtained by static analysis are source nodes, retain the child nodes and their edge relationships at the same time; delete the remaining nodes with the same name;
[0035] Then complete the supplementation of missing nodes with different names; to avoid randomly adding nodes, making them difficult to find, add edges to the nodes by calculating the in-degree and out-degree of the UP nodes in G0, that is, using G0 as the basic model graph, calculate the core node with the most in-degree and out-degree in it. If there are the same in-degree and out-degree, select the node with the most out-degree as the core node, and connect the missing nodes in the graph to the core node to form a complete graph model;
[0036] Step 232: Add FP nodes. The page nodes obtained from the program source code only exist in the G1 model. As a functional extension of the UP nodes, FP realizes edge connection following the UP nodes it contains. It is necessary to solve the connection problem between the UP nodes with the same name and FP; since the child nodes of the nodes with the same name are selected as the final node set in the merger of UP, connect the child nodes and FP separately; first, identify the FP nodes connected to the UP nodes with the same name, and change their edge relationship to the connection between the UP child nodes with the same name and FP;
[0037] Step 233: Integrate the site map model to generate the site map model G. The identification formula is as follows:
[0038]
[0039] In the formula: G represents the site map model; q0 represents the starting link node; F represents the set of end links; A represents the inter-procedural user annotations.
[0040] Preferably, the access control policies Gr of different users in the mined site map model in step 3 are specifically as follows:
[0041] Extract the characteristic attributes of the complex multi-attribute site map model G, abstract the key attributes to form an access control rule constraint model, which is represented by the triple <R, U, Gr>. The access control policy is as follows:
[0042] Gr = {P path , P sub-graph};
[0043] In the formula: Gr represents the access control policy; P path represents the path rules of different roles; P sub-graph represents the sub-graph rules;
[0044] Inter-procedural abstraction of the site map model G, based on the extracted access control rule constraint model <R, U, Gr>, conduct correlation analysis between attributes by calculating the attribute correlation degree, and formulate conditional relevant and conditional irrelevant strategy mappings between attributes to the correlation degree Pr.
[0045] Preferably, the attack vectors in step 4 include vertical privilege escalation attack vectors and horizontal privilege escalation attack vectors, specifically as follows:
[0046] The intrusion strategy constructed by the cross - recombination method of the vertical privilege escalation attack vector for different roles is used to detect vertical privilege escalation vulnerabilities, as follows:
[0047]
[0048] In the formula: r0 represents the anonymous user role; r1 represents the ordinary user role; Φatts_v1 represents the set of attack vectors for the anonymous user role to access the resources of the ordinary user role and the administrator role, u v Under the r0 role, access r z role's u w resources owned by the user, including the node set N and the edge set E; Φatts_v2 represents the set of attack vectors for the constructed ordinary user role to access the resources of the administrator role, u v Under the r1 role, access the u of the r2 role w resources owned by the user, including the node set N and the edge set E;
[0049] The intrusion strategy constructed by the cross - recombination method of the horizontal privilege escalation attack vector between different users with the same role is used to detect horizontal privilege escalation vulnerabilities, as follows:
[0050] Φatts_h = { <r s , u v > → {N, E, <r s , u w >}|u v , u w ∈U; s ∈ [1, 2]; v ≠ w; N = [a1,..., a n};
[0051] In the formula: Φatts_h constructs, under the same role r s u v uses to access u w resources owned by the user, including the node set N and the edge set E.
[0052] Preferably, the vulnerability detection rules in step 5 are as follows:
[0053] Step 51: Match the link of the client's normal rendering page with the link after the attack vector forcibly accesses the page. If they are different, end the judgment and there is no vulnerability in this node;
[0054] Step 52: If they are the same, remove the common static content, meta - tags, scripts, and footer information in both web pages to obtain the architecture of the page, and match the architectures. If the page architectures are different, end the judgment and there is no vulnerability in this node page;
[0055] Step 53: If the page structures are the same, further perform hash fuzzy matching on the rendered content of both pages. If the content of the two pages is different, there is no vulnerability. If the content is similar or the same, the page is defined as a vulnerable page. If the links are the same, compare the page structures. If the rendered pages obtained by accessing the same link have the same structure, extract the page tags and organize them into page structures. If the page structures are different, end the judgment and the node page does not have a vulnerability.
[0056] Step 54: Use Burpsuite (an integrated platform for attacking web applications) and Appscan (a web security scanning tool) to obtain the HTTP request response parameters of the client's normal response and the request response parameters of the page forcibly accessed by the attack vector. The parameters mainly include content-length (the length of the HTTP entity body), User-Agent (the user agent, which informs the server of the name of the application initiating the request), Accept (used to inform the server which media types can be sent), and Referer (provides the URL of the document containing the current request URI). If the parameter values obtained by the two methods are the same, the link of the page being visited is defined as a suspected vulnerability response link, otherwise the link does not have a vulnerability.
[0057] Preferably, another aspect of the present invention also provides an access control vulnerability detection system for Web applications based on the RBAC mode, which includes a data acquisition unit, a data processing unit, an access control policy mining unit, an attack vector generation unit for Web applications, and an access control vulnerability detection unit, wherein the data acquisition unit is used to acquire basic data in the Web application database, the data processing unit is used to process the basic data, construct a dynamic node connection graph and a static link jump graph, and merge them to form a site map model, the access control policy mining unit is used to mine the access control policies Gr of different users in the site map model, the attack vector generation unit for Web applications is used to violate the access control policy and generate an attack vector for the Web application, and the access control vulnerability detection unit is used to access the program based on the correct access control policy and attack vector set obtained, and perform fuzzy matching on the obtained response results based on the response parameters and response content to detect whether there is an access control vulnerability and establish vulnerability detection rules; if the results match, it indicates the existence of a vulnerability and a report is made.
[0058] Compared with the prior art, the present invention has the following beneficial effects:
[0059] (1) The present invention performs fine-grained modeling on a program through a dynamic and static mixing method, combines permission verification with identity information in database entries, analyzes the expected behaviors of different roles and users to ensure that correctly authenticated users access their corresponding resources, constructs a multi-attribute site map model by collecting response information through simulating user operation tracking, and derives the access control policy of the program based on browsing traces.
[0060] (2) The present invention constructs three types of attack vectors based on a qualified condition attribute recombination method, simulates vulnerability attacks to achieve frequent and reproducible vulnerability detection, evaluates the response of a Web program through a designed fuzzy matching vulnerability discrimination rule based on response parameters and response content, determines two types of vulnerabilities, namely vertical privilege escalation and horizontal privilege escalation, and completes the access control vulnerability detection of a Web application program. Brief Description of the Drawings
[0061] Figure 1 It is a control block diagram of the access control vulnerability detection method for Web application security based on the RBAC model in an embodiment of the present invention;
[0062] Figure 2 It is a flowchart of the access control vulnerability full detection method for a Web application program in an embodiment of the present invention;
[0063] Figure 3 It is an example diagram of a multi-attribute site map model G in an embodiment of the present invention;
[0064] Figure 4 (a), (b), and (c) are respectively schematic diagrams of the merging of UP same-name nodes of G0, G1, and G in an embodiment of the present invention;
[0065] Figure 5 (a), (b), and (c) are respectively schematic diagrams of adding UP different-name nodes of G0, G1, and G in an embodiment of the present invention;
[0066] Figure 6 (a), (b), and (c) are respectively schematic diagrams of adding FP nodes of G0, G1, and G in an embodiment of the present invention;
[0067] Figure 7 It is a structural schematic block diagram of the access control vulnerability detection system for a Web application program based on the RBAC model of the present invention. Detailed Embodiment
[0068] Hereinafter, the embodiments of the present invention will be described with reference to the drawings.
[0069] The implementation of the present invention models the program in a fine-grained manner through a dynamic and static hybrid approach, combines permission verification with identity information in database entries, and analyzes the expected behaviors of different roles and users; constructs three types of attack vectors based on the qualified condition attribute recombination method, simulates vulnerability attacks to achieve frequent and reproducible vulnerability detection, evaluates the response of the Web program through the designed fuzzy matching vulnerability discrimination rules based on response parameters and response content, determines two types of access control vulnerabilities, namely vertical privilege escalation and horizontal privilege escalation, and completes the access control vulnerability detection of the Web application. Through the analysis and comparison of the detection results, it can be proved that the proposed method has good practical application effects. As Figure 1 shown in the control block diagram of the access control vulnerability detection method for Web application security based on the RBAC model according to the embodiment of the present invention.
[0070] The embodiment of the present invention provides an access control vulnerability detection method for Web application security based on the RBAC model, as Figure 2 shown in the flow chart of the access control vulnerability full detection method for the Web application program according to the embodiment of the present invention; in order to prove the applicability of the present invention, it is applied to an example, which specifically includes the following steps:
[0071] S1: Obtain the basic data in the database of the Web application program;
[0072] The basic data in the database of the Web application program is composed of the start link node SN, the account password information PL of the user login, and the local file directory SC of the program source code.
[0073] The start link node SN and the account password information PL of the user login are used as the start entry points for simulating user behaviors in the dynamic analysis stage, so that the program can automatically simulate the user login operation.
[0074] The local file directory SC of the program source code is used as the start entry point for constructing the connection between pages in the static analysis stage, so that the program can perform in-depth access based on the existing positions.
[0075] The Web application program usually sets three roles: r2 (administrator role), r1 (ordinary user role), and r0 (anonymous user role), and their permission levels are divided as follows: In this example, four users are set: Alice, Bob, Cindy, and Jack, where Alice is the administrator r2, Bob and Cindy are ordinary users r1, and Jack is the anonymous user r0.
[0076] S2: Process the basic data, construct a dynamic node connection graph and a static link jump graph, and merge them to form a site map model;
[0077] S21: Based on the dynamic analysis method, when the specific composition of the unknown application is not known, the application is regarded as a black-box system. By designing a prototype to simulate all the expected operations of the user, a dynamic node connection diagram of the black-box system is constructed. The dynamic analysis method can simulate all the expected operations of the user by itself and adapt to the dynamic changes of the program, truly record the execution process of the program, and at the same time characterize the dynamic changes of the pages based on roles and users in the program. Performing dynamic access to the program in a role-based manner helps directly identify and obtain the access paths and access permissions of different roles.
[0078] Form a page node set N0 with the user resource page links accessed by the user's expected operations. The access and being accessed relationships between the user resource page links form an edge set E0. The session information, user, and role information transmitted between the page nodes constitute an edge weight set W. Construct a dynamic framework graph model G0 based on multiple roles as follows:
[0079]
[0080] In the formula: G0 represents the dynamic node connection diagram; N0 represents the page node set formed by the user resource page links; E0 represents the edge set formed by the access and being accessed relationships between the page nodes formed by the user resource page links; W represents the edge weight set constituted by the session information, user, and role information transmitted between the page nodes; N0 represents the set of resource page nodes of all users, denoted as UP0, which contains n resource nodes a, where nodes a1 to a k represents the same node obtained in dynamic analysis and static analysis, and node a k to a n represents the different nodes obtained in dynamic analysis and static analysis; <a i , a j > represents an edge formed by nodes a i and a j ; w l represents the weight value of the l-th edge; n represents the total number of resource nodes; k represents the segmentation point number of the same and different nodes of the resources; i and j respectively represent the first edge number and the second edge number of the resource nodes.
[0081] For example Figure 3The set of nodes N0 that can be captured in this step is shown by the solid - line circle, the set of edges E0 represented by the arrows between the nodes, and the set of edge weights W represented by the annotations on the edges. The dynamic node - connection graph G0 composed of the above - mentioned elements. The access starting point of the program is usually the public page index.php(1). At this time, users of all roles can access the content of this page. Subsequently, the user logs in through the login.php(2) page to the admin.php(3) page. At this time, the nodes include {index.php, login.php, admin.php}, and the edge relationship between the nodes is {<index.php,login,php>,<login.php,admin.php>}. At the same time, the conditions for capturing the jump relationship between nodes are used as edge weights. For example, the access from node 1 to 2 is allowed for roles r0, r1, r2. During the access process, the username username (John, Bob, Cindy, Alice), the current session session, and the jump URL of the current page as ' / index.php' can be captured. When the accessible page nodes of different roles change after passing through node 3, nodes 5 - 6 can be accessed by roles r2, r1. At the same time, the jump conditions between the current nodes can be captured, including the username username (Bob, Cindy, Alice), the session session, and the jump URL as ' / admin.php'.
[0082] S22: Based on the static analysis method, taking the application program as a white - box system, analyze the page - to - page jump situations involved in the source code and construct a static link - jump graph. The static analysis method is based on the systematic analysis of the program source - code pages, which can comprehensively represent all resource - page sets in the program and the relationships between pages. By analyzing the connection relationships between pages, it can effectively identify sensitive operations corresponding to resource pages and avoid the situation of missing program access - control policies.
[0083] Analyze the source code of the Web application program to obtain the source - code directory structure of the Web application program and the directory hierarchy where the pages are located, and complete the links in the static code. During the static analysis, the pages are identified as individual nodes, and these nodes are similar - page nodes. Therefore, the states of the nodes and the complex relationships of the edges in UP0 are more than those in UP0′. Therefore, the static analysis pays more attention to the relationship between UP0′ and FP nodes. Finally, the static page - connection graph is constructed as shown below:
[0084]
[0085] In the formula: G1 represents the static link jump graph; N1 represents the set of page nodes obtained by static analysis, including the resource page node UP and the function page node FP; E1 represents the set of edges formed by the call and being called between the resource page node UP set and the function node FP set; UP1 represents the set of resource pages obtained during the static analysis process; UP'0 represents that some UP nodes obtained by static analysis coincide with those obtained by dynamic analysis; <a p ,b q > represents a node a p and b q constitute an edge; bm represents the mth node b; n′ represents the total number of nodes a p ; m represents the total number of nodes b q .
[0086] As Figure 3 shown by the dotted circle, the set of nodes N1 that can be captured in this step, the set of edges E1 represented by the arrows between the nodes, and the static link jump graph G1 formed above. It can be seen that in the user login operation from node 2 to node 3, node 2 needs to jump to the function.php page to implement the backend authentication operation. After successful authentication, it can jump to node 3. At this time, the obtained nodes include {login.php, function.php, admin.php}, and the edge relationship between the nodes for connecting the nodes is {<login.php, function.php>, <function.php, admin.php>}.
[0087] S23: Based on the KM maximum matching algorithm and the union-find set algorithm, merging the dynamic node connection graph G0 obtained in S21 and the static link jump graph G1 obtained in S22 can reflect the real execution behavior of the program, improve the page coverage rate of the program without increasing the system analysis consumption, and comprehensively characterize the relationship between the resource pages of the program; at the same time, based on the analysis of roles in the RBAC model, the access control conditions based on roles and users can be obtained, and the relationship between roles, users, and resource permissions can be directly determined during the model construction process.
[0088] Establish a user-based site map model, including node merging and edge merging; the merging of edges follows the movement of nodes, simplifying the problem to the integration of UP and the addition of FP during the node merging process. As Figure 4 (a)(b)(c) show the schematic diagrams of the same-name nodes of G0, G1, and G in the embodiments of the present invention respectively; As Figure 5 (a)(b)(c) show the schematic diagrams of the different-name nodes of G0, G1, and G in the embodiments of the present invention respectively; As Figure 6(a), (b), and (c) respectively show the schematic diagrams of the FP nodes of Embodiment G0, G1, and G of the present invention. Let a represent the set of UP nodes and b represent the set of FP nodes.
[0089] S231: Integrate the UP nodes to complete the unification of nodes with the same name and supplement the missing nodes with different names;
[0090] First, complete the unification of nodes with the same name; for the UP nodes with the same name existing in G0 and the static link jump graph G1 obtained in S22, to ensure the comprehensiveness of the nodes obtained by the model, as many nodes as possible are adopted. When there are nodes with the same name, only their child nodes are retained; by comparing the similarity of node links, the nodes with the same name in G0 and G1 are determined. It is stipulated that the nodes obtained by dynamic analysis are the child nodes, and the nodes obtained by static analysis are the source nodes. The child nodes are retained, and their edge relationships are also retained; the remaining nodes with the same name are deleted.
[0091] As Figure 4 As shown in (a), G0 has nodes including a1, a2, a31’, and a32’; Figure 4 (b) is G1, which has nodes including a1, a2, and a3, where a31’ and a32’ are the child nodes with the same name as a3. According to the above steps, the graph G can be obtained, as shown in Figure 4 (c).
[0092] Then, complete the supplement of missing nodes with different names; to avoid randomly adding nodes making them difficult to find, the edges of the nodes are added by calculating the in-degree and out-degree of the UP nodes in G0. That is, taking G0 as the basic model graph, calculate the core node with the most in-degree and out-degree in it. If there are the same in-degree and out-degree, select the node with the most out-degree as the core node, and connect the missing nodes in the graph to the core node to form a complete graph model.
[0093] As Figure 5 As shown in (a), G0 has the same nodes as Figure 4 (a); Figure 5 (b) is G1, which has nodes including a1 - a4, where node a4 is a node with a different name. According to the above steps, the graph G can be obtained, as shown in Figure 5 (c).
[0094] S232: Add FP nodes. The page nodes obtained from the program source code only exist in the G1 model. As a functional extension of the UP nodes, the FP follows the UP nodes it is included in to achieve edge connection. It is necessary to solve the connection problem between the UP nodes with the same name and the FP; since the child nodes of the nodes with the same name are selected as the final node set in the merger of the UP, the child nodes and the FP are connected separately; first, identify the FP nodes connected to the UP nodes with the same name, and change their edge relationships to the connections between the child nodes with the same name of the UP and the FP.
[0095] As Figure 6(a) shows G0, where the nodes are the same as Figure 5 (a); Figure 6 (b) shows G1, where the nodes include a1 - a4, b1 - b3, and the nodes b1 - b3 are FP nodes. According to the above steps, the graph G can be obtained as shown in Figure 6 (c).
[0096] S233: Integrate the site map model to generate the site map model G, and the identification formula is as follows:
[0097]
[0098] In the formula: G represents the site map model; q0 represents the starting link node; F represents the set of end links; A represents the inter - process user annotations, including the user's role R, username U, the session S that the user is currently accessing, etc.
[0099] S3: Mine the access control policies Gr of different users in the site map model;
[0100] Extract the characteristic attributes of the complex multi - attribute site map model G, as shown in Figure 3 the example diagram of the multi - attribute site map model G based on the embodiment of the present invention; Abstract the key attributes to form an access control rule constraint model, represented by the triple {Gr, <R, U>}, where the access control policy is as follows:
[0101] Gr = {P path , P sub-graph};
[0102] In the formula: Gr represents the access control policy, which is composed of the combination of the node N and the edge set E; P path represents the path rule of different roles; P sub-graph represents the sub - graph rule.
[0103] The inter - process abstraction of the site map model G, based on the extracted access control rule constraint model <R, U, Gr>, conducts the correlation analysis between attributes by calculating the attribute correlation degree, and formulates the conditional correlation and conditional independence strategies between attributes and maps them to the correlation degree Pr.
[0104] As shown in Figure 3 , according to the above steps, the site map G can be split into sub - graph P sub-graph or path P path according to the role, that is, the access control policy. The Gr of John includes the nodes 1 - 2 and the edge relationship between the nodes, and Gr John can be obtained; The Gr of Bob and Cindy includes the nodes 1 - 6 and the edge relationship between the nodes, and Gr Bob and Gr Cindy; Alice's Gr includes nodes 1 - 10 and the edge relationships between nodes, and Gr can be obtained Alice .
[0105] S4: Violate the access control policy and generate attack vectors for the Web application;
[0106] Based on the multi - attribute cross - recombination method, reorganize the access logic between the accessing user and the accessed resource to achieve vulnerability intrusion; based on the membership relationship between roles and the resource pages that can be accessed, force different types of role users to access resource pages from each other to construct vulnerability attack vectors; generate a streamlined attack vector based on the ordered correspondence relationship between roles and resources, as shown in the following formula:
[0107] Φatts = {<r s ,u v >→{N,E,<r z ,u w >}|u v ,u w ∈U; r s ,r z ∈R, v≠w};
[0108] In the formula: Φatts represents the set of attack vectors; r s represents the first role, and s takes values in [0,1,2]; u v represents the first user; <r s ,u v > represents that the access subject of the attack is the u s user with the r v role; N represents the set of nodes of the site map G; E represents the set of edge relationships of the site map G; r z represents the second role, and z takes values in [0,1,2]; u w represents the second user, where v≠w means that u v ,u w are different users; U represents the set of users; R represents the set of roles; {N,E,<r z ,u w >} represents that the accessed resource is all nodes N and edge relationships E of the u z user with the r w role.
[0109] The attack vectors include vertical privilege escalation attack vectors and horizontal privilege escalation attack vectors, specifically:
[0110] The vertical privilege escalation attack vector is used to detect vertical privilege escalation vulnerabilities for the intrusion strategy constructed by the cross - recombination method for different roles, as follows:
[0111]
[0112] Where: r0 represents the anonymous user role; r1 represents the ordinary user role; r3 represents the administrator user role; Φatts_v1 represents the set of attack vectors for the anonymous user role to access the resources of the ordinary user role and the administrator role, u v Under the r0 role, access r z role's u w resources owned by the user, including the node set N and the edge set E; Φatts_v2 represents the set of attack vectors for the constructed ordinary user role to access the resources of the administrator role, u v Under the r1 role, access the u of the r2 role w resources owned by the user, including the node set N and the edge set E.
[0113] Φatts_v1 is that John, Bob, and Cindy access the resources Gr of user Alice Alice , or John accesses the resources Gr of users Bob and Cindy Bob and Gr Cindy ; Φatts_v2 is that Bob and Cindy access the resources Gr of user Alice Alice .
[0114] The intrusion strategy constructed for the cross-recombination method between different users with the same role by the horizontal privilege escalation attack vector is used to detect horizontal privilege escalation vulnerabilities, as follows:
[0115] Φatts_h = {<r s , u v > → {N, E, <r s , u w >}|u v , u w ∈U; s ∈ [1, 2]; v ≠ w; N = [a1,..., a n};
[0116] Where: Φatts_h constructs the resources owned by u s under the same role r v to access u w resources owned by the user, including the node set N and the edge set E.
[0117] Φatts_h is that users Bob and Cindy access each other's resources, Bob accesses Gr Cindy , and Cindy accesses Gr Bob .
[0118] S5: Complete the access control vulnerability detection of the Web application;
[0119] Based on the correct access control policy in S3 and the set of attack vectors in S4, access the program according to the policies of the above two steps, and perform fuzzy matching on the obtained response results based on the response parameters and response content to detect whether there are access control vulnerabilities and establish vulnerability detection rules; if the results match, it indicates the existence of vulnerabilities and a report is made.
[0120] S51: Match the normal rendering page link of the client with the link after forcibly accessing the page with the attack vector. If they are different, end the judgment and there is no vulnerability at this node.
[0121] S52: If they are the same, remove the common static content, meta tags, scripts, and footer information in both web pages to obtain the page architecture and match the architecture; if the page architectures are different, end the judgment and there is no vulnerability at this node page.
[0122] S53: If the page architectures are the same, further perform hash fuzzy matching on the rendered content of both pages. If the contents of the two pages are different, there is no vulnerability; if the contents are similar or the same, this page is defined as a vulnerable page; if the links are the same, compare the page architectures; if the rendered page structures obtained by accessing the same link are the same, at this time, extract the tags of the page as the page architecture. If the page architectures are different, end the judgment and there is no vulnerability at this node page.
[0123] S54: Use tools such as burpsuite and Appscan to obtain the HTTP request response parameters of the normal response of the client and the request response parameters of the page forcibly accessed with the attack vector. The parameters mainly include content - length, User - Agent, Accept, and Referer information; if the parameter values obtained by both methods are the same, the page link accessed is defined as a suspected vulnerability response link, otherwise this link has no vulnerability.
[0124] If the results match, it indicates the existence of vulnerabilities and a report is made. As shown in Table 1 are the number of constructed attack vectors and the improvement ratio. The first row in Table 1 is the ten Web application programs tested in the present invention, the second row is the number of attack vectors constructed in this method, the third row is the number of attack vectors constructed by the traditional method, and the fourth row is the improvement ratio of the attack vectors constructed by this method in units of %, and the calculation method is: increase ratio=(payload - traditional payload) / traditional payload.
[0125] Table 1 Number of constructed attack vectors and improvement ratio
[0126]
[0127] As shown in Table 2, the number of detected vulnerabilities and the accuracy rate are presented. The first row in Table 2 lists the ten Web application programs tested in the present invention. The second row, TP, represents the number of vulnerabilities correctly detected. The third row, FP, represents the number of vulnerabilities wrongly detected. The fourth row is the detection accuracy rate, and the calculation method is: detection rate = TP / (TP + FP).
[0128] Table 2 Number of Detected Vulnerabilities and Accuracy Rate
[0129]
[0130] In summary, the prediction results of the access control vulnerability detection method for Web application security based on the RBAC model in this case prove to have good effects.
[0131] On the other hand, an access control vulnerability detection system for Web application programs based on the RBAC model is also provided. As Figure 7 shown, it includes a data acquisition unit 1, a data processing unit 2, an access control policy mining unit 3, an attack vector generation unit 4 for Web application programs, and an access control vulnerability detection unit 5. The data acquisition unit 1 is used to acquire the basic data in the Web application program database. The data processing unit 2 is used to process the basic data, construct a dynamic node connection graph and a static link jump graph, and merge them to form a site map model. The access control policy mining unit 3 is used to mine the access control policies Gr of different users in the site map model. The attack vector generation unit 4 for Web application programs is used to violate the access control policy and generate the attack vectors of the Web application programs. The access control vulnerability detection unit 5 is used to, based on the obtained correct access control policies and the set of attack vectors, use the above policies to access the program, and perform fuzzy matching based on the response parameters and response content on the obtained response results to detect whether there are access control vulnerabilities and establish vulnerability detection rules; if the results match, it indicates the existence of vulnerabilities and a report is made.
[0132] (1) In the implementation of the present invention, the program is modeled in a fine-grained manner through a dynamic and static hybrid method. The permission verification is combined with the identity information in the database entries to analyze the expected behaviors of different roles and users, so as to ensure that the correctly authenticated users access their corresponding resources. The response information is collected by simulating user operations to construct a multi-attribute site map model, and the access control policy of the program is deduced based on the browsing traces.
[0133] (2) The embodiments of the present invention construct three types of attack vectors based on the restricted condition attribute recombination method, simulate vulnerability attacks to achieve frequent and reproducible vulnerability detection, evaluate the response of the Web program through the designed fuzzy matching vulnerability discrimination rules based on response parameters and response content, determine two types of access control vulnerabilities, namely vertical privilege escalation and horizontal privilege escalation, and complete the access control vulnerability detection of the Web application. The good practical application effect of this method can be proved by the analysis and comparison of the detection results.
[0134] The embodiments described above are only descriptions of the preferred embodiments of the present invention, and do not limit the scope of the present invention. Without departing from the design spirit of the present invention, various deformations and improvements made by those of ordinary skill in the art to the technical solutions of the present invention shall fall within the protection scope determined by the claims of the present invention.
Claims
1. A method for detecting access control vulnerabilities in the security of Web applications based on the RBAC model, characterized in that, It includes the following steps: Step 1: Obtain the basic data in the Web application database; Obtain the basic data in the Web application database, where the basic data includes the start link node SN, the account password information PL logged in by the user, and the local file directory SC of the program source code; Step 2: Process the basic data, construct a dynamic node connection graph and a static link jump graph, and merge them to form a site map model, including the following sub-steps; Step 21: Based on the dynamic analysis method, when the specific composition of the application program is unknown, regard the application program as a black-box system, and through designing a prototype, simulate all expected operations of the user by itself, and construct a dynamic node connection graph of the black-box system; Form a page node set N0 from the user resource page links accessed by the user's expected operations, form an edge set E0 from the access and being accessed relationships between the page nodes formed by the user resource page links, and the session information, user, and role information passed between the page nodes constitute an edge weight set W, and construct a multi-role-based dynamic framework graph model G0 as follows: In the formula: G0 represents the dynamic node connection graph; E0 represents the edge set formed by the access and being accessed relationships between the page nodes formed by the user resource page links; W represents the edge weight set constituted by the session information, user, and role information passed between the page nodes; Let \(N_0\) represent the set of page nodes formed by the user resource page links, denoted as \(UP_0\), which contains \(n\) resource nodes \(a\), where nodes \(a_1\) to \(a\) k represents the same nodes obtained from dynamic analysis and static analysis. Node \(a\) k to \(a\) n represents the different nodes obtained from dynamic analysis and static analysis; \(\lt a\) i , \(a\) j \(\gt\) represents an edge formed by nodes \(a\) i and \(a\) j ; \(w\) l represents the weight value of the \(l\)-th edge; \(n\) represents the total number of resource nodes; \(k\) represents the segmentation point number of the same and different nodes of the resources; \(i\) and \(j\) respectively represent the first number and the second number of the resource nodes; Step 22: Based on the static analysis method, regard the application program as a white-box system, analyze the page jump situations involved in the source code, and construct a static link jump graph; Analyze the source code of the Web application, obtain the source code directory structure of the Web application and the directory hierarchy where the pages are located, and complete the links in the static code; During the static analysis, the pages are identified as single nodes, and these nodes are similar page nodes. Therefore, the state of the nodes and the complex relationships of the edges in UP0 are more than those in UP0′. Therefore, the static analysis pays more attention to the relationship between UP0′ and the FP node, and finally constructs a static page connection graph as follows: Where: G1 represents the static link jump graph; N1 represents the set of page nodes obtained by static analysis, including the resource page node UP1 and the function page node FP; E1 represents the set of edges formed by calls and being called between the set of resource page nodes UP and the set of function nodes FP; UP1 represents the set of resource pages obtained during static analysis; UP′0 represents the overlapping nodes between some UP nodes obtained by static analysis and those obtained by dynamic analysis; <a p ,b q > represents an edge formed by nodes a p and b q ; bm represents the m-th node b; n′ represents the total number of nodes a p ; m represents the total number of nodes b q . Step 23: Based on the KM maximum matching algorithm and the union-find set algorithm, merge the dynamic node connection graph G0 obtained in Step 21 and the static link jump graph G1 obtained in Step 22, and establish a user-based site map model; Step 3: Mine the access control policies Gr of different users in the site map model; Step 4: Violate the access control policy and generate an attack vector for the Web application; Based on the multi-attribute cross-recombination method, recombine the access logic between the accessing user and the accessed resource to achieve vulnerability intrusion; based on the membership relationship between the role and the resource pages that can be accessed, construct a vulnerability attack vector by forcing different types of role users to access the resource pages mutually; generate a refined attack vector based on the ordered correspondence relationship between the role and the resource, as shown in the following formula: Φatts = {<r s , u v > → {N, E, <r z , u w >}|u v , u w ∈U; r s , r z ∈R, v ≠ w}; Where: Φatts represents the set of attack vectors; r s represents the first role, and s takes values in [0, 1, 2]; u v represents the first user; <r s , u v > indicates that the access subject of the attack is the u s user with role r v ; N represents the set of nodes of the site map G; E represents the edge relationship set of the site map G; r z represents the second role, and z takes values in [0, 1, 2]; u w represents the second user, where v ≠ w indicates that u v , u w are different users; U represents the set of users; R represents the set of roles; {N, E, <r z , u w >} indicates that the accessed resource is all nodes N and edge relationships E of the u z user with role r w ; Step 5: Complete the access control vulnerability detection of the Web application; Based on the correct access control policy in Step 3 and the set of attack vectors in Step 4, access the program according to the policies of the above two steps, and perform fuzzy matching on the obtained response results based on response parameters and response content to detect whether there are access control vulnerabilities and establish vulnerability detection rules; if the results match, it indicates the existence of vulnerabilities and a report is made.
2. The access control vulnerability detection method for Web application security based on the RBAC model according to claim 1, characterized in that The start link node SN, the account password information PL of the user login, and the local file directory SC of the program source code in Step 1 are as follows: The start link node SN and the account password information PL of the user login are used as the start entry point for simulating user behavior in the dynamic analysis phase, so that the program can automatically simulate the user login operation; The local file directory SC of the program source code is used as the start entry point for constructing the connection between pages in the static analysis phase, so that the program can perform in-depth access based on the existing positions.
3. The access control vulnerability detection method for Web application security based on the RBAC model according to claim 1, characterized in that, The implementation of the dynamic analysis method in Step 21 can simulate all expected operations of the user by itself and adapt to the dynamic changes of the program, truly record the execution process of the program, and at the same time characterize the dynamic changes of pages based on roles and users in the program; performing dynamic access to the program in a role-based manner helps to directly identify and obtain the access paths and access permissions of different roles.
4. The access control vulnerability detection method for Web application security based on the RBAC model according to claim 1, wherein The static analysis method in Step 22, based on the system analysis of the program source code pages, can comprehensively characterize all resource page sets and the relationships between pages in the program; by analyzing the connection relationships between pages, it can effectively identify sensitive operations corresponding to resource pages and avoid the situation of missing program access control policies.
5. The access control vulnerability detection method for Web application security based on the RBAC model according to claim 1, wherein Merging the dynamic node connection graph G0 obtained in Step 21 and the static link jump graph G1 obtained in Step 22 in Step 23 can reflect the real execution behavior of the program, improve the page coverage rate of the program without increasing the consumption of system analysis, and comprehensively characterize the relationships between program resource pages; at the same time, based on the analysis of roles in the RBAC model, the access control constraints based on roles and users can be obtained, and the relationships between roles, users, and resource permissions can be directly determined during the model construction process.
6. The access control vulnerability detection method for Web application security based on the RBAC model according to claim 1, characterized in that In Step 23, site map model integration is required to establish a user-based site map model. Specifically: The site map model integration includes node merging and edge merging; the edge merging follows the node movement, and the problem is simplified to the UP integration and FP addition problems during the node merging process. Let a represent the set of UP nodes and b represent the set of FP nodes; Step 231: UP node integration, which completes the unification of the same-name nodes and the supplementation of the missing different-name nodes; First, complete the unification of the same-name nodes; for the same-name UP nodes existing in G0 and the static link jump graph G1 obtained in Step 22, when there are the same-name nodes, only keep their child nodes; by comparing the similarity of node links, determine the same-name nodes in G0 and G1, stipulate that the nodes obtained from dynamic analysis are the child nodes, and the nodes obtained from static analysis are the source nodes, keep the child nodes and their edge relationships; Delete the remaining same-name nodes; Then complete the supplementation of missing nodes with different names. To avoid randomly adding nodes and making them difficult to find, the edges of nodes are added by calculating the in-degree and out-degree of UP nodes in G0. That is, based on G0 as the basic model graph, calculate the core node with the most in-degree and out-degree in it. If there are nodes with the same in-degree and out-degree, select the node with the most out-degree as the core node, and connect the missing nodes in the graph to the core node to form a complete graph model. Step 232: Add FP nodes. The page nodes obtained from the program source code only exist in the G1 model. As a functional extension of the UP nodes, FP realizes edge connection following the UP nodes it contains. It is necessary to solve the connection problem between the UP nodes with the same name and FP. Since the child nodes of the nodes with the same name are selected as the final node set during the merging of UP, the child nodes and FP are connected separately. First, identify the FP nodes connected to the UP nodes with the same name, and change their edge relationship to the connection between the child nodes of the UP nodes with the same name and FP. Step 233: Integrate the site map model to generate the site map model G. The identification formula is as follows: In the formula: G represents the site map model; q0 represents the starting link node; F represents the set of end links; A represents the inter-procedural user annotations, N is the set of nodes, and E is the set of edges.
7. The access control vulnerability detection method for Web application security based on the RBAC model according to claim 1, characterized in that The mining of the access control policies Gr of different users in the site map model in step 3 is specifically as follows: Extract the characteristic attributes of the complex multi-attribute site map model G, abstract the key attributes to form an access control rule constraint model, which is represented by the triple <R, U, Gr>. The access control policy is as follows: Gr = {P path , P sub-graph}; Where: Gr represents the access control policy; P path represents the path rules for different roles; P sub-graph represents the subgraph rules; Inter-procedural abstraction of the site map model G. Based on the extracted access control rule constraint model <R, U, Gr>, perform correlation analysis between attributes by calculating the attribute correlation degree, and formulate conditional relevant and conditional irrelevant policy mappings between attributes to the correlation degree Pr.
8. The access control vulnerability detection method for Web application security based on the RBAC model according to claim 1, characterized in that, The attack vectors in step 4 include vertical privilege escalation attack vectors and horizontal privilege escalation attack vectors, specifically as follows: The intrusion strategy constructed by the vertical privilege escalation attack vector for the cross-recombination method of different roles is used to detect vertical privilege escalation vulnerabilities, as follows: Where: r0 represents the anonymous user role; r1 represents the ordinary user role; Φatts_v1 represents the set of attack vectors for the anonymous user role to access the resources of the ordinary user role and the administrator role, u v Under the r0 role, access r z The u of the role w The resources owned by the user, including the node set N and the edge set E; Φatts_v2 represents the set of attack vectors for an ordinary user role in the construction to access the resources of an administrator role, u v Under the r1 role, access u of the r2 role w Resources owned by the user, including the node set N and the edge set E; The intrusion strategy constructed by the horizontal privilege escalation attack vector for the cross-recombination method between different users with the same role is used to detect horizontal privilege escalation vulnerabilities, as follows: Φatts_h = {<r s , u v > → {N, E, <r s , u w >} | u v , u w ∈ U; s ∈ [1, 2]; v ≠ w; N = [a1,..., a n}; Where: Φatts_h constructs the same role r s Under, u v Use access u w Resources owned by the user, including the node set N and the edge set E.
9. The access control vulnerability detection method for Web application security based on the RBAC model according to claim 1, wherein The vulnerability detection rules in step 5 are as follows: Step 51: Match the link of the page normally rendered by the client with the link after the attack vector forcibly accesses the page. If they are different, end the judgment, and there is no vulnerability in this node. Step 52: If they are the same, remove the common static content, meta tags, scripts, and footer information in both web pages to obtain the architecture of the page, and match the architecture. If the page architectures are different, end the judgment, and there is no vulnerability in this node page. Step 53: If the page architectures are the same, further perform hash fuzzy matching on the rendered content of both pages. If the contents of the two pages are different, there is no vulnerability. If the contents are similar or the same, this page is defined as a vulnerable page. If the links are the same, compare the page architectures. The rendered page structures obtained by accessing the same link are the same. At this time, the tags of the page are extracted and organized as the page architecture. If the page architectures are different, the judgment ends, and there are no vulnerabilities in this node page. Step 54: Use tools such as burpsuite and Appscan to obtain the HTTP request-response parameters of the normal response of the client and the request-response parameters of the page accessed by forcing the attack vector. The parameters include content-length, User-Agent, Accept, and Referer information. If the parameter values obtained by both methods are the same, the page link accessed is defined as a suspected vulnerability response link; otherwise, there are no vulnerabilities in this link.
10. An access control vulnerability detection system for the security of a Web application based on the RBAC model according to the access control vulnerability detection method described in any one of claims 1-9, characterized in that, It includes a data acquisition unit, a data processing unit, an access control policy mining unit, an attack vector generation unit for Web applications, and an access control vulnerability detection unit. The data acquisition unit is used to acquire the basic data in the Web application database. The data processing unit is used to process the basic data, construct a dynamic node connection graph and a static link jump graph, and merge them to form a site map model. The access control policy mining unit is used to mine the access control policies Gr of different users in the site map model. The attack vector generation unit for Web applications is used to violate the access control policy and generate attack vectors for Web applications. The access control vulnerability detection unit is used to access the program based on the obtained correct access control policy and the set of attack vectors, and perform fuzzy matching on the response results based on the response parameters and response content to detect whether there are access control vulnerabilities and establish vulnerability detection rules. If the results match, it indicates the existence of vulnerabilities and a report is made.
Citation Information
Patent Citations
Network attack detection device and method based on network security malicious behavior knowledge base
CN113612763A
Access control vulnerability detection method and system based on state deviation analysis
CN114417346A