JWT vulnerability automatic mining method and system

Through the automated process of dynamic monitoring, data analysis and vulnerability verification, the problem of insufficient coverage of JWT vulnerability detection in the existing technology is solved, efficient and automated JWT vulnerability detection is achieved, and the detection effect is significantly improved.

CN119996016APending Publication Date: 2025-05-13BEIJING VENUS INFORMATION SECURITY TECH +2
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510209287.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-25
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

The existing technology lacks flexible dynamic processing capabilities in JWT vulnerability mining, and cannot dynamically analyze and adjust JWT parameters according to the specific content of the request body. The vulnerability detection coverage is limited and highly relies on manual operations, resulting in poor detection results.

Method used

Through three core functional parts, dynamic monitoring, data analysis and vulnerability verification, the full process of JWT tokens is automated. The specific steps include: dynamically monitoring the JWT token, split the data analysis and processing into header, payload, signature and vulnerability testing, and vulnerability verification through automatic verification of output results.

Benefits of technology

It realizes the full process automation of JWT vulnerabilities, improves the comprehensiveness and accuracy of vulnerability detection, reduces dependence on manual operations, and significantly improves the breadth and depth of vulnerability discovery.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119996016A_ABST
    Figure CN119996016A_ABST
Patent Text Reader

Abstract

According to the JWT vulnerability automatic mining method and system, the whole processing process is divided into three core function parts including dynamic monitoring, data analysis processing and vulnerability verification, and through collaborative operation of the three parts, full-process automatic processing from JWT token capturing, data analysis to vulnerability verification is achieved; by designing a JWT parameter intelligent analysis and dynamic modification mechanism, a dynamic comparison analysis mechanism and the like, various vulnerabilities are accurately identified, and an automatic and all-around JWT security evaluation system is constructed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of Internet security technology, and in particular to a method for automatically mining JWT vulnerabilities. Background Art

[0002] JSON Web Token (JWT) is an open standard based on JSON (RFC 7519) and is widely used in identity authentication and authorization. Currently, the vulnerability discovery process for JWT often relies on a high degree of manual operation. The typical workflow is as follows: first extract the JWT string from the data stream, then use relevant tools (such as JWT.io, Burp Suite, Fuzzing, etc.) to decode the JWT, analyze its header, payload, and signature to detect potential vulnerabilities.

[0003] This method has the following main shortcomings:

[0004] 1) Lack of flexible dynamic processing capabilities. The existing technology has failed to establish an intelligent parameter parsing mechanism, and is unable to dynamically parse and adjust JWT parameters according to the specific content of the request body, which seriously affects the comprehensiveness and accuracy of vulnerability detection. The deeper problem is that after completing JWT parsing, existing tools lack the ability to automatically optimize attack strategies based on the request context. For example, they are unable to accurately tamper with and verify JWT payloads based on user roles, permission levels, or specific business logic, which greatly reduces the effectiveness of vulnerability detection. In particular, it performs poorly when performing in-depth security testing (such as SQL injection, etc.) on the parameters in the request body. This rigid detection mode is difficult to adapt to complex and changeable actual application scenarios, and has become a key bottleneck restricting the efficiency of vulnerability mining.

[0005] 2) Limited coverage of vulnerability detection. Existing technologies often only focus on certain specific types of vulnerabilities, such as weak signature algorithms or improper key management, while ignoring other equally important security threats, such as payload tampering, privilege escalation, signature bypass, etc. This one-sided vulnerability integration method cannot fully identify and detect all possible JWT security vulnerabilities, which in turn affects the overall security assessment effect.

[0006] 3) High reliance on manual operations. Although existing tools can initially identify potential vulnerabilities, they still rely heavily on manual inspection and testing by security analysts to confirm the authenticity and exploitability of the vulnerabilities. This high reliance on manual verification not only significantly increases labor costs and time expenditures, but is also more likely to lead to inconsistencies in detection results due to human factors, and even cause the omission of key vulnerabilities. Summary of the invention

[0007] The present invention provides a method and system for automatically mining JWT vulnerabilities, which divides the overall processing flow into three core functional parts: dynamic monitoring, data analysis and processing, and vulnerability verification. Through the coordinated operation of the three parts, the full process from JWT token capture, data analysis to vulnerability verification is automated, effectively solving the problems existing in the prior art.

[0008] The JWT vulnerability automated mining method provided by the present disclosure includes the following steps:

[0009] S1, dynamic monitoring: continuously track and record complete network communication data, and monitor and extract JWT tokens in the target application in real time;

[0010] S2, data analysis and processing: perform structural analysis on the JWT token and split it into header, payload, and signature, i.e., header, payload, and signature. Vulnerability tests are performed on each part to generate corresponding test cases.

[0011] S3, vulnerability verification: automatically verify the test cases output by the data analysis and processing steps and output the results.

[0012] Furthermore, the method of step S1 includes:

[0013] Deploy proxy servers and network packet capture tools to implement intelligent interception of data transmitted via HTTP / HTTPS protocols, including:

[0014] Configure SSL certificates and implement TLS interception in the proxy server, and establish TLS connections with the client and target server as a middleman to decrypt, analyze, and re-encrypt HTTPS encrypted traffic;

[0015] The network packet capture tool extracts the JWT token from the Authorization field and other custom fields in the HTTP request header based on the characteristics of JWT.

[0016] Furthermore, the step S2 specifically includes:

[0017] S21, JWT decoding and parsing: perform structural parsing on the JWT token and split it into three parts: header, payload, and signature;

[0018] S22, basic security vulnerability detection, is used to perform systematic testing of JWT headers and signatures;

[0019] S23, JWT payload test, includes the following steps:

[0020] Payload field identification: JWT payload content analysis, identification and extraction of custom key fields in JWT, including one or more of role, id, and permissions;

[0021] Payload permission control test: Systematically test the permission-related fields in the JWT payload;

[0022] Payload content testing: While keeping the header algorithm unchanged, perform security vulnerability testing by making various injection modifications to the fields in the JWT payload.

[0023] Furthermore, the basic security vulnerability detection in step S22 includes:

[0024] Algorithm verification test, key verification test and signature verification test, where:

[0025] Algorithm verification test: modify the alg field value to test the algorithm verification mechanism on the server side, including: using the none algorithm to bypass signature verification, and replacing the asymmetric algorithm with a symmetric algorithm;

[0026] Key verification test, including: key brute force cracking, JWK parameter injection, JWKS public key injection;

[0027] Signature verification test, including: removing signature, modifying signature;

[0028] After each modification, the signature is recalculated according to different test scenarios and a new JWT is generated for testing. No signature is required when testing the none algorithm.

[0029] Furthermore, the specific method of the JWT load test in step S23 includes:

[0030] Payload field identification: predefine a list of key field names, then decode the JWT payload to get the JSON object, traverse the field names and match them with the predefined list, so as to identify and extract the values ​​of these key fields for subsequent security testing;

[0031] Payload permission control test: Pre-build a permission level model and perform systematic testing on permission-related fields in the JWT payload. For the role field, enumerate common permission levels or numeric levels and replace the role value in the original JWT in sequence. For the permissions field, increase or decrease permissions to verify the system's permission control mechanism. After each modification, resend the request with the updated JWT and determine whether there is a permission control defect based on the server response.

[0032] Payload content test: While keeping the header algorithm unchanged, various injection modifications are performed on the fields in the JWT payload, including SQL injection, command injection, and XSS injection, and the signature is recalculated according to the currently used algorithm type to finally generate a new JWT; in addition, standard fields including the timestamp field are also modified to test the server-side validity verification mechanism.

[0033] Furthermore, the verification method of step S3 includes: verifying various JWT vulnerabilities one by one by sending a constructed HTTP / HTTPS request, including: one or more of algorithm vulnerabilities, key vulnerabilities, payload vulnerabilities, injection vulnerabilities, and business logic vulnerabilities.

[0034] Furthermore, in step S3, an intelligent strategy is used to apply and optimize test cases, specifically including:

[0035] a. Layered test payload generation: Based on the predefined JWT vulnerability feature library, basic test cases are constructed. For different types of vulnerabilities, according to the JWT structural features extracted from normal requests, combined with the current business scenarios, payload content that conforms to business logic is dynamically generated to ensure the practicality and effectiveness of the test cases;

[0036] b. Adaptive test optimization: record the response characteristics of each test. If a certain type of test obtains an abnormal response, further test the type and adjust the payload structure according to the server's error prompts.

[0037] c. Request validity assurance: extract and retain the session information in the original request, analyze the business process relevance, ensure that the test request complies with the business process sequence, maintain necessary status information, and determine whether the request is processed correctly through response analysis;

[0038] d. During the verification process, obtain and analyze the response status code, response header, and response body content returned by the server, and perform in-depth comparative analysis with the original data packet captured in step S1. By comparing the response characteristics and resource access results of users with different permissions, identify the unauthorized access and unauthorized access logic vulnerabilities in the system.

[0039] Furthermore, the step S3 also includes:

[0040] The verification results are standardized and collated to generate a standardized report including vulnerability type, verification status, and impact level factors.

[0041] The JWT vulnerability automated mining system using the above method includes:

[0042] Dynamic monitoring module, which is used to continuously track and record complete network communication data, and monitor and extract JWT tokens in target applications in real time;

[0043] The data analysis and processing module is used to perform structural analysis on the JWT token and split it into three parts: header, payload, and signature. Vulnerability tests are performed on each part to generate corresponding test cases.

[0044] The vulnerability verification module, as the execution verification unit of the system, is used to automatically verify the test cases output by the data analysis and processing module and standardize the output results.

[0045] Compared with the prior art, the beneficial effects of the present invention are: 1) an intelligent parsing and dynamic adjustment mechanism based on the characteristics of the JWT token is constructed, and the three-segment structure of Header.Payload.Signature of JWT is deeply understood. The fields in the request header are matched according to the characteristics of JWT, and the JWT token is extracted from the Authorization field or custom location of the HTTP request header, so as to realize the identification of key information in the request body (such as role, id, permissions, etc.), and implement differentiated verification strategies accordingly; at the same time, in the data analysis and processing step, dynamic adjustment of the header algorithm and payload content is realized based on the characteristics of the token structure, which provides reliable test data support for subsequent security assessments.

[0046] 2) Implement a comprehensive security vulnerability detection mechanism based on request features: The system integrates a rich vulnerability feature library and test case set, which not only conducts comprehensive detection of security risks of the JWT token itself, but also conducts in-depth security tests such as SQL injection in combination with payload parameter features. Through multi-dimensional detection strategies, a complete security assessment system is built, which effectively improves the breadth and depth of vulnerability discovery.

[0047] 3) Innovatively integrate dynamic monitoring data and test response results to accurately identify logical vulnerabilities such as unauthorized access and unauthorized access: By comparing and analyzing the response characteristics of users with different permissions, the system can accurately discover logical security risks such as unauthorized access and unauthorized access. This analysis method based on the difference in response characteristics significantly enhances the system's ability to detect logical security vulnerabilities.

[0048] 4) A standardized automated detection process system has been established: By building a complete vulnerability detection framework, the system has achieved full process automation from vulnerability identification to report generation. This not only ensures the standardization and repeatability of the detection process, but also automatically generates professional reports containing detailed vulnerability information, risk assessment and repair suggestions, providing reliable guarantees for the timely discovery and disposal of security risks. BRIEF DESCRIPTION OF THE DRAWINGS

[0049] The above and other objects, features and advantages of the present disclosure will become more apparent through a more detailed description of exemplary embodiments of the present disclosure in conjunction with the accompanying drawings, wherein like reference numerals generally represent like components throughout the exemplary embodiments of the present disclosure.

[0050] Figure 1 The figure is a system composition structure diagram according to an exemplary embodiment of the present disclosure. DETAILED DESCRIPTION

[0051] The preferred embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although the preferred embodiments of the present disclosure are shown in the accompanying drawings, it should be understood that the present disclosure can be implemented in various forms and should not be limited by the embodiments set forth herein. On the contrary, these embodiments are provided to make the present disclosure more thorough and complete, and to fully convey the scope of the present disclosure to those skilled in the art.

[0052] The present disclosure provides a method and system for automatically mining JWT vulnerabilities. According to an exemplary embodiment of the present disclosure, the system composition is as shown in the attached figure. Figure 1 As shown, the overall processing flow is divided into three core parts: dynamic monitoring, data analysis and processing, and vulnerability verification.

[0053] 1. Dynamic monitoring.

[0054] This module (or step) is mainly responsible for real-time monitoring and collection of JWT (JSON Web Token) tokens in the target application. By deploying proxy servers and network packet capture tools, intelligent interception of HTTP / HTTPS protocol transmission data is achieved, including:

[0055] Configure SSL certificates and implement TLS interception in the proxy server, and establish TLS connections with the client and target server as a middleman, so as to decrypt, analyze and re-encrypt HTTPS encrypted traffic. This black-box testing method based on network traffic analysis can effectively identify JWT-related vulnerabilities without accessing the source code of the target website.

[0056] The network packet capture tool uses regular matching to extract the JWT token from the Authorization field and other custom fields in the HTTP request header, and ensures the accuracy of token extraction based on the characteristics of JWT.

[0057] This module will continuously track and record complete network communication data, including key elements such as request URL, request header information, request parameters and response data, providing comprehensive data support for subsequent in-depth analysis and security assessment.

[0058] 2. Data analysis and processing

[0059] This module (or step) is mainly responsible for comprehensive parsing, analysis, and security assessment of captured JWT tokens.

[0060] First, through structured parsing, the token is split into three parts: Header, Payload, and Signature, which are used for in-depth analysis to evaluate the security of the token.

[0061] Then, the system generates test cases through a multi-dimensional layered testing strategy to expand the coverage of vulnerability detection. The specific strategies are as follows:

[0062] a. Basic security vulnerability detection. The system performs systematic testing on the JWT header and signature, including algorithm verification testing, key verification testing, and signature verification testing.

[0063] Algorithm verification test modifies the alg field value to test the algorithm verification mechanism of the server, such as using the none algorithm to bypass signature verification, replacing the asymmetric algorithm (RS256) with a symmetric algorithm (HS256), etc.

[0064] Key verification tests include key brute force cracking, JWK parameter injection, JWKS public key injection, etc.

[0065] Signature verification testing includes removing signatures, modifying signatures, etc.

[0066] After each modification, the system recalculates the signature according to different test scenarios (no signature is required when testing the none algorithm) and generates a new JWT for testing.

[0067] b. Load test, including:

[0068] 1) Payload field identification, used for payload content analysis, identification and extraction of key fields such as role, id, permissions, etc. During the JWT payload parsing process, the system focuses on common custom fields such as role, id, permissions, etc. (these are not JWT standard fields), and uses static rule matching to identify them. Specifically, a set of key field name lists are pre-defined (such as role / roles / user_role, id / user_id / uid, permissions / perms / access, etc.), and then the JSON object is obtained by decoding the JWT payload, traversing the field names and accurately matching them with the predefined list, so as to identify and extract the values ​​of these key fields for subsequent security testing.

[0069] 2) Payload permission control test. The system pre-builds a permission level model and performs systematic testing on permission-related fields in the JWT payload. For the role field, by enumerating common permission levels (such as admin / manager / user, etc.) or numeric levels (such as 1 / 2 / 3, etc.), replace the role value in the original JWT in turn; for the permissions field, by adding permissions (such as adding 'delete' permissions) or reducing permissions (such as removing 'write' permissions) to verify the system's permission control mechanism. After each modification, the system resends the request using the updated JWT, and determines whether there are permission control defects based on the server response.

[0070] 3) Payload content test. While keeping the header algorithm unchanged, the system performs various injection modifications on the fields in the JWT payload, including SQL injection, command injection, XSS injection, etc., and recalculates the signature according to the currently used algorithm type, and finally generates a new JWT; in addition, the system will also modify standard fields such as exp, iat and other timestamp fields to test the server's validity period verification mechanism.

[0071] 3. Vulnerability Verification

[0072] As the execution verification unit of the system, the vulnerability verification module is mainly responsible for automatically verifying the test cases output by the data analysis and processing module and standardizing the output results. This module verifies various JWT vulnerabilities one by one by sending constructed HTTP / HTTPS requests, including security vulnerabilities such as no signature verification, key cracking, JWK parameter injection, algorithm obfuscation, and JWKS public key injection.

[0073] The system uses intelligent strategies to apply and optimize test cases. The specific strategies are as follows:

[0074] a. Layered test payload generation. The system builds basic test cases based on the predefined JWT vulnerability feature library. For different types of vulnerabilities, such as algorithm vulnerabilities, key vulnerabilities, payload vulnerabilities, injection vulnerabilities, and business logic vulnerabilities, the system dynamically generates payload content that conforms to business logic based on the JWT structural features extracted from normal requests and combined with the current business scenarios to ensure the practicality and effectiveness of the test cases.

[0075] b. Adaptive test optimization. The system records the response characteristics of each test (status code, response content, etc.). If a certain type of test obtains an abnormal response, a more in-depth test of that type is performed, and the payload structure is adjusted according to the server's error prompt.

[0076] c. Ensure the validity of the request. The system extracts and retains the session information (such as Cookie, CSRFToken, etc.) in the original request, analyzes the business process relevance, ensures that the test request complies with the business process sequence, maintains the necessary status information (such as login status), and determines whether the request is processed correctly through response analysis.

[0077] During the verification process, the module will obtain and analyze the response status code, response header and response body content returned by the server, and conduct in-depth comparative analysis with the original data packets captured by the dynamic monitoring module. By comparing the response characteristics and resource access results of users with different permissions, it can accurately identify logical vulnerabilities such as unauthorized access and unauthorized access in the system.

[0078] In addition, the module will standardize the verification results and generate a standardized report containing elements such as vulnerability type, verification status, and impact level.

[0079] The implementation process of this embodiment is as follows:

[0080] (1) Hardware and software preparation

[0081] Hardware equipment: A computer.

[0082] Software environment: Access the website that needs to be tested and install the JWT vulnerability automated mining tool described in this disclosure.

[0083] (2) Actual operation process:

[0084] Open the website you want to test.

[0085] Start the vulnerability mining tool and enter the following information in the tool interface: URL address of the target website.

[0086] It can be seen that this embodiment designs three core functional units / steps: dynamic monitoring, data analysis and processing, and vulnerability verification. Through modular layered design and deep linkage mechanism, the full process of JWT vulnerability automatic mining is realized. Its innovative features are mainly reflected in:

[0087] Deploy proxy servers and network packet capture tools to achieve intelligent data interception and continuous tracking;

[0088] Design intelligent parsing and dynamic modification mechanism for JWT parameters;

[0089] Build a comprehensive JWT security assessment system;

[0090] Introduce a dynamic comparative analysis mechanism to accurately identify a variety of vulnerabilities.

[0091] The above technical scheme is only an exemplary embodiment of the present invention. For those skilled in the art, it is easy to make various types of improvements or modifications based on the application methods and principles disclosed in the present invention, and it is not limited to the method described in the above specific embodiment of the present invention. Therefore, the method described above is only preferred and does not have a restrictive meaning.

Claims

1. A JWT vulnerability automated mining method, comprising the following steps: S1, dynamic monitoring: continuously track and record complete network communication data, and monitor and extract JWT tokens in the target application in real time; S2, data analysis and processing: perform structural analysis on the JWT token and split it into header, payload, and signature, i.e., header, payload, and signature. Vulnerability tests are performed on each part to generate corresponding test cases. S3, vulnerability verification: automatically verify the test cases output by the data analysis and processing steps and output the results.

2. The method according to claim 1, characterized in that The method of step S1 comprises: Deploy proxy servers and network packet capture tools to implement intelligent interception of data transmitted via HTTP / HTTPS protocols, including: Configure SSL certificates and implement TLS interception in the proxy server, and establish TLS connections with the client and target server as a middleman to decrypt, analyze, and re-encrypt HTTPS encrypted traffic; The network packet capture tool extracts the JWT token from the Authorization field and other custom fields in the HTTP request header based on the characteristics of JWT.

3. The method according to claim 1, characterized in that The step S2 specifically includes: S21, JWT decoding and parsing: perform structural parsing on the JWT token and split it into three parts: header, payload, and signature; S22, basic security vulnerability detection, is used to perform systematic testing of JWT headers and signatures; S23, JWT payload test, includes the following steps: Payload field identification: JWT payload content analysis, identification and extraction of custom key fields in JWT, including one or more of role, id, and permissions; Payload permission control test: Systematically test the permission-related fields in the JWT payload; Payload content testing: While keeping the header algorithm unchanged, perform security vulnerability testing by making various injection modifications to the fields in the JWT payload.

4. The method according to claim 3, characterized in that The basic security vulnerability detection in step S22 includes: Algorithm verification test, key verification test and signature verification test, where: Algorithm verification test: modify the alg field value to test the algorithm verification mechanism on the server side, including: using the none algorithm to bypass signature verification, and replacing the asymmetric algorithm with a symmetric algorithm; Key verification test, including: key brute force cracking, JWK parameter injection, JWKS public key injection; Signature verification test, including: removing signature, modifying signature; After each modification, the signature is recalculated according to different test scenarios and a new JWT is generated for testing. No signature is required when testing the none algorithm.

5. The method according to claim 3, characterized in that: The specific method of the JWT load test in step S23 includes: Payload field identification: predefine a list of key field names, then decode the JWT payload to get the JSON object, traverse the field names and match them with the predefined list, so as to identify and extract the values ​​of these key fields for subsequent security testing; Payload permission control test: Pre-build a permission level model and perform systematic testing on permission-related fields in the JWT payload. For the role field, enumerate common permission levels or numeric levels and replace the role value in the original JWT in sequence. For the permissions field, increase or decrease permissions to verify the system's permission control mechanism. After each modification, resend the request with the updated JWT and determine whether there is a permission control defect based on the server response. Payload content test: While keeping the header algorithm unchanged, various injection modifications are performed on the fields in the JWT payload, including SQL injection, command injection, and XSS injection, and the signature is recalculated according to the currently used algorithm type to finally generate a new JWT; in addition, standard fields including the timestamp field are also modified to test the server-side validity verification mechanism.

6. The method according to claim 1, characterized in that The verification method of step S3 includes: verifying various JWT vulnerabilities one by one by sending a constructed HTTP / HTTPS request, including: one or more of algorithm vulnerabilities, key vulnerabilities, payload vulnerabilities, injection vulnerabilities, and business logic vulnerabilities.

7. The method according to claim 1 or 6, characterized in that: In step S3, an intelligent strategy is used to apply and optimize test cases, specifically including: a. Layered test payload generation: Based on the predefined JWT vulnerability feature library, basic test cases are constructed. For different types of vulnerabilities, according to the JWT structural features extracted from normal requests, combined with the current business scenarios, payload content that conforms to business logic is dynamically generated to ensure the practicality and effectiveness of the test cases; b. Adaptive test optimization: record the response characteristics of each test. If a certain type of test obtains an abnormal response, further test the type and adjust the payload structure according to the server's error prompts. c. Request validity assurance: extract and retain the session information in the original request, analyze the business process relevance, ensure that the test request complies with the business process sequence, maintain necessary status information, and determine whether the request is processed correctly through response analysis; d. During the verification process, obtain and analyze the response status code, response header, and response body content returned by the server, and perform in-depth comparative analysis with the original data packet captured in step S1. By comparing the response characteristics and resource access results of users with different permissions, identify the unauthorized access and unauthorized access logic vulnerabilities in the system.

8. The method according to claim 1, characterized in that The step S3 also includes: The verification results are standardized and collated to generate a standardized report including vulnerability type, verification status, and impact level factors.

9. A JWT vulnerability automatic mining system using the method described in any one of claims 1 to 8, characterized in that: include: Dynamic monitoring module, which is used to continuously track and record complete network communication data, and monitor and extract JWT tokens in target applications in real time; The data analysis and processing module is used to perform structural analysis on the JWT token and split it into three parts: header, payload, and signature. Vulnerability tests are performed on each part to generate corresponding test cases. The vulnerability verification module, as the execution verification unit of the system, is used to automatically verify the test cases output by the data analysis and processing module and standardize the output results.