A testing method, device, storage medium and electronic device

By receiving test requests, determining the network security protection layer and generating attack requests to simulate attacks, the abnormal problems in the existing technology that are difficult to detect and test network security protection measures in a timely manner are solved, and automated testing and vulnerability discovery of network security protection measures are achieved.

CN119172123BActive Publication Date: 2025-06-24GUANGZHOU YINGFENG NETWORK TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202411216642.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-08-30
Publication Date
2025-06-24
Estimated Expiration
2044-08-30

AI Technical Summary

Technical Problem

The prior art is difficult to detect and test abnormalities in network security protection measures in network service systems in a timely manner, resulting in possible data leakage and other network security threats.

Method used

By receiving test requests for the target system, determine the data to be protected and the corresponding network security protection layer, generate attack requests to simulate the attack, and obtain the response results of the target system to test the effectiveness of the network security protection layer.

Benefits of technology

Automatic testing of network security protection measures has been achieved, which can promptly detect and fix potential vulnerabilities and improve the effectiveness of network security protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119172123B_ABST
    Figure CN119172123B_ABST
Patent Text Reader

Abstract

This specification discloses a testing method, device, storage medium, and electronic device. The server can use the texts publicly recorded by users of each data source on each data source and indicating security issues existing in the network service system as reference texts. Thus, based on the reference texts, an attack request for attacking the vulnerabilities existing in the network security protection layer pointed out in the reference texts can be generated, and the data protected by the network security protection layer can be attacked through the generated attack request, so as to test the effectiveness of the network security protection layer.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This specification relates to the field of network security technology, and particularly to a testing method, device, storage medium, and electronic device. Background Art

[0002] With the rapid development of Internet technology, the network service systems used by various enterprises to provide network services for users have become important platforms for information exchange and resource sharing. However, network security issues have become increasingly prominent, and various forms of network security threats such as network attacks, data leaks, and malware have emerged in an endless stream, bringing great impacts to the network security of the network service systems of each business platform.

[0003] Generally, each enterprise can protect its network service system through measures such as firewalls, host intrusion detection systems, and data loss prevention measures. However, due to the increasing complexity and concealment of network attack methods, the reasons for the failure of the protection measures adopted by enterprises are diverse. As a result, when manually checking the effectiveness of the adopted protection measures, anomalies in the protection measures are often not discovered in a timely manner, which may cause losses to the business platform.

[0004] Therefore, how to test the effectiveness of the protection measures used to protect the network service system is an urgent problem to be solved. Summary of the Invention

[0005] This specification provides a testing method, device, storage medium, and electronic device to partially solve the above problems existing in the prior art.

[0006] This specification adopts the following technical solutions:

[0007] This specification provides a testing method, including:

[0008] Receiving a test request for a target system;

[0009] According to the test request, determining the data to be protected in the target system as target data, and determining the network security protection layer for protecting the target data;

[0010] According to the keywords of each reference text determined in advance, determining the reference text that matches the target data from the reference texts obtained in advance as the target reference text. For any one reference text, vulnerability information that causes the security problem recorded in the reference text is recorded in the reference text;

[0011] Determine the vulnerability type of the vulnerability existing in the network security protection layer when the target data is attacked according to the target reference text, determine a target attack strategy from each preset attack strategy according to the vulnerability type, and generate an attack request for attacking the target data according to the target attack strategy;

[0012] Send the attack request to the target system protected by the network security protection layer, and obtain the response result of the target system for the attack request, so as to perform a test according to the response result.

[0013] Optionally, according to the test request, determine the data to be protected in the target system as the target data, and determine the network security protection layer for protecting the target data, specifically including:

[0014] Determine the data to be protected in the target system from a preset database according to the test request as the target data; and

[0015] Obtain the log data of each network security protection layer, and determine the network security protection layer for protecting the target data according to the log data.

[0016] Optionally, obtaining each reference text specifically includes:

[0017] Determine at least one data source for generating reference texts;

[0018] Obtain each reference text from the at least one data source.

[0019] Optionally, sending the attack request to the target system protected by the network security protection layer, and obtaining the response result of the target system for the attack request, so as to perform a test according to the response result, specifically including:

[0020] Determine the predicted response result of the target system for the attack request according to the target reference text;

[0021] Send the attack request to the target system protected by the network security protection layer, and obtain the response result of the target system for the attack request;

[0022] Match the response result with the predicted response result to obtain a matching result, so as to test the network security protection layer according to the matching result.

[0023] Optionally, the method further includes:

[0024] If it is impossible to determine whether there is a vulnerability in the network security protection layer according to the matching result, a first candidate attack strategy is determined from each of the other attack strategies except the target attack strategy;

[0025] According to the first candidate attack strategy, an attack request for attacking the target data is regenerated, and the target system is tested based on the regenerated attack request.

[0026] Optionally, the method further includes:

[0027] If it is impossible to determine whether there is a vulnerability in the network security protection layer according to the matching result, an associated text associated with the target reference text is determined;

[0028] According to the associated text, a second candidate attack strategy is determined, and according to the second candidate attack strategy, an attack request for attacking the target data is regenerated, and the target system is tested based on the regenerated attack request.

[0029] Optionally, the method further includes:

[0030] If it is determined that there is a vulnerability in the network security protection layer according to the matching result, each piece of recorded data of the target system is obtained, and the pieces of recorded data include: log data of the target system, administrator operation records of the target system, alarm rule configuration data of the target system, and configuration data of the network security protection layer;

[0031] For each piece of recorded data, a detection strategy matching the recorded data is determined from each preset detection strategy as the detection strategy corresponding to the recorded data, and the recorded data is subjected to anomaly detection through the detection strategy corresponding to the recorded data to obtain a detection result of whether the recorded data is abnormal.

[0032] This specification provides a testing device, including:

[0033] A receiving module, configured to receive a test request for a target system;

[0034] A first determination module, configured to determine, according to the test request, data to be protected in the target system as target data, and determine a network security protection layer for protecting the target data;

[0035] A second determination module, configured to determine, according to keywords of each pre-determined reference text, a reference text matching the target data from each pre-obtained reference text as a target reference text, and for any one reference text, vulnerability information causing a security problem recorded in the reference text is recorded in the reference text;

[0036] A generation module, configured to determine, according to the target reference text, the vulnerability type of the vulnerability existing in the network security protection layer when the target data is attacked, determine a target attack strategy from each preset attack strategy according to the vulnerability type, and generate an attack request for attacking the target data according to the target attack strategy;

[0037] A testing module, configured to send the attack request to the target system protected by the network security protection layer, and obtain a response result of the target system for the attack request, so as to perform a test according to the response result.

[0038] The above at least one technical solution adopted in this specification can achieve the following beneficial effects:

[0039] In the testing method provided in this specification, a testing request for a target system is received. According to the testing request, the data that needs to be protected in the target system is determined as target data, and a network security protection layer for protecting the target data is determined. According to the keywords of each pre-determined reference text, a reference text that matches the target data is determined from each pre-obtained reference text as the target reference text. For any one reference text, the reference text records vulnerability information that causes the security problem recorded in the reference text. According to the target reference text, the vulnerability type of the vulnerability existing in the network security protection layer when the target data is attacked is determined. According to the vulnerability type, a target attack strategy is determined from each preset attack strategy, and an attack request for attacking the target data is generated according to the target attack strategy. The attack request is sent to the target system protected by the network security protection layer, and a response result of the target system for the attack request is obtained, so as to perform a test according to the response result.

[0040] As can be seen from the above method, the server can use the texts publicly recorded on each data source by users of each data source and indicating the security problems existing in the network service system as reference texts. Thus, an attack request for attacking the vulnerability existing in the network security protection layer pointed out in the reference text can be generated based on the reference text, and the data protected by the network security protection layer can be attacked through the generated attack request, so as to test the effectiveness of the network security protection layer. BRIEF DESCRIPTION OF THE DRAWINGS

[0041] The drawings described herein are used to provide a further understanding of this specification, and constitute a part of this specification. The illustrative embodiments and descriptions of this specification are used to explain this specification and do not constitute an improper limitation to this specification. In the drawings:

[0042] Figure 1 It is a schematic flowchart of a testing method provided in this specification;

[0043] Figure 2 It is a schematic diagram of the generation process of attack requests provided in this specification;

[0044] Figure 3 It is a schematic diagram of the anomaly detection process provided in this specification;

[0045] Figure 4 It is a schematic diagram of a test device provided in this specification;

[0046] Figure 5 It is provided in this specification corresponding to Figure 1 schematic diagram of an electronic device. Detailed implementation manners

[0047] To make the objectives, technical solutions, and advantages of this specification clearer, the technical solutions of this specification will be clearly and completely described below in conjunction with specific embodiments of this specification and the corresponding drawings. Obviously, the described embodiments are only a part of the embodiments of this specification, rather than all the embodiments. Based on the embodiments in this specification, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of this specification.

[0048] The technical solutions provided in each embodiment of this specification will be described in detail below with reference to the drawings.

[0049] Currently, in the field of network security, various enterprises invest a large amount of resources to implement various security protection measures to protect the network service systems that provide network services for users of each enterprise. For example, security protection measures such as implementing Web Application Firewall (WAF), Firewall (FW), Host-based Intrusion Detection System (HIDS), Data Loss Prevention (DLP), Intrusion Detection System (IDS), and honeypot are used to protect the network service systems.

[0050] However, since the above-mentioned protection measures may malfunction due to attacks during operation, enterprises usually collect the event logs generated by each protection measure and hand them over to security managers for manual investigation. However, when security managers investigate the event logs generated by each protection measure and do not see any alarms, it is difficult to determine whether there is no attack resulting in no alarms from each protection measure, or whether there is an attack but it has not been detected by each protection measure, resulting in no alarms. This makes it difficult to determine the effectiveness of each protection measure in a timely manner, which may in turn cause losses to enterprises. Therefore, it is particularly important to test the effectiveness of the protection measures adopted by the network service system of the business platform.

[0051] Figure 1 The following is a schematic flowchart of a testing method provided in this specification, including the following steps:

[0052] S101: Receive a test request for the target system.

[0053] S102: According to the test request, determine the data that needs to be protected in the target system as the target data, and determine the network security protection layer for protecting the target data.

[0054] In this specification, the business platform can receive a test request sent by a user for the target system, and then, in response to the received test request, test each network security protection layer deployed in the target system for protecting the target system.

[0055] Specifically, after receiving a test request sent by a user for the target system, the business platform can, according to the received test request, determine the data that needs to be protected in the target system as the target data from a preset database, obtain the log data of each network security protection layer, and determine the network security protection layer for protecting the target data according to the obtained log data of each network security protection layer.

[0056] Among them, the above-mentioned target system can be a network service system specified by the user. Here, the network service system refers to a system that provides specified business services or applications to users in a network environment, and provides functions such as data exchange, resource sharing, communication, and management for the devices deployed with the client provided by the business platform used by the users. The above-mentioned network service system can be composed of a series of software components (such as operating systems like Linux and Windows, server software like Web server software and mail server software, and middleware like message queues and cache systems) and hardware components (such as servers, routers, switches, and terminal devices) running in a network environment.

[0057] There can be multiple network security protection layers as described above. For each network security protection layer, the protection measures adopted by this network security protection layer are different from those adopted by other network security protection layers. Here, the protection measures can be products used to protect the network service system from various security threats, such as: Web application firewall, firewall, host-based intrusion detection system, data loss prevention, intrusion detection system, and honeypot, etc.

[0058] The above-mentioned preset database can be used to store and manage all configuration data of the network service system, such as: Configuration Management Database (CMDB).

[0059] The above-mentioned configuration data can refer to the detailed information of physical resources and virtual resources required by an enterprise during the process of providing business services, such as: the IP address of the business service provided by the enterprise, domain name, service port of the network service, status of the network service, security of the network service, model of the server, identification data of the server manufacturer, hardware configuration data of the server, location data of the server, configuration data of the disk array of the storage device, configuration data of the router of the network device, configuration data of the switch of the network device, configuration data of the firewall of the network device, wireless access point information of the network device, etc.

[0060] The data that needs to be protected in the above-mentioned target system can refer to at least one type of data in the above-mentioned configuration data.

[0061] It should be noted that the log data of the above-mentioned network security protection layer and the configuration data of the target system only record the data of a single party. Therefore, it is necessary to combine the log data of the network security protection layer to determine the network security protection layer for protecting the target data. For the sake of easy understanding, the following takes the above-mentioned network security protection layer as a firewall as an example to elaborate in detail the reason why it is necessary to combine the log data of the network security protection layer to determine the network security protection layer for protecting the target data.

[0062] Specifically, the configuration data of the target system is usually static (that is, it will not change again within a period of time after being configured by the user). It reflects how the target system is configured at a certain moment, but it cannot reflect the dynamic changes during the operation of the target system, such as: the opening and closing of temporary services, or the allocation of dynamic IP addresses, etc.

[0063] Therefore, when determining the network security protection layer for protecting the target data, it is necessary to determine it according to the log data of the network security protection layer.

[0064] Of course, the business platform can also directly receive a test request from a user for a certain protection measure, thereby obtaining the log data generated by the protection measure. Furthermore, based on the obtained log data of the protection measure and the various configuration parameters of the target system, the data protected by the protection measure in the target system can be determined as the target data, and an attack can be launched against the target data to test the protection measure.

[0065] In this specification, the execution entity for implementing the test method can refer to a specified device such as a server set up in the business platform, or can also refer to terminal devices such as desktop computers and laptop computers. For the sake of convenience in description, hereinafter, only the case where the server is the execution entity will be taken as an example to illustrate the test method provided in this specification.

[0066] S103: According to the keywords of each reference text determined in advance, determine the reference text that matches the target data from the reference texts obtained in advance as the target reference text. For any one reference text, vulnerability information that triggers the security issue recorded in the reference text is recorded in the reference text.

[0067] In this specification, the server can determine at least one data source, obtain each reference text from the determined at least one data source, and then, according to the keywords of each reference text determined in advance, determine the reference text that matches the target data from the obtained reference texts as the target reference text.

[0068] Among them, the above data source is used to generate reference texts, and the above data source can be, for example, websites such as security forums and Github.

[0069] The method for the server to determine the above data source can be to determine each data source according to a preset data source configuration file, and the data source configuration file here can contain the website addresses of each data source.

[0070] The method for the server to obtain each reference text from the above data source can be to use a preset network scraping tool to obtain, from each data source, the texts uploaded by other users to each data source and made public in each data source as each reference text.

[0071] There are various methods for the server to determine the reference text that matches the target data from the reference texts obtained in advance according to the keywords of each reference text determined in advance as the target reference text.

[0072] For example: The server can determine, from the keywords of each reference text determined in advance, the reference text whose contained keywords are the same as the target data as the reference text that matches the target data.

[0073] For another example: The server can also input the target data and the keywords of each pre-determined reference text into a pre-set matching model, so as to determine, through the pre-set matching model, for the keywords of each reference text, the degree of association between the target data and the keywords of that reference text, as the degree of association corresponding to that reference text. Furthermore, it is possible to determine, from each reference text, the reference text whose corresponding degree of association exceeds the pre-set degree-of-association threshold as the reference text that matches the target data.

[0074] In the above content, the method for the server to determine the keywords of each reference text can be to input each reference text into a pre-set large language model for semantic parsing of the reference text through the pre-set large language model, so as to determine at least one keyword contained in the reference text.

[0075] The above keywords can be used to characterize the data that needs to be protected involved in the security issues contained in the reference text (such as: data name, components to which the data belongs, etc.), vulnerability types (such as: buffer overflow, code injection, cross-site scripting, authentication issues, weak passwords, open ports, web attacks, etc.), protection measures, etc.

[0076] It should be noted that for any reference text, at least one security issue for the network service system is recorded in the reference text, and the vulnerability information that causes the above security issue is also recorded.

[0077] For example: In the reference text, it is recorded that there is a security issue in the database of the network service system where unauthorized operations are executed due to deception. The vulnerability is that an attacker inserts a special character sequence such as "OR 1=1" in the input field used to generate the query statement, thus circumventing the rights and permissions review mechanism of the network service system (for example: when the network service system concatenates the user input string into the SQL query statement, the normal SQL query statement should be SELECT * FROM users WHERE username='admin', where admin is the administrator account, and the network service system will conduct a rights and permissions review on admin. However, by inserting the above special character sequence, the network service system gets the SQL query statement to be executed as SELECT * FROM users WHERE username='admin' OR 'a'='a', that is, through the OR field, the statement WHERE username='admin' originally used to review the rights and permissions of the visitor in the SQL query statement to be executed is bypassed, so that the database wrongly executes the SQL query statement of the attacker who does not have access rights and displays the saved data to the attacker), which may lead to the situation that the data contained in the database is obtained by an attacker who does not have access rights, and further leads to data leakage.

[0078] S104: Determine the vulnerability type of the vulnerability existing in the network security protection layer when the target data is attacked according to the target reference text. According to the vulnerability type, determine a target attack strategy from each preset attack strategy, and generate an attack request for attacking the target data according to the target attack strategy.

[0079] As can be seen from the above content, the server can obtain reference texts of possible security problems and vulnerability information causing the above security problems in the publicly available network service systems of other users from multiple data sources. Thus, according to the target reference text in each reference text, it can determine the vulnerability type of the vulnerability existing in the network security protection layer when the target data is attacked. Furthermore, it can determine a target attack strategy from each preset attack strategy, and generate an attack request for attacking the target data according to the target attack strategy, as specifically Figure 2 shown.

[0080] Figure 2 It is a schematic diagram of the generation process of the attack request provided in this specification.

[0081] Combined with Figure 2 it can be seen that after the server determines the vulnerability type of the vulnerability existing in the network security protection layer when the target data is attacked according to the target reference text, it can determine, from each preset attack strategy, an attack strategy for attacking the above vulnerability type as the target attack strategy according to the vulnerability type of the vulnerability existing in the network security protection layer when the target data is attacked.

[0082] The above attack strategy can be a method for attacking different vulnerabilities determined in advance according to each historical reference text and saved in the database. For example: construct an SQL query statement containing a specific character sequence through a preset SQL statement template and input it into the target system to try to bypass the input verification mechanism of the network security protection layer that protects the target system, and directly query, modify, etc. the data in the database of the target system to attack the target data. Here, the running request for the SQL query statement containing a specific character sequence is the above attack request.

[0083] Another example: generate an attack script according to a preset script template and run the attack script on the website provided for users by the target system to perform a phishing attack on the target data. Here, the running request for the attack script is the above attack request.

[0084] S105: Send the attack request to the target system protected by the network security protection layer, and obtain the response result of the target system for the attack request to perform a test according to the response result.

[0085] In this specification, the server may send the generated attack request to the target system protected by the network security protection layer, and obtain the response result of the target system for the attack request, so as to determine the effectiveness of the network security protection layer according to the response result.

[0086] Specifically, the server may determine the predicted response result of the target system for the attack request according to the target reference text. For example, according to the target reference text, the predicted response result for the operation request of the target system for the SQL query statement containing a specific character sequence is the data query result or data modification result returned after performing operations such as querying and modifying the data in the database of the target system by executing the operation request of the SQL query statement containing the specific character sequence.

[0087] Furthermore, the server may send the attack request to the target system protected by the network security protection layer, obtain the response result of the target system for the attack request, match the response result with the predicted response result to obtain a matching result, and test the network security protection layer according to the matching result.

[0088] Specifically, if the server determines that the response result is consistent with the predicted response result, the server may determine that the response result matches the predicted response result, and further determine whether there is a vulnerability in the network security protection layer for protecting the data that needs to be protected in the target system.

[0089] Of course, the server may also input the response result and the predicted response result into a preset test model to determine the similarity between the response result and the predicted response result through the preset test model, and determine the confidence level of whether the network security protection layer for protecting the data that needs to be protected in the target system is effective according to the similarity between the response result and the predicted response result. When the confidence level of whether the network security protection layer for protecting the data that needs to be protected in the target system is effective is lower than the preset threshold, it may be determined that there is a vulnerability in the network security protection layer for protecting the data that needs to be protected in the target system. Among them, the higher the similarity between the response result and the predicted response result, the lower the confidence level of whether the network security protection layer for protecting the data that needs to be protected in the target system is effective.

[0090] Furthermore, if the server cannot determine whether there is a vulnerability in the network security protection layer according to the matching result, a first candidate attack strategy is determined from each other attack strategy except the target attack strategy. Then, an attack request for attacking the target data may be regenerated according to the first candidate attack strategy, and the target system may be tested based on the regenerated attack request.

[0091] Among them, there are two situations where the server cannot determine whether there is a vulnerability in the network security protection layer based on the matching result. The first is when the server determines that the response result is inconsistent with the predicted response result, and the server determines according to the log data of the network security protection layer that the network security protection layer has not intercepted, then the server cannot determine whether there is a vulnerability in the network security protection layer based on the matching result. The second is when the confidence level of whether the network security protection layer that protects the data to be protected in the target system is effective is lower than the preset threshold, and the server determines according to the log data of the network security protection layer that the network security protection layer has not intercepted, then the server cannot determine whether there is a vulnerability in the network security protection layer based on the matching result.

[0092] In addition, if the server cannot determine whether there is a vulnerability in the network security protection layer based on the matching result, it can also determine the associated text associated with the target reference text, and then determine the second candidate attack strategy according to the associated text, and regenerate the attack request for attacking the target data according to the second candidate attack strategy, and test the target system based on the regenerated attack request.

[0093] In actual application scenarios, the reasons for the failure of the network security protection layer may be not only that there are vulnerabilities in the network security protection layer itself, but also that the network security protection layer fails due to reasons such as administrator's misoperation or incorrect alarm rule configuration.

[0094] Based on this, if the server determines that there is a vulnerability in the network security protection layer according to the matching result, the server can obtain each record data of the target system and perform anomaly detection on each record data to determine whether there is an anomaly in each record data, specifically as Figure 3 shown.

[0095] Figure 3 This is a schematic diagram of the anomaly detection process provided in this specification.

[0096] Combined with Figure 3 It can be seen that if the server determines that there is a vulnerability in the network security protection layer according to the matching result, the server can obtain each record data of the target system, and for each record data, determine the detection strategy that matches the record data from each preset detection strategy as the detection strategy corresponding to the record data, and perform anomaly detection on the record data through the detection strategy corresponding to the record data to obtain the detection result of whether there is an anomaly in the record data.

[0097] Among them, the above-mentioned each record data includes: the log data of the target system, the administrator operation record of the target system, the alarm rule configuration data of the target system, the configuration data of the network security protection layer, etc.

[0098] The above detection strategy can be set according to actual requirements. For example, for the log data of the target system, it can be determined whether the state of the target system is an abnormal state based on the log data of the target system (such as: whether the target system has states such as shutdown, error, warning, etc.). If so, it is determined that there is an abnormality in the log data of the target system.

[0099] For another example: for the administrator operation records of the target system, it can determine the operation time of each operation executed by the administrator based on the administrator's operation records, and determine that there is an abnormality in the administrator operation records based on the difference between the operation time of each operation executed by the administrator and the sending time of the attack request to the target system protected by the network security protection layer (such as: if the administrator executed operations such as permission change operations, system update and maintenance operations, configuration file editing operations, etc. shortly before the sending time of the attack request to the target system protected by the network security protection layer, it may be that the operations executed by the administrator caused the network security protection layer to fail, so it can be considered that the operations executed by the administrator are abnormal).

[0100] In addition, the server can also input each record data of the target system into a preset detection model for each record data of the target system, so as to obtain the detection result of whether there is an abnormality in the record data through the preset detection model.

[0101] It can be seen from the above content that the server can use the text publicly recorded on each data source by users of each data source about the security problems existing in the network service system as a reference text. Thus, based on the reference text, an attack request can be generated to attack the vulnerabilities existing in the network security protection layer pointed out in the reference text, and the data protected by the network security protection layer can be attacked through the generated attack request, and then the effectiveness of the network security protection layer can be tested.

[0102] The above is one or more implementation test methods of this specification. Based on the same idea, this specification also provides a corresponding test device, such as Figure 4 shown.

[0103] Figure 4 It is a schematic diagram of a test device provided by this specification, including:

[0104] A receiving module 401, configured to receive a test request for the target system;

[0105] A first determination module 402, configured to determine, according to the test request, the data that needs to be protected in the target system as target data, and determine the network security protection layer for protecting the target data;

[0106] A second determination module 403, configured to determine, according to keywords of each pre-determined reference text, a reference text that matches the target data from the pre-obtained reference texts as a target reference text. For any one of the reference texts, vulnerability information that causes the security problem recorded in the reference text is recorded in the reference text;

[0107] A generation module 404, configured to determine, according to the target reference text, a vulnerability type of a vulnerability existing in the network security protection layer when the target data is attacked, determine a target attack strategy from each pre-set attack strategy according to the vulnerability type, and generate an attack request for attacking the target data according to the target attack strategy;

[0108] A test module 405, configured to send the attack request to the target system protected by the network security protection layer, and obtain a response result of the target system for the attack request, so as to perform a test according to the response result.

[0109] Optionally, the first determination module 402 is specifically configured to determine, according to the test request, data to be protected in the target system from a pre-set database as target data; and obtain log data of each network security protection layer, and determine a network security protection layer for protecting the target data according to the log data.

[0110] Optionally, the second determination module 403 is specifically configured to determine at least one data source for generating reference texts; and obtain each reference text from the at least one data source.

[0111] Optionally, the test module 405 is specifically configured to determine a predicted response result of the target system for the attack request according to the target reference text; send the attack request to the target system protected by the network security protection layer, and obtain a response result of the target system for the attack request; match the response result with the predicted response result to obtain a matching result, so as to test the network security protection layer according to the matching result.

[0112] Optionally, the test module 405 is specifically configured to, if it cannot be determined whether there is a vulnerability in the network security protection layer according to the matching result, determine a first candidate attack strategy from each other attack strategy except the target attack strategy; re-generate an attack request for attacking the target data according to the first candidate attack strategy, and perform a test on the target system based on the re-generated attack request.

[0113] Optionally, the test module 405 is specifically configured to, if it cannot be determined whether there is a vulnerability in the network security protection layer according to the matching result, determine an associated text associated with the target reference text; determine a second candidate attack strategy according to the associated text, and according to the second candidate attack strategy, regenerate an attack request for attacking the target data, and test the target system based on the regenerated attack request.

[0114] Optionally, the test module 405 is specifically configured to, if it is determined according to the matching result that there is a vulnerability in the network security protection layer, obtain each record data of the target system, and the each record data includes: log data of the target system, administrator operation records of the target system, alarm rule configuration data of the target system, and configuration data of the network security protection layer; for each type of record data, determine a detection strategy that matches the record data from each preset detection strategy as the detection strategy corresponding to the record data, and perform anomaly detection on the record data through the detection strategy corresponding to the record data to obtain a detection result of whether the record data has an anomaly.

[0115] This specification also provides a computer-readable storage medium, which stores a computer program, and the computer program can be used to execute the above Figure 1 provided test method.

[0116] This specification also provides Figure 5 a schematic structural diagram of an electronic device corresponding to Figure 1 as shown. As Figure 5 described above, at the hardware level, the electronic device includes a processor, an internal bus, a network interface, a memory, and a non-volatile memory. Of course, other hardware required for other services may also be included. The processor reads the corresponding computer program from the non-volatile memory into the memory and then runs it to implement the above Figure 1 described test method. Of course, in addition to the software implementation manner, this specification does not exclude other implementation manners, such as a logic device or a combination of software and hardware, etc. That is to say, the execution subject of the following processing flow is not limited to each logic unit, and may also be hardware or a logic device.

[0117] For an improvement in a technology, it can be clearly distinguished whether it is a hardware improvement (e.g., improvement in circuit structures such as diodes, transistors, switches, etc.) or a software improvement (improvement in method processes). However, with the development of technology, many improvements in method processes today can be regarded as direct improvements in hardware circuit structures. Almost all designers obtain the corresponding hardware circuit structure by programming the improved method process into the hardware circuit. Therefore, it cannot be said that an improvement in a method process cannot be implemented with a hardware entity module. For example, a Programmable Logic Device (PLD) (such as a Field Programmable Gate Array (FPGA)) is such an integrated circuit whose logical function is determined by the user programming the device. The designer can program by himself to "integrate" a digital system on a piece of PLD, without having to ask a chip manufacturer to design and fabricate a dedicated integrated circuit chip. Moreover, nowadays, instead of manually fabricating integrated circuit chips, this programming is mostly implemented using "logic compiler" software, which is similar to the software compiler used in program development and writing. The original code before compilation also has to be written in a specific programming language, which is called Hardware Description Language (HDL), and there is not only one type of HDL, but many types, such as ABEL (Advanced Boolean Expression Language), AHDL (Altera Hardware Description Language), Confluence, CUPL (Cornell University Programming Language), HDCal, JHDL (Java Hardware Description Language), Lava, Lola, MyHDL, PALASM, RHDL (Ruby Hardware Description Language), etc. Currently, the most commonly used are VHDL (Very-High-Speed Integrated Circuit Hardware Description Language) and Verilog. Those skilled in the art should also be aware that by simply performing a little logical programming on the method process with the above-mentioned several hardware description languages and programming it into the integrated circuit, it is easy to obtain the hardware circuit that implements the logical method process.

[0118] The controller can be implemented in any suitable manner. For example, the controller can take the form of, for example, a microprocessor or a processor and a computer-readable medium storing computer-readable program code (such as software or firmware) executable by the (micro)processor, logic gates, switches, an application specific integrated circuit (ASIC), a programmable logic controller, and an embedded microcontroller. Examples of the controller include, but are not limited to, the following microcontrollers: ARC 625D, Atmel AT91SAM, Microchip PIC18F26K20, and Silicone Labs C8051F320. The memory controller can also be implemented as part of the control logic of the memory. Those skilled in the art also know that in addition to implementing the controller in the form of pure computer-readable program code, it is entirely possible to make the controller implement the same function in the form of logic gates, switches, application specific integrated circuits, programmable logic controllers, and embedded microcontrollers by logically programming the method steps. Therefore, such a controller can be considered a hardware component, and the devices included therein for implementing various functions can also be regarded as the structures within the hardware component. Or even, the devices for implementing various functions can be regarded as either software modules for implementing the method or the structures within the hardware component.

[0119] The systems, devices, modules, or units illustrated in the above embodiments can be specifically implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer. Specifically, the computer can be, for example, a personal computer, a laptop computer, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or a combination of any of these devices.

[0120] For the convenience of description, when describing the above devices, they are described separately as various units according to their functions. Of course, when implementing this specification, the functions of each unit can be implemented in the same or multiple software and / or hardware.

[0121] Those skilled in the art should understand that the embodiments of this specification can be provided as a method, a system, or a computer program product. Therefore, this specification can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Moreover, this specification can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memories, CD-ROMs, optical memories, etc.) containing computer-usable program code.

[0122] This specification is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to embodiments of the specification. It should be understood that each flow and / or block in the flowchart and / or block diagram, and the combination of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing device produce a means for implementing the functions specified in one or more of the flows Figure 1 one or more of the flows and / or blocks Figure 1 a means for implementing the functions specified in one or more of the blocks or multiple blocks.

[0123] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory produce a manufactured article including an instruction means that implements the functions specified in one or more of the flows Figure 1 one or more of the flows and / or blocks Figure 1 a means for implementing the functions specified in one or more of the blocks or multiple blocks.

[0124] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, so that the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one or more of the flows Figure 1 one or more of the flows and / or blocks Figure 1 a means for implementing the functions specified in one or more of the blocks or multiple blocks.

[0125] In a typical configuration, a computing device includes one or more processors (CPUs), an input / output interface, a network interface, and a memory.

[0126] The memory may include non-permanent memory in the form of computer-readable media, random access memory (RAM), and / or non-volatile memory, such as read-only memory (ROM) or flash memory (flash RAM). The memory is an example of computer-readable media.

[0127] Computer readable media include permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. Information can be computer readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic tape magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer readable media does not include temporary computer readable media (transitory media), such as modulated data signals and carrier waves.

[0128] It should also be noted that the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, commodity or device. In the absence of more restrictions, the elements defined by the sentence "comprises a ..." do not exclude the existence of other identical elements in the process, method, commodity or device including the elements.

[0129] Those skilled in the art will appreciate that the embodiments of this specification may be provided as methods, systems or computer program products. Therefore, this specification may take the form of a complete hardware embodiment, a complete software embodiment or an embodiment combining software and hardware. Moreover, this specification may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0130] This specification may be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. This specification may also be practiced in distributed computing environments where tasks are performed by remote processing devices connected through a communication network. In a distributed computing environment, program modules may be located in local and remote computer storage media, including storage devices.

[0131] Each embodiment in this specification is described in a progressive manner. For the same or similar parts among the embodiments, reference can be made to each other. Each embodiment focuses on the differences from other embodiments. In particular, for the system embodiment, since it is basically similar to the method embodiment, the description is relatively simple. For the relevant parts, reference can be made to the corresponding descriptions in the method embodiment.

[0132] The above are only the embodiments of this specification and are not intended to limit this specification. For those skilled in the art, various modifications and changes can be made to this specification. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of this specification shall be included within the scope of the claims of this specification.

Claims

1. A testing method, characterized in that: include: receiving a test request for a target system; According to the test request, determining data that needs to be protected in the target system as target data, and determining a network security protection layer for protecting the target data; According to the predetermined keywords of each reference text, a reference text matching the target data is determined from the pre-acquired reference texts as the target reference text, and for any reference text, the reference text records at least one security issue for the network service system and records vulnerability information causing the security issue; The reference text is obtained from different data sources, including: security forums, Github; Determine, according to the target reference text, the vulnerability type of the vulnerability existing in the network security protection layer when the target data is attacked, determine, according to the vulnerability type, a target attack strategy from various preset attack strategies, and generate an attack request for attacking the target data according to the target attack strategy; The attack request is sent to the target system protected by the network security protection layer, and a response result of the target system to the attack request is obtained, so as to perform a test according to the response result.

2. The method according to claim 1, characterized in that According to the test request, determining data to be protected in the target system as target data, and determining a network security protection layer for protecting the target data, specifically including: According to the test request, determining data to be protected in the target system from a preset database as target data; and The log data of each network security protection layer is obtained, and based on the log data, a network security protection layer for protecting the target data is determined.

3. The method according to claim 1, characterized in that Get reference texts, including: determining at least one data source for generating a reference text; Each reference text is obtained from the at least one data source.

4. The method according to claim 1, characterized in that Sending the attack request to the target system protected by the network security protection layer, and obtaining a response result of the target system to the attack request, so as to perform a test according to the response result, specifically includes: Determining, according to the target reference text, a predicted response result of the target system to the attack request; Sending the attack request to the target system protected by the network security protection layer, and obtaining a response result of the target system to the attack request; The response result is matched with the predicted response result to obtain a matching result, so as to test the network security protection layer according to the matching result.

5. The method according to claim 4, characterized in that The method further comprises: If it cannot be determined whether the network security protection layer has a vulnerability according to the matching result, then determining a first candidate attack strategy from other attack strategies except the target attack strategy; According to the first candidate attack strategy, an attack request for attacking the target data is regenerated, and the target system is tested based on the regenerated attack request.

6. The method according to claim 4, characterized in that The method further comprises: If it cannot be determined whether the network security protection layer has a vulnerability according to the matching result, determining an associated text associated with the target reference text; A second candidate attack strategy is determined according to the associated text, and an attack request for attacking the target data is regenerated according to the second candidate attack strategy, and the target system is tested based on the regenerated attack request.

7. The method according to claim 4, characterized in that The method further comprises: If it is determined that the network security protection layer has a vulnerability according to the matching result, then obtaining various record data of the target system, wherein the various record data include: log data of the target system, administrator operation records of the target system, alarm rule configuration data of the target system, and configuration data of the network security protection layer; For each type of recorded data, a detection strategy matching the recorded data is determined from the preset detection strategies as the detection strategy corresponding to the recorded data, and anomaly detection is performed on the recorded data using the detection strategy corresponding to the recorded data to obtain a detection result of whether the recorded data has an anomaly.

8. A testing device, characterized in that: include: A receiving module, used for receiving a test request for a target system; A first determination module is used to determine, according to the test request, data that needs to be protected in the target system as target data, and to determine a network security protection layer for protecting the target data; A second determination module is used to determine, according to the predetermined keywords of each reference text, a reference text matching the target data from the pre-acquired reference texts as the target reference text, and for any reference text, the reference text records at least one security issue for the network service system and records vulnerability information causing the security issue; The reference text is obtained from different data sources, including: security forums, Github; A generating module, used to determine, based on the target reference text, the vulnerability type of the vulnerability existing in the network security protection layer when the target data is attacked, determine a target attack strategy from preset attack strategies based on the vulnerability type, and generate an attack request for attacking the target data based on the target attack strategy; The test module is used to send the attack request to the target system protected by the network security protection layer, and obtain the response result of the target system to the attack request, so as to perform a test according to the response result.

9. A computer-readable storage medium, characterized in that: The storage medium stores a computer program, and when the computer program is executed by a processor, the method according to any one of claims 1 to 7 is implemented.

10. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the program, the method according to any one of claims 1 to 7 is implemented.

Citation Information

Patent Citations

  • Method, device and equipment for testing protection system and computer readable storage medium

    CN116074060A