Security test method and device of interface, computer equipment and readable storage medium

By obtaining encrypted traffic logs from the interface gateway server, parsing and splicing them into request packets, decrypting with keys and adding attack payloads, encrypting and performing security tests, the automated security testing problem caused by API interface application layer encryption is solved, and efficient security testing and security improvement is achieved.

CN120050054APending Publication Date: 2025-05-27INDUSTRIAL AND COMMERCIAL BANK OF CHINA
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202410574694.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-05-10
Publication Date
2025-05-27

AI Technical Summary

Technical Problem

Faced with encrypted traffic after the API interface application layer encryption, automated security testing faces the challenge of parsing request messages, resulting in the inability to effectively conduct security testing.

Method used

By obtaining the encrypted traffic log from the interface gateway server, analyzing the key fields, splicing it into request messages, and using the corresponding keys for decryption, adding attack payloads, encrypting, and finally simulating the security test messages and sending them to the backend server for response processing.

Benefits of technology

It realizes automated security testing of the encryption API interface, reduces manual testing costs and improves the security of the application system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120050054A_ABST
    Figure CN120050054A_ABST
Patent Text Reader

Abstract

The invention relates to an interface security testing method and device, computer equipment and a computer readable storage medium, relates to the technical field of security testing, and can be applied to the field of information security, the field of financial science and technology or other related fields. The method comprises the following steps: acquiring an encrypted traffic log from an interface gateway server; splicing key fields analyzed from the encrypted traffic log to obtain at least one request message; decrypting the request message according to a key corresponding to the request message, adding an attack load, performing encryption by using the key, sending the encrypted request message to a back-end server, and receiving a response message sent by the back-end server; and determining a security test result according to the response message. According to the method, the request message is automatically decrypted and encrypted, the problem that an automatic security test cannot be carried out due to the encryption of an application layer of an API (Application Program Interface) can be solved, the encrypted message of the interface is simulated to carry out the automatic security test, the manual test cost is reduced, and the security of an application system is greatly improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of security testing technology and can be used in the field of information security, and in particular, to a method, device, computer equipment and computer-readable storage medium for security testing of an interface. Background Art

[0002] With the rapid development of the Internet, in order to export data and services, it is necessary to open interface calls. However, as the communication method of interface calls becomes popular, attackers are gradually using APIs (Application Programming Interface) to launch attacks. In order to strengthen the security control of API interfaces, enterprises use application layer encryption to perform data transmission of API interfaces with partners based on keys to improve privacy and security. In the face of encrypted traffic, the inability to parse request messages poses a great challenge to automated security testing. Summary of the invention

[0003] Based on this, it is necessary to provide an interface security testing method, device, computer equipment and computer-readable storage medium to address the above technical problems, which can simulate the encrypted messages of the interface to perform automated security testing and improve the security of the application system.

[0004] In a first aspect, the present application provides a method for security testing of an interface, comprising:

[0005] Get encrypted traffic logs from the interface gateway server;

[0006] Parse key fields from encrypted traffic logs;

[0007] Concatenate the key fields to obtain at least one request message;

[0008] For each request message, decrypt the request message according to the key corresponding to the request message to obtain the plaintext message;

[0009] Add attack payload to the plaintext message to obtain attack simulation message;

[0010] Encrypt the attack simulation message using the key to obtain a security test message;

[0011] Send the security test message to the backend server and receive the response message sent by the backend server;

[0012] The security test result is determined based on the response message.

[0013] In one embodiment, key fields are parsed from the encrypted traffic log, including:

[0014] Based on a preset rule, the encrypted traffic log is divided into at least one message block;

[0015] Based on the preset keywords, the corresponding key fields are matched from the message block.

[0016] In one embodiment, the process of obtaining the key corresponding to the request message includes:

[0017] A query is performed in a preset storage unit according to the uniform resource locator of the request message to obtain the key corresponding to the request message; the preset storage unit stores the partner key obtained from the interface platform, and the partner key is the key uploaded by the partner when applying for the interface service on the interface platform.

[0018] In one embodiment, adding an attack payload to a plaintext message to obtain an attack simulation message includes:

[0019] Obtain the attack payload of the security vulnerability to be tested;

[0020] The content of the plaintext message is replaced with the attack payload to obtain an attack simulation message.

[0021] In one embodiment, the process of determining the security vulnerability to be tested includes:

[0022] Determine the interface type of the request message;

[0023] Based on the interface type, determine at least one security vulnerability to be tested.

[0024] In one embodiment, determining a security test result according to the response message includes:

[0025] Obtain vulnerability judgment rules for security vulnerabilities to be tested;

[0026] The vulnerability judgment rules are used to judge the vulnerability of the response message and obtain the security test results.

[0027] In one embodiment, obtaining an encrypted traffic log from an interface gateway server includes:

[0028] Get traffic logs from the interface gateway server;

[0029] Unencrypted logs, error logs, and access failure logs are filtered out from traffic logs to obtain encrypted traffic logs.

[0030] In a second aspect, the present application also provides a safety testing device for an interface, comprising:

[0031] The acquisition module is used to obtain the encrypted traffic log from the interface gateway server;

[0032] Parsing module, used to parse key fields from encrypted traffic logs;

[0033] A splicing module, used for splicing key fields to obtain at least one request message;

[0034] A decryption module is used to decrypt each request message according to the key corresponding to the request message to obtain a plaintext message;

[0035] Add a module to add an attack payload to a plaintext message to obtain an attack simulation message;

[0036] The encryption module is used to encrypt the attack simulation message using a key to obtain a security test message;

[0037] A sending module, used to send the security test message to the back-end server and receive the response message sent by the back-end server;

[0038] The test module is used to determine the security test result according to the response message.

[0039] In a third aspect, the present application further provides a computer device, including a memory and a processor, wherein the memory stores a computer program, and when the processor executes the computer program, the following steps are implemented:

[0040] Get encrypted traffic logs from the interface gateway server;

[0041] Parse key fields from encrypted traffic logs;

[0042] Concatenate the key fields to obtain at least one request message;

[0043] For each request message, decrypt the request message according to the key corresponding to the request message to obtain the plaintext message;

[0044] Add attack payload to the plaintext message to obtain attack simulation message;

[0045] Encrypt the attack simulation message using the key to obtain a security test message;

[0046] Send the security test message to the backend server and receive the response message sent by the backend server;

[0047] The security test result is determined based on the response message.

[0048] In a fourth aspect, the present application further provides a computer-readable storage medium having a computer program stored thereon, wherein when the computer program is executed by a processor, the following steps are implemented:

[0049] Get encrypted traffic logs from the interface gateway server;

[0050] Parse key fields from encrypted traffic logs;

[0051] Concatenate the key fields to obtain at least one request message;

[0052] For each request message, decrypt the request message according to the key corresponding to the request message to obtain the plaintext message;

[0053] Add attack payload to the plaintext message to obtain attack simulation message;

[0054] Encrypt the attack simulation message using the key to obtain a security test message;

[0055] Send the security test message to the backend server and receive the response message sent by the backend server;

[0056] The security test result is determined based on the response message.

[0057] The security testing method, device, computer equipment and computer-readable storage medium of the above interface obtain encrypted traffic logs from the interface gateway server; parse key fields from the encrypted traffic logs; splice the key fields to obtain at least one request message; for each request message, decrypt the request message according to the key corresponding to the request message to obtain a plaintext message; add an attack payload to the plaintext message to obtain an attack simulation message; encrypt the attack simulation message using the key to obtain a security test message; send the security test message to the back-end server, and receive a response message sent by the back-end server; determine the security test result according to the response message. Through the above method, the key fields are parsed and spliced ​​into request messages, which can filter invalid data and ensure the compliance and accuracy of the request message. By automatically decrypting and encrypting the request message, the problem of API interface application layer encryption that leads to the inability to perform automated security testing can be solved. By adding an attack payload to the message and simulating the encrypted message of the interface for automated security testing, the cost of manual testing is reduced and the security of the application system is greatly improved. BRIEF DESCRIPTION OF THE DRAWINGS

[0058] In order to more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the drawings required for use in the embodiments of the present application or related technical descriptions will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other related drawings can be obtained based on these drawings without paying creative work.

[0059] Figure 1 An application environment diagram of a security testing method for an interface in an embodiment;

[0060] Figure 2 A schematic diagram of a flow chart of a method for security testing of an interface in an embodiment;

[0061] Figure 3 A flowchart of a key field parsing step in one embodiment;

[0062] Figure 4 A schematic diagram of a flow chart of a method for interface security testing in another embodiment;

[0063] Figure 5 A structural block diagram of a safety testing device for an interface in an embodiment;

[0064] Figure 6 FIG. 4 is a diagram showing the internal structure of a computer device in one embodiment. DETAILED DESCRIPTION

[0065] In order to make the purpose, technical solution and advantages of the present application more clearly understood, the present application is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.

[0066] The interface security testing method provided in the embodiment of the present application can be applied to Figure 1 In the application environment shown, the security test unit 104 accesses the interface gateway server 102 , obtains the encrypted traffic log from the interface gateway server 102 , simulates the encrypted message of the interface based on the encrypted traffic log, generates a security test message, and sends the security test message to the backend server 106 .

[0067] In one implementation, the security testing unit 104 is built-in or connected to a display unit, through which the security test result is provided to the tester 108. Optionally, the security testing unit 104 is built-in or connected to an input unit, through which the tester 108 can adjust the display screen, input a key to input an attack payload, or set a security vulnerability to be tested.

[0068] In one implementation, the security testing unit 104 is connected to the interface platform 110 , the partner applies for an interface service on the interface platform 110 , uploads an encryption key, and the security testing unit 104 periodically pulls the partner's key from the interface platform 110 .

[0069] In one implementation, the security testing unit 104 is integrated with or connected to a data storage system, which can store data that the security testing unit 104 needs to process, such as attack payloads of various vulnerabilities, vulnerability judgment rules, keys, etc. The data storage system can also be placed on the cloud or other network servers.

[0070] The security testing unit 104 may be, but is not limited to, various personal computers, laptops, smart phones, tablet computers, or other devices with networking and data processing functions. Optionally, the security testing unit 104 may be integrated in the interface gateway server 102 or the backend server 106.

[0071] The backend server 106 may be an independent physical server, a server cluster or a distributed system composed of multiple physical servers, or a cloud server providing cloud computing services. Optionally, the security testing unit 104 is connected to multiple backend servers 106, and the destination servers of different request messages are different. The security testing unit 104 sends each simulated security test message to the corresponding backend server 106 to implement security testing on each backend server 106.

[0072] In an exemplary embodiment, Figure 2 As shown, a security testing method for an interface is provided, which is applied to Figure 1 The safety test unit 104 in FIG. 1 is used as an example to illustrate, including:

[0073] Step 202: Obtain encrypted traffic logs from the interface gateway server.

[0074] Among them, the interface gateway server refers to the API Gateway, which is located between the application and the back-end server and provides a centralized way to manage API access. It can be understood that the interface gateway server is a collection of all interfaces, and all traffic accessing the interface must first be routed through the interface gateway, and then forwarded by the interface gateway server to the corresponding back-end server to process the corresponding business request, and return the processing result to the client. The encrypted traffic log refers to the transmission record of all encrypted data recorded by the interface gateway server. The transmission record may include information such as transmission time, transmission content, transmission source address, and transmission destination address. Optionally, check the fields of each traffic log of the interface gateway server to determine whether each traffic log contains an encryption mark. If a traffic log contains an encryption mark, the traffic log is determined to be an encrypted traffic log. The encryption mark can be an encryption protocol, an encryption port, a specific label, a specific source address, etc. This embodiment does not limit this.

[0075] In one implementation, the security testing unit 104 pulls the traffic log files recorded by the gateway from the location where the interface gateway server stores logs at regular intervals, and filters out the encrypted traffic logs.

[0076] Step 204: parse key fields from the encrypted traffic log.

[0077] Among them, the key field refers to the key field for constructing the request message, which may include but is not limited to the request downstream application path, interface name, request header and encrypted request body, etc. In one implementation, multiple keywords for constructing the request message are preset, and for each keyword, the keyword is searched in the encrypted traffic log, and the key information after the keyword in the encrypted traffic log is extracted to obtain the key field.

[0078] Step 206: concatenate the key fields to obtain at least one request message.

[0079] In one implementation, the key fields are sorted according to the composition order of the request message, and the sorted key fields are concatenated to obtain the request message.

[0080] In one implementation, the key field is composed of keywords and key information. A request message template is preset. The request message template includes multiple placeholders, each placeholder corresponds to a keyword, and according to the correspondence between the keywords and the placeholders, the key information in the key field is filled into the request message template to obtain a request message.

[0081] It is understandable that the same batch or the same encrypted traffic log may include multiple request messages. In one implementation, all key fields are divided into multiple groups of key fields according to the order of the key fields in the encrypted traffic log, each group of key fields corresponds to a request message, and each group of key fields is spliced ​​to obtain the corresponding request message.

[0082] Step 208: For each request message, decrypt the request message according to the key corresponding to the request message to obtain a plaintext message.

[0083] The request message includes an encrypted request body, which is decrypted according to the key corresponding to the request message, and a plaintext message is formed based on the decrypted request body and other fields in the request message. The key refers to a parameter input in an algorithm for converting plaintext to ciphertext or ciphertext to plaintext. In one implementation, keys corresponding to various request messages are pre-stored, and according to the message type of the current request message, a query is performed in a preset storage unit to determine the corresponding key.

[0084] In one implementation, keys corresponding to each partner are pre-stored, and the sender of the request message is determined according to the uniform resource locator corresponding to the request message, and the pre-stored key of the sender is determined as the key of the request message.

[0085] Step 210: Add the attack payload to the plaintext message to obtain an attack simulation message.

[0086] Among them, the attack payload can be understood as a weapon carrier for the attacker to launch an initial attack and establish a network connection. The attack payload can include a delivery attack payload, a connection control payload, and an independent attack payload. In one implementation, an attack payload is preset, and the preset attack payload is added to the plaintext message to obtain an attack simulation message. In one implementation, an attack payload selection window is provided, and the tester selects the security vulnerability to be tested, determines the attack payload corresponding to the security vulnerability to be tested from the pre-stored multiple attack payloads, and adds the attack payload to the plaintext message to obtain an attack simulation message.

[0087] Step 212: encrypt the attack simulation message using a key to obtain a security test message.

[0088] The attack simulation message includes a decrypted request body. The decrypted request body in the attack simulation message is encrypted according to the key corresponding to the request message. A security test message is constructed based on the encrypted request body and other fields in the attack simulation message.

[0089] Step 214: Send the security test message to the backend server, and receive a response message sent by the backend server.

[0090] Among them, the backend server can be understood as a downstream application system, which is a server responsible for processing client requests, data processing and storage. When the client sends a request through the interface gateway server, the backend server receives these requests and performs corresponding business processing according to the content of the request.

[0091] In this embodiment, an encrypted message sent by the attacker through the interface is simulated to obtain a security test message, and the security test message is sent to the back-end server to instruct the back-end server to process the security test message and generate and feedback a response message. In one implementation, the destination address of the security test message is determined, and the server corresponding to the destination address is determined as the back-end server.

[0092] Step 216: Determine the security test result according to the response message.

[0093] Among them, by judging whether the response message matches the vulnerability judgment rule, it is determined whether the interface has a security problem. If the response message matches the vulnerability judgment rule, it is determined that the interface has a security problem, and the security test result is that the interface is unsafe; if the response message does not match the vulnerability judgment rule, it is determined that there is no security problem on the interface, and the security test result is that the interface is safe.

[0094] Optionally, the vulnerability judgment rule can be to analyze whether the response message contains error information, debugging information, exception information or other sensitive data. For example, if the response message includes a response status code such as 500 (internal server error) or 403 (forbidden), it indicates that there is an unhandled exception or a problem with permission verification. In this case, it is determined that there is a security problem with the interface. Other sensitive data refers to sensitive data that should not be returned to the client, such as password hashes, database table structures, etc.

[0095] In one implementation, encrypted messages sent by a simulated attacker through multiple interfaces are respectively determined for security testing results of the multiple interfaces, the security testing results are recorded, and the feedback is displayed to testers for interface vulnerability management.

[0096] In the security testing method of the above interface, an encrypted traffic log is obtained from the interface gateway server; key fields are parsed from the encrypted traffic log; the key fields are spliced ​​to obtain at least one request message; for each request message, the request message is decrypted according to the key corresponding to the request message to obtain a plaintext message; an attack payload is added to the plaintext message to obtain an attack simulation message; the attack simulation message is encrypted using the key to obtain a security test message; the security test message is sent to the back-end server, and a response message sent by the back-end server is received; and the security test result is determined according to the response message. In the above manner, the key fields are parsed and spliced ​​into request messages, which can filter invalid data and ensure the compliance and accuracy of the request message. By automatically decrypting and encrypting the request message, the problem of API interface application layer encryption that leads to the inability to perform automated security testing can be solved. By adding an attack payload to the message and simulating the encrypted message of the interface for automated security testing, the cost of manual testing is reduced and the security of the application system is greatly improved.

[0097] In an exemplary embodiment, Figure 3 As shown, step 204 includes:

[0098] Step 302: based on a preset rule, the encrypted traffic log is divided into at least one message block.

[0099] The preset rule refers to a predefined rule for segmenting message blocks, which can be a pre-set regular matching rule. A message block refers to a text block corresponding to a request message log. It can be understood that an encrypted traffic log is composed of multiple request message logs. The log format is as follows:

[0100] "20XX-0X-XX XX:XX:XX info start api url:xxxx

[0101] 20XX-0X-XX XX:XX:XX info service url:xxxxxx

[0102] 20XX-0X-XX XX:XX:XX info request-header:xxxxx

[0103] 20XX-0X-XX XX:XX:XX info request-body:xxxx

[0104] 20XX-0X-XX XX:XX:XX info response-header:xxxx

[0105] 20XX-0X-XX XX:XX:XX info response-body:xxxxx

[0106] 20XX-0X-XX XX:XX:XX info finish

[0107] 20XX-0X-XX XX:XX:XX info start api url:xxxxx

[0108] 20XX-0X-XX XX:XX:XX info service url:xxxxxx

[0109] 20XX-0X-XX XX:XX:XX info request-header:xxxxx

[0110] 20XX-0X-XX XX:XX:XX info request-body:xxxx

[0111] 20XX-0X-XX XX:XX:XX erro 404 not found

[0112] 20XX-0X-XX XX:XX:XX info finish”。

[0113] It is understandable that the example log consists of two groups of request messages. In one implementation, the line where "start" and the line where "finish" are located in the encrypted traffic log are identified through a regular expression, and at least one first line mark (used to mark the line where "start" is located, and the first line mark can be set before the text of the line where "start" is located) and at least one second line mark (used to mark the line where "finish" is located, and the second line mark can be set after the text of the line where "finish" is located) in the encrypted traffic log are obtained, and the log between the adjacent first line mark and the second line mark (including the line where "start" and the line where "finish" are located) is divided into message blocks, thereby determining at least one message block.

[0114] Step 304: Match the corresponding key field from the message block based on the preset keyword.

[0115] Among them, for each message block, key information is extracted from the message block by keyword matching to obtain key fields. The preset keyword is a predefined specific word for keyword matching, such as request-header, request-body, api url, service url, etc. It can be understood that for each message block, the preset keyword is searched in the message block, and the information between the preset keyword and the preset marker (referring to the first preset marker after the preset keyword) is extracted as the key information. The preset marker can be a line break character, and invalid symbols in the key information, such as colons, can be removed.

[0116] In one implementation, the preset keywords may also include keywords such as "erro" or exception response status codes for identifying exceptions. By identifying these keywords, messages that prohibit access or report errors to the interface function are recorded as invalid messages and filtered, and the key fields of the valid message blocks are saved.

[0117] In this embodiment, based on preset rules, the encrypted traffic log is divided into at least one message block, and based on preset keywords, the corresponding key fields are matched from the message block. The key fields of multiple message blocks in the encrypted traffic log can be identified, providing data support for the construction of subsequent request messages. By removing redundant data, the efficiency of security testing can be improved.

[0118] In an exemplary embodiment, the process of obtaining the key corresponding to the request message includes: querying in a preset storage unit according to the uniform resource locator of the request message to obtain the key corresponding to the request message; the preset storage unit stores the partner key obtained from the interface platform, and the partner key is the key uploaded by the partner when applying for the interface service on the interface platform.

[0119] The interface platform manages multiple partner keys. Specifically, when a partner applies for an interface service on the interface platform, it needs to upload an encryption key. After issuing the interface service, the interface platform stores the uploaded key of the partner. The security test unit periodically pulls the partner key from the interface platform and stores it in a preset storage unit. In one implementation, the key is stored in the preset storage unit in the form of a key-value pair (key: value).

[0120] The uniform resource locator of the request message refers to the API URL, which is the URL (uniform resource locator) for accessing the API (application programming interface) service. The sender of the request message is determined according to the uniform resource locator, and the pre-stored key of the sender is used as the key of the request message. In one implementation, the sender corresponding to the uniform resource locator is matched with each key stored in the preset storage unit, and the value corresponding to the successfully matched key is determined as the key of the request message.

[0121] In one implementation, the security testing unit sends a key acquisition request to the interface platform once every preset period of time, the interface platform feeds back the newly added partner key to the security testing unit, and the security testing unit stores the newly added partner key in a preset storage unit.

[0122] In one implementation, the interface platform will feed back the newly added partner keys to the security testing unit in real time, and the security testing unit will store the partner keys fed back by the interface platform in a preset storage unit. Real-time feedback of the partner keys can be achieved through a distributed publish-subscribe message system.

[0123] In an exemplary embodiment, step 210 includes: obtaining an attack payload of the security vulnerability to be tested; and replacing the content of the plaintext message with the attack payload to obtain an attack simulation message.

[0124] The security test unit has a built-in vulnerability scanning rule library, which stores attack payloads of various security vulnerabilities. The tester selects the security vulnerability to be tested or the security test unit automatically sets the security vulnerability to be tested. After determining the security vulnerability to be tested, the corresponding attack payload is determined by querying the vulnerability scanning rule library, and the content in the plaintext message is replaced with the attack payload, simulating the attacker to generate an attack simulation message.

[0125] In an exemplary embodiment, the process of determining the security vulnerability to be tested includes: determining the interface type of the request message; and determining at least one security vulnerability to be tested according to the interface type.

[0126] The interface type refers to the type of interface called by the request message. In the specific implementation, the request message is matched according to the matching rules of each interface type. If the request message meets the matching rules of a certain interface type, the interface type that is successfully matched is determined as the interface type corresponding to the request message. For example, if the URL of the request message includes ".wsdl", the interface type corresponding to the request message is a SOAP interface, because the SOAP interface generally defines the service through a WSDL (Web Services Description Language) file. For another example, the request header is used to indicate the media type of the request body. If the media type indicated by the request header is application / xml or contains soap, the interface type corresponding to the request message is a SOAP interface; if the media type indicated by the request header is application / json, the interface type corresponding to the request message is a RESTful API interface. For another example, if the request body of the request message contains data in XML format, the interface type corresponding to the request message is a SOAP interface; if the request body of the request message contains data in JSON format, the interface type corresponding to the request message is a RESTful API interface.

[0127] In one implementation, at least one security vulnerability to be tested corresponding to each interface type is stored in advance. It is understandable that for each interface type, one or more common security vulnerabilities are determined, and the common security vulnerabilities determined based on experience are recorded as the security vulnerabilities to be tested corresponding to the interface type, and for each security vulnerability, vulnerability samples are collected, and attack payloads and vulnerability judgment rules corresponding to various security vulnerabilities are created. For example, common security vulnerabilities of RESTful API interfaces are cross-site scripting attacks (XSS), cross-site request forgery (CSRF), SQL injection, sensitive information leakage, etc.

[0128] It can be understood that for each security vulnerability to be tested corresponding to the interface type, the attack payload of the security vulnerability to be tested is determined through the vulnerability scanning rule library, and the content of the plaintext message is replaced with the attack payload to obtain an attack simulation message, thereby constructing one or more attack simulation messages, and encrypting each attack simulation message with a key to obtain one or more security test messages. Each security test message is sent to the back-end server to implement security testing of one or more security vulnerabilities.

[0129] Through the above method, targeted security testing can be performed according to the interface type of the request message, thereby improving the efficiency of security testing, discovering potential interface risks, and improving the security of interface calls.

[0130] In an exemplary embodiment, step 216 includes: obtaining vulnerability judgment rules for the security vulnerabilities to be tested; and performing vulnerability judgment on the response message according to the vulnerability judgment rules to obtain security test results.

[0131] Among them, the security test unit has a built-in vulnerability scanning rule library, which stores attack payloads and vulnerability judgment rules for various security vulnerabilities. According to the security vulnerabilities to be tested selected by the tester or the security vulnerabilities to be tested automatically set by the security test unit, the vulnerability scanning rule library is queried to determine the corresponding attack payload and vulnerability judgment rule. An attack simulation message is constructed based on the queried attack payload and sent to the back-end server to instruct the back-end server to process the security test message and generate and feedback a response message. Determine whether the response message matches the queried vulnerability judgment rule to determine whether there is a security problem with the interface. If the response message matches the vulnerability judgment rule, it is determined that the interface has a security problem, and the security test result is that the interface is unsafe; if the response message does not match the vulnerability judgment rule, it is determined that the interface does not have a security problem, and the security test result is that the interface is safe.

[0132] In an exemplary embodiment, step 202 includes: obtaining a traffic log from an interface gateway server; filtering out unencrypted logs, error logs, and access failure logs from the traffic log to obtain an encrypted traffic log.

[0133] Among them, traffic logs are pulled from the interface gateway server regularly, and the fields of the traffic logs are checked. By analyzing the fields of the traffic logs, it is determined whether each traffic log is an unencrypted log, an error log, or an access failure log. Unencrypted logs, error logs, and access failure logs are filtered out, and logs in which the interface responds normally and does not report errors are saved.

[0134] In one implementation, it is checked whether the traffic log contains an encryption mark. If a traffic log contains an encryption mark, the traffic log is determined to be an encrypted traffic log. Otherwise, the traffic log is marked as an unencrypted log. The encryption mark can be an encryption protocol, an encryption port, a specific label, a specific source address, etc. The encryption port is a pre-agreed port for transmitting encrypted messages, and the specific source address points to a pre-agreed requester for using encrypted messages for data transmission.

[0135] In one implementation, the error log usually contains a specific error code or message. By checking whether the log contains an error code, it is determined whether the traffic log is an error log. For example, a traffic log with a status code of 500 is marked as an error code.

[0136] In one implementation, the access failure log usually contains a specific exception code or message. By checking whether the log contains the exception code, it is determined whether the traffic log is an access failure log. For example, the traffic log with a status code of 403 is marked as an access failure log.

[0137] In one implementation, referring to Figure 4 , Figure 4 The flow of a method for security testing of an interface is shown, which specifically includes:

[0138] Step S1: Pull log files from the interface gateway server.

[0139] Step S2: Parse the log file, divide the log into multiple message blocks, and extract the key fields of each message block.

[0140] Step S3: unencrypted message blocks, message blocks with prohibited access functions or message blocks reporting errors are recorded as invalid messages and filtered, and key fields of valid message blocks (interface response is normal and no error is reported) are saved.

[0141] Step S4: concatenate the key fields into a request message;

[0142] Step S5: decrypt the request message using the key;

[0143] Step S6: Perform security test based on the decrypted message;

[0144] Step S7: Record the safety test results and feed them back to the tester for review.

[0145] It should be understood that, although the various steps in the flowcharts involved in the above-mentioned embodiments are displayed in sequence according to the indication of the arrows, these steps are not necessarily executed in sequence according to the order indicated by the arrows. Unless there is a clear explanation in this article, the execution of these steps does not have a strict order restriction, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above-mentioned embodiments can include multiple steps or multiple stages, and these steps or stages are not necessarily executed at the same time, but can be executed at different times, and the execution order of these steps or stages is not necessarily to be carried out in sequence, but can be executed in turn or alternately with other steps or at least a part of the steps or stages in other steps.

[0146] Based on the same inventive concept, the embodiment of the present application also provides an interface security testing device for implementing the interface security testing method involved above. The implementation scheme for solving the problem provided by the device is similar to the implementation scheme recorded in the above method, so the specific limitations in the embodiment of the security testing device for one or more interfaces provided below can refer to the limitations of the interface security testing method above, and will not be repeated here.

[0147] In an exemplary embodiment, Figure 5 As shown, a safety test device for an interface is provided, comprising:

[0148] The acquisition module 502 is used to acquire the encrypted traffic log from the interface gateway server.

[0149] The parsing module 504 is used to parse key fields from the encrypted traffic log.

[0150] The splicing module 506 is used to splice the key fields to obtain at least one request message.

[0151] The decryption module 508 is used to decrypt each request message according to the key corresponding to the request message to obtain a plaintext message.

[0152] The adding module 510 is used to add an attack payload to a plain text message to obtain an attack simulation message.

[0153] The encryption module 512 is used to encrypt the attack simulation message using a key to obtain a security test message.

[0154] The sending module 514 is used to send the security test message to the back-end server and receive the response message sent by the back-end server.

[0155] The testing module 516 is used to determine the security test result according to the response message.

[0156] In the security test device of the above interface, the encrypted traffic log is obtained from the interface gateway server; the key fields are parsed from the encrypted traffic log; the key fields are spliced ​​to obtain at least one request message; for each request message, the request message is decrypted according to the key corresponding to the request message to obtain a plaintext message; an attack payload is added to the plaintext message to obtain an attack simulation message; the attack simulation message is encrypted using the key to obtain a security test message; the security test message is sent to the back-end server, and a response message sent by the back-end server is received; the security test result is determined according to the response message. In the above manner, the key fields are parsed and spliced ​​into request messages, which can filter invalid data and ensure the compliance and accuracy of the request message. By automatically decrypting and encrypting the request message, the problem of API interface application layer encryption that leads to the inability to perform automated security testing can be solved. By adding an attack payload to the message and simulating the encrypted message of the interface for automated security testing, the cost of manual testing is reduced and the security of the application system is greatly improved.

[0157] In an exemplary embodiment, the parsing module 504 is further used to segment the encrypted traffic log into at least one message block based on a preset rule; and match a corresponding key field from the message block based on a preset keyword.

[0158] In an exemplary embodiment, the decryption module 508 is also used to query in a preset storage unit according to the uniform resource locator of the request message to obtain the key corresponding to the request message; the preset storage unit stores the partner key obtained from the interface platform, and the partner key is the key uploaded by the partner when applying for the interface service on the interface platform.

[0159] In an exemplary embodiment, the added module 510 is further used to obtain the attack payload of the security vulnerability to be tested; replace the content of the plaintext message with the attack payload to obtain an attack simulation message.

[0160] In an exemplary embodiment, the adding module 510 is further configured to determine the interface type of the request message; and determine at least one security vulnerability to be tested according to the interface type.

[0161] In an exemplary embodiment, the test module 516 is further used to obtain vulnerability judgment rules for the security vulnerabilities to be tested; perform vulnerability judgment on the response message according to the vulnerability judgment rules to obtain security test results.

[0162] In an exemplary embodiment, the acquisition module 502 is further used to obtain traffic logs from the interface gateway server; filter out unencrypted logs, error logs, and access failure logs from the traffic logs to obtain encrypted traffic logs.

[0163] Each module in the security testing device of the above interface can be implemented in whole or in part by software, hardware and their combination. Each module can be embedded in or independent of the processor in the computer device in the form of hardware, or can be stored in the memory of the computer device in the form of software, so that the processor can call and execute the operations corresponding to each module above.

[0164] In an exemplary embodiment, a computer device is provided. The computer device may be a server, and its internal structure diagram may be as shown in FIG. Figure 6 As shown. The computer device includes a processor, a memory, an input / output interface (Input / Output, referred to as I / O) and a communication interface. Among them, the processor, the memory and the input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store attack loads, vulnerability judgment rules or keys of various vulnerabilities. The input / output interface of the computer device is used to exchange information between the processor and an external device. The communication interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, a security testing method for an interface is implemented.

[0165] Those skilled in the art will understand that Figure 6 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine certain components, or have a different arrangement of components.

[0166] In an exemplary embodiment, a computer device is provided, including a memory and a processor, wherein a computer program is stored in the memory, and the processor implements the following steps when executing the computer program: obtaining an encrypted traffic log from an interface gateway server; parsing key fields from the encrypted traffic log; splicing the key fields to obtain at least one request message; for each request message, decrypting the request message according to a key corresponding to the request message to obtain a plaintext message; adding an attack payload to the plaintext message to obtain an attack simulation message; encrypting the attack simulation message using a key to obtain a security test message; sending the security test message to a backend server, and receiving a response message sent by the backend server; and determining a security test result according to the response message.

[0167] In one embodiment, when the processor executes the computer program, the following steps are also implemented: based on preset rules, the encrypted traffic log is divided into at least one message block; based on preset keywords, the corresponding key field is matched from the message block.

[0168] In one embodiment, when the processor executes the computer program, the following steps are also implemented: querying in a preset storage unit according to the uniform resource locator of the request message to obtain a key corresponding to the request message; the preset storage unit stores a partner key obtained from the interface platform, and the partner key is a key uploaded by the partner when applying for an interface service on the interface platform.

[0169] In one embodiment, when the processor executes the computer program, the following steps are also implemented: obtaining the attack payload of the security vulnerability to be tested; replacing the content of the plaintext message with the attack payload to obtain an attack simulation message.

[0170] In one embodiment, when the processor executes the computer program, the following steps are also implemented: determining the interface type of the request message; and determining at least one security vulnerability to be tested according to the interface type.

[0171] In one embodiment, when the processor executes the computer program, the following steps are also implemented: obtaining vulnerability judgment rules for the security vulnerabilities to be tested; performing vulnerability judgment on the response message according to the vulnerability judgment rules to obtain security test results.

[0172] In one embodiment, when the processor executes the computer program, the following steps are also implemented: obtaining a traffic log from the interface gateway server; filtering out unencrypted logs, error logs, and access failure logs from the traffic log to obtain an encrypted traffic log.

[0173] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored, and the computer program implements the following steps when executed by a processor: obtaining an encrypted traffic log from an interface gateway server; parsing key fields from the encrypted traffic log; splicing the key fields to obtain at least one request message; for each request message, decrypting the request message according to a key corresponding to the request message to obtain a plaintext message; adding an attack payload to the plaintext message to obtain an attack simulation message; encrypting the attack simulation message using a key to obtain a security test message; sending the security test message to a back-end server, and receiving a response message sent by the back-end server; and determining a security test result according to the response message.

[0174] In one embodiment, when the computer program is executed by the processor, the following steps are also implemented: based on preset rules, the encrypted traffic log is divided into at least one message block; based on preset keywords, the corresponding key field is matched from the message block.

[0175] In one embodiment, when the computer program is executed by the processor, the following steps are also implemented: querying in a preset storage unit according to the uniform resource locator of the request message to obtain a key corresponding to the request message; the preset storage unit stores a partner key obtained from the interface platform, and the partner key is the key uploaded by the partner when applying for the interface service on the interface platform.

[0176] In one embodiment, when the computer program is executed by the processor, the following steps are also implemented: obtaining the attack payload of the security vulnerability to be tested; replacing the content of the plaintext message with the attack payload to obtain an attack simulation message.

[0177] In one embodiment, when the computer program is executed by the processor, the following steps are also implemented: determining the interface type of the request message; and determining at least one security vulnerability to be tested according to the interface type.

[0178] In one embodiment, when the computer program is executed by the processor, the following steps are also implemented: obtaining vulnerability judgment rules for the security vulnerabilities to be tested; performing vulnerability judgment on the response message according to the vulnerability judgment rules to obtain security test results.

[0179] In one embodiment, when the computer program is executed by the processor, the following steps are also implemented: obtaining traffic logs from the interface gateway server; filtering out unencrypted logs, error logs, and access failure logs from the traffic logs to obtain encrypted traffic logs.

[0180] In one embodiment, a computer program product is provided, including a computer program, which implements the following steps when executed by a processor: obtaining an encrypted traffic log from an interface gateway server; parsing key fields from the encrypted traffic log; splicing the key fields to obtain at least one request message; for each request message, decrypting the request message according to a key corresponding to the request message to obtain a plaintext message; adding an attack payload to the plaintext message to obtain an attack simulation message; encrypting the attack simulation message using a key to obtain a security test message; sending the security test message to a back-end server, and receiving a response message sent by the back-end server; and determining a security test result according to the response message.

[0181] In one embodiment, when the computer program is executed by the processor, the following steps are also implemented: based on preset rules, the encrypted traffic log is divided into at least one message block; based on preset keywords, the corresponding key field is matched from the message block.

[0182] In one embodiment, when the computer program is executed by the processor, the following steps are also implemented: querying in a preset storage unit according to the uniform resource locator of the request message to obtain a key corresponding to the request message; the preset storage unit stores a partner key obtained from the interface platform, and the partner key is the key uploaded by the partner when applying for the interface service on the interface platform.

[0183] In one embodiment, when the computer program is executed by the processor, the following steps are also implemented: obtaining the attack payload of the security vulnerability to be tested; replacing the content of the plaintext message with the attack payload to obtain an attack simulation message.

[0184] In one embodiment, when the computer program is executed by the processor, the following steps are also implemented: determining the interface type of the request message; and determining at least one security vulnerability to be tested according to the interface type.

[0185] In one embodiment, when the computer program is executed by the processor, the following steps are also implemented: obtaining vulnerability judgment rules for the security vulnerabilities to be tested; performing vulnerability judgment on the response message according to the vulnerability judgment rules to obtain security test results.

[0186] In one embodiment, when the computer program is executed by the processor, the following steps are also implemented: obtaining traffic logs from the interface gateway server; filtering out unencrypted logs, error logs, and access failure logs from the traffic logs to obtain encrypted traffic logs.

[0187] It should be noted that the information collected by this application is information and data authorized by the user or fully authorized by all parties, and the collection, storage, use, processing, transmission, provision, disclosure and application of the relevant data comply with relevant regulations and standards, take necessary confidentiality measures, do not violate public order and good morals, and provide corresponding operation entrances for users to choose to authorize or refuse.

[0188] A person of ordinary skill in the art can understand that all or part of the processes in the above-mentioned embodiment method can be completed by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to the memory, database or other medium used in the embodiments provided in the present application can include at least one of non-volatile memory and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. As an illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM). The database involved in each embodiment provided in this application may include at least one of a relational database and a non-relational database. Non-relational databases may include distributed databases based on blockchains, etc., but are not limited to this. The processor involved in each embodiment provided in this application may be a general-purpose processor, a central processing unit, a graphics processor, a digital signal processor, a programmable logic device, a data processing logic device based on quantum computing, an artificial intelligence (AI) processor, etc., but are not limited to this.

[0189] The technical features of the above embodiments may be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this application.

[0190] The above-described embodiments only express several implementation methods of the present application, and the descriptions thereof are relatively specific and detailed, but they cannot be understood as limiting the scope of the present application. It should be pointed out that, for a person of ordinary skill in the art, several variations and improvements can be made without departing from the concept of the present application, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the attached claims.

Claims

1. A method for security testing of an interface, characterized in that: The method comprises: Get encrypted traffic logs from the interface gateway server; Parsing key fields from the encrypted traffic log; Concatenate the key fields to obtain at least one request message; For each request message, decrypt the request message according to the key corresponding to the request message to obtain a plaintext message; Adding an attack payload to the plaintext message to obtain an attack simulation message; Using the key to encrypt the attack simulation message to obtain a security test message; Sending the security test message to the back-end server, and receiving a response message sent by the back-end server; A security test result is determined according to the response message.

2. The method according to claim 1, characterized in that: The step of parsing key fields from the encrypted traffic log includes: Based on a preset rule, the encrypted traffic log is divided into at least one message block; Based on the preset keywords, the corresponding key fields are matched from the message blocks.

3. The method according to claim 1, characterized in that: The process of obtaining the key corresponding to the request message includes: A query is performed in a preset storage unit according to the uniform resource locator of the request message to obtain the key corresponding to the request message; the preset storage unit stores the partner key obtained from the interface platform, and the partner key is the key uploaded by the partner when applying for interface service on the interface platform.

4. The method according to claim 1, characterized in that: The step of adding an attack payload to the plaintext message to obtain an attack simulation message includes: Obtain the attack payload of the security vulnerability to be tested; The content of the plaintext message is replaced with the attack payload to obtain an attack simulation message.

5. The method according to claim 4, characterized in that The process of determining the security vulnerability to be tested includes: Determine the interface type of the request message; At least one security vulnerability to be tested is determined according to the interface type.

6. The method according to claim 4, characterized in that Determining the security test result according to the response message includes: Obtaining vulnerability judgment rules for the security vulnerability to be tested; The vulnerability judgment rule is used to perform vulnerability judgment on the response message to obtain a security test result.

7. The method according to any one of claims 1 to 6, characterized in that The step of obtaining the encrypted traffic log from the interface gateway server includes: Get traffic logs from the interface gateway server; Unencrypted logs, error logs, and access failure logs are filtered out from the traffic logs to obtain encrypted traffic logs.

8. A safety testing device for an interface, characterized in that: The device comprises: The acquisition module is used to obtain the encrypted traffic log from the interface gateway server; A parsing module, used to parse key fields from the encrypted traffic log; A splicing module, used for splicing the key fields to obtain at least one request message; A decryption module, used to decrypt each request message according to a key corresponding to the request message to obtain a plaintext message; An adding module is used to add an attack payload to the plaintext message to obtain an attack simulation message; An encryption module, used to encrypt the attack simulation message using the key to obtain a security test message; A sending module, used to send the security test message to the back-end server and receive a response message sent by the back-end server; A testing module is used to determine a security test result based on the response message.

9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 7 are implemented.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.

Citation Information

Cited By

  • Cross-network interface test method and system and computer readable storage medium

    CN120639663A