Protocol fuzz testing method and device based on proxy connectivity verification

By adopting a proxy connectivity verification method in protocol fuzz testing, the efficiency reduction problem caused by proxy server connection problems in traditional testing is solved, and a more efficient and accurate testing process is achieved.

CN120034458APending Publication Date: 2025-05-23SECZONE TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510238383.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-03
Publication Date
2025-05-23

AI Technical Summary

Technical Problem

In the traditional protocol fuzz testing method, connection problems or configuration errors in the proxy server cannot be discovered in a timely manner, resulting in the test data packets being unable to be correctly sent to the target system, reducing the testing efficiency.

Method used

Using a protocol fuzz testing method based on proxy connectivity verification, a verification request is generated and sent to a proxy server, and a hierarchical evaluation is performed based on preset multi-level proxy connectivity verification conditions to determine the basic communication capabilities and proxy capabilities of the proxy server, thereby marking the proxy server as passed or failed verification.

Benefits of technology

By performing efficient and accurate proxy connectivity verification on the proxy server, resource waste or test misjudgment caused by proxy server problems is effectively avoided, and the efficiency and accuracy of protocol fuzz testing is improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120034458A_ABST
    Figure CN120034458A_ABST
Patent Text Reader

Abstract

The invention relates to a protocol fuzz testing method and device based on proxy connectivity verification. The method comprises the following steps: determining a proxy server corresponding to a protocol fuzz test task; based on multi-level agent connectivity verification conditions, generating a verification request and sending the verification request to the agent server, the multi-level agent connectivity verification conditions including a basic connectivity verification condition and an agent capability verification condition; if response information returned by the proxy server based on the verification request is received, taking the proxy server as a first proxy server meeting a multi-level proxy connectivity verification condition, and executing a protocol fuzz test task based on the first proxy server; and if the response information is not received, taking the proxy server as a second proxy server which does not meet the multi-level proxy connectivity verification condition, and stopping the protocol fuzz test task. By adopting the method, efficient and accurate proxy connectivity verification can be carried out on the proxy server, and the efficiency and accuracy of protocol fuzz testing are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of security testing technology, and in particular to a protocol fuzz testing method and device based on proxy connectivity verification. Background Art

[0002] In the field of security testing technology, abnormal information is generated through a protocol fuzzy testing method, and security detection is performed on the device under test based on the abnormal information.

[0003] However, in traditional protocol fuzz testing methods, if the connection problem or configuration error of the proxy server is not discovered in time, the test data packet cannot be correctly sent to the target system, resulting in test blockage and reducing the efficiency of protocol fuzz testing. Summary of the invention

[0004] Based on this, it is necessary to provide a protocol fuzz testing method, device, computer equipment and computer-readable storage medium based on proxy connectivity verification to address the above-mentioned technical problems, which is used to perform efficient and accurate proxy connectivity verification on the proxy server, thereby improving the efficiency and accuracy of protocol fuzz testing.

[0005] In a first aspect, the present application provides a protocol fuzz testing method based on proxy connectivity verification, comprising: Generate a protocol fuzzy test task, and determine a proxy server corresponding to the protocol fuzzy test task; Based on the preset multi-level proxy connectivity verification conditions, a verification request is generated, and the verification request is sent to the proxy server, wherein the multi-level proxy connectivity verification conditions include basic connectivity verification conditions and proxy capability verification conditions, wherein the basic connectivity verification conditions are used to detect the basic communication capability of the proxy server, and the proxy capability verification conditions are used to detect the proxy capability of the proxy server based on the protocol fuzzy test task; If response information returned by the proxy server based on the verification request is received, the proxy server is used as a first proxy server that meets the multi-level proxy connectivity verification condition, and the protocol fuzzy test task is performed based on the first proxy server; If the response information returned by the proxy server based on the verification request is not received, the proxy server is regarded as a second proxy server that does not meet the multi-level proxy connectivity verification condition, and the protocol fuzzy test task is terminated.

[0006] In a second aspect, the present application also provides a protocol fuzz testing device based on proxy connectivity verification, comprising: A generation module, used to generate a protocol fuzzy test task and determine a proxy server corresponding to the protocol fuzzy test task; A verification module, used to generate a verification request based on a preset multi-level proxy connectivity verification condition, and send the verification request to the proxy server, wherein the multi-level proxy connectivity verification condition includes a basic connectivity verification condition and a proxy capability verification condition, wherein the basic connectivity verification condition is used to detect the basic communication capability of the proxy server, and the proxy capability verification condition is used to detect the proxy capability of the proxy server based on the protocol fuzzy test task; A first processing module is used for, upon receiving the response information returned by the proxy server based on the verification request, taking the proxy server as a first proxy server that meets the multi-level proxy connectivity verification condition, and performing the protocol fuzzy test task based on the first proxy server; The second processing module is used to treat the proxy server as a second proxy server that does not meet the multi-level proxy connectivity verification condition and terminate the protocol fuzzy test task when the response information returned by the proxy server based on the verification request is not received.

[0007] In a third aspect, the present application further provides a computer device, including a memory and a processor, wherein the memory stores a computer program, and the processor implements the above steps when executing the computer program.

[0008] In a fourth aspect, the present application further provides a computer-readable storage medium having a computer program stored thereon, wherein the computer program implements the above steps when executed by a processor.

[0009] The above-mentioned protocol fuzz testing method, device, computer equipment and computer-readable storage medium based on proxy connectivity verification first determine the proxy server corresponding to the protocol fuzz testing task, and based on the preset multi-level proxy connectivity verification conditions, hierarchically generate verification requests and send them to the proxy server, so as to comprehensively evaluate the basic communication capabilities and proxy capabilities of the proxy server based on the verification requests; secondly, according to the response of the proxy server based on the verification request, the proxy server is efficiently marked as the first proxy server that passes the proxy connectivity verification or the second proxy server that fails the proxy connectivity verification, and then according to the category of the marked proxy server, the execution status of the protocol fuzz testing task is accurately confirmed; based on this, according to the efficient and accurate proxy connectivity verification of the proxy server in advance, the waste of resources or test misjudgment caused by proxy server problems is effectively avoided, thereby improving the efficiency and accuracy of the protocol fuzz testing. BRIEF DESCRIPTION OF THE DRAWINGS

[0010] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the related technologies, the drawings required for use in the embodiments or the related technical descriptions are briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.

[0011] Figure 1 A schematic diagram of a flow chart of a protocol fuzz testing method based on proxy connectivity verification in one embodiment; Figure 2 It is a structural block diagram of a protocol fuzz testing device based on proxy connectivity verification in one embodiment. DETAILED DESCRIPTION

[0012] In order to make the purpose, technical solution and advantages of the present application more clearly understood, the present application is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.

[0013] In one embodiment, Figure 1 As shown, a protocol fuzzy testing method based on proxy connectivity verification is provided. This embodiment uses the method applied to a server as an example. It can be understood that the method can also be applied to a terminal, and can also be applied to a system including a terminal and a server, and is implemented through the interaction between the terminal and the server. In this embodiment, the method includes the following steps S101 to S104.

[0014] Step S101, generate a protocol fuzzy test task, and determine the proxy server corresponding to the protocol fuzzy test task.

[0015] The protocol fuzz testing task refers to the operational task of performing protocol fuzz testing on a specific network protocol, which is used to discover potential vulnerabilities or abnormal behaviors in the protocol implementation.

[0016] The proxy server refers to an intermediary server, which is used to transmit test data packets between the client and the target server and record response information.

[0017] Exemplarily, the test target of the protocol fuzz test task is determined according to information such as the communication protocol type and the communication protocol version; the test parameters of the protocol fuzz test task are determined according to information such as the data packet type, the test load range and the expected output results; based on the test target and the test parameters, the corresponding protocol fuzz test task is generated.

[0018] Exemplarily, the proxy server resource pool contains information on all available proxy servers, such as address, port, communication protocol type, current operating status, etc.; according to the test objectives and test parameters of the protocol fuzz testing task, combined with the information of each available proxy server in the proxy server resource pool, the proxy server corresponding to the protocol fuzz testing task is screened from each available proxy server.

[0019] Step S102, based on the preset multi-level proxy connectivity verification conditions, generate a verification request and send the verification request to the proxy server. The multi-level proxy connectivity verification conditions include basic connectivity verification conditions and proxy capability verification conditions. The basic connectivity verification conditions are used to detect the basic communication capabilities of the proxy server, and the proxy capability verification conditions are used to detect the proxy capabilities of the proxy server based on the protocol fuzz testing task.

[0020] Among them, the multi-level proxy connectivity verification conditions represent hierarchical conditions for judging the availability and functionality of the proxy server, which are used to comprehensively evaluate the basic communication capabilities and proxy capabilities of the proxy server.

[0021] Among them, the basic connectivity verification condition in the multi-level proxy connectivity verification condition is used to confirm whether the proxy server can establish a stable basic communication link. For example, it can represent a verification condition for confirming whether the proxy server can accept a connection and return a basic response.

[0022] Among them, the proxy capability verification condition in the multi-level proxy connectivity verification condition is used to confirm whether the proxy server has the necessary proxy function support, for example, it can indicate the verification condition whether the proxy server can parse and correctly forward specific protocol data packets.

[0023] The verification request represents a communication instruction generated based on the basic communication capability and proxy capability of the test proxy server, which is used to initiate proxy connectivity verification to the proxy server to detect the response capability of the proxy server.

[0024] Exemplarily, a verification request is generated through multi-level proxy connectivity verification conditions, that is, according to the basic connectivity verification conditions, the focus is initially on whether the proxy server can establish a basic communication link, and then according to the proxy capability verification conditions, the focus is further on whether the proxy server can support the requirements of a specific protocol fuzz testing task, thereby hierarchically designing data packets for testing the basic communication capabilities and proxy capabilities of the proxy server, generating a verification request based on the designed data packets, and sending it to the proxy server through the network interface.

[0025] Step S103: if response information returned by the proxy server based on the verification request is received, the proxy server is used as the first proxy server that meets the multi-level proxy connectivity verification condition, and the protocol fuzzy test task is performed based on the first proxy server.

[0026] The response information represents the communication data returned by the proxy server in response to the verification request, which is used to confirm whether the proxy server meets the multi-level proxy connectivity verification conditions.

[0027] Exemplarily, if the response information returned by the proxy server is successfully received, it is confirmed that the proxy server meets the multi-level proxy connectivity verification conditions, that is, the response information itself reflects that the proxy server has basic connectivity and proxy capabilities, and there is no need for additional parsing or analysis of the response information; then, the proxy server is marked as the first proxy server that meets the multi-level proxy connectivity verification conditions, and is bound to the current protocol fuzzy test task. After the binding is completed, the protocol fuzzy test task is started and executed through the first proxy server.

[0028] Step S104: If the response information returned by the proxy server based on the verification request is not received, the proxy server is regarded as a second proxy server that does not meet the multi-level proxy connectivity verification condition, and the protocol fuzzy test task is terminated.

[0029] Exemplarily, a timeout is set after sending a verification request, and the response of the proxy server is monitored during the timeout; if no response information is received from the proxy server at the end of the timeout, the proxy server is marked as a second proxy server that does not meet the multi-level proxy connectivity verification conditions; then, the current protocol fuzzy testing task is terminated to avoid test errors caused by the unavailability of the second proxy server.

[0030] Optionally, detailed exception information, such as the address and port of the second proxy server and the reason for the failure of the verification request, can be fed back through the user interface to ensure that the user can quickly identify the problem and make adjustments, such as changing the proxy server or reconfiguring the proxy parameters.

[0031] In the above-mentioned protocol fuzz testing method based on proxy connectivity verification, first, the proxy server corresponding to the protocol fuzz testing task is determined, and based on the preset multi-level proxy connectivity verification conditions, a verification request is hierarchically generated and sent to the proxy server, so as to comprehensively evaluate the basic communication capability and proxy capability of the proxy server based on the verification request; secondly, according to the response of the proxy server based on the verification request, the proxy server is efficiently marked as the first proxy server that has passed the proxy connectivity verification or the second proxy server that has not passed the proxy connectivity verification, and then according to the category of the marked proxy server, the execution status of the protocol fuzz testing task is accurately confirmed; based on this, according to the efficient and accurate proxy connectivity verification of the proxy server in advance, the waste of resources or test misjudgment caused by proxy server problems is effectively avoided, thereby improving the efficiency and accuracy of the protocol fuzz testing.

[0032] In an exemplary embodiment, determining a proxy server corresponding to a protocol fuzz testing task includes steps S201 to S203.

[0033] Step S201, obtain multiple candidate proxy servers, perform feature extraction processing on each candidate proxy server, and obtain feature data corresponding to each candidate proxy server, the feature data including the network address, supported communication protocol type, authentication method, maximum number of connections and response time history record of each candidate proxy server.

[0034] The candidate proxy server represents a group of proxy servers obtained from a proxy server resource pool and can be selected to perform a protocol fuzz testing task. For example, it can represent a set of proxy servers with different network addresses and supporting multiple types of communication protocols.

[0035] Exemplarily, in a proxy server resource pool, multiple currently available candidate proxy servers are retrieved, and feature extraction processing is performed on each candidate proxy server to obtain feature data corresponding to each candidate proxy server, wherein feature data such as network address, supported communication protocol type, authentication method, maximum number of connections, and response time history record are used to comprehensively describe the communication capability and status of the candidate proxy server.

[0036] Exemplarily, the network address is extracted to subsequently confirm whether the candidate proxy server can be correctly located and connected; the supported communication protocol type is extracted to subsequently confirm whether the candidate proxy server supports the communication protocol corresponding to the protocol fuzz testing task; the authentication method is extracted to subsequently confirm the security of the access rights corresponding to the candidate proxy server; the maximum number of connections is extracted to subsequently confirm the concurrent processing capability of the candidate proxy server; the response time history record is extracted to subsequently confirm the response performance of the candidate proxy server under different network environments.

[0037] Step S202, according to the task test requirements of the protocol fuzzy test task, the feature data corresponding to each candidate proxy server is respectively processed for adaptability calculation, and the adaptability evaluation results of each candidate proxy server corresponding to the task test requirements are obtained.

[0038] Among them, the task test requirements represent the specific requirements of the protocol fuzz testing task on the performance and functions of the proxy server, which is used to guide the screening and adaptability evaluation of candidate proxy servers. For example, it can indicate the need to support specific protocol types (such as HTTP or TCP), meet the minimum response time threshold, support specific authentication methods, etc.

[0039] Among them, the adaptability calculation processing refers to the process of calculating and comparing the characteristic data of the candidate proxy servers according to the task test requirements, which is used to evaluate whether each candidate proxy server matches the task requirements in terms of function and performance; the adaptability evaluation result refers to the evaluation result generated after the adaptability calculation processing, which is used to quantify the degree of matching between each candidate proxy server and the task test requirements, for example, it can be expressed as a score or grade.

[0040] Exemplarily, based on the task test requirements of the protocol fuzzy test task in terms of network address, supported communication protocol type, authentication method, number of connections and response time, the characteristic data of each candidate proxy server in terms of network address, supported communication protocol type, authentication method, maximum number of connections and response time history record are compared item by item, and then the adaptability evaluation results corresponding to the task test requirements of each candidate proxy server are determined according to the preset scoring mechanism. The adaptability evaluation results represent the matching degree of each candidate proxy server with the task test requirements in the form of scores or grades. For example, according to the importance of each task test requirement, weights are assigned to different characteristic data. For example, in the task test requirement to which the response time belongs, a higher score is given to the candidate proxy server with a shorter response time. Furthermore, the weights corresponding to each characteristic data can be dynamically adjusted according to the current network environment and task complexity.

[0041] Step S203, based on the adaptability evaluation results corresponding to each candidate proxy server, a proxy server corresponding to the protocol fuzzy test task is screened from multiple candidate proxy servers.

[0042] Exemplarily, first, each candidate proxy server is sorted according to the adaptability evaluation result of each candidate proxy server, for example, each candidate proxy server is sorted according to the score or level corresponding to the adaptability evaluation result, to obtain a sorting result; first, in the sorting result, the candidate proxy servers with lower rankings are identified as candidate proxy servers that do not meet the key task test requirements and are preferentially excluded, for example, candidate proxy servers that do not support the specified communication protocol or are not compatible with the specified authentication method are preferentially excluded; secondly, in the sorting result, for candidate proxy servers with closer rankings, they can be further distinguished by secondary screening, for example, referring to the stability of historical response time or the actual availability of the maximum number of connections, to further screen the candidate proxy servers.

[0043] Based on this, the proxy server corresponding to the protocol fuzzy testing task is screened out from multiple candidate proxy servers. Furthermore, a quick check is performed on the status of the screened proxy server to confirm that no state changes or abnormalities occur during the screening process, so as to ensure the validity of the screening results and the stability of task execution.

[0044] In this embodiment, first, the task test requirements of the protocol fuzz test task and the characteristic data corresponding to each candidate proxy server are subjected to adaptability calculation processing item by item, so as to obtain the adaptability evaluation results of each candidate proxy server based on the task test requirements in a multi-dimensional and accurate manner; secondly, according to the adaptability evaluation results corresponding to each candidate proxy server, the proxy server corresponding to the protocol fuzz test task is efficiently and accurately screened from multiple candidate proxy servers to ensure the task matching of the selected proxy server.

[0045] In an exemplary embodiment, based on a preset multi-level proxy connectivity verification condition, a verification request is generated, including steps S301 to S303.

[0046] Step S301, obtaining basic connectivity verification parameters in basic connectivity verification conditions, where the basic connectivity verification parameters represent basic parameters related to the communication network status, and the basic connectivity verification parameters include network reachability status, instant packet loss rate, and network delay fluctuation range.

[0047] Among them, the network reachability status is used to determine whether the proxy server can be normally accessed through the network, that is, to determine whether the proxy server is in a connectable network state. For example, it can indicate whether the proxy server is in a network state that can successfully respond to a PING request or establish a TCP connection.

[0048] Among them, the real-time packet loss rate is used to determine the proportion of communication data packet loss of the proxy server in the current network environment, that is, to evaluate the transmission quality of the proxy server in the current network environment. For example, it can indicate the percentage of unsuccessfully received response data packets to the total number of sent data packets after a certain number of data packets are sent.

[0049] Among them, the network delay fluctuation range is used to determine the delay variation of the proxy server in the current network environment, that is, it is used to evaluate the stability of the proxy server response speed. For example, it can represent the difference between the maximum and minimum values ​​of a set of test data packets in the round-trip time.

[0050] Step S302, obtaining proxy capability verification parameters in the proxy capability verification conditions, wherein the proxy capability verification parameters represent parameters related to proxy capability requirements, and the proxy capability verification parameters include protocol forwarding correctness requirements, dynamic load processing capability requirements, and special data verification capability requirements.

[0051] Among them, the protocol forwarding correctness requirement is used to determine whether the proxy server can maintain the integrity and accuracy of the data when forwarding the protocol data packet, that is, to verify whether the proxy server can correctly parse, forward and retain the content of the protocol data packet. For example, it can mean that after the proxy server forwards the data packet, it can determine whether the data content of the receiving end is completely consistent with that of the sending end and there is no data loss or change.

[0052] Among them, the dynamic load processing capability requirement is used to determine the processing capability and stability of the proxy server under high concurrency or dynamic traffic conditions, that is, to evaluate the performance of the proxy server in large-scale traffic or multi-tasking environments. For example, it can indicate whether the proxy server can maintain a low response delay and a high success processing rate when it receives a large number of requests in a short period of time.

[0053] Among them, the special data verification capability requirement is used to determine the proxy server's ability to handle exceptions, boundary values ​​or special format data, that is, to evaluate whether the proxy server can correctly parse and forward data packets that do not conform to the conventional format. For example, it can be used to determine whether the proxy server can correctly handle data packets containing special characters, extremely large or extremely small values, or malformed structures without errors or interruptions.

[0054] Step S303: Taking the basic connectivity verification parameter and the proxy capability verification parameter as request fields, a verification request including the request fields is generated.

[0055] Exemplarily, the basic connectivity verification parameters and the proxy capability verification parameters are organized and encapsulated according to the preset format of the verification request, and a request header containing identification content and a request body containing the basic connectivity verification parameters and the proxy capability verification parameters according to the verification request are generated. The verification request is obtained by combining the request header and the request body.

[0056] In this embodiment, the basic connectivity verification parameters in the basic connectivity verification conditions and the proxy capability verification parameters in the proxy capability verification conditions are used as request fields to generate a verification request including request fields, so that the verification request can comprehensively cover the verification of the communication network status and proxy capability requirements of the proxy server, and then adaptively perform multi-level proxy connectivity verification and comprehensive detection of the proxy server based on the verification request.

[0057] In an exemplary embodiment, if response information returned by the proxy server based on the verification request is received, the proxy server is used as the first proxy server that meets the multi-level proxy connectivity verification condition, including steps S401 to S403.

[0058] Step S401: If response information returned by the proxy server is received, the timestamp, header information and load information of the response information are parsed based on the request field of the verification request to obtain the parsing result of the response information.

[0059] Exemplarily, the response information is parsed in detail based on the request field of the verification request: first, the timestamp of the response information is extracted and parsed to calculate the delay time from sending the verification request to receiving the response information, so as to evaluate the response speed of the proxy server; secondly, the header information of the response information is extracted and parsed, and the key data such as the proxy server identification, communication protocol type and response status code contained in the header information are used to confirm whether the proxy server correctly understands and processes the verification request; thirdly, the load information of the response information is extracted and parsed, and the specific data returned by the proxy server in the process of processing the verification request contained in the load information, such as the forwarded test data packet or the result content of the operation, is used to confirm that the proxy server can return the expected data completely and correctly. These parsing processes are completed in a structured manner, and the generated parsing results completely include the timestamp parsing results, the header information parsing results and the load information parsing results.

[0060] Step S402: Obtain a response status record of the proxy server according to the parsing result, where the response status record includes a response success status and a data integrity status of the proxy server.

[0061] The response status record represents a comprehensive record of the proxy server's response behavior and capabilities in the process of processing the authentication request.

[0062] The successful response status indicates that the proxy server successfully returns a response within a preset time range, which is used to evaluate the basic connectivity and processing efficiency of the proxy server. For example, it may indicate that the proxy server completes the response operation of the verification request within a specified delay threshold.

[0063] Among them, the data integrity status indicates a state in which the load information returned by the proxy server is consistent with the content of the data expected to be returned by the verification request. It is used to confirm whether the proxy server correctly forwards or processes the data packet of the verification request. For example, it can be expressed as a state in which the load data has not been lost, tampered with, or abnormally modified.

[0064] Exemplarily, first, according to the parsing result corresponding to the timestamp, the timeliness of the proxy server's response to the verification request within the preset response time range is judged; secondly, according to the parsing result corresponding to the header information, the data refinement of the response structure returned by the proxy server according to the protocol type and field requirements in the verification request is judged; thirdly, according to the parsing result corresponding to the load information, the degree of data consistency between the load information returned by the proxy server and the expected return data of the verification request is judged. Based on the above judgment process, the response success status and data integrity status of the proxy server are obtained, thereby obtaining a response status record combining the response success status and data integrity status.

[0065] Step S403: The proxy server is regarded as the first proxy server that meets the multi-level proxy connectivity verification condition, and the response status record is associated with the first proxy server.

[0066] Exemplarily, the server identifier of the first proxy server is associated with its corresponding response status record, and the server identifier and the response status record are associated and stored in a database to ensure subsequent rapid retrieval and query, that is, when a subsequent task calls the first proxy server, the response status record associated with the server identifier can be quickly matched by querying the server identifier of the first proxy server, thereby directly obtaining reference content such as the response success status and data completeness status of the first proxy server.

[0067] In this embodiment, first, the timestamp, header information and load information of the response information are structured and parsed based on the request field of the verification request, and the parsing result of the response information is obtained in an integral and hierarchical manner; secondly, the response status record of the proxy server is adaptively obtained based on the parsing result, and the response status record is associated with the proxy server, thereby improving the retrieval efficiency and data reference of historical records such as the proxy server's response success status and data integrity status.

[0068] In an exemplary embodiment, obtaining a response status record of the proxy server according to the parsing result includes steps S501 to S503.

[0069] Step S501, performing phase analysis on the response success status of the proxy server according to the parsing result to obtain a phase identifier of the response success status, wherein the phase identifier of the response success status indicates the process phase of the proxy server when the response is successful.

[0070] Exemplarily, a timestamp is extracted from the response information and compared with the sending time of the verification request, the delay time of the response information is calculated, and then the delay time is compared with the preset response time limit to determine the performance of the proxy server in terms of response timeliness, that is, the stage identifier of the successful response status.

[0071] Among them, the stage identifier of the response success status can represent the different response stages determined by the proxy server based on the degree of timeliness when completing the verification request response, which is used to refine the description of the proxy server's processing efficiency and response timeliness to the verification request, that is, according to the degree of timeliness, the stage identifier can be subdivided into multiple measurement criteria, for example: the highest stage can be described as "quick and efficient response", which is used to indicate that the proxy server can complete the request response within the preset time range with extremely short delay; the medium stage can be described as "stable and timely response", which is used to indicate that the proxy server completes the response within a reasonable time range, meets the task test requirements but has no significant advantages; the lowest stage can be described as "completes the response within the critical time", which is used to indicate that the proxy server completes the response close to the time limit, and the performance is basically qualified but the processing efficiency is relatively low.

[0072] Step S502, performing phased analysis on the data integrity status of the proxy server according to the parsing result to obtain a dimension identifier of the data integrity status, wherein the dimension identifier of the data integrity status indicates the data dimension when the proxy server responds with complete data.

[0073] Exemplarily, header information and payload information are extracted from the response information, and length verification, structure analysis, and content comparison are performed to determine the data sophistication and consistency of the proxy server when returning the response information, that is, the dimensional identifier of the data integrity status.

[0074] Among them, the dimension identifier of the data integrity status can represent the different quality characteristics of the response information returned by the proxy server based on the data precision and data consistency, which is used to comprehensively evaluate the accuracy and integrity of the proxy server in data processing.

[0075] Among them, in terms of the degree of data sophistication, dimension identifiers can be divided into three levels: the highest level can be described as "data is rich and fully meets the requirements", which is used to indicate that the data returned by the proxy server is not only complete but also covers all the detailed requirements of the regulations; the middle level can be described as "data is complete and meets most requirements", which is used to indicate that the data meets the core requirements of the protocol but lacks some details; the lowest level can be described as "data basically meets the minimum regulations", which is used to indicate that the data is simple but meets the minimum requirements.

[0076] Among them, in terms of the degree of data consistency, dimension identifiers can also be divided into three levels: the highest level can be described as "data is complex and completely consistent", which is used to indicate that the data returned by the proxy server is accurate and completely matches the verification request expectations; the middle level can be described as "data is basically consistent with reasonable differences", which is used to indicate that the data content is basically consistent with expectations but there are slight acceptable deviations; the lowest level can be described as "data is simple and partially consistent", which is used to indicate that the data generally meets expectations but there are obvious deviations in key parts.

[0077] Step S503: obtaining a response status record of the proxy server based on the phase identifier of the response success status and the dimension identifier of the data complete status.

[0078] Exemplarily, the stage identifier of the response success status and the dimension identifier of the data complete status are integrated to obtain the response status record of the proxy server. In the response status record, the stage identifier of the response success status describes in detail the timeliness performance of the proxy server in the response, and the dimension identifier of the data complete status describes in detail the data refinement and data consistency of the proxy server in the response.

[0079] In this embodiment, on the one hand, by performing a stage-by-stage analysis on the response success status of the proxy server, the stage identifier of the proxy server in the response success status is accurately obtained. On the other hand, by performing a stage-by-stage analysis on the data integrity status of the proxy server, the dimension identifier of the proxy server in the data integrity status is accurately obtained. Then, based on the integration of the stage identifier of the response success status and the dimension identifier of the data integrity status, the response status record of the proxy server is obtained, so as to provide a comprehensive and detailed description of the proxy server in different aspects such as response timeliness performance and response data integrity performance in the response status record.

[0080] In an exemplary embodiment, if the response information returned by the proxy server based on the verification request is not received, the proxy server is regarded as a second proxy server that does not meet the multi-level proxy connectivity verification condition, including steps S601 to S603.

[0081] Step S601: If no response information returned by the proxy server is received within a preset period of time, timeout status information is generated, and the timeout status information includes the network address of the proxy server, the timeout time, the port number and the record of no response information received.

[0082] Among them, the timeout status information represents the status data recorded when the proxy server fails to complete the verification request response within a preset time period; among them, the network address and port number are used to identify the unresponsive proxy server, the timeout time is used to record the time point from sending the verification request to the timeout judgment, and the record of the unreceived response information is used to specifically describe the event corresponding to the failure to obtain the expected response to the verification request from the proxy server.

[0083] Exemplarily, based on the time point of sending the verification request and the listening time period, it is determined whether the current time has exceeded the preset response time limit; if the current time has exceeded the preset response time limit, it is determined that the proxy server has not completed the response operation on time, triggering the subsequent timeout processing mechanism and generating timeout status information.

[0084] Step S602: Perform abnormal analysis on the timeout status information to obtain an abnormal status record of the proxy server, where the abnormal status record includes the abnormal type, abnormal time and abnormal cause.

[0085] Among them, the abnormal status record represents a structured record generated after analyzing the abnormal situation in which the proxy server fails to complete the verification request response, which is used to comprehensively record the characteristics and impact of the abnormal situation; among them, the abnormal type represents the specific problem category in which the proxy server fails to complete the verification request response, for example, it can represent abnormal types such as "network unreachable", "response timeout" or "data transmission interruption"; the abnormal time represents the timeout time or the specific time point when the abnormality occurs; the abnormal reason represents the specific reason why the proxy server fails to complete the verification request response, for example, it can be represented as "network congestion causing high latency", "port blocked by firewall" or "proxy server overload causing response failure" and other reasons.

[0086] Exemplarily, first, in combination with the network address and port number in the timeout status information, the current network status of the proxy server is diagnosed through a network detection tool, for example, to detect whether the proxy server is still in a network reachable state, or whether there are problems such as port blocking; secondly, the relationship between the timeout time and the current network load is analyzed to evaluate whether the response delay problem is caused by network congestion or excessive proxy server load; based on this, the network status of the proxy server is detected, and combined with the record of not receiving response information, an abnormal status record including the abnormal type, abnormal time and abnormal cause is obtained.

[0087] Optionally, if it is detected that the network status of the proxy server is normal, the sending and receiving paths of the verification request can be further analyzed to detect whether there is packet loss or communication interception at intermediate nodes; furthermore, the historical operation data of the proxy server can be combined to determine whether there are frequent service interruptions or other performance issues.

[0088] Step S603: The proxy server is regarded as a second proxy server that does not meet the multi-level proxy connectivity verification condition, and the abnormal state record is associated with the second proxy server.

[0089] Exemplarily, the server identifier of the second proxy server is associated with its corresponding abnormal status record, and the server identifier and the abnormal status record are associated and stored in a database to ensure subsequent rapid retrieval and query. That is, when a subsequent task calls the second proxy server, the abnormal status record associated with the server identifier can be quickly matched by querying the server identifier of the second proxy server, thereby directly obtaining reference content such as the abnormal type, abnormal time and abnormal cause corresponding to the second proxy server.

[0090] In this embodiment, first, if no response information returned by the proxy server is received within a preset time period, the timeout status information of the proxy server is adaptively generated, and then the timeout status information is subjected to exception analysis processing, thereby completely obtaining an exception status record including the exception type, exception time and exception cause; furthermore, the exception status record is associated with the proxy server and marked, thereby improving the retrieval efficiency and data reference of historical records such as the exception type, exception time and exception cause corresponding to the proxy server.

[0091] In an exemplary embodiment, abnormal analysis is performed on the timeout status information to obtain an abnormal status record of the proxy server, including steps S701 to S702.

[0092] Step S701: extract the timeout event type and abnormal time corresponding to the proxy server from the timeout status information.

[0093] Among them, the timeout event type represents the category of the specific timeout event in the timeout process of the proxy server not completing the verification request response. It is used to classify and identify the nature of the timeout event. For example, it can represent the category of timeout events such as "network no response timeout", "request processing timeout" or "high load timeout".

[0094] For example, first, the subject of the timeout event is confirmed based on the network address and port number of the proxy server in the timeout status information; secondly, the type and characteristics of the verification request are analyzed in the record of the unreceived response information, such as the protocol type or data load characteristics involved in the verification request, and then the type of the timeout event is confirmed based on the type and characteristics of the verification request. On the other hand, according to the timeout time in the timeout status information, the abnormal time corresponding to the proxy server is confirmed.

[0095] Step S702, based on the timeout event type, obtain the exception type and exception cause corresponding to the timeout event type from a preset exception analysis rule library, and obtain the exception status record of the proxy server based on the exception type, exception cause and exception time.

[0096] Among them, the exception analysis rule base represents a pre-built rule set, which is used to associate and match timeout event types with corresponding exception types and exception causes; for example, the exception analysis rule base can represent a database containing multiple timeout event types (such as "network no response timeout", "high load timeout", etc.) and their corresponding exception types (such as "network unreachable", "server overload", etc.) and potential exception causes (such as "network interruption", "request queue too long", etc.).

[0097] Exemplarily, the exception analysis rule base is a pre-constructed database based on historical experience and problem induction, which covers the correspondence between various timeout event types and exception types and exception causes; according to the timeout event type, the exception type and exception cause corresponding to the timeout event type are matched from the preset exception analysis rule base.

[0098] Optionally, during the matching process, further context verification can be performed in combination with the abnormal time, that is, detecting the network traffic characteristics at the abnormal time point or time period to determine whether there are abnormal traffic peaks or sudden traffic fluctuations. For example, if significant network congestion or data packet loss is detected during the abnormal time period, the cause of the abnormality can be attributed to temporary exhaustion of network resources or instability of the transmission path, thereby inferring a more specific and accurate cause of the abnormality.

[0099] In this embodiment, the timeout event type and abnormal time are extracted from the timeout status information, and then the corresponding abnormal type and abnormal cause are efficiently and accurately matched in the abnormal analysis rule library based on the timeout event type, thereby generating an abnormal status record containing the abnormal type, abnormal cause and abnormal time, so as to improve the generation efficiency of abnormal status records and the analysis efficiency of timeout events.

[0100] It should be understood that, although the various steps in the flowcharts involved in the above-mentioned embodiments are displayed in sequence according to the indication of the arrows, these steps are not necessarily executed in sequence according to the order indicated by the arrows. Unless there is a clear explanation in this article, the execution of these steps does not have a strict order restriction, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above-mentioned embodiments can include multiple steps or multiple stages, and these steps or stages are not necessarily executed at the same time, but can be executed at different times, and the execution order of these steps or stages is not necessarily to be carried out in sequence, but can be executed in turn or alternately with other steps or at least a part of the steps or stages in other steps.

[0101] Based on the same inventive concept, the embodiment of the present application also provides a protocol fuzzy testing device based on proxy connectivity verification for implementing the above-mentioned protocol fuzzy testing method based on proxy connectivity verification. The implementation scheme for solving the problem provided by the device is similar to the implementation scheme recorded in the above-mentioned method, so the specific limitations in one or more embodiments of the protocol fuzzy testing device based on proxy connectivity verification provided below can refer to the limitations of the protocol fuzzy testing method based on proxy connectivity verification above, and will not be repeated here.

[0102] In an exemplary embodiment, Figure 2 As shown, a protocol fuzzy testing device based on proxy connectivity verification is provided, comprising: a generation module 201, a verification module 202, a first processing module 203 and a second processing module 204, wherein: A generation module 201 is used to generate a protocol fuzzy test task and determine a proxy server corresponding to the protocol fuzzy test task; Verification module 202, used to generate a verification request based on preset multi-level proxy connectivity verification conditions, and send the verification request to the proxy server, the multi-level proxy connectivity verification conditions include basic connectivity verification conditions and proxy capability verification conditions, the basic connectivity verification conditions are used to detect the basic communication capabilities of the proxy server, and the proxy capability verification conditions are used to detect the proxy capability of the proxy server based on the protocol fuzzy test task; The first processing module 203 is used to, upon receiving the response information returned by the proxy server based on the verification request, use the proxy server as the first proxy server that meets the multi-level proxy connectivity verification condition, and perform the protocol fuzzy test task based on the first proxy server; The second processing module 204 is used to treat the proxy server as a second proxy server that does not meet the multi-level proxy connectivity verification condition and terminate the protocol fuzzy test task when no response information returned by the proxy server based on the verification request is received.

[0103] In an exemplary embodiment, the generation module 201 is also used to: obtain multiple candidate proxy servers, perform feature extraction processing on each candidate proxy server, and obtain feature data corresponding to each candidate proxy server, the feature data including the network address of each candidate proxy server, the supported communication protocol type, the authentication method, the maximum number of connections and the response time history record; according to the task test requirements of the protocol fuzz testing task, perform adaptability calculation processing on the feature data corresponding to each candidate proxy server, and obtain the adaptability evaluation results corresponding to each candidate proxy server based on the task test requirements; according to the adaptability evaluation results corresponding to each candidate proxy server, screen the proxy server corresponding to the protocol fuzz testing task from multiple candidate proxy servers.

[0104] In an exemplary embodiment, the verification module 202 is also used to: obtain basic connectivity verification parameters in the basic connectivity verification conditions, the basic connectivity verification parameters represent basic parameters related to the communication network status, and the basic connectivity verification parameters include network reachability status, instant packet loss rate, and network delay fluctuation range; obtain proxy capability verification parameters in the proxy capability verification conditions, the proxy capability verification parameters represent parameters related to proxy capability requirements, and the proxy capability verification parameters include protocol forwarding correctness requirements, dynamic load processing capability requirements, and special data verification capability requirements; use the basic connectivity verification parameters and the proxy capability verification parameters as request fields to generate a verification request containing the request fields.

[0105] In an exemplary embodiment, the first processing module 203 is also used to: when receiving the response information returned by the proxy server, parse the timestamp, header information and load information of the response information based on the request field of the verification request to obtain the parsing result of the response information; obtain the response status record of the proxy server according to the parsing result, the response status record includes the response success status and data integrity status of the proxy server; use the proxy server as the first proxy server that meets the multi-level proxy connectivity verification conditions, and associate the response status record with the first proxy server.

[0106] In an exemplary embodiment, the first processing module 203 is also used to: perform a phased analysis on the response success status of the proxy server according to the parsing result to obtain a phase identifier of the response success status, wherein the phase identifier of the response success status indicates the process phase of the proxy server when the response is successful; perform a phased analysis on the data integrity status of the proxy server according to the parsing result to obtain a dimension identifier of the data integrity status, wherein the dimension identifier of the data integrity status indicates the data dimension of the proxy server when responding with complete data; obtain a response status record of the proxy server based on the phase identifier of the response success status and the dimension identifier of the data integrity status.

[0107] In an exemplary embodiment, the second processing module 204 is also used to: generate timeout status information when no response information returned by the proxy server is received within a preset time period, the timeout status information includes the network address of the proxy server, the timeout time, the port number and a record of no response information received; perform abnormal analysis processing on the timeout status information to obtain an abnormal status record of the proxy server, the abnormal status record includes the abnormal type, abnormal time and abnormal reason; treat the proxy server as a second proxy server that does not meet the multi-level proxy connectivity verification conditions, and associate the abnormal status record with the second proxy server.

[0108] In an exemplary embodiment, the second processing module 204 is also used to: extract the timeout event type and abnormal time corresponding to the proxy server from the timeout status information; based on the timeout event type, match the abnormal type and abnormal cause corresponding to the timeout event type from a preset abnormal analysis rule library, and based on the abnormal type, abnormal cause and abnormal time, obtain the abnormal status record of the proxy server.

[0109] Each module in the above-mentioned protocol fuzzy testing device based on proxy connectivity verification can be implemented in whole or in part by software, hardware and their combination. Each of the above-mentioned modules can be embedded in or independent of the processor in the computer device in the form of hardware, or can be stored in the memory in the computer device in the form of software, so that the processor can call and execute the operations corresponding to each of the above modules.

[0110] In an exemplary embodiment, a computer device is provided, including a memory and a processor, wherein a computer program is stored in the memory, and the processor implements the steps in any of the above embodiments when executing the computer program.

[0111] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the steps in any of the above embodiments are implemented.

[0112] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to the memory, database or other medium used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. As an illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM). The database involved in each embodiment provided in this application may include at least one of a relational database and a non-relational database. Non-relational databases may include distributed databases based on blockchains, etc., but are not limited to this. The processor involved in each embodiment provided in this application may be a general-purpose processor, a central processing unit, a graphics processor, a digital signal processor, a programmable logic device, a data processing logic device based on quantum computing, etc., but are not limited to this.

[0113] The technical features of the above embodiments may be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0114] The above-described embodiments only express several implementation methods of the present application, and the descriptions thereof are relatively specific and detailed, but they cannot be understood as limiting the scope of the present application. It should be pointed out that, for a person of ordinary skill in the art, several variations and improvements can be made without departing from the concept of the present application, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the attached claims.

Claims

1. A protocol fuzz testing method based on proxy connectivity verification, characterized in that: The method comprises: Generate a protocol fuzzy test task, and determine a proxy server corresponding to the protocol fuzzy test task; Based on the preset multi-level proxy connectivity verification conditions, a verification request is generated, and the verification request is sent to the proxy server, wherein the multi-level proxy connectivity verification conditions include basic connectivity verification conditions and proxy capability verification conditions, wherein the basic connectivity verification conditions are used to detect the basic communication capability of the proxy server, and the proxy capability verification conditions are used to detect the proxy capability of the proxy server based on the protocol fuzzy test task; If response information returned by the proxy server based on the verification request is received, the proxy server is used as a first proxy server that meets the multi-level proxy connectivity verification condition, and the protocol fuzzy test task is performed based on the first proxy server; If the response information returned by the proxy server based on the verification request is not received, the proxy server is regarded as a second proxy server that does not meet the multi-level proxy connectivity verification condition, and the protocol fuzzy test task is terminated.

2. The method according to claim 1, characterized in that The step of determining the proxy server corresponding to the protocol fuzz testing task includes: Acquire multiple candidate proxy servers, perform feature extraction processing on each candidate proxy server, and obtain feature data corresponding to each candidate proxy server, wherein the feature data includes a network address, a supported communication protocol type, an authentication method, a maximum number of connections, and a response time history record of each candidate proxy server; According to the task test requirements of the protocol fuzzy test task, adaptability calculation processing is performed on the feature data corresponding to each candidate proxy server, so as to obtain the adaptability evaluation results corresponding to each candidate proxy server based on the task test requirements; According to the adaptability evaluation results corresponding to each candidate proxy server, a proxy server corresponding to the protocol fuzzy testing task is screened from multiple candidate proxy servers.

3. The method according to claim 1, characterized in that: The generating of the verification request based on the preset multi-level proxy connectivity verification condition includes: Obtaining basic connectivity verification parameters in the basic connectivity verification conditions, wherein the basic connectivity verification parameters represent basic parameters related to the communication network state, and the basic connectivity verification parameters include network reachability state, instant packet loss rate, and network delay fluctuation range; Obtaining proxy capability verification parameters in the proxy capability verification condition, wherein the proxy capability verification parameters represent parameters related to proxy capability requirements, and the proxy capability verification parameters include protocol forwarding correctness requirements, dynamic load processing capability requirements, and special data verification capability requirements; The basic connectivity verification parameter and the proxy capability verification parameter are used as request fields, and a verification request including the request fields is generated.

4. The method according to claim 1, characterized in that: If the response information returned by the proxy server based on the verification request is received, the proxy server is used as a first proxy server that meets the multi-level proxy connectivity verification condition, including: If response information returned by the proxy server is received, the timestamp, header information and payload information of the response information are parsed based on the request field of the verification request to obtain a parsing result of the response information; According to the parsing result, a response status record of the proxy server is obtained, wherein the response status record includes a response success status and a data integrity status of the proxy server; The proxy server is used as a first proxy server that meets the multi-level proxy connectivity verification condition, and the response status record is associated with the first proxy server.

5. The method according to claim 4, characterized in that The step of obtaining a response status record of the proxy server according to the parsing result includes: Performing a phased analysis on the response success status of the proxy server according to the parsing result to obtain a phase identifier of the response success status, wherein the phase identifier of the response success status indicates the process phase of the proxy server when the response is successful; Performing a phased analysis on the data integrity status of the proxy server according to the parsing result to obtain a dimension identifier of the data integrity status, wherein the dimension identifier of the data integrity status indicates a data dimension of the proxy server when responding to the complete data; Based on the phase identifier of the response success status and the dimension identifier of the data complete status, a response status record of the proxy server is obtained.

6. The method according to claim 1, characterized in that If the response information returned by the proxy server based on the verification request is not received, the proxy server is used as a second proxy server that does not meet the multi-level proxy connectivity verification condition, including: If the response information returned by the proxy server is not received within the preset period of time, a timeout status information is generated, wherein the timeout status information includes the network address of the proxy server, the timeout time, the port number and the record of the response information not being received; Performing abnormal analysis on the timeout status information to obtain an abnormal status record of the proxy server, wherein the abnormal status record includes an abnormal type, abnormal time, and abnormal cause; The proxy server is used as a second proxy server that does not meet the multi-level proxy connectivity verification condition, and the abnormal status record is associated with the second proxy server.

7. The method according to claim 6, characterized in that The performing abnormal analysis on the timeout status information to obtain an abnormal status record of the proxy server includes: Extracting the timeout event type and abnormal time corresponding to the proxy server from the timeout status information; Based on the timeout event type, the exception type and exception cause corresponding to the timeout event type are matched from a preset exception analysis rule library, and based on the exception type, the exception cause and the exception time, the exception status record of the proxy server is obtained.

8. A protocol fuzz testing device based on proxy connectivity verification, characterized in that: The device comprises: A generation module, used to generate a protocol fuzzy test task and determine a proxy server corresponding to the protocol fuzzy test task; A verification module, used to generate a verification request based on a preset multi-level proxy connectivity verification condition, and send the verification request to the proxy server, wherein the multi-level proxy connectivity verification condition includes a basic connectivity verification condition and a proxy capability verification condition, wherein the basic connectivity verification condition is used to detect the basic communication capability of the proxy server, and the proxy capability verification condition is used to detect the proxy capability of the proxy server based on the protocol fuzzy test task; A first processing module is used for, upon receiving the response information returned by the proxy server based on the verification request, taking the proxy server as a first proxy server that meets the multi-level proxy connectivity verification condition, and performing the protocol fuzzy test task based on the first proxy server; The second processing module is used to treat the proxy server as a second proxy server that does not meet the multi-level proxy connectivity verification condition and terminate the protocol fuzzy test task when the response information returned by the proxy server based on the verification request is not received.

9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 7 are implemented.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.