Security test method and related equipment
By sending injection requests to a predetermined server and analyzing the return results, the problem of the inability to determine the success and execution of memory horse injection in the prior art is solved, and the feasibility of security testing and accurate evaluation of RASP interception capabilities is achieved.
Patent Information
- Application Number
- CN202311511638.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-13
- Publication Date
- 2025-05-13
AI Technical Summary
The prior art cannot determine whether the memory horse is injected successfully and whether the memory horse can execute instructions correctly, making it difficult to carry out security testing.
By sending an injection request to the predetermined server, the memory horse is injected into the predetermined program, and the return result is obtained by accessing the server multiple times, and the return result is analyzed to determine whether the memory horse is injected successfully and whether it is executed successfully.
Accurate detection of memory horse injection and execution is achieved, the problem of difficult security testing is solved, and the RASP interception capability is accurately evaluated through remote methods.
Smart Images

Figure CN119995911A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of computer and communication technology, and in particular to a security testing method and related equipment. Background Art
[0002] With the development of network technology, the corresponding hacker technology has also developed, and people's attention to network security has also increased. At present, when performing network security testing on Runtime Application Self-Protection (RASP) devices, after injecting the memory horse, it is impossible to determine whether the memory horse has been injected successfully and whether the memory horse can execute instructions correctly, making security testing difficult to carry out. Summary of the invention
[0003] The embodiments of the present application provide a security testing method and related equipment, which can at least to some extent overcome the problem in the prior art that it is impossible to determine whether the memory horse has been injected successfully and whether the memory horse can correctly execute instructions, making it difficult to carry out security testing.
[0004] Other features and advantages of the present application will become apparent from the following detailed description, or may be learned in part by the practice of the present application.
[0005] According to one aspect of an embodiment of the present application, a security testing method is provided, including: sending an injection request to a predetermined server to inject a memory horse into a predetermined program; accessing the predetermined server to obtain a preliminary analysis result, wherein the preliminary analysis result includes a result of whether the memory horse is injected successfully; based on the preliminary analysis result, accessing the predetermined server to obtain a secondary analysis result, wherein the secondary analysis result includes a result of whether the memory horse is executed successfully.
[0006] In an embodiment of the present application, the access to the predetermined server to obtain a preliminary analysis result, which includes the result of whether the memory horse is injected successfully, specifically includes: accessing the predetermined server to obtain preliminary return content returned by the predetermined program; analyzing the preliminary return content to obtain a preliminary analysis result, which includes the result of whether the memory horse is injected successfully.
[0007] In an embodiment of the present application, the accessing of the predetermined server to obtain preliminary return content returned by the predetermined program specifically includes: sending an execution request to the predetermined server to trigger the memory horse to write a first attribute value in the predetermined program; accessing the predetermined server to obtain preliminary return content returned by the predetermined program, wherein the preliminary return content is obtained according to the attribute value.
[0008] In an embodiment of the present application, sending an execution request to the predetermined server to trigger the memory horse to write the first attribute value in the predetermined program specifically includes: capturing a predetermined access path from the memory horse; sending an execution request to the predetermined server through the predetermined access path to trigger the memory horse to write the first attribute value in the predetermined program.
[0009] In an embodiment of the present application, the preliminary return content is analyzed to obtain a preliminary analysis result, and the preliminary analysis result includes the result of whether the memory horse is injected successfully, specifically including: determining whether the preliminary return content includes the first return value; if the preliminary return content includes the first return value, obtaining a first preliminary analysis result, and the first preliminary analysis result is the result of successful injection of the memory horse; if the preliminary return content does not include the first return value, obtaining a second preliminary analysis result, and the second preliminary analysis result is the result of unsuccessful injection of the memory horse.
[0010] In an embodiment of the present application, sending an execution request to the memory horse based on the preliminary analysis result so that the memory horse performs a predetermined action specifically includes: constructing a specific request based on the preliminary analysis result, the specific request including an execution request; sending a specific request to the predetermined server so that the memory horse performs a predetermined action.
[0011] In an embodiment of the present application, the access to the predetermined server obtains a secondary analysis result, and the secondary analysis result includes a result of whether the memory horse is executed successfully, specifically including: accessing the predetermined server to obtain secondary return content returned by the predetermined program; analyzing the secondary return content to obtain a secondary analysis result, and the secondary analysis result includes a result of whether the memory horse is executed successfully.
[0012] In an embodiment of the present application, the accessing of the predetermined server to obtain the secondary return content returned by the predetermined program specifically includes: accessing the predetermined server to obtain various attribute values in the predetermined program; and obtaining the secondary return content according to the various attribute values in the predetermined program.
[0013] In an embodiment of the present application, sending an execution request to a memory horse according to the preliminary analysis result so that the memory horse performs a predetermined action specifically includes: sending an execution request to a memory horse according to the preliminary analysis result so that the memory horse performs a predetermined action in the predetermined program and writes a second attribute value in the predetermined program; analyzing the secondary return content to obtain a secondary analysis result specifically includes: determining whether the secondary return content contains the second return value; if the secondary return content contains the second return value, obtaining a first secondary analysis result, the first secondary analysis result being the result of successful execution of the memory horse; if the secondary return content does not contain the second return value, obtaining a second secondary analysis result, the second secondary analysis result being the result of unsuccessful execution of the memory horse.
[0014] According to one aspect of an embodiment of the present application, a security testing device is provided, comprising: a memory horse injection module, used to send an injection request to a predetermined server to inject the memory horse into a predetermined program; a preliminary analysis module, used to access the predetermined server to obtain a preliminary analysis result, wherein the preliminary analysis result includes a result of whether the memory horse is injected successfully; a memory horse execution module, used to send an execution request to the memory horse based on the preliminary analysis result, so that the memory horse executes a predetermined action; and a secondary analysis module, used to access the predetermined server to obtain a secondary analysis result, wherein the secondary analysis result includes a result of whether the memory horse is executed successfully.
[0015] In an embodiment of the present application, the preliminary analysis module specifically includes: a preliminary return submodule, which is used to access the predetermined server and obtain the preliminary return content returned by the predetermined program; a preliminary analysis submodule, which is used to analyze the preliminary return content and obtain a preliminary analysis result, and the preliminary analysis result includes the result of whether the memory horse is injected successfully.
[0016] In an embodiment of the present application, the preliminary return submodule specifically includes: a first attribute writing unit, used to send an execution request to the predetermined server, triggering the memory horse to write a first attribute value in the predetermined program; a first content judgment unit, used to access the predetermined server, and obtain the preliminary return content returned by the predetermined program, and the preliminary return content is obtained according to the attribute value.
[0017] In an embodiment of the present application, the first attribute writing unit is specifically used to execute: capturing a predetermined access path from the memory horse; sending an execution request to the predetermined server through the predetermined access path, triggering the memory horse to write a first attribute value in the predetermined program.
[0018] In an embodiment of the present application, the preliminary analysis submodule specifically includes: a preliminary result determination unit, used to determine whether the preliminary return content contains the first return value; a first preliminary result unit, used to obtain a first preliminary analysis result if the preliminary return content contains the first return value, and the first preliminary analysis result is the result of successful injection of the memory horse; a second preliminary result unit, used to obtain a second preliminary analysis result if the preliminary return content does not contain the first return value, and the second preliminary analysis result is the result of unsuccessful injection of the memory horse.
[0019] In an embodiment of the present application, the memory horse execution module specifically includes: a request construction submodule, used to construct a specific request based on the preliminary analysis result, and the specific request includes an execution request; a request sending submodule, used to send a specific request to the predetermined server so that the memory horse performs a predetermined action.
[0020] In an embodiment of the present application, the secondary analysis module specifically includes: a secondary return submodule, used to access the predetermined server to obtain the secondary return content returned by the predetermined program; a secondary analysis submodule, used to analyze the secondary return content to obtain a secondary analysis result, and the secondary analysis result includes the result of whether the memory horse is executed successfully.
[0021] In an embodiment of the present application, the secondary return submodule specifically includes: an attribute acquisition unit, used to access the predetermined server to obtain various attribute values in the predetermined program; and a content generation unit, used to obtain the secondary return content according to the various attribute values in the predetermined program.
[0022] In an embodiment of the present application, the memory horse execution module is specifically used to execute: according to the preliminary analysis result, sending an execution request to the memory horse, so that the memory horse executes a predetermined action in the predetermined program and writes a second attribute value in the predetermined program; the secondary analysis submodule specifically includes: a secondary result determination unit, used to determine whether the secondary return content includes the second return value; a first secondary result unit, used to obtain a first secondary analysis result if the secondary return content includes the second return value, and the first secondary analysis result is the result of successful execution of the memory horse; a second secondary result unit, used to obtain a second secondary analysis result if the secondary return content does not include the second return value, and the second secondary analysis result is the result of unsuccessful execution of the memory horse.
[0023] According to one aspect of an embodiment of the present application, a computer-readable medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the security testing method described in the above embodiment is implemented.
[0024] According to one aspect of an embodiment of the present application, an electronic device is provided, comprising: one or more processors; a storage device for storing one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors implement the security testing method as described in the above embodiments.
[0025] In the technical solutions provided in some embodiments of the present application, after injecting the memory horse into the predetermined program, the predetermined server is accessed multiple times to obtain the return results, and the corresponding return results are analyzed to determine whether the memory horse is injected successfully and whether it is executed successfully, thereby solving the problem of the prior art that it is impossible to determine whether the memory horse is injected successfully and whether the memory horse can correctly execute instructions, which makes it difficult to carry out security testing. The embodiments of the present application can effectively simulate the injection and execution of the memory horse, and can accurately evaluate the RASP interception capability in a remote manner.
[0026] It should be understood that the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the present application. BRIEF DESCRIPTION OF THE DRAWINGS
[0027] The drawings herein are incorporated into the specification and constitute a part of the specification, showing embodiments consistent with the present application, and together with the specification, are used to explain the principles of the present application. Obviously, the drawings described below are only some embodiments of the present application, and for ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work. In the drawings:
[0028] Figure 1 A schematic diagram of an exemplary system architecture to which the technical solution of the embodiments of the present application can be applied is shown.
[0029] Figure 2 A flow chart of a safety testing method provided in an embodiment of the present application is shown.
[0030] Figure 3 Shown according to Figure 2 A specific implementation flow chart of step S200 in the safety testing method shown in the corresponding embodiment.
[0031] Figure 4 Shown according to Figure 3 A specific implementation flowchart of step S210 in the safety testing method shown in the corresponding embodiment.
[0032] Figure 5 Shown according to Figure 2 A specific implementation flow chart of step S300 in the safety testing method shown in the corresponding embodiment.
[0033] Figure 6Shown according to Figure 2 A specific implementation flow chart of step S400 in the safety testing method shown in the corresponding embodiment.
[0034] Figure 7 A schematic structural diagram of a safety testing device provided in an embodiment of the present application is shown.
[0035] Figure 8 A schematic diagram of the structure of a computer system suitable for implementing an electronic device of an embodiment of the present application is shown. DETAILED DESCRIPTION
[0036] Example embodiments will now be described more fully with reference to the accompanying drawings. However, example embodiments can be implemented in a variety of forms and should not be construed as limited to the examples set forth herein; rather, these embodiments are provided so that this application will be more comprehensive and complete and fully convey the concept of the example embodiments to those skilled in the art.
[0037] In addition, described feature, structure or characteristic can be combined in one or more embodiments in any suitable manner. In the following description, many specific details are provided to provide a full understanding of the embodiments of the present application. However, those skilled in the art will appreciate that the technical scheme of the present application can be put into practice without one or more of the specific details, or other methods, components, devices, steps, etc. can be adopted. In other cases, known methods, devices, realizations or operations are not shown or described in detail to avoid blurring the various aspects of the application.
[0038] The block diagrams shown in the accompanying drawings are merely functional entities and do not necessarily correspond to physically independent entities. That is, these functional entities may be implemented in software form, or in one or more hardware modules or integrated circuits, or in different networks and / or processor devices and / or microcontroller devices.
[0039] The flowcharts shown in the accompanying drawings are only exemplary and do not necessarily include all the contents and operations / steps, nor must they be executed in the order described. For example, some operations / steps can be decomposed, and some operations / steps can be combined or partially combined, so the actual execution order may change according to actual conditions.
[0040] Figure 1 A schematic diagram of an exemplary system architecture to which the technical solution of the embodiments of the present application can be applied is shown.
[0041] like Figure 1 As shown, the system architecture may include an attacking device (such as Figure 1The present invention relates to a network 104 and an attacked device 105. The network 104 is used to provide a medium for a communication link between the attacking device and the attacked device 105. The network 104 may include various connection types, such as a wired communication link, a wireless communication link, and the like.
[0042] It should be understood that Figure 1 The number of attacking devices, networks and attacked devices in the figure is only for illustration. According to the implementation requirements, there may be any number of attacking devices, networks and attacked devices. For example, the attacked device 105 may be a server cluster composed of multiple servers.
[0043] The user can use the attacking device to interact with the attacked device 105 through the network 104 to receive or send messages, etc. The attacked device 105 can be a server that provides various services. For example, the user uses the attacking device 103 (it can also be the attacking device 101 or 102) to send various requests to the attacked device 105, and the attacked device 105 can return corresponding information to the attacking device 103. Specifically, the user uses the attacking device 103 to send an injection request to the predetermined server of the attacked device 105, injects the memory horse into the predetermined program, and then accesses the predetermined server of the attacked device 105 to obtain a preliminary analysis result. Finally, based on the preliminary analysis result, the predetermined server of the attacked device 105 is accessed to obtain a secondary analysis result. The preliminary analysis result includes the result of whether the memory horse is injected successfully, and the secondary analysis result includes the result of whether the memory horse is executed successfully.
[0044] It should be noted that the security testing method provided in the embodiment of the present application is generally performed by the attacking device 103, and accordingly, the security testing device is generally provided in the attacking device 103. However, in other embodiments of the present application, the attacked device may also have similar functions to the attacking device, thereby executing the security testing solution provided in the embodiment of the present application.
[0045] The implementation details of the technical solution of the embodiment of the present application are described in detail below:
[0046] Figure 2 A flowchart of a security testing method according to an embodiment of the present application is shown. The security testing method can be performed by an attacking end device. The attacking end device can be Figure 1 The attacking device shown in . Figure 2 As shown, the safety testing method at least includes:
[0047] Step S100, sending an injection request to a predetermined server to inject the memory horse into a predetermined program.
[0048] Step S200, accessing the predetermined server to obtain a preliminary analysis result, wherein the preliminary analysis result includes a result indicating whether the memory horse has been injected successfully.
[0049] Step S300, according to the preliminary analysis result, sending an execution request to the memory horse, so that the memory horse executes a predetermined action.
[0050] Step S400, accessing the predetermined server to obtain a secondary analysis result, wherein the secondary analysis result includes a result indicating whether the memory horse is executed successfully.
[0051] In an embodiment of the present application, an injection request is first sent to a predetermined server of the attacked end to inject a memory horse into a predetermined program of the attacked end. Then, by accessing the predetermined server of the attacked end, a preliminary analysis result is obtained to determine whether the memory horse has been injected successfully. Then, based on the preliminary analysis result, the predetermined server is accessed to obtain a secondary analysis result to determine whether the memory horse has been injected successfully. This solves the problem of the prior art that it is impossible to determine whether the memory horse has been injected successfully and whether the memory horse can correctly execute instructions, which makes it difficult to carry out security testing. While being able to effectively simulate the injection and execution of memory horses, the embodiments of the present application can accurately evaluate the RASP interception capability remotely.
[0052] In step S100, the memory horse needs to be injected into a predetermined program of the attacked end device, and the predetermined program may be a servlet, a filter, a listener, etc. When the predetermined program is a server, it is the predetermined server mentioned above.
[0053] The pre-set server is a modified server that can convert the requests sent by the attacking device into corresponding action instructions, such as injecting memory horses, traversing directories, and reading files.
[0054] The specific injection method is that the attacking device sends an injection request to a predetermined server. After receiving the injection request, the predetermined server can activate a section of Java code contained in it and convert it into a memory horse, and inject it into the predetermined program.
[0055] Since the predetermined server has been modified, the request sent by the attacking device may not contain any suspicious features, that is, although it is an injection request, the security system of the attacked device cannot recognize that the injection request is a request to inject a memory horse, and the memory horse does not exist in the injection request. Therefore, the injection request does not contain any suspicious features and can safely pass the recognition of the security system of the attacked device.
[0056] In step S200, the predetermined server is accessed to obtain a preliminary analysis result to determine whether the memory injection is successful.
[0057] Specifically, in some embodiments, the specific implementation of step S200 can be found in Figure 3 . Figure 3 is based on Figure 2 The detailed description of step S200 in the safety testing method shown in the corresponding embodiment, in the safety testing method, step S200 may include the following steps:
[0058] Step S210, accessing the predetermined server to obtain the preliminary returned content returned by the predetermined program.
[0059] Step S220, analyzing the preliminary returned content to obtain a preliminary analysis result, wherein the preliminary analysis result includes a result indicating whether the memory horse has been successfully injected.
[0060] In an embodiment of the present application, the attacking device first accesses a predetermined server of the attacked device to obtain preliminary return content returned by a predetermined program of the attacked device; then the preliminary return content is analyzed to obtain an analysis result to determine whether the memory horse has been injected successfully.
[0061] In step S210, for different predetermined programs, the process of obtaining the preliminary returned content is also different.
[0062] Specifically, in some embodiments, the specific implementation of step S210 can be found in Figure 4 . Figure 4 is based on Figure 3 The detailed description of step S210 in the safety testing method shown in the corresponding embodiment, in the safety testing method, step S210 may include the following steps:
[0063] Step S212, sending an execution request to the predetermined server to trigger the memory horse to write the first attribute value into the predetermined program.
[0064] Step S214, accessing the predetermined server to obtain preliminary return content returned by the predetermined program, wherein the preliminary return content is obtained according to the attribute value.
[0065] In the embodiment of the present application, the predetermined program is a predetermined filter or a predetermined listener. At this time, it is necessary to first send an execution request to the predetermined server of the attacked end device to trigger the memory horse to write a first attribute value in the predetermined program of the attacked end device. The first attribute value can be used to prove that the memory horse has been successfully injected into the predetermined program. Then, the predetermined server is accessed to obtain the preliminary return content returned by the predetermined program, and the preliminary return content is determined by various attribute values in the predetermined program.
[0066] Specifically, the predetermined server can determine whether the memory horse is successfully injected into the predetermined program according to whether the predetermined program contains the first attribute value, and then give different preliminary return contents.
[0067] When the predetermined program is a predetermined server, it can directly obtain the memory horse from the predetermined server. After the injection, the predetermined server can directly determine whether the injection is successful without judging by the first attribute value.
[0068] In step S212, an execution request is sent to a predetermined server, triggering the memory to write the first attribute value into the predetermined program.
[0069] Specifically, in some embodiments, the specific implementation of step S212 can refer to the following embodiments. Figure 4 The detailed description of step S212 in the safety testing method shown in the corresponding embodiment, in the safety testing method, step S212 may include the following steps:
[0070] A predetermined access path is captured from the memory horse.
[0071] An execution request is sent to the predetermined server through the predetermined access path, triggering the memory horse to write a first attribute value in the predetermined program.
[0072] In an embodiment of the present application, it is necessary to first separate a predetermined access path from the memory horse, and then send an execution request to a predetermined server according to the predetermined access path to control the memory horse to perform a corresponding action in the predetermined program, for example, writing a first attribute value.
[0073] It should be noted that when the predetermined program is a listener, in addition to capturing the predetermined access path from the memory horse, it also monitors all request response events.
[0074] In step S214, after sending an execution request to the predetermined server to make the memory horse execute the corresponding action, the predetermined server is accessed again to obtain various attribute values in the predetermined program through the predetermined server to form preliminary return content.
[0075] When the attribute value in the predetermined program includes the first attribute value, the preliminary return content includes the first return value, proving that the memory horse injection is successful; when the attribute value in the predetermined program does not include the first attribute value, the preliminary return content does not include the first return value, proving that the memory horse injection fails.
[0076] In step S220, it can be determined whether the memory horse is injected successfully based on the preliminary returned content.
[0077] Specifically, in some embodiments, the specific implementation of step S220 can refer to the following embodiments. Figure 4 The detailed description of step S220 in the safety testing method shown in the corresponding embodiment, in the safety testing method, step S220 may include the following steps:
[0078] Determining whether the preliminary returned content includes the first returned value;
[0079] If the preliminary return content includes the first return value, a first preliminary analysis result is obtained, and the first preliminary analysis result is a result that the memory horse is successfully injected;
[0080] If the preliminary return content does not include the first return value, a second preliminary analysis result is obtained, and the second preliminary analysis result is a result that the memory horse is not injected successfully.
[0081] In the embodiment of the present application, whether the memory injection is successful is determined by determining whether the initial returned content is consistent with the expectation.
[0082] In the embodiment of the present application, the initial return content of the attacked device does not contain command execution results, directory traversal, file content, etc. It only has one result value, that is, injection success or injection failure, which further avoids the attacked segment response containing sensitive content being blocked by the intermediate security device.
[0083] If the preliminary return content includes the first return value (the first return value is the return value indicating successful injection, which may be specifically expressed as Deploy Success), it is consistent with expectations, proving that the memory horse has been successfully injected and the attribute value has been successfully written, and a first preliminary analysis result is obtained, which is the result of successful injection of the memory horse. If the preliminary return content does not include the first return value, but includes other return values (return values indicating failed injection, which may be specifically expressed as Deploy Filed), it is inconsistent with expectations, proving that the memory horse has not been successfully injected and that writing the attribute value has failed. A second preliminary analysis result is obtained, which is the result of the failure to inject the memory horse successfully, which may be caused by the RASP device intercepting the request, or by the intermediate security device intercepting it. But generally speaking, after the client request and the server response are minimally processed, it is theoretically impossible for them to be intercepted by the intermediate security device.
[0084] In step S300, the attacking device sends an execution request to the memory horse according to the preliminary analysis result.
[0085] When the predetermined program is a predetermined server, the attacking device sends an execution request to the predetermined server of the attacked device. After receiving the execution request, the predetermined server triggers the memory horse to execute the predetermined action in the predetermined program corresponding to the attacked device. When the attacked device accesses the predetermined server again, it can directly determine whether the execution is successful and generate preliminary return content.
[0086] When the predetermined program is a predetermined filter or a predetermined listener, the attacking device sends an execution request to the predetermined server of the attacked device. After receiving the execution request, the predetermined server triggers the memory horse to execute the predetermined action in the predetermined program corresponding to the attacked device. After executing the predetermined action, the memory horse will also write a second attribute value in the predetermined program, which is obtained by the predetermined server to prove that the memory horse successfully executes the predetermined action.
[0087] Since the predetermined server has been modified, the above execution request may be expressed as a string of character codes that are meaningless to the security system and do not carry any suspicious features in order to bypass the detection of the security system. The predetermined server may convert the meaningless character code into a corresponding execution command. For example, its expression may be as follows: {"aes":command}: trigger the execution of command, {"action":"aes1"}: trigger the acquisition of system environment variable information, {"action":"aes2"}: directory traversal, {"action":"aes3"}: read files, etc.
[0088] Specifically, in some embodiments, the specific implementation of step S300 can be found in Figure 5 . Figure 5 is based on Figure 2 The detailed description of step S300 in the safety testing method shown in the corresponding embodiment, in the safety testing method, step S300 may include the following steps:
[0089] Step S310: construct a specific request according to the preliminary analysis result, wherein the specific request includes an execution request.
[0090] Step S320, sending a specific request to the predetermined server to enable the memory horse to perform a predetermined action.
[0091] In an embodiment of the present application, after obtaining the preliminary analysis results, a specific request (the specific request includes an execution request) is constructed and sent to a predetermined server, so that the predetermined server triggers a predetermined program to perform a predetermined action. After executing the predetermined action, the memory horse writes a second attribute value in the predetermined program. The second return value can be used to prove that the memory horse successfully executes the predetermined action.
[0092] In step S400, the predetermined server is accessed to obtain a preliminary analysis result to determine whether the memory horse is executed successfully.
[0093] Specifically, in some embodiments, the specific implementation of step S400 can be found in Figure 6 . Figure 6 is based on Figure 5 The detailed description of step S400 in the safety testing method shown in the corresponding embodiment, in the safety testing method, step S400 may include the following steps:
[0094] Step S410, accessing the predetermined server to obtain the secondary return content returned by the predetermined program.
[0095] Step S420, analyzing the secondary returned content to obtain a secondary analysis result, wherein the secondary analysis result includes a result indicating whether the memory horse is executed successfully.
[0096] In an embodiment of the present application, the attacking device first accesses a predetermined server of the attacked device to obtain secondary return content returned by a predetermined program of the attacked device; then the secondary return content is analyzed to obtain an analysis result to determine whether the memory horse is executed successfully.
[0097] In step S410, for different predetermined programs, the process of obtaining the secondary return content is also different.
[0098] When the predetermined program is a predetermined server, it can directly obtain the result of the memory horse execution from the predetermined server and generate corresponding secondary return content.
[0099] When the predetermined program is a predetermined filter or a predetermined listener, it is necessary to capture various attribute values in the predetermined program through the predetermined server to generate corresponding secondary return content.
[0100] Specifically, in some embodiments, the specific implementation of step S410 can refer to the following embodiments. Figure 6 The detailed description of step S410 in the safety testing method shown in the corresponding embodiment, in the safety testing method, step S410 may include the following steps:
[0101] Accessing the predetermined server to obtain various attribute values in the predetermined program;
[0102] The secondary return content is obtained according to various attribute values in the predetermined program.
[0103] The predetermined program is a predetermined filter or a predetermined listener. After executing the predetermined action, the memory horse writes a second attribute value in the predetermined program, and the second attribute value can be used to prove that the memory horse successfully executes the predetermined action. The second return value is obtained by the predetermined server. When the attacked end device accesses the predetermined server again, the predetermined server obtains various attribute values in the predetermined program, and determines whether the memory horse is executed successfully based on the various attribute values in the predetermined program, and then generates secondary return content.
[0104] In step S420, it can be determined whether the memory horse is executed successfully based on the secondary return content.
[0105] Specifically, in some embodiments, the specific implementation of step S420 can refer to the following embodiments. Figure 6 Detailed description of step S420 in the security testing method shown in the corresponding embodiment. In the security testing method, the specific execution steps of step S300 are: according to the preliminary analysis result, sending an execution request to the memory horse so that the memory horse performs a predetermined action in the predetermined program and writes a second attribute value in the predetermined program.
[0106] Correspondingly, step S420 may include the following steps:
[0107] Determine whether the secondary return content includes the second return value.
[0108] If the secondary return content includes the second return value, a first secondary analysis result is obtained, and the first secondary analysis result is the result of successful execution of the memory horse.
[0109] If the secondary return content does not include the second return value, a second secondary analysis result is obtained, and the second secondary analysis result is the result that the memory horse was not successfully executed.
[0110] In the embodiment of the present application, the secondary return content of the attacked end device does not contain command execution results, directory traversal, file content, etc. It only has one result value, that is, injection success or injection failure, which further avoids the attacked segment response containing sensitive content being blocked by the intermediate security device.
[0111] If the secondary return content includes the second return value (the first return value is the return value indicating successful injection, which may be specifically expressed as Exec Success), it is consistent with expectations, proving that the memory horse is successfully executed and the attribute value is successfully written, and the first secondary analysis result is obtained, which is the result of the successful execution of the memory horse;
[0112] If the secondary return content does not contain the second return value but contains other return values (return values indicating injection failure, which may be specifically expressed as Exec Filed), it is inconsistent with expectations, proving that the memory horse was not successfully executed and that its writing of attribute values failed. The second secondary analysis result is obtained, and the second secondary analysis result is the result that the memory horse was not successfully executed. It may be that the RASP device intercepted the request, or it may be caused by the intermediate security device intercepting it. But in general, after the client request and the server response are minimally processed, it is theoretically impossible for them to be intercepted by the intermediate security device.
[0113] In the above embodiment, the first preliminary analysis result proves that the memory horse bypasses the interception of the security system and the RASP device and is successfully injected; the second preliminary analysis result proves that the memory horse is intercepted by the security system and the RASP device and is not successfully injected. That is, the RASP device that obtains the second preliminary analysis result has better security than the RASP device that obtains the first preliminary analysis result.
[0114] In the case of obtaining the first preliminary analysis result, the protection effect of the RASP device on the execution of the memory horse can be further tested. The first and second analysis results prove that the memory horse bypasses the interception of the security system and the RASP device and is successfully executed; the second and second analysis results prove that the memory horse is intercepted by the security system and the RASP device and is not successfully executed. That is, the RASP device that obtains the second and second analysis results has better security than the RASP device that obtains the first and second analysis results.
[0115] After obtaining the second secondary analysis results, you can continue to test other test items of the RASP device on memory horses, such as killing, to achieve more comprehensive detection.
[0116] The following describes an embodiment of the device of the present application, which can be used to perform the security testing method in the above embodiment of the present application. For details not disclosed in the embodiment of the device of the present application, please refer to the embodiment of the security testing method in the above embodiment of the present application.
[0117] Figure 7 A block diagram of a safety testing device according to an embodiment of the present application is shown.
[0118] Reference Figure 7 As shown, a safety testing device 700 according to an embodiment of the present application includes:
[0119] The memory horse injection module 710 is used to send an injection request to a predetermined server to inject the memory horse into a predetermined program;
[0120] A preliminary analysis module 720 is used to access the predetermined server to obtain a preliminary analysis result, wherein the preliminary analysis result includes a result of whether the memory horse is injected successfully;
[0121] A memory horse execution module 730, used to send an execution request to the memory horse according to the preliminary analysis result, so that the memory horse executes a predetermined action;
[0122] The secondary analysis module 740 is used to access the predetermined server to obtain a secondary analysis result, wherein the secondary analysis result includes a result indicating whether the memory horse is executed successfully.
[0123] In an embodiment of the present application, the preliminary analysis module specifically includes: a preliminary return submodule, which is used to access the predetermined server and obtain the preliminary return content returned by the predetermined program; a preliminary analysis submodule, which is used to analyze the preliminary return content and obtain a preliminary analysis result, and the preliminary analysis result includes the result of whether the memory horse is injected successfully.
[0124] In an embodiment of the present application, the preliminary return submodule specifically includes: a first attribute writing unit, used to send an execution request to the predetermined server, triggering the memory horse to write a first attribute value in the predetermined program; a first content judgment unit, used to access the predetermined server, and obtain the preliminary return content returned by the predetermined program, and the preliminary return content is obtained according to the attribute value.
[0125] In an embodiment of the present application, the first attribute writing unit is specifically used to execute: capturing a predetermined access path from the memory horse; sending an execution request to the predetermined server through the predetermined access path, triggering the memory horse to write a first attribute value in the predetermined program.
[0126] In an embodiment of the present application, the preliminary analysis submodule specifically includes: a preliminary result determination unit, used to determine whether the preliminary return content contains the first return value; a first preliminary result unit, used to obtain a first preliminary analysis result if the preliminary return content contains the first return value, and the first preliminary analysis result is the result of successful injection of the memory horse; a second preliminary result unit, used to obtain a second preliminary analysis result if the preliminary return content does not contain the first return value, and the second preliminary analysis result is the result of unsuccessful injection of the memory horse.
[0127] In an embodiment of the present application, the memory horse execution module specifically includes: a request construction submodule, used to construct a specific request based on the preliminary analysis result, and the specific request includes an execution request; a request sending submodule, used to send a specific request to the predetermined server so that the memory horse performs a predetermined action.
[0128] In an embodiment of the present application, the secondary analysis module specifically includes: a secondary return submodule, used to access the predetermined server to obtain the secondary return content returned by the predetermined program; a secondary analysis submodule, used to analyze the secondary return content to obtain a secondary analysis result, and the secondary analysis result includes the result of whether the memory horse is executed successfully.
[0129] In an embodiment of the present application, the secondary return submodule specifically includes: an attribute acquisition unit, used to access the predetermined server to obtain various attribute values in the predetermined program; and a content generation unit, used to obtain the secondary return content according to the various attribute values in the predetermined program.
[0130] In an embodiment of the present application, the memory horse execution module is specifically used to execute: according to the preliminary analysis result, sending an execution request to the memory horse, so that the memory horse executes a predetermined action in the predetermined program and writes a second attribute value in the predetermined program; the secondary analysis submodule specifically includes: a secondary result determination unit, used to determine whether the secondary return content includes the second return value; a first secondary result unit, used to obtain a first secondary analysis result if the secondary return content includes the second return value, and the first secondary analysis result is the result of successful execution of the memory horse; a second secondary result unit, used to obtain a second secondary analysis result if the secondary return content does not include the second return value, and the second secondary analysis result is the result of unsuccessful execution of the memory horse.
[0131] Figure 8 A schematic diagram of the structure of a computer system suitable for implementing an electronic device of an embodiment of the present application is shown.
[0132] It should be noted that Figure 8 The computer system of the electronic device shown is only an example and should not bring any limitation to the functions and scope of use of the embodiments of the present application.
[0133] like Figure 8As shown, the computer system includes a central processing unit (CPU) 1801, which can perform various appropriate actions and processes according to the program stored in the read-only memory (ROM) 1802 or the program loaded from the storage part 1808 to the random access memory (RAM) 1803, such as executing the method described in the above embodiment. In RAM 1803, various programs and data required for system operation are also stored. CPU 1801, ROM 1802 and RAM 1803 are connected to each other through bus 1804. Input / output (I / O) interface 1805 is also connected to bus 1804.
[0134] The following components are connected to the I / O interface 1805: an input section 1806 including a keyboard, a mouse, etc.; an output section 1807 including a cathode ray tube (CRT), a liquid crystal display (LCD), etc., and a speaker, etc.; a storage section 1808 including a hard disk, etc.; and a communication section 1809 including a network interface card such as a LAN (Local Area Network) card, a modem, etc. The communication section 1809 performs communication processing via a network such as the Internet. A drive 1810 is also connected to the I / O interface 1805 as needed. A removable medium 1811, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 1810 as needed so that a computer program read therefrom is installed into the storage section 1808 as needed.
[0135] In particular, according to an embodiment of the present application, the process described above with reference to the flowchart can be implemented as a computer software program. For example, an embodiment of the present application includes a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program includes a computer program for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from a network through a communication section 1809, and / or installed from a removable medium 1811. When the computer program is executed by a central processing unit (CPU) 1801, various functions defined in the system of the present application are executed.
[0136] It should be noted that the computer-readable medium shown in the embodiment of the present application may be a computer-readable signal medium or a computer-readable storage medium or any combination of the above two. The computer-readable storage medium may be, for example, - but not limited to - an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or device, or any combination of the above. More specific examples of computer-readable storage media may include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM), a flash memory, an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present application, a computer-readable storage medium may be any tangible medium containing or storing a program, which may be used by an instruction execution system, device or device or used in combination with it. In the present application, a computer-readable signal medium may include a data signal propagated in a baseband or as part of a carrier wave, wherein a computer-readable computer program is carried. Such propagated data signals may take a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. Computer-readable signal media may also be any computer-readable medium other than computer-readable storage media, which may send, propagate, or transmit programs for use by or in conjunction with an instruction execution system, apparatus, or device. The computer program contained on the computer-readable medium may be transmitted using any appropriate medium, including but not limited to: wireless, wired, etc., or any suitable combination of the above.
[0137] The flowchart and block diagram in the accompanying drawings illustrate the possible architecture, functions and operations of the system, method and computer program product according to various embodiments of the present application. Wherein, each box in the flowchart or block diagram can represent a module, a program segment, or a part of the code, and the above-mentioned module, program segment, or a part of the code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a different order from the order marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram or flowchart, and the combination of boxes in the block diagram or flowchart can be implemented with a dedicated hardware-based system that performs a specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.
[0138] The units involved in the embodiments described in this application may be implemented by software or hardware, and the units described may also be set in a processor. The names of these units do not, in some cases, constitute limitations on the units themselves.
[0139] As another aspect, the present application also provides a computer-readable medium, which may be included in the electronic device described in the above embodiment; or may exist independently without being assembled into the electronic device. The above computer-readable medium carries one or more programs, and when the above one or more programs are executed by an electronic device, the electronic device implements the method described in the above embodiment.
[0140] It should be noted that, although several modules or units of the equipment for action execution are mentioned in the above detailed description, this division is not mandatory. In fact, according to the embodiments of the present application, the features and functions of two or more modules or units described above can be embodied in one module or unit. On the contrary, the features and functions of one module or unit described above can be further divided into being embodied by multiple modules or units.
[0141] Through the description of the above implementation methods, it is easy for those skilled in the art to understand that the example implementation methods described here can be implemented by software or by combining software with necessary hardware. Therefore, the technical solution according to the implementation methods of the present application can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, and includes several instructions to enable a computing device (which can be a personal computer, a server, a touch terminal, or a network device, etc.) to execute the method according to the implementation methods of the present application.
[0142] Those skilled in the art will readily appreciate other embodiments of the present application after considering the specification and practicing the embodiments disclosed herein. The present application is intended to cover any variations, uses or adaptations of the present application, which follow the general principles of the present application and include common knowledge or customary technical means in the art that are not disclosed in the present application.
[0143] It should be understood that the present application is not limited to the precise structures that have been described above and shown in the drawings, and that various modifications and changes may be made without departing from the scope thereof. The scope of the present application is limited only by the appended claims.
Claims
1. A safety testing method, characterized in that: The safety testing method comprises: Send an injection request to a predetermined server to inject the memory horse into a predetermined program; Accessing the predetermined server to obtain a preliminary analysis result, wherein the preliminary analysis result includes a result of whether the memory horse is injected successfully; According to the preliminary analysis result, sending an execution request to the memory horse so that the memory horse executes a predetermined action; The predetermined server is accessed to obtain a secondary analysis result, wherein the secondary analysis result includes a result indicating whether the memory horse is executed successfully.
2. The safety testing method according to claim 1, characterized in that: The accessing of the predetermined server to obtain a preliminary analysis result includes a result of whether the memory horse is successfully injected, specifically including: Accessing the predetermined server to obtain preliminary returned content returned by the predetermined program; Analyze the initial return content to obtain a preliminary analysis result, which includes whether the memory horse is injected successfully.
3. The safety testing method according to claim 2, characterized in that: The accessing of the predetermined server to obtain the preliminary returned content returned by the predetermined program specifically includes: Sending an execution request to the predetermined server to trigger the memory horse to write a first attribute value into the predetermined program; The predetermined server is accessed to obtain preliminary return content returned by the predetermined program, wherein the preliminary return content is obtained according to the attribute value.
4. The safety testing method according to claim 3, characterized in that: The sending of the execution request to the predetermined server to trigger the memory horse to write the first attribute value in the predetermined program specifically includes: Capturing a predetermined access path from the memory horse; An execution request is sent to the predetermined server through the predetermined access path, triggering the memory horse to write a first attribute value in the predetermined program.
5. The safety testing method according to claim 1, characterized in that: The sending of an execution request to the memory horse according to the preliminary analysis result so that the memory horse performs a predetermined action specifically includes: constructing a specific request according to the preliminary analysis result, wherein the specific request includes an execution request; A specific request is sent to the predetermined server to enable the memory horse to perform a predetermined action.
6. The safety testing method according to claim 1, characterized in that: The accessing of the predetermined server to obtain a secondary analysis result includes a result of whether the memory horse is executed successfully, specifically including: Accessing the predetermined server to obtain secondary return content returned by the predetermined program; Analyze the secondary returned content to obtain a secondary analysis result, wherein the secondary analysis result includes a result indicating whether the memory horse is executed successfully.
7. The safety testing method according to claim 6, characterized in that: The accessing of the predetermined server to obtain the secondary return content returned by the predetermined program specifically includes: Accessing the predetermined server to obtain various attribute values in the predetermined program; The secondary return content is obtained according to various attribute values in the predetermined program.
8. A safety testing device, characterized in that: The safety testing device comprises: A memory horse injection module is used to send an injection request to a predetermined server to inject the memory horse into a predetermined program; A preliminary analysis module, used for accessing the predetermined server to obtain a preliminary analysis result, wherein the preliminary analysis result includes a result of whether the memory horse is injected successfully; A memory horse execution module, used for sending an execution request to the memory horse according to the preliminary analysis result, so that the memory horse executes a predetermined action; The secondary analysis module is used to access the predetermined server to obtain a secondary analysis result, wherein the secondary analysis result includes a result indicating whether the memory horse is executed successfully.
9. A computer readable medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the security testing method according to any one of claims 1 to 7 is implemented.
10. An electronic device, characterized in that: include: one or more processors; A storage device for storing one or more programs, which, when executed by the one or more processors, enables the one or more processors to implement the security testing method as described in any one of claims 1 to 7.