Vulnerability detection method and device of API (Application Program Interface) and nonvolatile storage medium
By using the trained vulnerability detection model to perform multi-dimensional vulnerability detection on API attribute information, the problem of low accuracy of vulnerability detection in the existing technology is solved, and more accurate API vulnerability detection is achieved.
Patent Information
- Application Number
- CN202510176600.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-17
- Publication Date
- 2025-05-16
AI Technical Summary
When detecting API vulnerabilities, the prior art usually only considers the vulnerability attributes of a single dimension, and cannot fully consider the multi-dimensional attributes, resulting in low accuracy of vulnerability detection.
By obtaining the API attribute information of the API to be detected, the trained vulnerability detection model is used to detect this information to obtain multi-dimensional vulnerability attribute information. This model trains the initial model through historical vulnerability data to ensure the accuracy of the detection results.
Multi-dimensional attribute detection of API vulnerabilities is realized, the accuracy of vulnerability detection is improved, and the vulnerabilities in the API can be more comprehensively identified.
Smart Images

Figure CN120012113A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of information technology, and in particular to an API vulnerability detection method, device and non-volatile storage medium. Background Art
[0002] As network attack methods continue to evolve and innovate, the security protection technology of Application Programming Interface (API) must also be continuously updated and improved to cope with increasingly complex network threats. Currently, the main types of attacks faced by API include authentication bypass, Structured Query Language (SQL) injection, and cross-site scripting attacks, which may lead to serious security issues such as API service interruption and sensitive data leakage. Therefore, it is crucial to adopt effective vulnerability detection technology to prevent these attacks.
[0003] The research background of API security issues covers many aspects, including the operation mechanism of API, the challenges of large-scale data exchange, the diversity of API, and the growing means of API attacks. These challenges require the development of more effective API vulnerability detection technologies. In order to improve the security and reliability of APIs, researchers have proposed a variety of new API vulnerability detection methods and technologies, including: API vulnerability detection technologies based on static and dynamic analysis or the use of automated vulnerability detection tools. However, when performing vulnerability detection on APIs in related technologies, they usually only detect vulnerability attributes in a single dimension, and fail to fully consider the multi-dimensional attributes of vulnerability detection, resulting in low accuracy of vulnerability detection.
[0004] To address the above-mentioned problems, no effective solution has been proposed yet. Summary of the invention
[0005] The embodiments of the present application provide an API vulnerability detection method, device and non-volatile storage medium to at least solve the technical problem that when performing vulnerability detection on an API in the related art, usually only single-dimensional vulnerability attributes are detected, and the multi-dimensional attributes of vulnerability detection cannot be fully considered, resulting in low accuracy of vulnerability detection.
[0006] According to one aspect of an embodiment of the present application, a method for vulnerability detection of an API is provided, including: obtaining API attribute information corresponding to an API to be detected; performing vulnerability detection on the API attribute information using a vulnerability detection model to obtain a vulnerability detection result of the API to be detected, wherein the vulnerability detection model is obtained by training an initial vulnerability detection model using historical vulnerability data, and the vulnerability detection result includes multi-dimensional vulnerability attribute information corresponding to the API to be detected.
[0007] In some embodiments of the present application, a vulnerability detection model is obtained in the following manner: obtaining historical vulnerability data; determining annotated historical vulnerability data based on the historical vulnerability data, wherein the annotated historical vulnerability data includes annotated data and historical vulnerability data, the annotated data includes correct multi-dimensional vulnerability attribute information corresponding to the historical vulnerability data, the multi-dimensional vulnerability attribute information includes at least the vulnerability type, the danger level corresponding to the vulnerability type, and the vulnerability position of the vulnerability corresponding to the vulnerability type; dividing the annotated historical vulnerability data into an initial training set and a test set according to a preset ratio; determining the initial training set and the feature set corresponding to the initial training set as a training set; training the initial vulnerability detection model based on the training set, and stopping the training until the training accuracy reaches a preset accuracy threshold, to obtain a vulnerability detection model.
[0008] In some embodiments of the present application, the feature set corresponding to the initial training set is determined in the following manner: using a recursive feature elimination algorithm to perform feature selection on the training set to obtain a feature subset; and a feature importance score for each feature in the feature subset; based on the feature importance score, deleting a preset number of features from the feature subset to obtain a feature set.
[0009] In some embodiments of the present application, an initial vulnerability detection model is trained based on a training set until the training accuracy reaches a preset accuracy threshold and the training is stopped to obtain a vulnerability detection model, including: iteratively executing the following process until the training accuracy reaches a preset accuracy threshold and the training is stopped to obtain a vulnerability detection model: training the initial vulnerability detection model based on the training set to obtain an initial detection result, wherein the initial detection result includes initial multi-dimensional vulnerability attribute information corresponding to the training set; determining the number of historical vulnerability data that matches the initial detection result with the labeled data corresponding to the labeled historical vulnerability data as the number of correct detections; determining the training accuracy based on a functional relationship between the number of correct detections and the total number of historical vulnerability data in the training set.
[0010] In some embodiments of the present application, the method also includes: determining the detection values of multiple preset performance indicators of the vulnerability detection model based on the test set, and re-training the vulnerability detection model when the detection value of any preset performance indicator is less than the corresponding preset indicator threshold.
[0011] In some embodiments of the present application, the method also includes: updating the vulnerability detection results determined by the vulnerability detection model to the historical vulnerability data every first preset time period; obtaining the historical vulnerability data within a third preset time period as a verification data set every second preset time period; determining a confusion matrix based on the verification data set, wherein the elements in the confusion matrix include the number of positive samples and negative samples, the positive samples are the historical vulnerability data in the verification data set that are correctly detected by the vulnerability detection model, and the negative samples are the historical vulnerability data in the verification data set that are incorrectly detected by the vulnerability detection model; determining the detection accuracy based on the confusion matrix; and when the detection accuracy is less than a preset detection rate threshold, retraining the vulnerability detection model based on the historical vulnerability data.
[0012] In some embodiments of the present application, a vulnerability detection model is used to perform vulnerability detection on API attribute information to obtain vulnerability detection results of the API to be detected, including: determining the vulnerability detection sub-vector corresponding to the vulnerability attribute information of each dimension in the multi-dimensional vulnerability attribute information based on the task layer of the vulnerability detection model, wherein the task layer includes a preset number of sub-task layers, and each sub-task layer is used to perform vulnerability detection on the vulnerability attribute information of one dimension in the multi-dimensional vulnerability attribute information based on the corresponding target loss function to obtain a vulnerability detection sub-vector of one dimension; summarizing the vulnerability detection sub-vectors of the dimensions corresponding to the preset number of sub-task layers, and combining the vulnerability detection sub-vectors of the dimensions corresponding to the preset number of sub-task layers into a vulnerability detection vector; wherein each element in the vulnerability detection vector corresponds to the vulnerability attribute information of one dimension; and determining the vulnerability detection results based on the vulnerability detection vector.
[0013] In some embodiments of the present application, after determining the vulnerability detection result of the API to be detected based on the attribute information and the vulnerability detection model, the method also includes: generating alarm information based on the vulnerability detection result, wherein the alarm information at least includes the alarm information and the processing method; and pushing the alarm information to the user terminal.
[0014] According to another aspect of an embodiment of the present application, there is also provided an API vulnerability detection device, including: an acquisition module, used to obtain API attribute information corresponding to the API to be detected; a detection module, used to perform vulnerability detection on the API attribute information using a vulnerability detection model, and obtain vulnerability detection results of the API to be detected, wherein the vulnerability detection model is obtained by training an initial vulnerability detection model through historical vulnerability data, and the vulnerability detection results include multi-dimensional vulnerability attribute information corresponding to the API to be detected.
[0015] According to another aspect of an embodiment of the present application, a non-volatile storage medium is provided, in which a program is stored, wherein when the program is running, a device where the non-volatile storage medium is located is controlled to execute the above-mentioned API vulnerability detection method.
[0016] According to another aspect of an embodiment of the present application, there is also provided an electronic device, including: a memory and a processor, the processor being used to run a program stored in the memory, wherein the above-mentioned API vulnerability detection method is executed when the program is running.
[0017] According to another aspect of an embodiment of the present application, a computer program product is also provided, including computer instructions, which implement the above-mentioned API vulnerability detection method when executed by a processor.
[0018] In an embodiment of the present application, the API attribute information corresponding to the API to be detected is obtained; and a vulnerability detection model is used to perform vulnerability detection on the API attribute information to obtain a vulnerability detection result of the API to be detected, wherein the vulnerability detection model is obtained by training an initial vulnerability detection model through historical vulnerability data, and the vulnerability detection result includes multi-dimensional vulnerability attribute information corresponding to the API to be detected. The multi-dimensional vulnerability attribute information corresponding to the API to be detected is obtained through the vulnerability detection model, thereby solving the technical problem that when performing vulnerability detection on the API in the related technology, usually only a single-dimensional vulnerability attribute is detected, and the multi-dimensional attributes of the vulnerability detection cannot be fully considered, resulting in low accuracy of the vulnerability detection. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:
[0020] Figure 1 It is a hardware structure block diagram of a computer terminal for implementing an API vulnerability detection method provided in an embodiment of the present application;
[0021] Figure 2 is a flow chart of an API vulnerability detection method according to an embodiment of the present application;
[0022] Figure 3 is a flow chart of a vulnerability detection model training according to an embodiment of the present application;
[0023] Figure 4 is a flow chart of another API vulnerability detection method according to an embodiment of the present application;
[0024] Figure 5 It is a structural diagram of an API vulnerability detection device according to an embodiment of the present application. DETAILED DESCRIPTION
[0025] In order to enable those skilled in the art to better understand the solution of the present application, the technical solution in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of the present application.
[0026] The information collected in the embodiments of the present application is information and data authorized by the user or fully authorized by all parties, and the collection, storage, use, processing, transmission, provision, disclosure and application of the relevant data comply with the relevant laws, regulations and standards of the relevant regions, take necessary confidentiality measures, do not violate public order and good morals, and provide corresponding operation entrances for users to choose to authorize or reject automated decision-making results; if the user chooses to reject, the expert decision-making process will be entered.
[0027] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device comprising a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0028] In order to better understand the embodiments of the present application, the technical terms involved in the embodiments of the present application are explained as follows:
[0029] Application Programming Interface (API): API is a convention or interface that enables software to communicate and interact with each other. It defines the methods and rules for how applications interact with operating systems, libraries, or other services. Through API, developers can use predefined functions or methods to access and use a range of functions without having to understand their internal working principles, thereby simplifying the development process and improving code reuse and interoperability between systems.
[0030] In the related art, the research background of API security issues covers many aspects, including the operating mechanism of API, the challenges of large-scale data exchange, the diversity of API, and the growing means of API attacks. These challenges require the development of more effective API vulnerability detection technology. When performing vulnerability detection on API in the related art, usually only single-dimensional vulnerability attributes are detected, and the multi-dimensional attributes of vulnerability detection cannot be fully considered, resulting in low accuracy of vulnerability detection. In order to solve this problem, a relevant solution is provided in the embodiment of the present application, which is described in detail below.
[0031] According to an embodiment of the present application, an embodiment of an API vulnerability detection method, device and non-volatile storage medium is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.
[0032] The method embodiments provided in the embodiments of the present application can be executed in a computer terminal or a similar computing device. Figure 1 The hardware structure block diagram of a computer terminal for implementing an API vulnerability detection method is shown. Figure 1 As shown, the computer terminal 10 may include one or more (102a, 102b, ..., 102n are used to illustrate) processors 102 (the processor 102 may include but is not limited to a processing device such as a microprocessor MCU or a programmable logic device FPGA), a memory 104 for storing data, and a transmission device 106 for communication functions. In addition, it may also include: a display, an input / output interface (I / O interface), a universal serial bus (USB) port (which may be included as one of the ports of the BUS bus), a network interface, a power supply and / or a camera. It can be understood by those skilled in the art that Figure 1 The structure shown is only for illustration and does not limit the structure of the above electronic device. Figure 1 More or fewer components as shown, or with Figure 1 Different configurations are shown.
[0033] It should be noted that the one or more processors 102 and / or other data processing circuits described above may generally be referred to herein as "data processing circuits". The data processing circuits may be embodied in whole or in part as software, hardware, firmware, or any other combination thereof. In addition, the data processing circuit may be a single independent processing module, or may be incorporated in whole or in part into any of the other components in the computer terminal 10. As described in the embodiments of the present application, the data processing circuit acts as a processor control (e.g., selection of a variable resistor terminal path connected to an interface).
[0034] The memory 104 can be used to store software programs and modules of application software, such as the program instructions / data storage device corresponding to the vulnerability detection method of the API in the embodiment of the present application. The processor 102 executes various functional applications and data processing by running the software programs and modules stored in the memory 104, that is, the vulnerability detection method of the API described above is implemented. The memory 104 may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 104 may further include a memory remotely arranged relative to the processor 102, and these remote memories may be connected to the computer terminal 10 via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0035] The transmission device 106 is used to receive or send data via a network. The specific example of the above network may include a wireless network provided by a communication provider of the computer terminal 10. In one example, the transmission device 106 includes a network adapter (Network Interface Controller, NIC), which can be connected to other network devices through a base station so as to communicate with the Internet. In one example, the transmission device 106 can be a radio frequency (RF) module, which is used to communicate with the Internet wirelessly.
[0036] The display may be, for example, a touch screen liquid crystal display (LCD) that enables a user to interact with a user interface of the computer terminal 10 .
[0037] In the above operating environment, an embodiment of the present application provides an embodiment of an API vulnerability detection method. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.
[0038] like Figure 2FIG. 1 is a flowchart of an API vulnerability detection method provided in an embodiment of the present application, including:
[0039] Step S202, obtaining API attribute information corresponding to the API to be detected.
[0040] In the technical solution provided in step S202, API attribute information refers to various types of data and descriptions related to the API to be detected, and the API attribute information includes but is not limited to the following specific contents: API metadata: including basic information such as the name, version number, description, author, and update date of the API. Request and response data: API request parameter information (for example, Hyper Text Transfer Protocol (HTTP) header, Uniform Resource Locator (URL) parameters, etc.) and response information (such as returned HTTP status code, response content, etc.), which can be used to analyze the input and output behavior of the API and detect possible abnormal or unsafe data processing methods. Code structure and logic: API code implementation, including function definition, call flow, permission control, data verification logic, etc. Runtime behavior: API behavior during operation, such as the actual API path called, execution time, exception records, log information, etc. (provided by dynamic analysis tools). Dependent library and framework information: External libraries, frameworks or API calls used by the API. These dependencies may introduce third-party vulnerabilities and are points that need to be paid attention to during detection. Data flow and control flow: The data flow and control flow information within the API helps analyze the source and purpose of the data, as well as potential security issues in the control process. Configuration information: The API's configuration files and environment settings, such as database connection information, key storage methods, error handling strategies, etc. These settings may affect the security of the API. Network communication information: The methods and protocols by which the API communicates with other systems or services, such as whether HTTPS is used, whether there is an appropriate authentication mechanism, etc. Permissions and roles: The API's permission control policies for different users or roles, as well as security settings such as access control lists, are important information for detecting access control vulnerabilities. Error handling and logging: The API's processing logic in error and exception situations, as well as the level of detail in logging, which helps detect whether potential sensitive information leaks are handled correctly.
[0041] Step S204, use the vulnerability detection model to perform vulnerability detection on the API attribute information to obtain the vulnerability detection result of the API to be detected, wherein the vulnerability detection model is obtained by training the initial vulnerability detection model through historical vulnerability data, and the vulnerability detection result includes multi-dimensional vulnerability attribute information corresponding to the API to be detected.
[0042] In the technical solution provided in step S204, a vulnerability detection model is used to perform vulnerability detection on API attribute information to obtain vulnerability detection results of the API to be detected, including: determining the vulnerability detection sub-vector corresponding to the vulnerability attribute information of each dimension in the multi-dimensional vulnerability attribute information based on the task layer of the vulnerability detection model, wherein the task layer includes a preset number of sub-task layers, and each sub-task layer can be an independent classification model, such as a decision tree, a support vector machine or a neural network. Each sub-task layer is used to perform vulnerability detection on the vulnerability attribute information of one dimension in the multi-dimensional vulnerability attribute information based on the corresponding target loss function to obtain a vulnerability detection sub-vector of one dimension; summarize the vulnerability detection sub-vectors of the dimensions corresponding to the preset number (the same as the number of dimensions) of the sub-task layers, and combine the vulnerability detection sub-vectors of the dimensions corresponding to the preset number of sub-task layers into a vulnerability detection vector; wherein each element in the vulnerability detection vector corresponds to the vulnerability attribute information of one dimension; determine the vulnerability detection results based on the vulnerability detection vector.
[0043] The following are specific embodiments:
[0044] The feature extraction layer of the vulnerability detection model (e.g., an improved deep learning model) extracts feature information from the API attribute information, and inputs the API attribute information and feature information into the task layer of the vulnerability detection model. The task layer includes multiple subtask layers, each of which is responsible for detecting vulnerability attribute information of one dimension. Each subtask layer includes two fully connected layers for converting shared features into detection outputs of a specific dimension, and a target loss function selected for the task characteristics. The choice of the target loss function for each task layer depends on the nature of the problem, and each subtask layer is trained independently based on its own target loss function. During training, the subtask layer attempts to minimize the target loss function to optimize the model parameters. For example, for classification tasks (e.g., vulnerability type and vulnerability location of the vulnerability corresponding to the vulnerability type), the cross entropy loss function is used; for regression tasks (e.g., the danger level corresponding to the hole type), the mean square error loss function can be used. The weighted sum of the loss functions of all tasks is used as the overall objective function, for example, the weights can be (0.4, 0.3, 0.3). The design of the loss function should take into account the characteristics of the task to ensure that the model can effectively learn information in each dimension. The training process includes steps such as data set partitioning, feature selection, hyperparameter tuning, and cross-validation. After each subtask layer is trained, it will output a vulnerability detection subvector of one dimension based on the input feature information. The elements of the subvector represent the probability or score of the API belonging to a specific vulnerability attribute in that dimension. For example, the output of the vulnerability type subtask layer may be a vector indicating the probability that the API belongs to the type of SQL injection, cross-site scripting (XSS), etc.
[0045] For example, the multi-dimensional vulnerability attribute information includes three dimensions: vulnerability type, the danger level corresponding to the vulnerability type, and the vulnerability location of the vulnerability corresponding to the vulnerability type. The task layer includes three sub-task layers. When detecting, the neural network model of the vulnerability type sub-task layer outputs a vector with the same length as the number of vulnerability types, and each element represents the probability that the API belongs to this type of vulnerability. For example, for a model containing three types of vulnerabilities, the output sub-vector may be [0.2, 0.7, 0.1], indicating that the probability of the detected API belonging to SQL injection is 0.2, the probability of belonging to Cross-Site Scripting (XSS) is 0.7, and the probability of belonging to command injection is 0.1. The fusion layer of the vulnerability detection model is responsible for fusing the vulnerability detection sub-vectors from different sub-task layers to generate the final vulnerability detection results. The fusion strategy can be weighted summation or decision-making based on specific rules. The decision-making of specific rules includes threshold rules: only when the probability of the model detecting a certain vulnerability type or danger level exceeds this threshold, it is considered a real vulnerability. Position-related rules: For the output of the vulnerability location subtask layer, position rules can be set to specify the processing priority of different locations. For example, an additional fully connected layer can be used to connect the outputs from the vulnerability type layer, the hazard level layer, and the vulnerability location layer, and then processed through an activation function, such as the soft maximum function (Softmax function), to generate the final vulnerability detection vector.
[0046] When the vulnerability detection model is a model implemented based on the random forest algorithm, a preset number of independent random forest models can be created for vulnerability attribute information of one dimension in the multi-dimensional vulnerability attribute information, or a multi-output random forest can be constructed to simultaneously process multiple detection tasks corresponding to the multi-dimensional vulnerability attribute information through the idea of multi-task learning. Specifically: based on a multi-output classifier (MultiOutputClassifier) or a multi-output regressor (MultiOutputRegressor), the single-task random forest is packaged into a multi-task model. For classification tasks (such as vulnerability type, vulnerability location), use MultiOutputClassifier; for regression tasks (such as the danger level corresponding to the vulnerability type), use MultiOutputRegressor. The leaf node of each decision tree will output a vector containing information such as vulnerability type, severity, and location.
[0047] In the technical solution provided in step S204, the vulnerability detection model is obtained in the following manner: obtaining historical vulnerability data; determining the annotated historical vulnerability data based on the historical vulnerability data, wherein the annotated historical vulnerability data includes the annotated data and the historical vulnerability data, the annotated data includes the correct multi-dimensional vulnerability attribute information corresponding to the historical vulnerability data, the multi-dimensional vulnerability attribute information includes at least the vulnerability type, the danger level corresponding to the vulnerability type, and the vulnerability position of the vulnerability corresponding to the vulnerability type; dividing the annotated historical vulnerability data into an initial training set and a test set according to a preset ratio; determining the initial training set and the feature set corresponding to the initial training set as the training set; training the initial vulnerability detection model based on the training set, and stopping the training when the training accuracy reaches a preset accuracy threshold, to obtain the vulnerability detection model.
[0048] In the above steps, the feature set corresponding to the initial training set is determined in the following way: using the recursive feature elimination algorithm to perform feature selection on the training set to obtain a feature subset; determining the feature importance score of each feature in the feature subset based on the initial vulnerability detection model; and deleting a preset number of features from the feature subset based on the feature importance score to obtain a feature set.
[0049] The initial vulnerability detection model is trained based on the training set until the training accuracy reaches a preset accuracy threshold and the training is stopped. There are many ways to implement the vulnerability detection model, for example: the following process is iteratively performed until the training accuracy reaches a preset accuracy threshold and the training is stopped to obtain the vulnerability detection model: the initial vulnerability detection model is trained based on the training set to obtain an initial detection result, wherein the initial detection result includes the initial multi-dimensional vulnerability attribute information corresponding to the training set; the number of historical vulnerability data that matches the initial detection result with the labeled data corresponding to the labeled historical vulnerability data is determined as the number of correct detections; the training accuracy is determined based on the functional relationship between the number of correct detections and the total number of historical vulnerability data in the training set.
[0050] The following are specific embodiments:
[0051] First, perform attribute selection to determine that the vulnerability detection results include attributes in the multi-dimensional vulnerability attribute information corresponding to the API to be detected, such as the multi-dimensional vulnerability attribute information at least selects the vulnerability type, the danger level corresponding to the vulnerability type, and the vulnerability location of the vulnerability corresponding to the vulnerability type. Obtain historical vulnerability data, which includes but is not limited to the description of the vulnerability, the environment in which it occurs, the scope of impact, and the corresponding API attribute information collected using static analysis tools (such as SonarQube) and dynamic analysis tools (such as OWASP ZAP). Clean the collected historical vulnerability data to remove duplicate and invalid data. Then, perform feature extraction on these historical vulnerability data, that is, corresponding to the annotation instructions of professionals, to generate annotation data. The annotation process involves matching each historical vulnerability data with the correct multi-dimensional vulnerability attribute information, including the specific type of each historical vulnerability data (such as SQL injection, XSS attack, etc.), danger level (such as high risk, medium risk, low risk) and the location of the vulnerability (client, server, database, etc.). This step is crucial to establishing a training set, because the correct annotation data is a guide for model learning. The annotation data can also include the frequency of the vulnerability type corresponding to each historical vulnerability data in all vulnerability types and the distribution of danger levels.
[0052] In the model design phase, a vulnerability detection model is designed based on the multi-dimensional vulnerability attribute information determined by attribute selection (for example, the vulnerability detection model is an improved deep learning model or a model implemented based on the random forest algorithm), and the historical vulnerability data is divided into an initial training set and a test set according to a preset ratio (for example, 7:3), and the initial training set and the feature set corresponding to the initial training set are determined as the training set. The feature set corresponding to the initial training set is determined in the following way: the training set is selected using the recursive feature elimination algorithm to obtain a feature subset and a feature importance score of each feature in the feature subset; based on the feature importance score, a preset number of features are deleted from the feature subset to obtain a feature set. Specifically: feature selection using the recursive feature elimination algorithm (RFE for short) is a process of systematically evaluating feature importance and gradually removing the least important features. The RFE algorithm is used in combination with cross validation (CV). First, the historical vulnerability data is preprocessed, including removing missing values and outliers, performing data type conversion (such as one-hot encoding of categorical variables), and possible feature scaling (such as standardization). The RFE algorithm requires a base model to calculate the importance of features. In the vulnerability detection task, classifiers or regressors such as decision trees, random forests, and support vector machines can be used as base models. Here, the random forest classifier is taken as an example. Create an RFE instance, which specifies the base model and the steps for recursively reducing features. Execute the RFE instance. During the fitting process of the RFE algorithm, the base model will be trained multiple times. After each training, one or more of the least important features will be removed until the preset number of features is reached to obtain a feature subset. The importance of the features is calculated in each iteration of the RFE algorithm. Based on the importance score of each feature in the last iteration of the RFE algorithm, the features in the feature subset are sorted in descending order according to the importance score, and the features ranked in the top preset number of places are determined as the feature set to find the most valuable features for model training.
[0053] The following process is iterated until the training accuracy reaches a preset accuracy threshold, and the training is stopped to obtain a vulnerability detection model: the initial vulnerability detection model is trained based on the training set to obtain an initial detection result, wherein the initial detection result includes the initial multi-dimensional vulnerability attribute information corresponding to the training set (at least including the vulnerability type detected by the initial vulnerability detection model, the danger level corresponding to the vulnerability type, and the vulnerability location of the vulnerability corresponding to the vulnerability type); the number of historical vulnerability data that matches the initial detection result with the annotated data corresponding to the annotated historical vulnerability data (i.e., the number of historical vulnerability data correctly detected by the initial vulnerability detection model) is determined as the number of correct detections; the training accuracy is determined based on the functional relationship between the number of correct detections and the total number of historical vulnerability data in the training set. For example, the functional relationship between the number of correct detections and the total number of historical vulnerability data in the training set is the quotient between the number of correct detections and the total number of historical vulnerability data in the training set, and the training is stopped until the training accuracy reaches a preset accuracy threshold (e.g., 0.9), and the vulnerability detection model is obtained.
[0054] In the above training process, the hyperparameter tuning of the model is performed based on grid search. For example, when the vulnerability detection model is a model implemented based on the random forest algorithm, grid search is used to tune the hyperparameters such as the number and maximum depth of decision trees of the random forest algorithm. When training the training set, the cross-validation method is adopted. The model performance is trained and tested by dividing the training set into several subsets to ensure that the model can perform well on unseen data. For example, 10-fold cross-validation is used to evaluate the generalization ability of the model. The complete training set is randomly divided into 10 subsets of equal size. 9 of the 10 subsets are used as training data, and the remaining 1 subset is used as verification data. This is repeated 10 times, and a different subset is used as verification data each time. In this way, each data instance has the opportunity to become verification data in 10 iterations, so that a more comprehensive model evaluation can be obtained. Figure 3 As shown, it is a flowchart of a vulnerability detection model training according to an embodiment of the present application. When training the vulnerability detection model, firstly, the data set is divided (that is, the historical vulnerability data is divided into an initial training set and a test set according to a preset ratio (for example, 7:3)), and then feature selection is performed (that is, the training set is trained using a recursive feature elimination algorithm), and then model selection is performed to select an initial vulnerability detection model, and finally a cross-validation and training process is performed (that is, the initial vulnerability detection model is trained based on the training set until the training accuracy reaches a preset accuracy threshold, and the training is stopped to obtain a vulnerability detection model. At the same time, when the training set is trained, a cross-validation method is adopted, in which the model performance is trained and tested by dividing the training set into several subsets to ensure that the model can perform well on unseen data).
[0055] After determining the vulnerability detection model, the detection values of multiple preset performance indicators of the vulnerability detection model are determined based on the test set. When the detection value of any preset performance indicator is less than the corresponding preset indicator threshold, the vulnerability detection model is retrained. Specifically, the multiple preset performance indicators may include recall rate, F1 score, receiver operating characteristic curve (ROC Curve, referred to as ROC curve) and area under the curve (Area Under the Curve, referred to as AUC), etc.
[0056] Recall is a measure of the model's ability to correctly identify all positive examples. In the vulnerability detection scenario, recall reflects how many of all the actual vulnerabilities are correctly detected by the model. It is defined as the true positives (the number of positive examples correctly identified by the vulnerability detection model) divided by the sum of true positives and false negatives (the number of positive examples that the vulnerability detection model fails to identify). When the detection value of the recall rate is less than the corresponding preset recall rate indicator threshold, the vulnerability detection model is retrained; the F1 score is the harmonic mean of precision and recall, which is used to find a balance between precision and recall. In the binary classification problem, the F1 score can prevent the model from being biased towards either side in the case of high precision and low recall or high recall and low precision. Among them, Precision is the number of true positives divided by the sum of true positives and false positives (the number of negative examples incorrectly identified by the vulnerability detection model). When the detection value of the F1 score is less than the corresponding preset F1 score indicator threshold, the vulnerability detection model is retrained; Receiver Operating Characteristic Curve (ROC Curve, referred to as ROC curve), ROC curve is used to evaluate the performance of the classifier at different thresholds. It is a two-dimensional graph, where the horizontal axis is the false positive rate (False Positive Rate, referred to as FPR), defined as the false positive divided by the sum of false positives and true instances (actually negative examples but correctly classified); the vertical axis is the true positive rate (True Positive Rate, referred to as TPR). The points on the ROC curve represent the FPR and TPR of the model at different thresholds. A perfect classifier will have a point at the coordinates (0, 1), that is, there are no false positives, but all true positives are correctly classified. Area Under the Curve (AUC) is the area under the ROC curve, which is used to quantify the discrimination ability of the model and its value ranges from 0 to 1. The AUC value reflects the performance of the classifier, especially in terms of the ability to distinguish between positive and negative examples. When the ROC curve and AUC value are used for threshold determination, see whether the corresponding AUC value is less than the preset indicator threshold. When the corresponding AUC value is less than the preset indicator threshold, retrain the vulnerability detection model.
[0057] In order to continuously ensure the detection accuracy of the vulnerability detection model, the vulnerability detection results determined by the vulnerability detection model are updated to the historical vulnerability data every first preset time period; the historical vulnerability data within the third preset time period is obtained as a verification data set every second preset time period; a confusion matrix is determined based on the verification data set, wherein the elements in the confusion matrix include the number of positive samples and negative samples, the positive samples are the historical vulnerability data in the verification data set that the vulnerability detection model detects correctly, and the negative samples are the historical vulnerability data in the verification data set that the vulnerability detection model detects incorrectly; the detection accuracy is determined based on the confusion matrix; the detection accuracy is the ratio of the number of positive samples to the total number of historical vulnerabilities in the verification data set. When the detection accuracy is less than the preset detection rate threshold, the vulnerability detection model is retrained based on the historical vulnerability data.
[0058] The following are specific embodiments:
[0059] Every first preset time period (e.g., 1 week), the vulnerability detection results determined by the vulnerability detection model are updated to the historical vulnerability data; every second preset time period (e.g., 1 month), the historical vulnerability data within the third preset time period (e.g., the past two months) is obtained as a verification data set; based on the verification data set, a confusion matrix is determined, specifically: based on the vulnerability detection results corresponding to the verification data set, the confusion matrix is determined; the confusion matrix is a two-dimensional table, whose rows represent the actual real categories, and the columns represent the categories detected by the vulnerability detection model (i.e., the above-mentioned vulnerability detection results). Each element in the matrix represents the number of samples that actually belong to category (i) but are detected as category (j) by the vulnerability detection model (the samples are the historical vulnerability data in the verification data set), where i and j are the attribute information of any dimension in the multi-dimensional vulnerability attribute information. The elements on the diagonal of the confusion matrix represent the number of correctly classified samples, while the elements on the non-diagonal represent the number of misclassified samples. The elements in the confusion matrix include the number of positive samples and negative samples, and the positive samples are further divided into: True Positive (TP for short): the number of samples correctly detected as positive classes (e.g., APIs that do have vulnerabilities) by the vulnerability detection model. True Negative (TN): The number of samples that the model correctly detects as negative classes (for example, APIs that do not have vulnerabilities).
[0060] Negative samples are further divided into: False Positive (FP): The number of samples that the vulnerability detection model mistakenly detects as positive (for example, a vulnerability is detected, but it does not actually exist or the detected vulnerability is wrong), also known as the first type of error. False Negative (FN): The number of samples that the vulnerability detection model mistakenly detects as negative (for example, a vulnerability is detected but it does not actually exist), also known as the second type of error. The confusion matrix is an (n×n) matrix, where n is the number of categories in the classification problem (that is, the dimension in the multi-dimensional vulnerability attribute information). For a binary classification problem, the confusion matrix will be a 2x2 matrix; for a multi-classification problem, it will be a matrix of larger dimensions. For example, if we are evaluating the detection performance of the model for API vulnerability types (for example, API vulnerability types are SQL injection, XSS, no vulnerability), the confusion matrix is shown in Table 1 below:
[0061] Table 1
[0062]
[0063] In this matrix: TP1 represents the number of samples that are actually SQL injections and are correctly detected as SQL injections. TP2 represents the number of samples that are actually XSS vulnerabilities and are correctly detected as XSS vulnerabilities. TN3 represents the number of samples that are actually not vulnerable and are correctly detected as not vulnerable. FP1 represents the number of samples that are actually XSS vulnerabilities but are incorrectly detected as SQL injections. FP2 represents the number of samples that are actually not vulnerable but are incorrectly detected as SQL injections. FP3 represents the number of samples that are actually SQL injections but are incorrectly detected as XSS vulnerabilities. FP4 represents the number of samples that are actually not vulnerable but are incorrectly detected as XSS vulnerabilities. FN1 represents the number of samples that are actually SQL injections but are incorrectly detected as not vulnerable. FN2 represents the number of samples that are actually XSS vulnerabilities but are incorrectly detected as not vulnerable.
[0064] The detection accuracy is determined based on the confusion matrix, and the detection accuracy is the ratio of the number of correctly detected samples (TP+TN) to the total number of historical vulnerabilities in the verification data set. When the detection accuracy is less than a preset detection rate threshold (e.g., 0.9), the vulnerability detection model is retrained based on the historical vulnerability data.
[0065] After determining the vulnerability detection results of the API to be detected based on the attribute information and the vulnerability detection model, generate an alarm message based on the vulnerability detection results, where the alarm message at least includes the alarm message and the processing method (the processing method can be specific repair steps, mitigation measures or links to related resources to help users quickly respond to and solve security issues); push the alarm message to the user terminal. When pushing the alarm message, the priority and frequency of the alarm are also taken into account to avoid generating too many alarms and causing users to ignore important information. For example, high-risk vulnerabilities should be notified immediately, while low-risk vulnerabilities can be summarized into daily or weekly reports.
[0066] The present application also provides a flowchart of another API vulnerability detection method, such as Figure 4 As shown, first, attribute selection is performed, that is, attribute selection is performed to determine that the vulnerability detection result includes the attributes in the multi-dimensional vulnerability attribute information corresponding to the API to be detected, such as the multi-dimensional vulnerability attribute information at least selects the vulnerability type, the danger level corresponding to the vulnerability type, and the vulnerability location of the vulnerability corresponding to the vulnerability type. Then the model training process begins: data collection (i.e., the acquisition of historical vulnerability data as mentioned above), data preprocessing, and feature extraction (i.e., the use of the recursive feature elimination algorithm training set for feature selection as mentioned above), model design (i.e., the model design stage as mentioned above, the vulnerability detection model is designed based on the multi-dimensional vulnerability attribute information determined by the attribute selection), and then model training is performed (i.e., the initial vulnerability detection model is trained based on the training set as mentioned above, and the training is stopped when the training accuracy reaches the preset accuracy threshold to obtain the vulnerability detection model), and then model evaluation is performed (i.e., the detection values of multiple preset performance indicators of the vulnerability detection model are determined based on the test set as mentioned above, and when the detection value of any preset performance indicator is less than the corresponding preset indicator threshold, the model is re-evaluated). Training the vulnerability detection model) and application optimization (i.e., updating the vulnerability detection results determined by the vulnerability detection model to the historical vulnerability data every first preset time period; obtaining the historical vulnerability data within a third preset time period as a verification data set every second preset time period; determining a confusion matrix based on the verification data set, wherein the elements in the confusion matrix include the number of positive samples and negative samples, the positive samples are the historical vulnerability data in the verification data set that the vulnerability detection model detects correctly, and the negative samples are the historical vulnerability data in the verification data set that the vulnerability detection model detects incorrectly; determining the detection accuracy based on the confusion matrix; and when the detection accuracy is less than a preset detection rate threshold, retraining the vulnerability detection model based on the historical vulnerability data).
[0067] The present application embodiment provides a schematic diagram of the structure of an API vulnerability detection device, such as Figure 5 As shown, including:
[0068] The acquisition module 502 is used to acquire API attribute information corresponding to the API to be detected.
[0069] The detection module 504 is used to perform vulnerability detection on the API attribute information using a vulnerability detection model to obtain vulnerability detection results of the API to be detected, wherein the vulnerability detection model is obtained by training an initial vulnerability detection model through historical vulnerability data, and the vulnerability detection results include multi-dimensional vulnerability attribute information corresponding to the API to be detected.
[0070] The detection module 504 is also used to obtain historical vulnerability data; determine the annotated historical vulnerability data based on the historical vulnerability data, wherein the annotated historical vulnerability data includes the annotated data and the historical vulnerability data, the annotated data includes the correct multi-dimensional vulnerability attribute information corresponding to the historical vulnerability data, and the multi-dimensional vulnerability attribute information includes at least the vulnerability type, the danger level corresponding to the vulnerability type, and the vulnerability position of the vulnerability corresponding to the vulnerability type; divide the annotated historical vulnerability data into an initial training set and a test set according to a preset ratio; determine the initial training set and the feature set corresponding to the initial training set as the training set; train the initial vulnerability detection model based on the training set, and stop the training when the training accuracy reaches a preset accuracy threshold to obtain a vulnerability detection model.
[0071] The detection module 504 is also used to perform feature selection using a recursive feature elimination algorithm training set to obtain a feature subset; determine the feature importance score of each feature in the feature subset based on the initial vulnerability detection model; and delete a preset number of features from the feature subset based on the feature importance score to obtain a feature set.
[0072] The detection module 504 is also used to iteratively execute the following process until the training accuracy reaches a preset accuracy threshold, and the training is stopped to obtain a vulnerability detection model: the initial vulnerability detection model is trained based on the training set to obtain an initial detection result, wherein the initial detection result includes the initial multi-dimensional vulnerability attribute information corresponding to the training set; the number of historical vulnerability data that matches the initial detection result with the annotated data corresponding to the annotated historical vulnerability data is determined as the number of correct detections; the training accuracy is determined based on the functional relationship between the number of correct detections and the total number of historical vulnerability data in the training set.
[0073] It should be noted that Figure 5 The API vulnerability detection device shown is used to perform Figure 2 The vulnerability detection method of the API shown, therefore Figure 2 The relevant explanations in the vulnerability detection method of the API in are also applicable to the vulnerability detection device and will not be repeated here.
[0074] It should be noted that the various modules in the vulnerability detection device of the above-mentioned API can be program modules (for example, a set of program instructions that implement a certain specific function) or hardware modules. For the latter, it can be expressed in the following forms, but is not limited to this: the expression form of each of the above-mentioned modules is a processor, or the functions of each of the above-mentioned modules are implemented by a processor.
[0075] The embodiment of the present application also provides a non-volatile storage medium, the non-volatile storage medium includes a stored program, wherein when the program is running, the device where the non-volatile storage medium is located is controlled to execute the above API vulnerability detection device. For example, obtain API attribute information corresponding to the API to be detected; use a vulnerability detection model to perform vulnerability detection on the API attribute information to obtain a vulnerability detection result of the API to be detected, wherein the vulnerability detection model is obtained by training an initial vulnerability detection model with historical vulnerability data, and the vulnerability detection result includes multi-dimensional vulnerability attribute information corresponding to the API to be detected.
[0076] The embodiment of the present application also provides an electronic device, the electronic device includes a processor, the processor is used to run a program, wherein the above API vulnerability detection device is executed when the program is running. For example, the API attribute information corresponding to the API to be detected is obtained; the vulnerability detection model is used to perform vulnerability detection on the API attribute information to obtain the vulnerability detection result of the API to be detected, wherein the vulnerability detection model is obtained by training the initial vulnerability detection model with historical vulnerability data, and the vulnerability detection result includes multi-dimensional vulnerability attribute information corresponding to the API to be detected.
[0077] According to another aspect of the embodiment of the present application, a computer program product is also provided, including a computer program, which implements the above API vulnerability detection device when executed by a processor. For example, obtain API attribute information corresponding to the API to be detected; use a vulnerability detection model to perform vulnerability detection on the API attribute information to obtain a vulnerability detection result of the API to be detected, wherein the vulnerability detection model is obtained by training an initial vulnerability detection model with historical vulnerability data, and the vulnerability detection result includes multi-dimensional vulnerability attribute information corresponding to the API to be detected.
[0078] In the above embodiments of the present application, the description of each embodiment has its own emphasis. For parts that are not described in detail in a certain embodiment, please refer to the relevant description of other embodiments.
[0079] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are only schematic. For example, the division of the units can be a logical function division. There may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of units or modules, which can be electrical or other forms.
[0080] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple units. Some or all of the units may be selected according to actual needs to achieve the purpose of the present embodiment.
[0081] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of software functional units.
[0082] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the relevant technology or all or part of the technical solution, can be embodied in the form of a software product, which is stored in a storage medium and includes several instructions for a computer device (which can be a personal computer, a server or a network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: U disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), mobile hard disk, disk or optical disk, etc. Various media that can store program codes.
[0083] The above is only a preferred implementation of the present application. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present application. These improvements and modifications should also be regarded as the scope of protection of the present application.
Claims
1. A method for detecting API vulnerabilities, characterized in that: include: Get the API attribute information corresponding to the API to be detected; A vulnerability detection model is used to perform vulnerability detection on the API attribute information to obtain a vulnerability detection result of the API to be detected, wherein the vulnerability detection model is obtained by training an initial vulnerability detection model through historical vulnerability data, and the vulnerability detection result includes multi-dimensional vulnerability attribute information corresponding to the API to be detected.
2. The method according to claim 1, characterized in that The vulnerability detection model is obtained in the following way: Get historical vulnerability data; Determine the annotated historical vulnerability data based on the historical vulnerability data, wherein the annotated historical vulnerability data includes the annotated data and the historical vulnerability data, the annotated data includes the correct multi-dimensional vulnerability attribute information corresponding to the historical vulnerability data, and the multi-dimensional vulnerability attribute information includes at least the vulnerability type, the danger level corresponding to the vulnerability type, and the vulnerability position of the vulnerability corresponding to the vulnerability type; Dividing the annotated historical vulnerability data into an initial training set and a test set according to a preset ratio; Determine the initial training set and the feature set corresponding to the initial training set as a training set; The initial vulnerability detection model is trained based on the training set, and the training is stopped when the training accuracy reaches a preset accuracy threshold, thereby obtaining the vulnerability detection model.
3. The method according to claim 2, characterized in that The feature set corresponding to the initial training set is determined in the following way: Perform feature selection on the training set using a recursive feature elimination algorithm to obtain a feature subset and a feature importance score of each feature in the feature subset; A preset number of features are deleted from the feature subset based on the feature importance scores to obtain the feature set.
4. The method according to claim 2, characterized in that: The initial vulnerability detection model is trained based on the training set until the training accuracy reaches a preset accuracy threshold, and the training is stopped to obtain the vulnerability detection model, including: The following process is iterated and performed until the training accuracy reaches the preset accuracy threshold, and the training is stopped to obtain the vulnerability detection model: Training the initial vulnerability detection model based on the training set to obtain an initial detection result, wherein the initial detection result includes initial multi-dimensional vulnerability attribute information corresponding to the training set; Determine the number of historical vulnerability data that matches the initial detection result with the annotated data corresponding to the annotated historical vulnerability data as the number of correct detections; The training accuracy is determined based on a functional relationship between the number of correct detections and the total number of historical vulnerability data in the training set.
5. The method according to claim 2, characterized in that: The method further comprises: The detection values of multiple preset performance indicators of the vulnerability detection model are determined based on the test set, and when the detection value of any one of the preset performance indicators is less than the corresponding preset indicator threshold, the vulnerability detection model is retrained.
6. The method according to claim 2, characterized in that The method further comprises: updating the vulnerability detection result determined by the vulnerability detection model into the historical vulnerability data every first preset time period; Acquire historical vulnerability data within a third preset time period as a verification data set every second preset time period; Determine a confusion matrix based on the validation data set, wherein the elements in the confusion matrix include the number of positive samples and negative samples, the positive samples are historical vulnerability data in the validation data set that are correctly detected by the vulnerability detection model, and the negative samples are historical vulnerability data in the validation data set that are incorrectly detected by the vulnerability detection model; Determining the detection accuracy based on the confusion matrix; When the detection accuracy is less than a preset detection rate threshold, the vulnerability detection model is retrained based on the historical vulnerability data.
7. The method according to claim 1, characterized in that The adopting the vulnerability detection model to perform vulnerability detection on the API attribute information to obtain the vulnerability detection result of the API to be detected includes: Determine a vulnerability detection subvector corresponding to the vulnerability attribute information of each dimension in the multi-dimensional vulnerability attribute information based on the task layer of the vulnerability detection model, wherein the task layer includes a preset number of sub-task layers, each sub-task layer is used to perform vulnerability detection on the vulnerability attribute information of one dimension in the multi-dimensional vulnerability attribute information based on a corresponding target loss function, and obtain a vulnerability detection subvector of one dimension; Summarize the vulnerability detection sub-vectors of the dimensions corresponding to the preset number of sub-task layers, and combine the vulnerability detection sub-vectors of the dimensions corresponding to the preset number of sub-task layers into a vulnerability detection vector; wherein each element in the vulnerability detection vector corresponds to vulnerability attribute information of one dimension; The vulnerability detection result is determined based on the vulnerability detection vector.
8. The method according to claim 1, characterized in that After determining the vulnerability detection result of the API to be detected based on the attribute information and the vulnerability detection model, the method further includes: Generate warning information based on the vulnerability detection result, wherein the warning information at least includes the warning information and a processing method; The warning information is pushed to the user terminal.
9. An API vulnerability detection device, characterized in that: include: The acquisition module is used to obtain the API attribute information corresponding to the API to be detected; The detection module is used to use a vulnerability detection model to perform vulnerability detection on the API attribute information to obtain a vulnerability detection result of the API to be detected, wherein the vulnerability detection model is obtained by training an initial vulnerability detection model through historical vulnerability data, and the vulnerability detection result includes multi-dimensional vulnerability attribute information corresponding to the API to be detected.
10. A non-volatile storage medium, characterized in that: The non-volatile storage medium stores a program, wherein when the program is running, the device where the non-volatile storage medium is located is controlled to execute the API vulnerability detection method described in any one of claims 1 to 8.
11. An electronic device, characterized in that: include: A memory and a processor, wherein the processor is used to run a program stored in the memory, wherein the API vulnerability detection method described in any one of claims 1 to 8 is executed when the program is run.
12. A computer program product comprising computer instructions, characterized in that: When the computer instructions are executed by a processor, the API vulnerability detection method described in any one of claims 1 to 8 is implemented.
Citation Information
Cited By
Interface risk detection method and device and electronic equipment
CN120632895A