Data acquisition method and device based on encryption request, electronic equipment and medium

By creating a sandbox isolation environment and enhancing byte code in data source requests, the complex steps of decryption of encrypted data requests are solved, and the method of efficiently obtaining encrypted data source requests is realized, which improves data acquisition efficiency and security.

CN120030568AActive Publication Date: 2025-05-23PARK DO CREDIT CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510099926.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-22
Publication Date
2025-05-23
Estimated Expiration
2045-01-22

AI Technical Summary

Technical Problem

When processing encrypted data requests, the decryption steps are complicated and inefficient, resulting in a large load on the data source test application, low data acquisition efficiency and low security.

Method used

By creating a sandbox isolation environment for data source requests, byte code enhancement processing is performed, the decryption steps are avoided, the plain text parameter is directly identified, and the data corresponding to the encrypted data source request is obtained.

Benefits of technology

Reduces intrusion into the original code, omits decryption steps, improves data acquisition efficiency, reduces the load on the data source test application side, and enhances data security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120030568A_ABST
    Figure CN120030568A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses a data acquisition method and device based on an encryption request, electronic equipment and a medium. A specific embodiment of the method comprises the following steps: determining plaintext request position information; creating a data source request sandbox isolation environment; performing byte code enhancement processing on the plaintext data source request code to obtain an enhanced plaintext data source request code; performing isolation environment starting on the data source request sandbox isolation environment; performing information verification processing on the plaintext data source request information to obtain a request information verification result; performing input parameter identification on the plaintext data source request information to obtain a data source request interface input parameter set; and obtaining request data corresponding to the encrypted data source request information. According to the embodiment, the data corresponding to the encrypted data source request is acquired through a code non-invasion method, so that the invasion of an original code can be reduced, the decryption step of the encrypted data source request information is omitted, the data acquisition efficiency is improved, and the load of a data source test application end is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Embodiments of the present disclosure relate to the field of computer technology, and in particular to a method, device, electronic device, and medium for acquiring data based on an encryption request. Background Art

[0002] At present, with the development of encryption technology, people pay more and more attention to the protection of privacy data. How to identify the interface parameters of encrypted data requests and obtain accurate data request input parameters to request data has become an important issue. For data acquisition of encrypted requests, the usual method is to decrypt the encrypted request and obtain the data request parameters for the encrypted request. Then, according to the data request parameters, the request data is obtained.

[0003] However, it is found in practice that when the above method is used to operate log files, the following technical problems often occur: Since decryption requires a large number of calculations and the decryption steps are complicated, the accuracy of identifying the input parameters after decryption is low, resulting in a large load on the data source test application, low efficiency in obtaining the data source, long acquisition time, and low data security.

[0004] The above information disclosed in this Background section is only for enhancement of understanding of the background of the present disclosure concept and therefore it may contain information that does not form the prior art that is already known in this country to a person of ordinary skill in the art. Summary of the invention

[0005] The content of this disclosure is used to introduce concepts in a brief form, which will be described in detail in the detailed implementation section below. The content of this disclosure is not intended to identify the key features or essential features of the technical solution claimed for protection, nor is it intended to limit the scope of the technical solution claimed for protection.

[0006] Some embodiments of the present disclosure propose a data acquisition method, device, electronic device, and medium based on an encryption request to solve one or more of the technical problems mentioned in the above background technology section.

[0007] In a first aspect, some embodiments of the present disclosure provide a method for obtaining data based on an encrypted request, including: in response to detecting encrypted data source request information sent to a test interface of a data source test application, determining the plaintext request location information of the plaintext data source request information corresponding to the encrypted data source request information; creating a data source request sandbox isolation environment according to the plaintext request location information, where the data source request sandbox isolation environment is a non-invasive embedded environment created for the plaintext data source request method; performing bytecode enhancement processing on the plaintext data source request code corresponding to the plaintext data source request information to obtain an enhanced plaintext data source request code; starting the isolation environment of the data source request sandbox isolation environment according to the enhanced plaintext data source request code; in response to detecting successful startup of the isolation environment, performing information verification processing on the plaintext data source request information to obtain a request information verification result; in response to determining that the request information verification result indicates passing the verification, performing input parameter identification on the plaintext data source request information to obtain a data source request interface input parameter set; and obtaining the request data corresponding to the encrypted data source request information from the data source test application according to the data source request interface input parameter set.

[0008] In a second aspect, some embodiments of the present disclosure provide a device for obtaining data based on an encrypted request, including: a determination unit configured to, in response to detecting encrypted data source request information sent to a test interface of a data source test application, determine the plaintext request location information of the plaintext data source request information corresponding to the encrypted data source request information; a creation unit configured to create a data source request sandbox isolation environment according to the plaintext request location information, where the data source request sandbox isolation environment is a non-invasive embedded environment created for the plaintext data source request method; a bytecode enhancement unit configured to perform bytecode enhancement processing on the plaintext data source request code corresponding to the plaintext data source request information to obtain an enhanced plaintext data source request code; an isolation environment startup unit configured to start the isolation environment of the data source request sandbox isolation environment according to the enhanced plaintext data source request code; an information verification unit configured to, in response to detecting successful startup of the isolation environment, perform information verification processing on the plaintext data source request information to obtain a request information verification result; an input parameter identification unit configured to, in response to determining that the request information verification result indicates passing the verification, perform input parameter identification on the plaintext data source request information to obtain a data source request interface input parameter set; and an acquisition unit configured to obtain the request data corresponding to the encrypted data source request information from the data source test application according to the data source request interface input parameter set.

[0009] In a third aspect, some embodiments of the present disclosure provide an electronic device comprising: one or more processors; a storage device on which one or more programs are stored, and when the one or more programs are executed by the one or more processors, the one or more processors implement the method described in any implementation manner in the first aspect.

[0010] In a fourth aspect, some embodiments of the present disclosure provide a computer-readable medium having a computer program stored thereon, wherein when the computer program is executed by a processor, the method described in any implementation manner in the first aspect is implemented.

[0011] The above-mentioned various embodiments of the present disclosure have the following beneficial effects: the data acquisition method based on the encrypted request of some embodiments of the present disclosure obtains the data corresponding to the encrypted data source request through a code-free intrusion method, which can reduce the intrusion into the original code, omit the decryption step of the encrypted data source request information, improve the efficiency of data acquisition, and reduce the load of the data source test application end. Specifically, the reason why the relevant data source test application end has a large load, low efficiency in acquiring the data source, long acquisition time, and low data security is that: since the decryption requires a large number of operations, and the decryption steps are complicated and prone to low accuracy in identifying the input parameters after decryption, the data source test application end has a large load, low efficiency in acquiring the data source, long acquisition time, and low data security. Based on this, the image segmentation method of some embodiments of the present disclosure can first, in response to detecting the encrypted data source request information of the test interface sent to the data source test application end, determine the plaintext request location information of the plaintext data source request information corresponding to the above-mentioned encrypted data source request information. Here, it is convenient to create a data source request sandbox isolation environment in the future. Secondly, according to the above-mentioned plaintext request location information, a data source request sandbox isolation environment is created, wherein the above-mentioned data source request sandbox isolation environment is a non-intrusive embedded environment created for the above-mentioned plaintext data source request method. Here, the code can be non-invasively embedded without affecting the original code, thereby improving the extensibility and maintainability of the data source test application end, and further improving the stability of the data source test application end. Again, the plaintext data source request code corresponding to the plaintext data source request information is subjected to byte code enhancement processing to obtain the enhanced plaintext data source request code. Here, the byte code enhancement processing of the original code is non-invasively performed, which can improve the stability, maintainability and extensibility of the data source test application end. Subsequently, according to the enhanced plaintext data source request code, the data source request sandbox isolation environment is started in an isolated environment. Here, isolation from the original code and non-invasive embedding of the code can be achieved. Then, in response to detecting that the isolation environment is successfully started, the plaintext data source request information is subjected to information verification processing to obtain a request information verification result. Here, it can be detected whether the plaintext data source request information has a problem of malicious code injection, improve the security of the request, and further improve the security of the privacy data of the data source data, and reduce the risk of data leakage. Then, in response to determining that the request information verification result indicates that the verification is passed, the plaintext data source request information is input parameter identified to obtain a data source request interface input parameter set. Here, the identification of plain text input parameters can remove the decryption step of the encrypted parameters, reduce the large number of mathematical operations in the encryption step, reduce the complexity of input parameter identification and the computing load of the data source test application. Finally, according to the above data source request interface input parameter set, the request data corresponding to the above encrypted data source request information is obtained from the above data source test application.Here, by simulating the real data source server through the data source test application end, the security of the real data can be improved, and the test interface can be tested independently, isolating the test environment that has a dependency relationship with the test interface, and improving the accuracy of the test and the efficiency of data acquisition. It can be obtained that the data acquisition method based on the encrypted request obtains the data corresponding to the encrypted data source request through a code-free intrusion method, which can reduce the intrusion into the original code, omit the decryption step of the encrypted data source request information, improve the efficiency of data acquisition, and reduce the load of the data source test application end. BRIEF DESCRIPTION OF THE DRAWINGS

[0012] The above and other features, advantages and aspects of the embodiments of the present disclosure will become more apparent with reference to the following detailed description in conjunction with the accompanying drawings. Throughout the accompanying drawings, the same or similar reference numerals represent the same or similar elements. It should be understood that the drawings are schematic and that components and elements are not necessarily drawn to scale.

[0013] Figure 1 is a flowchart of some embodiments of a data acquisition method based on an encryption request according to the present disclosure;

[0014] Figure 2 is a schematic structural diagram of some embodiments of a data acquisition device based on an encryption request according to the present disclosure;

[0015] Figure 3 It is a schematic diagram of the structure of an electronic device suitable for implementing some embodiments of the present disclosure. DETAILED DESCRIPTION

[0016] Embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although certain embodiments of the present disclosure are shown in the accompanying drawings, it should be understood that the present disclosure can be implemented in various forms and should not be construed as being limited to the embodiments set forth herein. On the contrary, these embodiments are provided to provide a more thorough and complete understanding of the present disclosure. It should be understood that the drawings and embodiments of the present disclosure are only for exemplary purposes and are not intended to limit the scope of protection of the present disclosure.

[0017] It should also be noted that, for ease of description, only the parts related to the invention are shown in the drawings. In the absence of conflict, the embodiments and features in the embodiments of the present disclosure can be combined with each other.

[0018] It should be noted that the concepts such as "first" and "second" mentioned in the present disclosure are only used to distinguish different devices, modules or units, and are not used to limit the order or interdependence of the functions performed by these devices, modules or units.

[0019] It should be noted that the modifications of "one" and "plurality" mentioned in the present disclosure are illustrative rather than restrictive, and those skilled in the art should understand that unless otherwise clearly indicated in the context, it should be understood as "one or more".

[0020] The names of the messages or information exchanged between multiple devices in the embodiments of the present disclosure are only used for illustrative purposes and are not used to limit the scope of these messages or information.

[0021] The present disclosure will be described in detail below with reference to the accompanying drawings and in conjunction with embodiments.

[0022] Figure 1 The process 100 of some embodiments of the data acquisition method based on encryption request according to the present disclosure is shown. The data acquisition method based on encryption request includes the following steps:

[0023] Step 101 , in response to detecting encrypted data source request information sent to a test interface of a data source test application, determining plaintext request location information of plaintext data source request information corresponding to the encrypted data source request information.

[0024] In some embodiments, the execution subject (e.g., electronic device) of the above-mentioned data acquisition method based on encrypted request can determine the plaintext request location information of the plaintext data source request information corresponding to the above-mentioned encrypted data source request information in response to the detection of the encrypted data source request information of the test interface sent to the data source test application end. Among them, the above-mentioned data source test application end can be a virtual platform that simulates the data source request response of the real data source storage server and returns the data source. For example, the above-mentioned data source test application end can be a mock platform. The above-mentioned test interface can be a communication interface between the client and the above-mentioned data source test application end. The above-mentioned plaintext data source request information can be a request information for calling the data stored in the above-mentioned data source test application end. The above-mentioned encrypted data source request information can be a request information of the ciphertext obtained by encrypting the above-mentioned plaintext data source request information. The above-mentioned plaintext request location information can be the location of the code after receiving the encrypted request information in the original code for processing the request data in the above-mentioned data source test application end and before the data source requests the client to send the encrypted data source request information.

[0025] In the process of adopting technical solutions to solve the above-mentioned technical problem one, the following technical problem two is often accompanied: how to use a small number of test cases to improve the test accuracy and stability of the data source test application end. For the above-mentioned technical problem two, the conventional solution is generally: generate a large number of test cases for the data source test application end through expert experience for random testing. However, the above-mentioned conventional solution still has the following technical problems: since a large number of test case sets are generated by expert experience, there is a certain degree of subjectivity, and the test of the data source test application end is not comprehensive, the quality of the test cases cannot be guaranteed and there is a certain degree of repeatability, resulting in a large test load on the data source test application end, and the accuracy of the application end simulation test is low, which in turn leads to low efficiency and security of data acquisition. The inventor, taking into account the shortcomings of the conventional solution and combining the advantages / technical status of the data source test application end test owned by the inventor, can decide to adopt the following solution:

[0026] In some optional implementations of some embodiments, before determining the plaintext request location information of the plaintext data source request information corresponding to the encrypted data source request information in response to detecting the encrypted data source request information of the test interface sent to the data source test application end, the method may further include:

[0027] The first step is to obtain application platform requirement information of the initial data source test application platform, wherein the application platform requirement information may be text information describing the functions and performance required for designing the initial data source test application platform.

[0028] The second step is to generate an application-side test case set for the initial data source test application platform based on the application platform requirement information. The application-side test cases in the application-side test case set may be test cases related to functional testing, abnormal testing, boundary condition testing, load testing, stress testing, resource utilization testing, and security testing of the data source test application platform.

[0029] As an example, the execution subject may use an automated test case generation tool to generate an application-side test case set for testing the application platform for the initial data source according to the application platform requirement information. The automated test case generation tool may be an automated test framework TestNG.

[0030] The third step is to test the application based on the initial data source and perform the following test steps:

[0031] Sub-step 1, performing text similarity calculation on the above-mentioned application-side test case set to obtain a first similarity matrix. Each element in the above-mentioned first similarity matrix can represent the similarity between the corresponding two application-side test cases. For example, the element in the i-th row and j-th column in the above-mentioned first similarity matrix can represent the similarity value between application-side test case i and application-side test case j.

[0032] As an example, the execution subject may first perform text preprocessing on the application-side test case sequence to obtain a test case text information set. The text preprocessing may be a process of removing numbers, spaces and comment characters in the test case sequence. Then, the test case text information set is subjected to topic modeling using the implicit Dirichlet distribution model to obtain a probability numerical matrix. The probability numerical matrix may represent the probability numerical value of each topic in the topic set to which each test case text information in the test case text information set belongs. The topic in the topic set may be a topic obtained by extracting keywords from the text information included in the test case using the implicit Dirichlet distribution model, and classifying the keyword set. The element in the i-th row and j-th column in the probability numerical matrix may represent the summary numerical value of the i-th test case belonging to the j-th topic. For example, the topic set may include at least one of the following: an equivalence class, a decision table and a boundary value. Finally, a similarity operation is performed on each row vector in the probability numerical matrix to obtain a first similarity matrix. The similarity operation may be a similarity operation based on Euclidean distance.

[0033] Sub-step 2, performing statement coverage similarity processing on the above-mentioned application-side test case set to obtain a second similarity matrix. The elements in the above-mentioned second similarity matrix can represent the degree of overlap of the test statements executed when the corresponding two application-side test cases are tested. The above-mentioned statement coverage similarity processing can be a similarity processing of the code statements of each function of the code coverage simulation application in the above-mentioned application-side test case.

[0034] As an example, the execution subject may first determine the test statement set of each application-side test case in the application-side test case sequence, and then determine the similarity between any two application-side test cases in the application-side test cases using the Jaccard distance similarity to obtain a second similarity matrix.

[0035] Sub-step 3, performing a weighted operation on the first similarity matrix and the second similarity matrix to obtain a third similarity matrix, wherein the weight of the first similarity matrix may be 0.7, and the weight of the second similarity matrix may be 0.3.

[0036] Sub-step 4, clustering the above-mentioned application-side test case set according to the above-mentioned third similarity matrix to obtain multiple application-side test case clusters. Among them, the number of application-side test case clusters in the above-mentioned multiple application-side test case clusters can be a number determined according to the DB index (Davies-Bouldin Index). The above-mentioned DB index can characterize the effect of clustering. The smaller the DB index, the better the clustering effect.

[0037] As an example, the execution entity may utilize a hierarchical clustering algorithm to perform clustering processing on the application-side test case sequence according to the third similarity matrix to obtain a plurality of test case clusters.

[0038] Sub-step 5: for each application-side test case cluster in the above-mentioned multiple application-side test case clusters, perform the following determination steps:

[0039] In the first sub-step, each application-side test case included in the above application-side test case class cluster is determined as an application-side test case set within the cluster.

[0040] The second sub-step is to determine the feature vector of each intra-cluster application-side test case in the intra-cluster application-side test case set as a test case feature vector set, wherein the test case feature vector can represent the attribute characteristics of the data source test application side.

[0041] The third sub-step is to input the above-mentioned feature vector set into the defect prediction classification model to obtain a classification result set. Among them, the classification results in the above-mentioned classification result set include: classification type and probability value corresponding to the classification type. The above-mentioned classification types include: defective and non-defective. Defective can represent that the execution result of the application-side test case on the data source test application end is inconsistent with the preset execution result. The above-mentioned preset execution result can be the result predicted before the application-side test case is executed. For example, when the application-side test case performs a login boundary value test on the simulation application, the preset execution result is login failure, and the execution result is login success, indicating that the test case is defective. The probability value corresponding to the above-mentioned classification type can represent the probability value of whether the test case corresponding to the feature vector is a defective test case. For example, the above-mentioned test case feature vector set includes: a first feature vector and a second feature vector. The classification type of the above-mentioned first feature vector can be non-defective and, and the probability value corresponding to non-defective is 0.8959. The classification type of the above-mentioned second feature vector can be defective, and the probability value corresponding to defective is 0.7895. The defect prediction classification model may be a model for classifying defects in the above-mentioned intra-cluster application-side test case set. For example, the defect prediction classification model may be a SVM (Support Vector Machine) model.

[0042] The fourth sub-step is to sort the intra-cluster application-side test cases with a classification type of defective in the above classification result set to obtain an intra-cluster application-side test case sequence. The above sorting is to sort the probability values ​​corresponding to the intra-cluster test cases with a classification type of defective in the above classification result set in order from large to small.

[0043] The fifth sub-step is to determine the distance value between the application-side test cases classified as defect-free in the above classification result set and the cluster center within the cluster to obtain a distance value set. The cluster center within the cluster may be the cluster test case located at the center of the application-side test case class cluster. The distance value may be a Euclidean distance.

[0044] The sixth sub-step is to sort the distance value set to obtain a distance value sequence, wherein the sorting may be performed in ascending order.

[0045] Sub-step 6, based on the obtained multiple intra-cluster application-side test case sequences and multiple distance value sequences, the above-mentioned multiple application-side test case class clusters are sorted between clusters to obtain inter-cluster application-side test case sequences. Among them, the above-mentioned inter-cluster application-side test case sequence can be a sequence obtained by inter-cluster sorting of multiple application-side test case class clusters. The above-mentioned inter-cluster sorting can be sorted in order from large to small according to the number of test cases classified as defective in each application-side test case class cluster. When multiple application-side test case class clusters include the same number of defective application-side test cases, the inter-cluster sorting is performed in order from large to small according to the corresponding probability values ​​of the intra-cluster application-side test cases located at the initial position in the intra-cluster test case sequence. When multiple application-side test case class clusters do not include defective application-side test cases, the inter-cluster sorting is performed in order from large to small according to the distance values ​​located at the end position in the distance value set.

[0046] As an example, the execution subject may first determine the number of in-cluster test cases of defective classification type in each in-cluster application-side test case in the multiple in-cluster application-side test case sequences to obtain a number set. Secondly, sort the number set to obtain a number sequence. The sorting may be sorted in order from large to small. Thirdly, in response to determining that multiple application-side test case clusters include a set of defective application-side test case clusters with the same number, determine the probability value set of the test cases located at the starting position in the corresponding multiple in-cluster application-side test case sequences as a defect probability data set. The corresponding multiple in-cluster application-side test case sequences may be multiple in-cluster application-side test case sequences corresponding to the set of defective application-side test cases with the same number. Next, perform inter-cluster sorting on the defect probability value set. The inter-cluster sorting may be sorted from large to small according to the defect probability value. Then, in response to determining that multiple application-side test case clusters do not include a set of defective application-side test case clusters, determine the distance value located at the end position in the corresponding multiple distance value sequences to obtain the defect distance value. The corresponding multiple distance value sequences may be multiple test case clusters that do not include defects. Finally, the defect distance values ​​are sorted between clusters to obtain a cluster application test case sequence. The inter-cluster distance sorting may be performed in descending order of the distance values.

[0047] Sub-step 7, sampling and adjusting the above-mentioned inter-cluster application-side test case sequence to obtain an adjusted test case sequence. The above-mentioned adjusted test case sequence can be a test case sequence obtained by sampling the above-mentioned inter-cluster test cases. In practice, the above-mentioned execution subject can be first, sorting the test cases classified as defective in multiple application-side test case clusters from large to small according to the probability value, and then, for the application-side test cases in multiple application-side test case clusters classified as non-defective, one application-side test case is selected from the multiple application-side test case clusters in the order of the above-mentioned inter-cluster application-side test case sequence for sampling and adjustment.

[0048] Sub-step 8, sending the above-mentioned adjustment test case sequence to the initial data source test application end for testing, and obtaining the application end test result. Among them, the above-mentioned application end test result can represent whether the response result of inputting the above-mentioned adjustment test case sequence into the above-mentioned initial data source test application end is consistent with the prediction result. The above-mentioned prediction result can be the desired result corresponding to each adjustment test case in the adjustment test case sequence.

[0049] Sub-step 9, in response to determining that the above-mentioned application-end test result indicates that the test is successful, determining the initial data source test application end as the data source test application end.

[0050] In step 4, in response to determining that the above application-side test result indicates a test failure, the initial data source test application is adjusted to obtain an adjusted data source test application as the data source test application to perform the above test steps again. The above adjustment may be an adjustment of the interface, request load, etc. of the above ignored application test application.

[0051] The above technical scheme and its related contents, as an inventive point of an embodiment of the present disclosure, solve the second technical problem mentioned in the background technology, "Since a large number of test case sets are generated by expert experience, there is a certain degree of subjectivity, and the test on the data source test application end is not comprehensive, the quality of the test cases cannot be guaranteed and there is a certain degree of repeatability, resulting in a large test load on the data source test application end, and low accuracy of the application-end simulation test, which in turn leads to low efficiency and security of data acquisition." The factors that lead to a large test load on the data source test application end, low accuracy of the application-end simulation test, and low efficiency and security of data acquisition are often as follows: Since a large number of test case sets are generated by expert experience, there is a certain degree of subjectivity, and the test on the data source test application end is not comprehensive, the quality of the test cases cannot be guaranteed and there is a certain degree of repeatability. If the above factors are solved, the effect of reducing the test load on the data source test application end, improving the low accuracy of the application-end simulation test, and improving the efficiency and security of data acquisition can be achieved. In order to achieve this effect, the present disclosure first generates an application-side test case set through platform demand information. Automatically generating test cases can avoid the subjectivity generated through expert experience, improve the objectivity and comprehensiveness of the application-side test case set, and facilitate the accuracy of subsequent testing of the data source test application end. Secondly, the above-mentioned test case sequence is subjected to text similarity calculation and statement coverage similarity processing, and the similarity of the application-side test case to the data source test application end test is considered from the perspective of static text and dynamic statement coverage, which is conducive to improving the subsequent optimization effect of the test case sequence. Thirdly, the above-mentioned first similarity matrix and the above-mentioned second similarity matrix are weighted. From the perspective of static text and dynamic coverage statements, the similarity of the application-side test case can be more comprehensively evaluated, which is conducive to improving the accuracy of subsequent clustering processing. Then, according to the above-mentioned third similarity matrix, the above-mentioned test case sequence is clustered, and the similar test cases are divided into the same cluster, which is convenient for faster identification of defects existing in the data source test application end. Subsequently, for each of the above-mentioned multiple application-side test case clusters, the following determination steps are performed: feature extraction is performed on the test case set within the cluster and then input into the defect prediction classification model, and the application-side test cases within the cluster are sorted, which can speed up the identification of defects existing in the data source test application end, thereby improving the test efficiency. Then, the multiple application-side test case clusters are sorted within the cluster and between clusters, and the test cases with defects can be put in front, which is conducive to faster identification of defects in the data source test application end, improving the detection rate of the application-side test cases and reducing the load of the data source test application end.Afterwards, the inter-cluster test case sequence is sampled and adjusted. By testing the application-side test case that can best detect the data source test application-side in advance, the number of application-side test cases can be reduced, the test rate of the data source test application-side can be improved, and the test load of the data source test application-side can be reduced. Finally, by adjusting the test results of the test case sequence and determining whether to make application-side adjustments to the data source test application-side, the accuracy of the data source test application-side response request can be improved, the accuracy and efficiency of data acquisition can be improved, the security of the data can be ensured, and the load of the data source test application-side test case on the application-side can be reduced.

[0052] Step 102: Create a data source request sandbox isolation environment based on the plaintext request location information.

[0053] In some embodiments, the execution subject may create a data source request sandbox isolation environment based on the plaintext request location information, wherein the data source request sandbox isolation environment is a non-invasive embedded environment created for the plaintext data source request method. The data source request sandbox isolation environment may be a code environment for non-invasive aspect-oriented programming in the original code in the data source test application. The creation may be performed using the after method in the sandbox.

[0054] As an example, the above-mentioned execution subject can use Spring AOP (Spring Aspect-Oriented Programming Dynamic Proxy) to create a data source request sandbox isolation environment according to the above-mentioned plaintext request location information.

[0055] Step 103: Perform byte code enhancement processing on the plaintext data source request code corresponding to the plaintext data source request information to obtain an enhanced plaintext data source request code.

[0056] In some embodiments, the execution subject may perform byte code enhancement processing on the plaintext data source request code corresponding to the plaintext data source request information to obtain an enhanced plaintext data source request code. The plaintext data source request code may be the original code related to the data source request in the data source test application. The enhanced plaintext data source request code may be a code that implements input parameter recognition after class isolation of the original code.

[0057] As an example, the execution subject may utilize the bytecode manipulation and analysis framework ASM to perform bytecode enhancement processing on the plaintext data source request code corresponding to the plaintext data source request information to obtain an enhanced plaintext data source request code.

[0058] Step 104: According to the enhanced plaintext data source request code, the data source request sandbox isolation environment is started.

[0059] In some embodiments, the above-mentioned execution subject can start the isolation environment of the above-mentioned data source request sandbox isolation environment according to the above-mentioned enhanced plaintext data source request code. Among them, the above-mentioned isolation environment startup can be achieved through the following steps: first, it is necessary to use the Attach interface or javaagent parameters to mount the proxy agent, and initialize the proxy agent. Secondly, the above-mentioned enhanced plaintext data source request code is appended to the startup class loader in the initialization for loader loading, so as to communicate with the original code. Then, in response to the successful code communication, the isolation environment of the above-mentioned data source request sandbox isolation environment is started.

[0060] In some optional implementations of some embodiments, the above-mentioned starting the isolation environment of the data source request sandbox isolation environment according to the above-mentioned enhanced plaintext data source request code may include the following steps:

[0061] The first step is to perform spy method tracking on the enhanced plaintext data source request code to obtain the plaintext request spy code. The plaintext request spy code can be the user data collection code added after the plaintext data source request code. For example, the plaintext code request spy code can be the spy sandbox spy code in the sandbox.

[0062] The second step is to perform cross-cutting declarative loading on the above plaintext request spy class code. The above cross-cutting declarative loading can be loaded through dynamic proxy in the original code.

[0063] The third step is to establish code communication between the above-mentioned plaintext request spy class code and the business original code in response to detecting that the above-mentioned plaintext request spy class code is loaded successfully.

[0064] In the fourth step, in response to detecting that the code communication is successful, the data source is started to request a sandbox isolation environment.

[0065] In some optional implementations of some embodiments, the cross-cutting declarative loading of the above-mentioned plaintext request spy class code may include the following steps:

[0066] The first step is to construct an abstract syntax tree for the plaintext data source request code corresponding to the plaintext data source request information to obtain a test interface call syntax tree. The test interface call syntax tree can represent the tree structure of the call relationship between the call method set and the call object set included in the source code. In practice, the execution subject can first perform word segmentation on the source code file to obtain an interface syntax unit set. The interface syntax unit in the interface syntax unit set can be the smallest indivisible unit in the source code file. For example, the interface syntax unit set can include but is not limited to at least one of the following: keywords, identifiers, operators, parameter values, strings, spaces, and comments. Then, the interface syntax unit set is parsed to obtain an interface call syntax tree.

[0067] The second step is to parse the above test interface call syntax tree to obtain an interface call connectivity graph. The above interface call connectivity graph can be a directed graph that shows the call relationship and process between each node. The nodes included in the above interface call connection graph include interface call method nodes and data nodes. The above interface call method nodes can represent method calls and operators in interface calls. The above data nodes can represent objects and parameter values ​​in interface calls. The edges in the above interface call connection graph can represent the call relationship between interface call method nodes and data nodes.

[0068] The third step is to perform a breadth-first search on the interface call connectivity graph to obtain application interface parameter configuration information. The application interface parameter configuration information may be configuration information of test interface parameters. The interface parameter configuration information may include but is not limited to at least one of the following: interface address information, interface parameter name, interface type information, and interface parameter format.

[0069] The fourth step is to adopt the sandbox class loading parent delegation model, and determine the parent request class loader of the above-mentioned plaintext request spy class code according to the above-mentioned application interface parameter configuration information. Among them, the above-mentioned sandbox class loading parent delegation model can be a model that is built into the Java virtual machine and loaded by the classification loader of the loader, and if the parent class loader cannot load, it loads itself. The above-mentioned parent request class loader can be the parent loader of the application class loader that loads the plaintext request spy class code. For example, the built-in loaders of the Java virtual machine include: startup class loader, extension class loader, application class loader and user-defined loader. The above-mentioned startup class loader is the class loader of the top-level parent class. It should be noted that by adopting the sandbox class loading parent delegation model, the code loaded by the class loader can have a hierarchical relationship with priority, ensuring that the data source test application end loads the same code when loading the enhanced plaintext data source request code, ensuring the security and uniformity of the loader loading, avoiding the problem of repeated loading, and reducing the load and security of the data source test application end.

[0070] In step 5, in response to determining that the parent request class loader is not the target parent request class loader, determine the parent request class loader of the parent request class loader as the parent parent request loader. The target parent request class loader may be a startup class loader.

[0071] Step 6: In response to determining that the parent parent request loader is loading the target parent request class, the parent parent request loader is cross-cuttingly declaratively loaded to obtain a request loading result, wherein the request loading result may indicate whether the loading is successful.

[0072] In the seventh step, in response to determining that the above request loading result indicates that the loading is not successful, the above plain text request spy class code is cross-cuttingly loaded declaratively.

[0073] Step 105, in response to detecting that the isolation environment is successfully started, information verification processing is performed on the above-mentioned plaintext data source request information to obtain a request information verification result.

[0074] In some embodiments, the execution subject may, in response to detecting that the isolation environment is successfully started, perform information verification processing on the plaintext data source request information to obtain a request information verification result. The request information verification result may indicate whether there is an abnormality in the request code corresponding to the plaintext data source request information.

[0075] In some optional implementations of some embodiments, the information verification process is performed on the plaintext data source request information to obtain the request information verification result, which may include the following steps:

[0076] The first step is to convert the data source request code corresponding to the plaintext data source request information to obtain the converted data source request code. The data source request code may be a code of the data source request information written in Java. The converted data source request code may be Jimple intermediate code, which is used to simplify the data source request code and turn it into a code that is easy to analyze and optimize. In practice, the execution entity may use a bytecode parsing compiler to convert the data source request code corresponding to the plaintext data source request information to obtain the converted data source request code. The bytecode parsing compiler may be a Soot tool.

[0077] The second step is to determine the conditional judgment statement code set in the converted data source request code, wherein the conditional judgment statement in the conditional judgment statement code set may be a code statement with judgment words and conditions.

[0078] The third step is to perform static code instrumentation processing on each conditional judgment statement code in the above conditional judgment statement code set to obtain an instrumented conditional judgment statement code set. Among them, the instrumented conditional judgment statement in the above instrumented conditional judgment statement code set can be a statement that inserts a virtual call statement before the above conditional judgment statement code and sets the variable parameters involved in the conditional judgment statement code to the parameters in the virtual call statement. In practice, the above execution subject can first perform the following setting steps for each conditional judgment statement code in the above conditional judgment statement code set: the first step is to insert a target virtual method call statement in front of the above conditional judgment statement code to obtain a post-insertion judgment statement. Among them, the above target virtual method call statement can be a call statement with a virtual method ifMethod(). The second step is to set the variables involved in the above conditional judgment statement code to the parameters of ifMethod(). Then, the obtained virtual methods are determined as methods in the target virtual class. Finally, ifMethod() is set to Sink API (SinkApplication Programming Interface). Among them, the above Sink API can be used to define the destination of the data flow. It should be noted that the static taint analysis method can be used to determine the data source flow path from the specified data source start flow interface to the call statement corresponding to the ifMethod() virtual method.

[0079] The fourth step is to generate a data flow control flow chart for the plaintext data source request information according to the above-mentioned instrumentation condition judgment statement code set. The above-mentioned data flow control flow chart can represent a directed graph of the flow process of the data source request.

[0080] As an example, the execution subject may utilize the interface analysis method in the static control flow analysis method to generate a data flow control flow chart for the plaintext data source request information according to the insertion condition judgment statement code set.

[0081] The fifth step is to extract the out-of-domain context of the above-mentioned insert condition judgment statement code set according to the above-mentioned data flow control flow chart to obtain an out-of-domain context information set, wherein the out-of-domain context information is the information that controls the judgment result of the above-mentioned condition judgment statement code set.

[0082] As an example, the execution subject may adopt a static detection method to determine the statement code with the data source start flow interface in the above-mentioned instrumentation condition judgment statement code set as the out-of-domain condition judgment statement code set. Then, the parameter set included in the above-mentioned out-of-domain condition judgment statement code set is determined as the out-of-domain context information set.

[0083] The sixth step is to determine the conditional judgment statement code set corresponding to the above-mentioned out-of-domain context information set as the target conditional judgment statement code set.

[0084] In the seventh step, control flow dependency analysis is performed on the target condition judgment statement code set to generate a condition judgment scope for each target condition judgment statement code in the target condition judgment statement code set to obtain a condition judgment scope set. The condition judgment scope can represent the scope of the code context covered by the target condition judgment statement code.

[0085] In the eighth step, based on the above conditional judgment range set, the above binary data source request code is subjected to in-domain context extraction to obtain an in-domain context information set, wherein the in-domain context information represents the data flow within the conditional judgment range.

[0086] As an example, the execution subject may first determine each target conditional judgment statement code included in each conditional judgment scope in the conditional judgment scope set to obtain a conditional judgment statement code group set within the scope, and then determine each data flow parameter included in the conditional judgment statement code group set within the scope as the domain context information set.

[0087] In the ninth step, based on the above-mentioned in-domain context information set and the above-mentioned out-of-domain context information set, the above-mentioned plaintext data source request information is subjected to anomaly detection processing to obtain an anomaly detection result as the request information verification result. The above-mentioned anomaly detection result can indicate whether the above-mentioned data source request code is the result of an abnormality.

[0088] Optionally, performing anomaly detection processing on the plaintext data source request information according to the in-domain context information set and the out-of-domain context information set to obtain an anomaly detection result as the request information verification result may include the following steps:

[0089] In the first step, feature extraction is performed on the above-mentioned in-domain context information set and the above-mentioned out-of-domain context information set to obtain an in-domain feature information set and an out-of-domain feature information set. Among them, the in-domain feature information in the above-mentioned in-domain feature information set can represent the information of the features of the in-domain context information. The out-of-domain feature information in the above-mentioned out-of-domain feature information set can represent the information of the features in the above-mentioned out-of-domain context information. The above-mentioned out-of-domain feature information set may include: out-of-domain privacy data, out-of-domain reflection mechanism information, and out-of-domain URL (Uniform Resource Locator) call information. The above-mentioned in-domain feature information set may include: in-domain privacy data, in-domain dynamic loading information, in-domain reflection mechanism information, in-domain URL call information, and in-domain conditional judgment branch similarity. The in-domain conditional judgment branch similarity can represent the degree of difference between two conditional judgment branches within the conditional judgment scope. The greater the in-domain conditional judgment branch similarity, the greater the possibility that the out-of-domain conditional judgment statement code corresponding to the in-domain context information has an abnormality. The in-domain conditional judgment branch similarity can be obtained by the following steps: In the first step, the union and intersection of the parameter sets included in the two conditional judgment branches within the conditional judgment scope are determined. The second step is to determine the ratio of the intersection and the union. The third step is to determine the difference between the preset value and the above ratio as the domain condition to determine the branch similarity. The above preset value can be a pre-set value. For example, the above preset value can be 1.

[0090] The second step is to embed the above-mentioned in-domain feature information set and the above-mentioned out-of-domain feature information set to obtain an out-of-domain feature vector set and an in-domain feature vector set. Among them, the in-domain feature vectors in the above-mentioned in-domain feature vector set can be vectors that represent the in-domain feature information. The out-of-domain feature vectors in the above-mentioned out-of-domain feature vector set can be vectors that represent the out-of-domain feature information. In practice, the above-mentioned execution entity can use a text embedding algorithm to embed the above-mentioned in-domain feature information set and the above-mentioned out-of-domain feature information set to obtain an out-of-domain feature vector set and an in-domain feature vector set.

[0091] The third step is to determine the feature similarity between each out-of-domain feature vector in the out-of-domain feature vector set and each in-domain feature vector in the in-domain feature vector set to obtain a feature similarity group set.

[0092] In the fourth step, at least one in-domain feature vector and at least one out-domain feature vector whose corresponding feature similarity is greater than or equal to a preset similarity threshold are selected from the in-domain feature vector set and the out-domain feature vector set. The preset similarity threshold may be a preset maximum value of the similarity. For example, the preset similarity threshold may be 0.8.

[0093] The fifth step is to optimize the code anomaly detection model to obtain an optimized code anomaly detection model. The optimized code anomaly detection model may be a model that selects parameters that best match the code anomaly detection model and the information verification scenario. The code anomaly detection model may be a deep network model that determines whether the input data source request code is an abnormal code. The code anomaly detection model may be a random forest anomaly detection model.

[0094] In the sixth step, the at least one in-domain feature vector and the at least one out-of-domain feature vector are input into the trained optimized code anomaly detection model to obtain an anomaly detection result as the request information verification result.

[0095] In some optional implementations of some embodiments, the above-mentioned optimization process of the code anomaly detection model to obtain the optimized code anomaly detection model may include the following steps:

[0096] The first step is to initialize the parameter set of the code anomaly detection model to obtain an initial parameter set as an initial ant colony and an initial ant lion colony, wherein the initial parameter set includes at least one of the following: a penalty factor and a kernel function parameter. The parameters in the parameter set can characterize the generalization performance of the code anomaly detection model to improve the classification accuracy of the code anomaly detection model. The penalty factor can characterize the trade-off between the complexity of controlling the code anomaly detection model and the accuracy of anomaly classification. The kernel function parameter can characterize the complexity and structure of the mapping of the training sample data of the code anomaly detection model to a high-dimensional feature space. The initialized ant colony can be an ant colony initial position information set obtained by initializing the position of the ant colony. The initialized ant lion colony can be an ant lion initial position information set obtained by initializing the position of the ant lion colony. The initialization process can be an initialization performed using a tent chaos mapping algorithm.

[0097] The second step is to generate a model fitness function for the above-mentioned code anomaly detection model. Among them, the above-mentioned model fitness function can characterize the classification accuracy performance of the above-mentioned code anomaly detection model. The above-mentioned model fitness function may include: a classification hyperplane function and a classification category discrimination function. The above-mentioned classification hyperplane constraint function may characterize the function of finding the optimal classification hyperplane to maximize the classification interval. The above-mentioned classification hyperplane constraint function aims to balance the complexity and classification error rate of the above-mentioned code anomaly detection model based on the principle of structural risk minimization. The above-mentioned classification hyperplane function may include: a classification hyperplane objective function and a classification hyperplane constraint function. The above-mentioned classification hyperplane objective function can be ω can represent the normal vector of the hyperplane. It can represent the maximum interval between any two sample data. ||ω|| 2 It can represent the square of the normal vector of the hyperplane. C can represent the penalty factor. ξ i It can be a non-negative relaxation factor, which indicates the classification error allowed for the i-th sample partition. l can represent the number of training samples for the anomaly detection model in the above code. It can be expressed as the degree of penalty for controlling misclassified training samples. The above classification hyperplane constraint function can be y i Can represent the classification label of the i-th training sample. b can be a bias term, which represents the degree of translation of the hyperplane. The above classification category discriminant function can be The fitness function of the above model can be. f(x) can represent the classification category discrimination function. sgn() can represent the sign function. α i It can represent the Lagrange multiplier. K(x i , x) can represent sample x i and the Gaussian radial basis kernel function of sample x. The Gaussian radial basis kernel function can be Among them, σ can represent the kernel function parameters. j Can represent the classification label of the jth training sample. x can represent the training sample of the anomaly detection model in the above code. i It can represent the i-th training sample. j It can represent the jth training sample. It can be a classification bias term, which represents the degree of translation of the translation hyperplane. It can represent the sample x i and sample x j Gaussian radial basis kernel function.

[0098] The third step is to perform the following determination steps based on the initialization of the ant colony and the initialization of the ant lion colony:

[0099] Sub-step 1, substituting the initialized ant colony and the initialized ant lion colony into the above model fitness function to obtain the ant colony fitness function value set and the ant lion fitness function value set.

[0100] Sub-step 2, selecting the antlion fitness function value with the largest value from the antlion fitness function value set as the target antlion fitness function value, and determining the antlion corresponding to the target antlion fitness function value as the target antlion.

[0101] Sub-step 3, determining the initialization ant lion corresponding to each initialization ant in the initialization ant colony as the associated ant lion colony. In practice, the above execution subject can use a roulette wheel selection algorithm to determine the initialization ant lion corresponding to each initialization ant in the initialization ant colony as the associated ant lion colony.

[0102] Sub-step 4, updating the position of the initialized ant colony according to the associated ant lion colony and the target ant lion to obtain an updated ant colony. The position of each updated ant in the updated ant colony may be the position information of the ant's random walk being affected by the random walk of the target ant lion and the associated ant lion, and the range of the ant's random walk is getting smaller and smaller.

[0103] As an example, the execution subject may perform the following update steps for each initialized ant in the initialized ant colony: determine the associated ant lion of the initialized ant colony. The sum of the product of the associated ant lion and the first weight threshold and the product of the target ant lion and the second weight threshold is determined as the updated ant. The first weight threshold may be obtained by the following steps: first, determine the ratio of the number of times the determination step has been executed to the preset executed threshold and the cosine value of π as the number cosine value. Secondly, determine the sum of the number cosine value and the first preset factor threshold as the first numerical sum. The first preset factor threshold may be a preset maximum factor threshold that characterizes the search of the ant lion for the ant. The first preset factor threshold may be 0.7. Thirdly, determine the sum of the first preset factor threshold and the second preset factor threshold as the second numerical sum. The second preset factor threshold may be a preset minimum factor threshold that characterizes the search of the ant lion for the ant. The first preset factor threshold may be 0.2. Then, the ratio of the sum of the first numerical value and the product of the sum of the second numerical value to 2 is determined. Finally, the sum of the ratio value and the preset threshold is determined as the first weight threshold. The preset threshold may be a preset value. For example, the preset threshold may be 0.2. The second weight threshold may be the difference between 1 and the first weight threshold. This step can make the search range of the constructed ant lion and ant colony more consistent with the search range of the ant colony and ant lion in nature by presetting the weight threshold, thereby enhancing the solution efficiency and reducing the probability of falling into the local end to a certain extent.

[0104] Sub-step 5, substituting the updated ant colony into the above model fitness function to obtain the updated fitness function value set of the ant colony.

[0105] Sub-step 6, comparing each ant colony updated fitness function value in the ant colony updated fitness function value set with the ant lion fitness function value corresponding to the ant colony updated fitness function value in the ant lion fitness function value set to obtain a comparison result set.

[0106] Sub-step 7, based on the comparison result set, the updated ant colony and the initial ant lion colony are updated to obtain the target updated ant colony and the updated ant lion colony. The target updated ant colony may be a position information set of the remaining ant colony after some ants are captured by ant lions and the remaining ant colony walks randomly. The updated ant lion may be the position information of all ant lions after the ant lion captures the ant and uses the ant's position as the ant lion's finer position and then walks randomly.

[0107] As an example, the execution subject may first, in response to determining at least one comparison result in the comparison result set that characterizes that the updated fitness function value of the ant colony is greater than the corresponding ant lion fitness function value, determine the position information of each ant corresponding to the updated fitness function value of each ant colony corresponding to the at least one comparison result as the position information of the corresponding ant lion. Then, the updated ant colony is removed from the at least one updated ant corresponding to the at least one comparison result, and is determined as the target updated ant colony. Finally, the ant lions corresponding to the position information of each ant lion and at least one initialized ant lion whose updated fitness function value characterizes that the ant colony is less than or equal to the corresponding ant lion fitness function value are determined as the updated ant lion colony.

[0108] Sub-step 8, determining the number of times the above determination step has been executed.

[0109] Sub-step 9, in response to determining that the number of executions is greater than or equal to a preset execution threshold, the target update ant colony and the update ant lion colony are determined as the target parameter set of the code anomaly detection model to obtain an optimized code anomaly detection model. The preset execution threshold may be a pre-set maximum number of cycles of the determination step. For example, the preset execution threshold may be 100.

[0110] In the fourth step, in response to determining that the number of executions is less than the above-mentioned preset execution threshold, the target update ant colony and the update ant lion colony are determined as the initialization ant colony and the initialization ant lion colony, and the sum of the number of executions and the preset threshold is determined as the number of executions, so as to perform the above-mentioned determination step again. Among them, the above-mentioned preset threshold may be a preset threshold. For example, the above-mentioned preset threshold may be 1. It should be noted that by using ant colonies and ant lion colonies to perform cyclic iterative processing on the relevant parameters of the above-mentioned code anomaly detection model, the accuracy of the code anomaly detection model in identifying code anomalies can be improved, and the code anomaly detection model can be made more in line with the information detection scenario, thereby improving the security of the data source test application end, improving the security of obtaining data, and reducing the risk of data leakage stored in the data source test application end.

[0111] Step 106 , in response to determining that the request information verification result indicates that the verification has passed, the plaintext data source request information is subjected to input parameter identification to obtain a data source request interface input parameter set.

[0112] In some embodiments, the execution subject may identify the input parameters of the plaintext data source request information in response to determining that the verification result of the request information indicates that the verification has passed, and obtain a data source request interface input parameter set. Among them, the data source request interface input parameter parameters in the data source request interface input parameter set may be parameters of the requested data source.

[0113] Step 107: Obtain request data corresponding to the encrypted data source request information from the data source test application according to the input parameter set of the data source request interface.

[0114] In some embodiments, the execution subject may obtain the request data corresponding to the encrypted data source request information from the data source test application according to the input parameter set of the data source request interface. The request data may be the data stored in the data source test application obtained by the encrypted data source request information.

[0115] Optionally, after step 107, the execution subject may further perform the following steps:

[0116] In response to determining that the request information verification result indicates that the verification has failed, the data request for the encrypted data source request information is terminated.

[0117] The above-mentioned various embodiments of the present disclosure have the following beneficial effects: The data acquisition method based on encrypted requests in some embodiments of the present disclosure can obtain the data corresponding to the encrypted data source requests through a code non-invasive method, which can reduce the intrusion into the original code, omit the decryption step of the encrypted data source request information, improve the data acquisition efficiency, and reduce the load on the data source test application side. Specifically, the reasons for the relatively large load on the relevant data source test application side, low efficiency in obtaining the data source, long acquisition time, and low data security are as follows: Since decryption requires a large amount of operations, and the decryption steps are complex and prone to low accuracy in identifying the decrypted input parameter values, it leads to a relatively large load on the data source test application side, low efficiency in obtaining the data source, long acquisition time, and low data security. Based on this, the image segmentation method in some embodiments of the present disclosure can first, in response to detecting the encrypted data source request information sent to the test interface of the data source test application side, determine the plaintext request location information of the plaintext data source request information corresponding to the above-mentioned encrypted data source request information. Here, it is convenient to create a data source request sandbox isolation environment subsequently. Secondly, according to the above-mentioned plaintext request location information, create a data source request sandbox isolation environment, where the above-mentioned data source request sandbox isolation environment is a non-invasive embedded environment created for the above-mentioned plaintext data source request method. Here, code can be embedded non-invasively without affecting the original code, improving the scalability and maintainability of the data source test application side, and thus improving the stability of the data source test application side. Thirdly, perform bytecode enhancement processing on the plaintext data source request code corresponding to the above-mentioned plaintext data source request information to obtain the enhanced plaintext data source request code. Here, non-invasively performing bytecode enhancement processing on the original code can improve the stability, maintainability, and scalability of the data source test application side. Subsequently, according to the above-mentioned enhanced plaintext data source request code, start the isolation environment of the above-mentioned data source request sandbox isolation environment. Here, isolation from the original code and non-invasive embedding of the code can be achieved. Then, in response to detecting the successful startup of the isolation environment, perform information verification processing on the above-mentioned plaintext data source request information to obtain a request information verification result. Here, it can detect whether there is a problem of malicious code injection in the plaintext data source request information, improve the security of the request, and thus improve the security of the private data of the data source data, reducing the risk of data leakage. Then, in response to determining that the above-mentioned request information verification result indicates that the verification has passed, perform input parameter identification on the above-mentioned plaintext data source request information to obtain a data source request interface input parameter set. Here, the identification of plaintext input parameters can eliminate the decryption step of encrypted parameters, reduce the large amount of mathematical operations in the encryption step, reduce the complexity of input parameter identification, and the operation load on the data source test application side. Finally, according to the above-mentioned data source request interface input parameter set, obtain the request data corresponding to the above-mentioned encrypted data source request information from the above-mentioned data source test application side.Here, by simulating the real data source server through the data source test application end, the security of the real data can be improved, and the test interface can be tested independently, isolating the test environment that has a dependency relationship with the test interface, and improving the accuracy of the test and the efficiency of data acquisition. It can be obtained that the data acquisition method based on the encrypted request obtains the data corresponding to the encrypted data source request through a code-free intrusion method, which can reduce the intrusion into the original code, omit the decryption step of the encrypted data source request information, improve the efficiency of data acquisition, and reduce the load of the data source test application end.

[0118] Further references Figure 2 As an implementation of the methods shown in the above figures, the present disclosure provides some embodiments of a data acquisition device based on an encryption request. These device embodiments are similar to Figure 1 Corresponding to the method embodiments shown, the data acquisition device based on encryption request can be specifically applied to various electronic devices.

[0119] like Figure 2 As shown, a data acquisition device 200 based on an encrypted request includes: a determination unit 201, a creation unit 202, a byte code enhancement unit 203, an isolation environment startup unit 204, an information verification unit 205, an input parameter identification unit 206 and an acquisition unit 207. Among them, the determination unit 201 is configured to: in response to detecting the encrypted data source request information of the test interface sent to the data source test application end, determine the plaintext request location information of the plaintext data source request information corresponding to the above encrypted data source request information. The creation unit 202 is configured to: create a data source request sandbox isolation environment according to the above plaintext request location information, wherein the above data source request sandbox isolation environment is a non-intrusive embedded environment created for the above plaintext data source request method. The byte code enhancement unit 203 is configured to: perform byte code enhancement processing on the plaintext data source request code corresponding to the above plaintext data source request information to obtain the enhanced plaintext data source request code. The isolation environment startup unit 204 is configured to: according to the enhanced plaintext data source request code, start the isolation environment of the above data source request sandbox isolation environment. The information verification unit 205 is configured to: in response to detecting that the isolation environment is successfully started, perform information verification processing on the above-mentioned plaintext data source request information to obtain the request information verification result. The input parameter identification unit 206 is configured to: in response to determining that the above-mentioned request information verification result indicates that the verification has passed, perform input parameter identification on the above-mentioned plaintext data source request information to obtain the data source request interface input parameter set. The acquisition unit 207 is configured to: according to the above-mentioned data source request interface input parameter set, obtain the request data corresponding to the above-mentioned encrypted data source request information from the above-mentioned data source test application end.

[0120] It can be understood that the units recorded in the data acquisition device 200 based on the encryption request are similar to the reference Figure 1 Therefore, the operations, features and beneficial effects described above for the method are also applicable to the data acquisition device 200 based on encryption request and the units contained therein, and will not be described in detail here.

[0121] Reference below Figure 3 , which shows a structural schematic diagram of an electronic device (eg, an electronic device) 300 suitable for implementing some embodiments of the present disclosure. Figure 3 The electronic device shown is only an example and should not bring any limitation to the functions and scope of use of the embodiments of the present disclosure.

[0122] like Figure 3 As shown, the electronic device 300 may include a processing device (e.g., a central processing unit, a graphics processing unit, etc.) 301, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 302 or a program loaded from a storage device 308 into a random access memory (RAM) 303. In the RAM 303, various programs and data required for the operation of the electronic device 300 are also stored. The processing device 301, the ROM 302, and the RAM 303 are connected to each other via a bus 304. An input / output (I / O) interface 305 is also connected to the bus 304.

[0123] Typically, the following devices may be connected to the I / O interface 305: input devices 306 including, for example, a touch screen, a touch pad, a keyboard, a mouse, a camera, a microphone, an accelerometer, a gyroscope, etc.; output devices 307 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; storage devices 308 including, for example, a magnetic tape, a hard disk, etc.; and communication devices 309. The communication devices 309 may allow the electronic device 300 to communicate with other devices wirelessly or by wire to exchange data. Although Figure 3 The electronic device 300 is shown with various devices, but it should be understood that it is not required to implement or possess all the devices shown. More or fewer devices may be implemented or possessed instead. Figure 3 Each block shown in the figure may represent one device, or may represent multiple devices as required.

[0124] In particular, according to some embodiments of the present disclosure, the process described above with reference to the flowchart can be implemented as a computer software program. For example, some embodiments of the present disclosure include a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program includes a program code for executing the method shown in the flowchart. In some such embodiments, the computer program can be downloaded and installed from the network through the communication device 309, or installed from the storage device 308, or installed from the ROM 302. When the computer program is executed by the processing device 301, the above-mentioned functions defined in the method of some embodiments of the present disclosure are executed.

[0125] It should be noted that the computer-readable medium in some embodiments of the present disclosure may be a computer-readable signal medium or a computer-readable storage medium or any combination of the two. The computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or device, or any combination of the above. More specific examples of computer-readable storage media may include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In some embodiments of the present disclosure, the computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in combination with an instruction execution system, device or device. In some embodiments of the present disclosure, the computer-readable signal medium may include a data signal propagated in a baseband or as part of a carrier wave, in which a computer-readable program code is carried. This propagated data signal may take a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The computer readable signal medium may also be any computer readable medium other than a computer readable storage medium, which may send, propagate or transmit a program for use by or in conjunction with an instruction execution system, apparatus or device. The program code contained on the computer readable medium may be transmitted using any suitable medium, including but not limited to: wires, optical cables, RF (radio frequency), etc., or any suitable combination of the above.

[0126] In some embodiments, the client and the server may communicate using any currently known or future developed network protocol such as HTTP (Hyper Text Transfer Protocol), and may be interconnected with any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include a local area network ("LAN"), a wide area network ("WAN"), an internet (e.g., the Internet), and a peer-to-peer network (e.g., an ad hoc peer-to-peer network), as well as any currently known or future developed network.

[0127] The computer-readable medium may be included in the electronic device, or may exist independently without being incorporated into the electronic device. The computer-readable medium carries one or more programs. When the one or more programs are executed by the electronic device, the electronic device: in response to detecting the encrypted data source request information of the test interface sent to the data source test application end, determines the plaintext request location information of the plaintext data source request information corresponding to the encrypted data source request information; creates a data source request sandbox isolation environment according to the plaintext request location information, wherein the data source request sandbox isolation environment is a non-intrusive embedded environment created for the plaintext data source request method; performs byte code enhancement processing on the plaintext data source request code corresponding to the plaintext data source request information to obtain the enhanced plaintext data source request code; according to the enhanced plaintext data source request code, performs an isolation environment startup on the data source request sandbox isolation environment; in response to detecting that the isolation environment startup is successful, performs information verification processing on the plaintext data source request information to obtain a request information verification result; in response to determining that the request information verification result indicates that the verification is passed, performs input parameter identification on the plaintext data source request information to obtain a data source request interface input parameter set; according to the data source request interface input parameter set, obtains the request data corresponding to the encrypted data source request information from the data source test application end.

[0128] Computer program code for performing the operations of some embodiments of the present disclosure may be written in one or more programming languages ​​or a combination thereof, including object-oriented programming languages ​​such as Java, Smalltalk, C++, and conventional procedural programming languages ​​such as "C" or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, as a separate software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving a remote computer, the remote computer may be connected to the user's computer via any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., via the Internet using an Internet service provider).

[0129] The flow chart and block diagram in the accompanying drawings illustrate the possible architecture, function and operation of the system, method and computer program product according to various embodiments of the present disclosure. In this regard, each square box in the flow chart or block diagram can represent a module, a program segment or a part of a code, and the module, the program segment or a part of the code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some implementations as replacements, the functions marked in the square box can also occur in a sequence different from that marked in the accompanying drawings. For example, two square boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each square box in the block diagram and / or flow chart, and the combination of the square boxes in the block diagram and / or flow chart can be implemented with a dedicated hardware-based system that performs a specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.

[0130] The units described in some embodiments of the present disclosure may be implemented by software or by hardware. The described units may also be provided in a processor, for example, may be described as: a processor including a determination unit, a creation unit, a byte code enhancement unit, an isolation environment startup unit, an information verification unit, an input parameter identification unit, and an acquisition unit. Among them, the names of these units do not constitute a limitation on the unit itself under certain circumstances, for example, the determination unit may also be described as "a unit that determines the plaintext request location information of the plaintext data source request information corresponding to the above-mentioned encrypted data source request information in response to detecting the encrypted data source request information of the test interface sent to the data source test application end".

[0131] The functions described above herein may be performed at least in part by one or more hardware logic components. For example, without limitation, exemplary types of hardware logic components that may be used include: field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on chips (SOCs), complex programmable logic devices (CPLDs), and the like.

[0132] The above descriptions are only some preferred embodiments of the present disclosure and an explanation of the technical principles used. Those skilled in the art should understand that the scope of the invention involved in the embodiments of the present disclosure is not limited to the technical solutions formed by a specific combination of the above-mentioned technical features, but should also cover other technical solutions formed by any combination of the above-mentioned technical features or their equivalent features without departing from the above-mentioned inventive concept. For example, the above-mentioned features are replaced with the technical features with similar functions disclosed in the embodiments of the present disclosure (but not limited to) and the technical solutions formed.

Claims

1. A data acquisition method based on an encryption request, comprising: In response to detecting encrypted data source request information sent to the test interface of the data source test application, determining plaintext request position information of plaintext data source request information corresponding to the encrypted data source request information; Creating a data source request sandbox isolation environment according to the plaintext request location information, wherein the data source request sandbox isolation environment is a non-invasive embedded environment created for the plaintext data source request information; Performing byte code enhancement processing on the plaintext data source request code corresponding to the plaintext data source request information to obtain an enhanced plaintext data source request code; According to the enhanced plaintext data source request code, the data source request sandbox isolation environment is started in an isolation environment; In response to detecting that the isolation environment is successfully started, performing information verification processing on the plaintext data source request information to obtain a request information verification result; In response to determining that the request information verification result indicates that the verification has passed, identifying input parameter of the plaintext data source request information to obtain a data source request interface input parameter set; According to the data source request interface input parameter set, request data corresponding to the encrypted data source request information is obtained from the data source test application end.

2. The method according to claim 1, wherein: The method further comprises: In response to determining that the request information verification result indicates that the verification has failed, terminating the data request of the encrypted data source request information.

3. The method according to claim 1, wherein: The step of starting the isolation environment of the data source request sandbox isolation environment according to the enhanced plaintext data source request code includes: Perform spy method tracking on the enhanced plaintext data source request code to obtain the plaintext request spy code; Perform cross-cutting declarative loading on the plaintext request spy class code; In response to detecting that the plaintext request spy class code is successfully loaded, establishing code communication between the plaintext request spy class code and the business original code; In response to detecting that the code communication is successful, the data source request sandbox isolation environment is started.

4. The method according to claim 3, wherein: The cross-cutting declarative loading of the plaintext request spy class code includes: Performing an abstract syntax tree construction on the plaintext data source request code corresponding to the plaintext data source request information to obtain a test interface call syntax tree; Parsing the test interface call syntax tree to obtain an interface call connectivity graph; Performing a breadth-first search on the interface call connectivity graph to obtain application interface parameter configuration information; Adopting the sandbox class loading parent delegation model, determining the parent request class loader of the plaintext request spy class code according to the application interface parameter configuration information; In response to determining that the parent request class loader is not the target parent request class loader, determining a parent request class loader of the parent request class loader as a parent parent request loader; In response to determining that the parent parent request loader is loading the target parent request class, performing cross-cutting declarative loading on the parent parent request loader to obtain a request loading result; In response to determining that the request loading result indicates that the loading was not successful, cross-cutting declarative loading is performed on the plaintext request spy class code.

5. The method according to claim 1, wherein: The performing information verification processing on the plaintext data source request information to obtain the request information verification result includes: Performing code conversion on the data source request code corresponding to the plaintext data source request information to obtain a converted data source request code; Determine a conditional judgment statement code set in the converted data source request code; Performing static code instrumentation processing on each conditional judgment statement code in the conditional judgment statement code set to obtain an instrumented conditional judgment statement code set; Generate a data flow control flow chart for the plaintext data source request information according to the instrumentation condition judgment statement code set; According to the data flow control flow chart, extracting the out-of-domain context of the instrumentation condition judgment statement code set to obtain an out-of-domain context information set, wherein the out-of-domain context information is information that controls the judgment result of the condition judgment statement code set; Determine a conditional judgment statement code set corresponding to the out-of-domain context information set as a target conditional judgment statement code set; Performing control flow dependency analysis on the target condition judgment statement code set to generate a condition judgment range for each target condition judgment statement code in the target condition judgment statement code set to obtain a condition judgment range set; According to the conditional judgment range set, the data source request code is subjected to in-domain context extraction to obtain an in-domain context information set, wherein the in-domain context information represents the data flow situation within the conditional judgment range; According to the in-domain context information set and the out-of-domain context information set, anomaly detection processing is performed on the plaintext data source request information to obtain an anomaly detection result as a request information verification result.

6. The method according to claim 5, wherein: The performing anomaly detection processing on the plaintext data source request information according to the in-domain context information set and the out-of-domain context information set to obtain an anomaly detection result as the request information verification result includes: Performing feature extraction on the in-domain context information set and the out-of-domain context information set to obtain an in-domain feature information set and an out-of-domain feature information set; Performing feature embedding on the in-domain feature information set and the out-of-domain feature information set to obtain an out-of-domain feature vector set and an in-domain feature vector set; Determine the feature similarity of each out-of-domain feature vector in the out-of-domain feature vector set and each in-domain feature vector in the in-domain feature vector set to obtain a feature similarity group set; Filtering at least one in-domain feature vector and at least one out-domain feature vector whose corresponding feature similarity is greater than or equal to a preset similarity threshold from the in-domain feature vector set and the out-domain feature vector set; Optimizing the code anomaly detection model to obtain an optimized code anomaly detection model; The at least one in-domain feature vector and the at least one out-of-domain feature vector are input into the trained optimized code anomaly detection model to obtain an anomaly detection result as a request information verification result.

7. The method according to claim 6, wherein: The optimizing process of the code anomaly detection model to obtain the optimized code anomaly detection model includes: Initializing the parameter set of the code anomaly detection model to obtain an initial parameter set as an initial ant colony and an initial ant lion colony, wherein the initial parameter set includes at least one of the following: a penalty factor and a kernel function parameter; Generating a model fitness function for the code anomaly detection model; Based on the initialization of the ant colony and the initialization of the ant lion colony, the following determination steps are performed: Substituting the initialized ant colony and the initialized ant lion colony into the model fitness function to obtain an ant colony fitness function value set and an ant lion fitness function value set; Selecting the antlion fitness function value with the largest value from the antlion fitness function value set as the target antlion fitness function value, and determining the antlion corresponding to the target antlion fitness function value as the target antlion; Determine the initialization ant lion corresponding to each initialization ant in the initialization ant colony, and obtain the associated ant lion colony; According to the associated antlion group and the target antlion, the position of the initialized ant colony is updated to obtain the updated ant colony; Substituting the updated ant colony into the model fitness function to obtain a fitness function value set of the ant colony after update; Compare each ant colony updated fitness function value in the ant colony updated fitness function value set with the ant lion fitness function value corresponding to the ant colony updated fitness function value in the ant lion fitness function value set to obtain a comparison result set; According to the comparison result set, the updated ant colony and the initial ant lion colony are updated to obtain the target updated ant colony and the updated ant lion colony; determining a number of times the determining step has been performed; In response to determining that the number of executions is greater than or equal to a preset execution threshold, the target update ant colony and the update ant lion colony are determined as a target parameter set of the code anomaly detection model to obtain an optimized code anomaly detection model; In response to determining that the number of executions is less than the preset execution threshold, the target update ant colony and the update ant lion colony are determined as the initialization ant colony and the initialization ant lion colony, and the sum of the number of executions and the preset threshold is determined as the number of executions, so as to perform the determination step again.

8. A data acquisition device based on an encryption request, comprising: a determining unit configured to, in response to detecting encrypted data source request information sent to the test interface of the data source test application end, determine plaintext request position information of plaintext data source request information corresponding to the encrypted data source request information; A creating unit, configured to create a data source request sandbox isolation environment according to the plaintext request location information, wherein the data source request sandbox isolation environment is a non-intrusive embedded environment created for the plaintext data source request information; a byte code enhancement unit configured to perform byte code enhancement processing on the plaintext data source request code corresponding to the plaintext data source request information to obtain an enhanced plaintext data source request code; An isolation environment startup unit, configured to start the isolation environment for the data source request sandbox isolation environment according to the enhanced plaintext data source request code; An information verification unit is configured to, in response to detecting that the isolation environment is successfully started, perform information verification processing on the plaintext data source request information to obtain a request information verification result; An input parameter identification unit is configured to, in response to determining that the request information verification result indicates that the verification has passed, identify the input parameter of the plaintext data source request information to obtain a data source request interface input parameter set; The acquisition unit is configured to acquire request data corresponding to the encrypted data source request information from the data source test application end according to the data source request interface input parameter set.

9. An electronic device, comprising: one or more processors; a storage device having one or more programs stored thereon, When the one or more programs are executed by the one or more processors, the one or more processors implement the method according to any one of claims 1 to 7.

10. A computer readable medium having a computer program stored thereon, wherein: When the computer program is executed by a processor, the method according to any one of claims 1 to 7 is implemented.

Citation Information

Patent Citations

  • Wasm-based general data encryption method and system

    CN118118209A

  • Audio stream adaptive decryption method, system and device and storage medium

    CN119337396A

  • The internet of things

    US20190349426A1