Unauthorized access vulnerability detection method and device

By deploying unauthorized access vulnerability detection devices within the operating system and generating detection lists using unified resource locators and file paths, the problem that traditional methods cannot fully detect unauthorized access vulnerabilities is solved, achieving higher detection accuracy and efficiency.

CN119939601APending Publication Date: 2025-05-06袁利荣
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510037505.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-09
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

Traditional unauthorized access vulnerability detection methods are not comprehensive enough to detect some vulnerabilities that cannot be obtained through dictionary blasting or code resources.

Method used

Deploy unauthorized access vulnerability detection device inside the operating system. By determining the unified resource locator of the target application, obtaining its root directory and file path, generating application file lists and access lists, sending request messages and analyzing response messages to detect unauthorized access vulnerabilities.

Benefits of technology

This method can more comprehensively detect the application file path of the application and improve the detection accuracy and efficiency of unauthorized access vulnerabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119939601A_ABST
    Figure CN119939601A_ABST
Patent Text Reader

Abstract

The invention discloses a method and a device for identifying unauthorized access of an application. The method comprises the following steps: determining a uniform resource locator of a target application; obtaining a root directory of the target application and all file paths in the root directory; generating an application file list based on all file paths of the target application; generating an application file access list by aggregating file paths of the applications behind the uniform resource locator of the target application; for each file path in the application file access list, sending a request message to the file path of the application based on the uniform resource locator, and obtaining a response message returned by the file path in response to the request message; and determining whether an unauthorized access vulnerability exists in the file path of the application according to the response message. The method does not need to maintain a set of unauthorized vulnerability identification rules for each application, and is more universal. Therefore, the detection accuracy and the detection efficiency of the unauthorized access vulnerability can be effectively improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer technology, and in particular to a method and device for detecting unauthorized access vulnerabilities. Background Art

[0002] In order to meet application security requirements, enterprises usually detect unauthorized access vulnerabilities in applications. Traditional technologies for identifying unauthorized access to applications generally use dictionary blasting and obtain application code resources for vulnerability detection. However, the unauthorized access vulnerabilities detected by such methods are not comprehensive enough, and some unauthorized access vulnerabilities cannot be detected. Summary of the invention

[0003] Multiple aspects of the present application provide a method and device for detecting an unauthorized access vulnerability, so as to improve the detection accuracy of the unauthorized access vulnerability.

[0004] An embodiment of the present application provides an unauthorized access vulnerability detection method, which is applied to an application unauthorized access vulnerability detection device inside an operating system where an application is deployed, and the method includes: determining a uniform resource locator of a target application; obtaining a root directory of the target application and all file paths in the root directory thereof; generating an application file list based on all file paths of the target application; generating an application file access list by aggregating the file paths of the application after the uniform resource locator of the target application; for each file path in the application file access list, sending a request message to the file path of the application based on the uniform resource locator, and obtaining a response message returned by the file path in response to the request message; and determining whether the file path of the application has an unauthorized access vulnerability based on the response message.

[0005] An embodiment of the present application provides a device for identifying unauthorized access to an application, and the device may include: a data acquisition module, used to acquire the root directory of a target application within an operating system where the target application is located, and used to acquire the file path and the uniform resource locator of the target application in the root directory of the target application within the operating system where the target application is located; an application file list generation module, used to split and deduplicate all the file paths of the acquired target application to obtain the application file list; an application file access list generation module, used to receive an operation by the user to aggregate the uniform resource locator with the file path in the application file list to obtain the application file access list; an interaction module, used to send a request message to the file path of the application based on the uniform resource locator for at least one file in the application file access list, and acquire a response message returned by the file path of the application in response to the request message; and a vulnerability detection module, used to determine whether there is an unauthorized access vulnerability in the file path of the application based on the response message.

[0006] In this embodiment, an unauthorized access vulnerability detection device is deployed inside the operating system where the application is located, and the unauthorized access vulnerability detection device is used to perform unauthorized access vulnerability detection on the file path of the application. Different from the method of dictionary blasting and obtaining the code resources of the application for vulnerability detection, the unauthorized access vulnerability detection device determines the uniform resource locator of the target application when performing unauthorized access vulnerability detection; obtains the root directory of the target application and all the file paths in its root directory; generates an application file list based on all the file paths of the target application; generates an application file access list by aggregating the file paths of the application behind the uniform resource locator of the target application; for each file path in the application file access list, sends a request message to the file path of the application based on the uniform resource locator, and obtains the response message returned by the file path response request message; determines whether the file path of the application has an unauthorized access vulnerability according to the response message. As a result, the unauthorized access vulnerability detection device can more comprehensively detect the application file path of the application, and detect whether the application file path of the application has an unauthorized access vulnerability, effectively improving the detection accuracy and efficiency of the unauthorized access vulnerability. BRIEF DESCRIPTION OF THE DRAWINGS

[0007] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:

[0008] Figure 1 A flowchart of an unauthorized access vulnerability detection method provided in an embodiment of the present application;

[0009] Figure 2 A structural schematic diagram of an unauthorized access vulnerability detection device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0010] In order to make the purpose, technical solution and advantages of the present application clearer, the technical solution of the present application will be clearly and completely described below in combination with the specific embodiments of the present application and the corresponding drawings. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present application.

[0011] In order to meet application security requirements, enterprises usually detect unauthorized access vulnerabilities in applications. Traditional technologies for identifying unauthorized access to applications generally use dictionary blasting and obtain application code resources for vulnerability detection. However, the unauthorized access vulnerabilities detected by such methods are not comprehensive enough. If the application file of the application is independent in the directory where the application is located, the application file of the application does not appear in the code resources, and the unauthorized vulnerability scanning tool does not have a scanning rule for a certain application file, it cannot be identified.

[0012] In this embodiment, an unauthorized access vulnerability detection device is deployed inside the operating system, and the unauthorized access vulnerability detection device is used to perform unauthorized access detection on the application files of the application in the operating system. Different from the method of using dictionary blasting and obtaining the code resources of the application for vulnerability detection, the unauthorized access vulnerability detection device determines the uniform resource locator of the target application when performing unauthorized access vulnerability detection; obtains the root directory of the target application and all the file paths in its root directory; generates an application file list based on all the file paths of the target application; generates an application file access list by aggregating the file paths of the application behind the uniform resource locator of the target application; for each file path in the application file access list, sends a request message to the file path of the application based on the uniform resource locator, and obtains the response message returned by the file path response request message; determines whether the file path of the application has an unauthorized access vulnerability according to the response message. As a result, the unauthorized access vulnerability detection device can more comprehensively detect the application file path of the application, and detect whether the application file path of the application has an unauthorized access vulnerability, effectively improving the detection accuracy and efficiency of the unauthorized access vulnerability.

[0013] The technical solutions provided by various embodiments of the present application are described in detail below in conjunction with the accompanying drawings.

[0014] Figure 1 A flowchart of an unauthorized access vulnerability detection method provided by an embodiment of the present application is provided, which is applied to an unauthorized access vulnerability detection device for applications deployed inside an operating system, and the unauthorized access vulnerability detection device may be composed of software and / or hardware.

[0015] See also Figure 1 , the method may include the following steps:

[0016] 101. Determine the uniform resource locator of the target application.

[0017] Specifically, after the unauthorized access vulnerability detection device is deployed inside the operating system where the application is located, the unauthorized access vulnerability detection device scans the uniform resource locator of the application in the application middleware configuration file, or scans the uniform resource locator of the application in the application log, or manually fills in and reports the uniform resource locator of the target application to obtain the uniform resource locator of the target application. The uniform resource locator (URL) is a representation method used to specify the location of information on the World Wide Web service program of the Internet. The basic uniform resource locator includes the protocol type (such as http, https, etc.), the server (usually a domain name, but also an IP address), and the port number.

[0018] 102. Obtain the root directory of the target application and all file paths in the root directory.

[0019] In the operating system where the target application is located, all file paths in the target application root directory are obtained by searching all files in the target application root directory in the operating system where the target application is located, where the file path refers to the location of the file in the operating system, including the directory where the file is located and the file name. The application root directory refers to the highest level directory that stores all files and subdirectories of the application. In this directory, the application executable file, configuration file, resource file, library file, etc. can be stored.

[0020] 103. Generate an application file list based on all file paths of the target application.

[0021] Deduplication is performed based on all file paths in the target application root directory, and the paths of these application files are written into a list to obtain an application file list, wherein the application file list includes the file paths in the application root directory after deduplication.

[0022] 104. Generate an application file access list by aggregating the file path of the application behind the uniform resource locator of the target application. After obtaining the application file list, split the file path to obtain the relative file path of the application. The relative file path of the application refers to the path from a specified reference point (usually the current application working directory or a specific directory) to the target file or directory; use the uniform resource locator and the application file relative path obtained according to the application file list to aggregate, write the uniform resource locators of these aggregated complete application files into the application file access list, and the uniform resource locator in the obtained application file access list includes the protocol type (such as http, https, etc.), server (usually a domain name, but can also be an IP address), port number, file directory, and file name.

[0023] 105. For each file path in the application file access list, send a request message to the file path of the application based on the uniform resource locator, and obtain a response message returned by the file path in response to the request message.

[0024] In this embodiment, for each file path in the application file access list, after sending a request message to the application file path based on the uniform resource locator, a response message to the request message is obtained, and a response message is returned to the unauthorized access vulnerability detection device.

[0025] 106. Determine whether the file path of the application has an unauthorized access vulnerability based on the response message.

[0026] Specifically, after receiving a request message sent to the file path of the application based on a uniform resource locator, the unauthorized access vulnerability detection device returns a response message, and determines whether the file path of the application has an unauthorized access vulnerability according to the response message. Exemplarily, when the unauthorized access vulnerability detection device determines whether the file path of the application has an unauthorized access vulnerability according to the response message, it can determine whether the status code in the response message is a specified status code; if the judgment result is yes, it is determined that the file path of the application has an unauthorized access vulnerability. If the judgment result is no, it is determined that the file path of the application does not have an unauthorized access vulnerability.

[0027] In this embodiment, the specified status code is a status code related to the successful sending of the request message. In practical applications, the specified status code can be flexibly defined, and the specified status code includes, but is not limited to: 200, 401, 403. Among them, the 200 status code indicates a successful status code, indicating that the request is normal; the 401 status code indicates that the current request requires user verification; the 403 status code indicates that the server successfully receives the request but refuses to execute it.

[0028] Further optionally, after determining that an unauthorized access vulnerability exists in the file path of the application, the unauthorized access vulnerability in the file path of the application can be classified into vulnerability levels according to the request address of the file path. Thus, the vulnerability level classification can provide guidance for subsequent targeted vulnerability repairs.

[0029] In actual applications, vulnerability levels can be flexibly classified according to the request address of the file path. For example, the vulnerability levels can be ranked from high to low, such as high-risk vulnerabilities, medium-risk vulnerabilities, and low-risk vulnerabilities.

[0030] For example, if the request address of the file path contains paths such as / admin, / *config.*, / *.conf, / *.log (where * represents a wildcard and can replace one or more real characters), a malicious attacker can easily crack the request address of the file path. In this case, the unauthorized access vulnerability of the file path is classified as a high-risk vulnerability; among them, the / admin path is a path related to the administrator file; / *config.* and / *.conf are paths related to the application configuration files; and the / *.log path is a path related to the application log.

[0031] If the request address of the file path does not contain: / admin, / *config.*, / *.conf, / *.log and other paths (* represents a wildcard, which can replace one or more real characters), and it is an ordinary and uncommon path, the unauthorized access vulnerability of the file path is classified as a medium-risk vulnerability; if the request address of the file path is a request to return pictures, js files, css files and other content, the unauthorized access vulnerability of the file path is classified as a low-risk vulnerability.

[0032] Figure 2 This is a schematic diagram of the structure of an unauthorized access vulnerability detection device provided in an embodiment of the present application. The device is deployed inside the operating system where the application is located. Figure 2 , the device may include:

[0033] The data acquisition module 21 is used to acquire the root directory of the target application in the operating system where the target application is located, and is used to acquire all file paths and the uniform resource locator of the target application in the root directory of the target application in the operating system where the target application is located;

[0034] An application file list generating module 22 is used to split and remove duplicates of all file paths of the acquired target application to obtain the application file list;

[0035] The application file access list generation module 23 is used to receive the user's operation of aggregating the uniform resource locator with the file path in the application file list to obtain the application file access list;

[0036] An interaction module 24, configured to send a request message to a file path of an application based on a uniform resource locator for at least one file in an application file access list, and obtain a response message returned by the file path of the application in response to the request message;

[0037] The vulnerability detection module 25 is used to determine whether there is an unauthorized access vulnerability in the file path of the application according to the response message.

[0038] Further optionally, when the data acquisition module 21 obtains the root directory of the target application inside the operating system where the target application is located, it is specifically used to: obtain the root directory of the application in the application middleware configuration file through scanning and detection by an unauthorized access vulnerability detection device, or manually fill in and report the root directory of the target application in the unauthorized access vulnerability detection device.

[0039] Further optionally, when the data acquisition module 21 obtains the file path in the target application root directory within the operating system where the target application is located, it is specifically used to: based on the obtained root directory of the target application, obtain all file paths in the target application root directory within the operating system by scanning and detecting through an authorized access vulnerability detection device.

[0040] Further optionally, when the data acquisition module 21 obtains the uniform resource locator of the target application, it is specifically used to: obtain the uniform resource locator of the application in the application middleware configuration file through scanning and detection by the unauthorized access vulnerability detection device, or obtain the uniform resource locator of the application in the application log through scanning and detection by the unauthorized access vulnerability detection device, or manually fill in and report the uniform resource locator of the target application in the unauthorized access vulnerability detection device.

[0041] Further optionally, when the application file list generation module 22 splits all the file paths of the acquired target application, it is specifically used to: split all the file paths of the target application based on the acquired root directory of the application to obtain the file relative path of the application, and the file relative path of the application refers to the path from a specified reference point (usually the current application working directory or a specific directory) to the target file or directory.

[0042] Further optionally, when the application file list generation module 22 performs deduplication on all the acquired file paths of the target application, it is specifically used to perform deduplication on all the file paths of the target application and write the deduplication results into the application file list.

[0043] Further optionally, when the application file access list generation module 23 aggregates the uniform resource locator with the file path in the application file list, it is specifically used to: use the uniform resource locator and the relative path of the application file obtained according to the application file list to aggregate, and write the uniform resource locators of these aggregated complete application files into the application file access list, and the uniform resource locator in the obtained application file access list includes the protocol type (such as http, https, etc.), server (usually a domain name, but can also be an IP address), port number, file directory, and file name.

[0044] Further optionally, when the interaction module 24 sends a request message to the file path of the application based on the uniform resource locator for at least one in the application file access list, it is specifically used to: obtain the file path request address of the application from the application file access list, and construct a request message for accessing the file path of the application based on the uniform resource locator; and send a request message to the file path of the application according to the file path of the application.

[0045] Further optionally, when the vulnerability detection module 25 determines whether there is an unauthorized access vulnerability in the file path of the application based on the response message, it is specifically used to: determine whether the status code in the response message is a specified status code, and the specified status code is a status code related to the successful sending of the request message; if the judgment result is yes, it is determined that there is an unauthorized access vulnerability in the file path of the application.

[0046] Figure 2 The device shown can perform Figure 1 The method of the illustrated embodiment.

[0047] It should be noted that the execution subject of each step of the method provided in the above embodiment may be the same device, or the method may be executed by different devices. For example, the execution subject of steps 101 to 106 may be device A; for another example, the execution subject of steps 101 and 102 may be device A, and the execution subject of steps 103 to 106 may be device B; and so on.

[0048] In addition, in some of the processes described in the above embodiments and the accompanying drawings, multiple operations appearing in a specific order are included, but it should be clearly understood that these operations may not be executed in the order in which they appear in the text or may be executed in parallel, and the serial numbers of the operations, such as 101, 102, etc., are only used to distinguish different operations, and the serial numbers themselves do not represent any execution order. In addition, these processes may include more or fewer operations, and these operations may be executed in sequence or in parallel.

[0049] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with the relevant laws, regulations and standards of the relevant countries and regions, and provide corresponding operation entrances for users to choose to authorize or refuse.

Claims

1. A method for identifying unauthorized access to an application, characterized in that: The method for detecting unauthorized access vulnerabilities of applications deployed in an operating system where an application is located includes: Determine the uniform resource locator of the target application; Get the root directory of the target application and all file paths in its root directory; Generate an application file list based on all file paths of the target application; Generate an application file access list by aggregating the file path of the application after the uniform resource locator of the target application; For each file path in the application file access list, a request message is sent to the application file path based on the uniform resource locator, and a response message is obtained in response to the file path request message. Determine whether the application's file path has unauthorized access vulnerabilities based on the response message.

2. The method according to claim 1, characterized in that The step of determining the uniform resource locator of the target application includes: The uniform resource locator of the target application is obtained by scanning and detecting the uniform resource locator of the application in the application middleware configuration file, or scanning and detecting the uniform resource locator of the application in the application log, or manually filling in and reporting the uniform resource locator of the target application.

3. The method according to claim 1, characterized in that The obtaining of the root directory of the target application and all file paths in the root directory thereof includes: obtaining the root directory of the application in the application middleware configuration file by scanning and detecting, or manually filling in and reporting the root directory of the target application; By retrieving all files in the target application root directory within the operating system where the target application is located, all file paths in the target application root directory are obtained, where the file path refers to the location of the file in the operating system, including the directory where the file is located and the file name.

4. The method according to claim 1, characterized in that The method of generating an application file list based on all file paths of the target application includes: deduplicating all file paths in the acquired target application root directory to obtain the application file list, wherein the application file list includes the deduplicated file paths in the application root directory.

5. The method according to claim 1, characterized in that The generating of the application file access list by aggregating the file paths in the application file list after the uniform resource locator of the target application comprises: Providing the file path in the application file list to the user; Receiving an operation by the user to split the file path in the application file list based on the application definition mode; According to the operation, the file path in the application file list is aggregated with the uniform resource locator of the target application to generate an application file access list that is accessible through the application, wherein the application file access list includes the application file path aggregated by the uniform resource locator after deduplication.

6. The method according to claim 1, characterized in that The method of sending a request message to the file path of the application based on the uniform resource locator for each file path in the application file access list, and obtaining a response message returned by the file path in response to the request message, includes: Obtaining a file path based on a uniform resource locator and an application from an application file access list, and constructing an access request message; A request message is sent from the construction access request message, and a response message returned by the response request message is obtained by obtaining the file path in the request message.

7. The method according to claim 1, characterized in that Determining whether the file path of the application has an unauthorized access vulnerability according to the response message includes: Determine whether the status code in the response message is a specified status code, where the specified status code is a status code related to the successful sending of the request message; if the judgment result is yes, determine that there is an unauthorized access vulnerability in the file path of the application.

8. The method according to claim 7, characterized in that After determining that the file path of the application has an unauthorized access vulnerability, the method further includes: classifying the unauthorized access vulnerability in the file path of the application according to a request address or a request method of the file path of the application.

9. A device for identifying unauthorized access to an application, characterized in that: include: A data acquisition module, used to acquire the root directory of the target application in the operating system where the target application is located, and to acquire the file path in the root directory of the target application in the operating system where the target application is located and the uniform resource locator of the target application; An application file list generation module, used for splitting and deduplicating all file paths of the acquired target application to obtain the application file list; An application file access list generation module, used for receiving an operation of the user aggregating a uniform resource locator with a file path in the application file list to obtain an application file access list; An interaction module, configured to send a request message to a file path of an application based on a uniform resource locator for at least one file in an application file access list, and obtain a response message returned by the file path of the application in response to the request message; The vulnerability detection module is used to determine whether there is an unauthorized access vulnerability in the file path of the application according to the response message.

10. The device according to claim 9, characterized in that The data acquisition module acquires the file path of the target application and the uniform resource locator of the target application in the operating system where the target application is located, specifically for: Obtain the root directory of the application in the application middleware configuration file through scanning detection, or manually fill in and report the root directory of the target application; Based on the obtained root directory of the target application, all file paths in the root directory of the target application inside the operating system are obtained through scanning and detection; the uniform resource locator of the application in the application middleware configuration file is obtained through scanning and detection, or the uniform resource locator of the application in the application log is obtained through scanning and detection, or the uniform resource locator of the target application is manually filled in and reported.

11. The device according to claim 9, characterized in that The application file list generation module is specifically used for: Split all file paths in the target application root directory within the obtained operating system to obtain relative paths of all files in the target application root directory; De-duplicate files are removed based on the relative paths of all files in the target application root directory to obtain the application file list.

12. The device according to claim 9, characterized in that The application file access list generation module is specifically used for: Used to provide the application file list to the user; The method is used to receive an operation of aggregating a uniform resource locator with a file path in an application file list by the user to obtain an application file access list.

13. The device according to claim 9, characterized in that The interaction module is specifically used for: Used to send a request message to the file path of the application based on the uniform resource locator for at least one in the application file access list, and obtain a response message returned by the file path of the application in response to the request message.

14. The device according to claim 9, characterized in that The vulnerability detection module is specifically used for: Determine whether the status code of the response message returned by the request message is a specified status code, where the specified status code is a status code related to the successful sending of the request message; if the judgment result is yes, determine that there is an unauthorized access vulnerability in the file path of the application.