Security test method and device, computer equipment, readable storage medium and program product

By automatically generating and sending test data packets, the problems of poor flexibility and low efficiency of security testing methods in the prior art are solved, and efficient security testing is achieved.

CN120050055APending Publication Date: 2025-05-27INDUSTRIAL AND COMMERCIAL BANK OF CHINA
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410576541.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-05-10
Publication Date
2025-05-27

AI Technical Summary

Technical Problem

In the prior art, the safety testing method has poor flexibility and low efficiency, resulting in low testing work efficiency.

Method used

By obtaining the first service data packets of multiple different services sent by the client to the server to be tested, multiple second service data packets related to the service to be tested are selected, and multiple test data packets are generated based on the item to be tested, and the response data is automatically sent to the server to obtain the test results.

Benefits of technology

Automatic testing is realized, which improves the flexibility and efficiency of safety testing methods and significantly improves work efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120050055A_ABST
    Figure CN120050055A_ABST
Patent Text Reader

Abstract

The invention relates to a security test method and device, computer equipment, a computer readable storage medium and a computer program product. The method relates to the field of information security, can be used in the field of security testing, and comprises the following steps: acquiring first business data packets of a plurality of different businesses sent to a to-be-tested server by a client in a business execution process; screening out a plurality of second service data packets related to a to-be-tested service from the first service data packet according to the to-be-tested service, and generating a plurality of test data packets based on to-be-tested items of the to-be-tested service and the second service data packets; and sending the plurality of test data packets to the to-be-tested server, receiving test response data returned by the to-be-tested server, and obtaining a test result corresponding to the to-be-tested item according to the test response data. By adopting the safety test method provided by the invention, the test flexibility and efficiency can be improved, and the working efficiency of the safety test method is effectively improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of information security and can be used in the field of security testing. In particular, it relates to a security testing method, device, computer device, computer-readable storage medium, and computer program product. Background Art

[0002] In network security technology, packet capture testing plays a very important role. Through packet capture testing, the data packets sent and returned by the client and the server can be obtained to analyze the content and protocol of the data packets, so as to test whether they meet the design requirements.

[0003] In the prior art, it is usually manually tested by technicians. The technicians need to manually send test data packets to the server and determine the test results according to the responses returned by the server.

[0004] However, this testing method requires technicians to repeat the steps before sending the test data packets, resulting in poor flexibility and low efficiency of the testing method, and thus low working efficiency of the testing method. Summary of the Invention

[0005] Based on this, it is necessary to provide a security testing method, device, computer device, computer-readable storage medium, and computer program product with relatively high working efficiency for the above technical problems.

[0006] In a first aspect, this application provides a security testing method, including:

[0007] Obtain multiple first service data packets of different services sent by a client to a server to be tested during the execution of services; screen out multiple second service data packets related to the service to be tested from the first service data packets according to the service to be tested, and generate multiple test data packets based on the test items of the service to be tested and the second service data packets; send the multiple test data packets to the server to be tested, and receive the test response data returned by the server to be tested, and obtain the test results corresponding to the test items according to the test response data.

[0008] In one of the embodiments, the generating multiple test data packets based on the test items of the service to be tested and the second service data packets includes: determining a target service execution step from multiple service execution steps of the service to be tested according to the test item; performing test tampering on the service data packets corresponding to the target service execution step in the second service data packets to obtain target test data packets; using the target test data packets and other second service data packets that have not been tested and tampered as the multiple test data packets.

[0009] In one embodiment, screening out a plurality of second service data packets related to the service to be tested from the first service data packets according to the service to be tested includes: determining the service type of the service to be tested; screening out the plurality of second service data packets with the same service type as the service type from the first service data packets.

[0010] In one embodiment, screening out a plurality of second service data packets related to the service to be tested from the first service data packets according to the service to be tested includes: determining a plurality of test parameters included in the service to be tested; screening out the plurality of second service data packets related to the plurality of test parameters from the first service data packets.

[0011] In one embodiment, generating a plurality of test data packets based on the item to be tested of the service to be tested and the second service data packets includes: determining a first test parameter from the plurality of test parameters according to the item to be tested; performing a test replacement process on the first test parameter to obtain a target test parameter; using the target test parameter and the test parameters without the test replacement process as the plurality of test data packets.

[0012] In one embodiment, after performing a test replacement process on the first test parameter to obtain a target test parameter, the method further includes: performing a marking process on the target test parameter.

[0013] In one embodiment, sending the plurality of test data packets to the service server to be tested includes: performing a marking detection on the plurality of test data packets; performing an encryption and coding process on the test data packets with marks, and after the encryption and coding process, sending the plurality of test data packets to the service server to be tested.

[0014] In a second aspect, the present application further provides a security testing device, including:

[0015] An acquisition module, configured to acquire a plurality of first service data packets of different services sent by a client to a service server to be tested during the execution of the service;

[0016] A first execution module, configured to screen out a plurality of second service data packets related to the service to be tested from the first service data packets according to the service to be tested, and generate a plurality of test data packets based on the item to be tested of the service to be tested and the second service data packets;

[0017] A second execution module, configured to send the plurality of test data packets to the service server to be tested, receive test response data returned by the service server to be tested, and obtain a test result corresponding to the item to be tested according to the test response data.

[0018] In one embodiment, the first execution module is specifically configured to determine a target service execution step from multiple service execution steps of the service to be tested according to the item to be tested; perform test tampering on the service data packet corresponding to the target service execution step in the second service data packet to obtain a target test data packet; use the target test data packet and other second service data packets that have not been tested and tampered with as the multiple test data packets.

[0019] In one embodiment, the first execution module is specifically configured to determine the service type of the service to be tested; screen out the multiple second service data packets with the same service type as the service type from the first service data packet.

[0020] In one embodiment, the first execution module is further specifically configured to determine multiple test parameters included in the service to be tested; screen out the multiple second service data packets related to the multiple test parameters from the first service data packet.

[0021] In one embodiment, the first execution module is further specifically configured to determine a first test parameter from the multiple test parameters according to the item to be tested; perform test replacement processing on the first test parameter to obtain a target test parameter; use the target test parameter and the test parameters that have not been tested and replaced as the multiple test data packets.

[0022] In one embodiment, the second execution module is further configured to perform marking processing on the target test parameter.

[0023] In one embodiment, the second execution module is specifically configured to perform marking detection on the multiple test data packets; perform encryption and encoding processing on the test data packets with marks, and after the encryption and encoding processing, send the multiple test data packets to the service server to be tested.

[0024] In a third aspect, the present application further provides a computer device, including a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the method described in any one of the embodiments in the first aspect is implemented.

[0025] In a fourth aspect, the present application further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the method described in any one of the embodiments in the first aspect is implemented.

[0026] In a fifth aspect, the present application further provides a computer program product, including a computer program. When the computer program is executed by a processor, the method described in any one of the embodiments in the first aspect is implemented.

[0027] The above security testing method, device, computer device, computer-readable storage medium, and computer program product obtain first service data packets of multiple different services sent by a client to a server to be tested during the execution of services; filter out multiple second service data packets related to the service to be tested from the first service data packets according to the service to be tested, and generate multiple test data packets based on the test items of the service to be tested and the second service data packets; send the multiple test data packets to the server to be tested, and receive test response data returned by the server to be tested, and obtain the test results corresponding to the test items according to the test response data. The security testing method provided by this application, when a user needs to test a server, only requires the user to input the service to be tested and the test items, and multiple test data packets can be automatically generated, and the multiple test data packets are sent to the server to be tested to receive the test response data returned by the server to be tested, and the test results corresponding to the test items are obtained according to the test response data. By using the security testing method provided by this application, the user only needs to input the service to be tested and the test items to achieve automated testing of the server to be tested, without the user manually testing the server to be tested and repeating the steps before sending the test data packets, which improves the flexibility and efficiency of the security testing method, and thus effectively improves the working efficiency of the security testing method. BRIEF DESCRIPTION OF THE DRAWINGS

[0028] In order to more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the following will briefly introduce the drawings required for use in the description of the embodiments of the present application or related technologies. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other related drawings can also be obtained based on these drawings.

[0029] Figure 1 It is a schematic flowchart of a security testing method in an embodiment;

[0030] Figure 2 It is a schematic flowchart of a method for filtering out multiple second service data packets related to the service to be tested from the first service data packets according to the service to be tested in an embodiment;

[0031] Figure 3 It is a schematic flowchart of a method for generating multiple test data packets based on the test items of the service to be tested and the second service data packets in an embodiment;

[0032] Figure 4 It is a schematic flowchart of a method for filtering out multiple second service data packets related to the service to be tested from the first service data packets according to the service to be tested in an embodiment;

[0033] Figure 5 A schematic flowchart of a method for generating multiple test data packets based on test items of a service to be tested and the second service data packet in an embodiment;

[0034] Figure 6 A schematic flowchart of a security test method in another embodiment;

[0035] Figure 7 A schematic flowchart of a security test method in another embodiment;

[0036] Figure 8 A structural block diagram of a security test device in an embodiment;

[0037] Figure 9 An internal structure diagram of a computer device in another embodiment;

[0038] Figure 10 An internal structure diagram of a computer device in an embodiment. Detailed implementation manners

[0039] In order to make the objectives, technical solutions and advantages of the present application clearer and more understandable, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.

[0040] In the field of network security, packet capture testing plays a very important role. Through packet capture testing, the data packets sent and returned by the client and the server can be obtained to analyze the content and protocol of the data packets, so as to test whether they meet the design requirements.

[0041] In the prior art, usually, technical personnel perform the testing manually. The technical personnel need to manually send test data packets to the server and determine the test results according to the responses returned by the server.

[0042] However, this testing method requires technical personnel to repeat the steps before sending the test data packets, resulting in poor flexibility and low efficiency of the testing method, and further resulting in low working efficiency of the testing method.

[0043] In view of this, the present application provides a security testing method, which does not require technical personnel to repeat the steps before sending the test data packets, effectively improves the flexibility and efficiency of the security testing method, and further improves the working efficiency of the security testing method.

[0044] The security testing method provided by the present application may have a computer device as its execution subject, and the computer device may be a server or a terminal.

[0045] In an exemplary embodiment, as Figure 1As shown, a security testing method is provided, and the method includes the following steps:

[0046] Step 101: Obtain multiple first service data packets of different services sent by a client to a server to be tested during the execution of a service.

[0047] Optionally, the first service data may be legal request messages of multiple different services sent by the client to the server to be tested during the execution of a service.

[0048] In a possible implementation manner, the first service data packet may be obtained through a data packet storage server, which is used to store the request messages transmitted during the interaction between the client and the server to be tested. Through the data packet storage server, detailed information of the request messages can also be queried, such as request addresses, request parameters, request headers, request bodies, etc. The request messages include legal request messages and illegal request messages. For example, if the server to be tested executes the operation corresponding to the request message after receiving the request message sent by the client, it can be determined that the request message is a legal request message; otherwise, it can be determined that the request message is an illegal request message. Or, it is determined whether the request message is a legal request message according to the response data returned by the server to be tested after receiving the request message sent by the client.

[0049] Step 102: Screen out multiple second service data packets related to the service to be tested from the first service data packets according to the service to be tested, and generate multiple test data packets based on the test items of the service to be tested and the second service data packets.

[0050] Optionally, the service to be tested can be set by a technician according to actual needs.

[0051] In a possible implementation manner, since there are multiple services on the server to be tested, therefore, the service type of the service to be tested can be determined first, and then the multiple second service data packets of the same service type can be screened out from the first service data packets according to the service type.

[0052] In another possible implementation manner, the multiple test parameters included in the service to be tested can also be determined first, and then the multiple second service data packets related to the multiple test parameters can be screened out from the first service data packets.

[0053] In another possible implementation manner, multiple second service data packets related to the service to be tested can also be screened out from the first service data packets based on a keyword algorithm and the service to be tested.

[0054] In another possible implementation, the service to be tested can be input into a pre-trained second service data packet determination model to obtain the second service data packet output by the model.

[0055] Optionally, the item to be tested can also be set by a technician according to actual requirements. The service to be tested can include multiple execution steps, and each execution step can be used as an item to be tested. The service to be tested can also include multiple test parameters, and each test parameter can be used as an item to be tested.

[0056] In one possible implementation, if the service to be tested includes multiple execution steps, the target service execution step can be determined from the multiple service execution steps of the service to be tested according to the item to be tested. The service data packet corresponding to the target service execution step in the second service data packet is tested and tampered with to obtain a target test data packet, and the target test data packet and the other second service data packets that have not been tested and tampered with are used as the multiple test data packets.

[0057] In another possible implementation, if the service to be tested includes multiple test parameters, the first test parameter can be determined from the multiple test parameters according to the item to be tested; the first test parameter is subjected to test replacement processing, and the first test parameter after the test replacement processing and the other test parameters that have not been subjected to test replacement processing are used as the multiple test data packets.

[0058] In another possible implementation, the item to be tested and the second service data packet can also be input into a pre-trained test data packet generation model to obtain the test data packet output by the model.

[0059] Step 103: Send the multiple test data packets to the service under test, and receive the test response data returned by the service under test. Obtain the test result corresponding to the item to be tested according to the test response data.

[0060] In one possible implementation, the multiple test data packets can be sent to the service under test in sequence according to the data packet sending order corresponding to the service to be tested, so as to receive the test response data returned by the service under test.

[0061] In another possible implementation, the multiple test data packets can also be sent to the service under test in the data packet sending order pre-set by a technician according to actual test requirements, so as to receive the test response data returned by the service under test.

[0062] As described above, after receiving the test response data returned by the service under test, it is also necessary to obtain the test result corresponding to the item to be tested according to the test response data.

[0063] In a possible implementation manner, as described above, the data packet storage server is used to store the request messages transmitted during the interaction between the client and the server to be tested. Therefore, after sending a legal request message corresponding to the item to be tested to the server to be tested through the data packet storage server, the legal response data returned by the server to be tested can also be obtained, and the test result corresponding to the item to be tested can be determined according to the legal response data and the test response data.

[0064] The above security testing method includes: obtaining multiple first service data packets of different services sent by the client to the server to be tested during the execution of the service; screening out multiple second service data packets related to the service to be tested from the first service data packets according to the service to be tested, and generating multiple test data packets based on the item to be tested of the service to be tested and the second service data packets; sending the multiple test data packets to the server to be tested, and receiving the test response data returned by the server to be tested, and obtaining the test result corresponding to the item to be tested according to the test response data. The security testing method provided in this application only requires the user to input the service to be tested and the item to be tested when the user needs to test the server. Multiple test data packets can be automatically generated, and the multiple test data packets are sent to the server to be tested in sequence according to the sending order of the data packets corresponding to the service to be tested, so as to receive the test response data returned by the server to be tested, and obtain the test result corresponding to the item to be tested according to the test response data. By using the security testing method provided in this application, the user only needs to input the service to be tested and the item to be tested to achieve automated testing of the server to be tested, without the user manually testing the server to be tested and repeating the steps before sending the test data packets, which improves the flexibility and efficiency of the security testing method, and thus effectively improves the working efficiency of the security testing method.

[0065] In an exemplary embodiment, as Figure 2 shown, screening out multiple second service data packets related to the service to be tested from the first service data packets according to the service to be tested includes the following steps:

[0066] Step 201: Determine the service type of the service to be tested;

[0067] Step 202: Screen out the multiple second service data packets with the same service type as the service type from the first service data packets according to the service type.

[0068] Optionally, the service type of the service to be tested can be used to characterize the function corresponding to the service to be tested.

[0069] In a possible implementation, the service type of the service to be tested can be determined first, and then multiple service test data packets of the same service type as the service type can be filtered out from the multiple service data packets. For example, if the service to be tested is a resource value transfer service, the service type of the service to be tested can be determined as resource value transfer, and then data packets of the resource value transfer type can be filtered out from the first service data packets, and these data packets can be determined as the second service data packets.

[0070] In an exemplary embodiment, as Figure 3 shown, generating multiple test data packets based on the test items of the service to be tested and the second service data packets includes the following steps:

[0071] Step 301: Determine the target service execution step from multiple service execution steps of the service to be tested according to the test item.

[0072] In a possible implementation, as described above, the service to be tested may include multiple service execution steps, and each service execution step can be used as a test item. Taking the service to be tested as a resource value transfer service as an example, the resource value transfer service includes service execution steps of inputting resource value transfer information, querying account resource values, and executing resource value transfer. Then, at least one target service execution step can be determined from the multiple service execution steps of the service to be tested according to the test items preset by technicians.

[0073] Step 302: Test and tamper with the service data packets corresponding to the target service execution step in the second service data packets to obtain target test data packets;

[0074] Step 303: Use the target test data packets and the other second service data packets that have not been tested and tampered with as the multiple test data packets.

[0075] Optionally, the test tampering can be performed on the service data packets corresponding to the target service execution step based on the tampering instructions pre-input by technicians.

[0076] In a possible implementation, taking the service to be tested as a resource value transfer service as an example, and taking the target service execution step as the service execution step of executing resource value transfer as an example, then the service data packets corresponding to the service execution step of executing resource value transfer in the second service data packets are subjected to test replacement processing to obtain target test data packets, and then the target test data packets, the data packets corresponding to the service execution step of inputting resource value transfer information that have not been tested and tampered with, and the data packets corresponding to the service execution step of querying account resource values that have not been tested and tampered with are determined as the multiple test data packets.

[0077] In another possible implementation, taking the business to be tested as a resource value transfer business as an example, if the target business execution steps are the resource value transfer business execution steps and the query account resource value business execution steps, then the business data packets in the second business data packet corresponding to the resource value transfer business execution steps and the query account resource value business execution steps are subjected to test replacement processing to obtain a target test data packet, and then the target test data packet and the data packet corresponding to the input resource value transfer information business execution step that has not been tested and tampered with are determined as the multiple test data packets.

[0078] In an exemplary embodiment, as Figure 4 shown, the steps of screening out multiple second business data packets related to the business to be tested from the first business data packet according to the business to be tested include the following steps:

[0079] Step 401: Determine multiple test parameters included in the business to be tested;

[0080] Step 402: Screen out the multiple second business data packets related to the multiple test parameters from the first business data packet.

[0081] In a possible implementation, the business to be tested may include multiple parameters, and each parameter can be used as a test item. Therefore, the identifiers of the multiple test parameters included in the business to be tested can be determined first, and then the multiple test parameters are screened out from the first business data packet according to the identifiers, and the multiple test parameters are determined as the multiple second business data packets. For example, if the business to be tested includes parameter A, parameter B, and parameter C, the corresponding identifiers are A, B, and C. Then, parameter A, parameter B, and parameter C are obtained from the first business data packet according to the identifiers and used as the second business data packets.

[0082] In an exemplary embodiment, as Figure 5 shown, the steps of generating multiple test data packets based on the test items of the business to be tested and the second business data packet include the following steps:

[0083] Step 501: Determine a first test parameter from the multiple test parameters according to the test item.

[0084] Optionally, the test item can be a test parameter.

[0085] In a possible implementation, as described above, the business to be tested may include multiple test parameters, and each test parameter can be used as a test item. Taking the business to be tested as a password input business as an example, if the resource value transfer business includes multiple parameters, at least one parameter can be determined as the first test parameter from the multiple parameters of the business to be tested according to the test item preset by the technician.

[0086] Step 502: Perform test replacement processing on the first test parameter to obtain a target test parameter;

[0087] Step 503: Use the target test parameter and the test parameter without test replacement processing as the multiple test data packets.

[0088] Optionally, the test replacement processing includes parameter content replacement processing.

[0089] In a possible implementation manner, the content of the first test parameter can be replaced based on the parameter content pre-input by the technician to obtain a target test parameter. Taking the service to be tested as the password input service as an example, if the first test parameter is the pass parameter, then first replace the content of the pass parameter based on the parameter content pre-input by the technician to obtain a target test parameter. Then, use the target test parameter and other test parameters without test replacement processing as the multiple test data packets.

[0090] In another possible implementation manner, taking the service to be tested as the password input service as an example, if the first test parameter is the A parameter and the B parameter, then first replace the content of the A parameter and the B parameter based on the parameter content pre-input by the technician to obtain the target test parameters, the A' parameter and the B' parameter. Then, use the A' parameter, the B' parameter, and other test parameters without test replacement processing as the multiple test data packets.

[0091] In an exemplary embodiment, after performing test replacement processing on the first test parameter to obtain a target test parameter, the method further includes: performing marking processing on the target test parameter.

[0092] Optionally, the marking processing is used to distinguish the target test parameter from other test parameters. The specific marking processing method can be set by the technician according to actual needs, and the present application does not limit this.

[0093] In an exemplary embodiment, sending the multiple test data packets to the service to be tested includes:

[0094] Performing marking detection on the multiple test data packets; performing encryption encoding processing on the test data packets with marks, and after the encryption encoding processing, sending the multiple test data packets to the service to be tested.

[0095] Optionally, the encryption encoding processing can be base64 encoding processing or encryption processing based on a target secret key.

[0096] In a possible implementation, the business to be tested includes multiple test parameters. Before sending the test parameters to the server to be tested, they must be processed by base64 encoding or encrypted based on a target secret key. Since the content of the first test parameter among the multiple test parameters has been replaced with the parameter content pre-entered by the technician through test replacement processing, and the other test parameters among the multiple test parameters have all been processed by base64 encoding or encrypted through the target secret key, only the first test parameter has not been processed by base64 encoding or encrypted through the target secret key. Therefore, before sending the multiple test data packets to the server to be tested, that is, before sending the multiple test parameters to the server to be tested, the multiple test data packets can be marked and detected to determine the target test data that needs to be encrypted and encoded, and then the first test parameter is encrypted and encoded. After the encryption and encoding process, the multiple test data packets are sent to the server to be tested.

[0097] In an exemplary embodiment, as Figure 6 shown, another security test method is provided. The business to be tested of this security test method may include multiple business execution steps. The method includes the following steps:

[0098] Step 601, obtain the first business data packets of multiple different businesses sent by the client to the server to be tested during the business execution process;

[0099] Step 602, determine the business type of the business to be tested; screen out the multiple second business data packets with the same business type as the business type from the first business data packets;

[0100] Step 603, determine the target business execution step from the multiple business execution steps of the business to be tested according to the item to be tested; tamper with the business data packets corresponding to the target business execution step in the second business data packets to obtain target test data packets; use the target test data packets and the other second business data packets that have not been tested and tampered with as the multiple test data packets;

[0101] Step 604, send the multiple test data packets to the server to be tested, and receive the test response data returned by the server to be tested, and obtain the test result corresponding to the item to be tested according to the test response data.

[0102] The above security testing method, in the case where the service to be tested includes multiple service execution steps, first obtains the first service data packets of multiple different services sent by the client to the service to be tested during the execution of the service, and then determines the service type of the service to be tested; filters out the multiple second service data packets with the same service type as the service type from the first service data packets, and then determines the target service execution step from the multiple service execution steps of the service to be tested according to the item to be tested; tests and tampers with the service data packets corresponding to the target service execution step in the second service data packets to obtain target test data packets; uses the target test data packets and other second service data packets that have not been tested and tampered with as the multiple test data packets, and finally, sends the multiple test data packets to the service to be tested and receives the test response data returned by the service to be tested, and obtains the test result corresponding to the item to be tested according to the test response data. Compared with the prior art, if the service to be tested includes multiple service execution steps, each service execution step can be used as an independent item to be tested. If the target service execution step corresponding to the item to be tested is in the middle step or the last step of the entire service execution process, technicians need to manually execute all the steps before the target service execution step first to test the target service execution step. If multiple types and multiple times of testing are required for the target execution step, technicians need to repeat the execution of all the steps before the target service execution step multiple times, resulting in poor flexibility and low efficiency of the security testing method, and further resulting in low working efficiency of the security testing method. By using the security testing method provided in this application, technicians only need to input the service to be tested, the item to be tested, and the tampering instruction, and can automatically generate test data packets to test the service to be tested, which can effectively improve the flexibility and efficiency of the security testing method, and further effectively improve the working efficiency of the security testing method.

[0103] In an exemplary embodiment, as Figure 7 shown, another security testing method is provided. The service to be tested of this security testing method may include multiple test parameters, and the method includes the following steps:

[0104] Step 701, obtain the first service data packets of multiple different services sent by the client to the service to be tested during the execution of the service;

[0105] Step 702, determine the multiple test parameters included in the service to be tested; filter out the multiple second service data packets related to the multiple test parameters from the first service data packets;

[0106] Step 703 determines a first test parameter from the multiple test parameters according to the item to be tested; performs test replacement processing on the first test parameter to obtain a target test parameter; performs marking processing on the target test parameter; and uses the target test parameter and the test parameters without test replacement processing as the multiple test data packets.

[0107] Step 704 performs marking detection on the multiple test data packets; performs encryption encoding processing on the test data packets with marks, and after the encryption encoding processing, sends the multiple test data packets to the server to be tested.

[0108] In the above security test method, when the service to be tested includes multiple test parameters, multiple first service data packets of different services sent by the client to the server to be tested during the execution of the service are obtained, and then the multiple test parameters included in the service to be tested are determined; the multiple second service data packets related to the multiple test parameters are filtered out from the first service data packets, and then a first test parameter is determined from the multiple test parameters according to the item to be tested; test replacement processing is performed on the first test parameter to obtain a target test parameter, then marking processing is performed on the target test parameter, the target test parameter and the test parameters without test replacement processing are used as the multiple test data packets, marking detection is performed on the multiple test data packets, encryption encoding processing is performed on the test data packets with marks, after the encryption encoding processing, the multiple test data packets are sent to the server to be tested, and the test response data returned by the server to be tested is received, and the test result corresponding to the item to be tested is obtained according to the test response data. Compared with the prior art, if the service to be tested includes multiple test parameters, each test parameter can be used as an individual item to be tested. When it is necessary to test the test parameter, the technician needs to first modify the content of the test parameter, then perform encryption encoding processing on the test parameter, and then send the test parameter to the server to be tested. If it is necessary to perform multiple types and multiple times of tests on the test parameter, the technician needs to continuously repeat the encryption encoding processing, resulting in poor flexibility and low efficiency of the security test method, and thus low working efficiency of the security test method. However, by using the security test method provided in this application, the technician only needs to input the service to be tested, the item to be tested, and the parameter content to be replaced, and then the test data packets can be automatically generated to test the server to be tested, which can effectively improve the flexibility and efficiency of the security test method, and thus effectively improve the working efficiency of the security test method.

[0109] It should be understood that although the steps in the flowcharts involved in the above-described embodiments are sequentially shown according to the indications of the arrows, these steps are not necessarily executed sequentially in the order indicated by the arrows. Unless there is a clear description in this article, there is no strict order limit for the execution of these steps, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above-described embodiments may include multiple steps or multiple stages. These steps or stages are not necessarily executed at the same moment, but can be executed at different moments. The execution order of these steps or stages is not necessarily sequential, but can be executed alternately or in turn with at least a part of other steps or steps or stages in other steps.

[0110] Based on the same inventive concept, an embodiment of the present application further provides a security testing device for implementing the above-mentioned security testing method. The solution provided by this device to solve the problem is similar to the solution described in the above method. Therefore, the specific limitations in one or more embodiments of the security testing device provided below can refer to the limitations on the security testing method in the above text, and will not be repeated here.

[0111] In an exemplary embodiment, as Figure 8 shown, a security testing device 800 is provided, including: an acquisition module 801, a first execution module 802, and a second execution module 803, where:

[0112] The acquisition module 801 is configured to acquire a first service data packet of multiple different services sent by the client to the server to be tested during the execution of the service.

[0113] The first execution module 802 is configured to screen out multiple second service data packets related to the service to be tested from the first service data packet according to the service to be tested, and generate multiple test data packets based on the test items of the service to be tested and the second service data packets.

[0114] The second execution module 803 is configured to send the multiple test data packets to the server to be tested, receive the test response data returned by the server to be tested, and obtain the test results corresponding to the test items according to the test response data.

[0115] In one embodiment, the first execution module 802 is specifically configured to determine a target service execution step from multiple service execution steps of the service to be tested according to the test item; perform test tampering on the service data packet corresponding to the target service execution step in the second service data packet to obtain a target test data packet; use the target test data packet and other second service data packets that have not been tested and tampered with as the multiple test data packets.

[0116] In one embodiment, the first execution module 802 is specifically configured to determine the service type of the service to be tested; and screen out the multiple second service data packets with the same service type from the first service data packet.

[0117] In one embodiment, the first execution module 802 is further specifically configured to determine multiple test parameters included in the service to be tested; and screen out the multiple second service data packets related to the multiple test parameters from the first service data packet.

[0118] In one embodiment, the first execution module 802 further specifically determines a first test parameter from the multiple test parameters according to the item to be tested; performs a test replacement process on the first test parameter to obtain a target test parameter; and uses the target test parameter and the test parameters without the test replacement process as the multiple test data packets.

[0119] In one embodiment, the second execution module 803 is further configured to perform a marking process on the target test parameter.

[0120] In one embodiment, the second execution module 803 is specifically configured to perform a marking detection on the multiple test data packets; perform an encryption and encoding process on the test data packets with markings, and after the encryption and encoding process, send the multiple test data packets to the server to be tested.

[0121] Each module in the above security testing device can be implemented in whole or in part by software, hardware, and their combination. Each of the above modules can be embedded in or independent of a processor in a computer device in the form of hardware, or stored in a memory in the computer device in the form of software, so as to facilitate the processor to call and execute the operations corresponding to each of the above modules.

[0122] In an exemplary embodiment, a computer device is provided. The computer device can be a server, and its internal structure diagram can be as Figure 9As shown in the figure. The computer device includes a processor, a memory, an input / output interface (Input / Output, abbreviated as I / O), and a communication interface. Among them, the processor, the memory, and the input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store data. The input / output interface of the computer device is used to exchange information between the processor and external devices. The communication interface of the computer device is used to communicate with external terminals through a network connection. When the computer program is executed by the processor, it implements a security test method.

[0123] In an exemplary embodiment, a computer device is provided. The computer device can be a terminal, and its internal structure diagram can be as Figure 10 shown in the figure. The computer device includes a processor, a memory, an input / output interface, a communication interface, a display unit, and an input device. Among them, the processor, the memory, and the input / output interface are connected through a system bus, and the communication interface, the display unit, and the input device are connected to the system bus through the input / output interface. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The input / output interface of the computer device is used to exchange information between the processor and external devices. The communication interface of the computer device is used to communicate with external terminals in a wired or wireless manner. The wireless manner can be implemented through WIFI, a mobile cellular network, near field communication (Near Field Communication, NFC), or other technologies. When the computer program is executed by the processor, it implements a security test method.

[0124] Those skilled in the art can understand that Figure 9 and Figure 10 the structures shown in the figure are only block diagrams of some structures related to the solution of the present application, and do not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine some components, or have different component arrangements.

[0125] In an exemplary embodiment, a computer device is provided, including a memory and a processor. A computer program is stored in the memory. When the processor executes the computer program, the following steps are implemented:

[0126] Obtain a plurality of first service data packets of different services sent by a client to a server to be tested during the execution of a service; screen out a plurality of second service data packets related to the service to be tested from the first service data packets according to the service to be tested, and generate a plurality of test data packets based on the test items of the service to be tested and the second service data packets; send the plurality of test data packets to the server to be tested, and receive test response data returned by the server to be tested, and obtain a test result corresponding to the test item according to the test response data.

[0127] In one embodiment, when the processor executes the computer program, the following steps are further implemented: determine a target service execution step from a plurality of service execution steps of the service to be tested according to the test item; perform test tampering on the service data packet corresponding to the target service execution step in the second service data packets to obtain a target test data packet; use the target test data packet and other second service data packets that have not been tested and tampered with as the plurality of test data packets.

[0128] In one embodiment, when the processor executes the computer program, the following steps are further implemented: determine the service type of the service to be tested; screen out the plurality of second service data packets with the same service type as the service type from the first service data packets according to the service type.

[0129] In one embodiment, when the processor executes the computer program, the following steps are further implemented: determine a plurality of test parameters included in the service to be tested; screen out the plurality of second service data packets related to the plurality of test parameters from the first service data packets.

[0130] In one embodiment, when the processor executes the computer program, the following steps are further implemented: determine a first test parameter from the plurality of test parameters according to the test item; perform test replacement processing on the first test parameter to obtain a target test parameter; use the target test parameter and the test parameters that have not been tested and replaced as the plurality of test data packets.

[0131] In one embodiment, when the processor executes the computer program, the following steps are further implemented: perform marking processing on the target test parameter.

[0132] In one embodiment, when the processor executes the computer program, the following steps are further implemented: perform marking detection on the plurality of test data packets; perform encryption coding processing on the test data packets with marks, and after the encryption coding processing, send the plurality of test data packets to the server to be tested.

[0133] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the following steps are implemented:

[0134] Obtain a plurality of first service data packets of different services sent by a client to a server to be tested during the execution of a service; screen out a plurality of second service data packets related to the service to be tested from the first service data packets according to the service to be tested, and generate a plurality of test data packets based on the test items of the service to be tested and the second service data packets; send the plurality of test data packets to the server to be tested, and receive test response data returned by the server to be tested, and obtain a test result corresponding to the test item according to the test response data.

[0135] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented: determine a target service execution step from a plurality of service execution steps of the service to be tested according to the test item; perform test tampering on the service data packet corresponding to the target service execution step in the second service data packets to obtain a target test data packet; use the target test data packet and other second service data packets that have not been tested and tampered with as the plurality of test data packets.

[0136] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented: determine the service type of the service to be tested; screen out the plurality of second service data packets with the same service type as the service type from the first service data packets according to the service type.

[0137] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented: determine a plurality of test parameters included in the service to be tested; screen out the plurality of second service data packets related to the plurality of test parameters from the first service data packets.

[0138] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented: determine a first test parameter from the plurality of test parameters according to the test item; perform a test replacement process on the first test parameter to obtain a target test parameter; use the target test parameter and test parameters that have not been tested and replaced as the plurality of test data packets.

[0139] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented: perform a marking process on the target test parameter.

[0140] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented: perform a marking detection on the plurality of test data packets; perform an encryption and encoding process on the test data packets with marks, and after the encryption and encoding process, send the plurality of test data packets to the server to be tested.

[0141] In one embodiment, a computer program product is provided, including a computer program which, when executed by a processor, implements the following steps:

[0142] Obtain a plurality of first service data packets of different services sent by a client to a server to be tested during the execution of a service; screen out a plurality of second service data packets related to the service to be tested from the first service data packets according to the service to be tested, and generate a plurality of test data packets based on the test items of the service to be tested and the second service data packets; send the plurality of test data packets to the server to be tested, and receive test response data returned by the server to be tested, and obtain a test result corresponding to the test item according to the test response data.

[0143] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented: determine a target service execution step from a plurality of service execution steps of the service to be tested according to the test item; perform test tampering on the service data packet corresponding to the target service execution step in the second service data packets to obtain a target test data packet; use the target test data packet and other second service data packets that have not been tested and tampered with as the plurality of test data packets.

[0144] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented: determine the service type of the service to be tested; screen out the plurality of second service data packets with the same service type as the service type from the first service data packets.

[0145] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented: determine a plurality of test parameters included in the service to be tested; screen out the plurality of second service data packets related to the plurality of test parameters from the first service data packets.

[0146] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented: determine a first test parameter from the plurality of test parameters according to the test item; perform test replacement processing on the first test parameter to obtain a target test parameter; use the target test parameter and test parameters that have not been tested and replaced as the plurality of test data packets.

[0147] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented: perform marking processing on the target test parameter.

[0148] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented: perform marking detection on the plurality of test data packets; perform encryption coding processing on the test data packets with marks, and after the encryption coding processing, send the plurality of test data packets to the server to be tested.

[0149] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, database, or other medium used in the embodiments provided in the present application can include at least one of non-volatile memory and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The databases involved in the embodiments provided in the present application can include at least one of relational databases and non-relational databases. Non-relational databases can include distributed databases based on blockchain, etc., without limitation. The processors involved in the embodiments provided in the present application can be general-purpose processors, central processors, graphics processors, digital signal processors, programmable logic devices, data processing logics based on quantum computing, artificial intelligence (AI) processors, etc., without limitation.

[0150] The technical features of the above embodiments can be combined arbitrarily. For the sake of concise description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope recorded in the present application.

[0151] The above-described embodiments merely represent several implementation manners of the present application. The description thereof is relatively specific and detailed, but it should not be construed as a limitation on the patent scope of the present application. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all fall within the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the appended claims.

Claims

1. A safety testing method, characterized in that: The method comprises: Acquire first service data packets of multiple different services sent by the client to the server to be tested during the service execution process; Filtering a plurality of second service data packets related to the service to be tested from the first service data packet according to the service to be tested, and generating a plurality of test data packets based on the test items of the service to be tested and the second service data packets; The plurality of test data packets are sent to the server to be tested, and test response data returned by the server to be tested is received, and the test result corresponding to the item to be tested is obtained according to the test response data.

2. The method according to claim 1, characterized in that The generating a plurality of test data packets based on the test items of the service to be tested and the second service data packet comprises: Determining a target service execution step from a plurality of service execution steps of the service to be tested according to the test item; Testing and tampering the service data packet corresponding to the target service execution step in the second service data packet to obtain a target test data packet; The target test data packet and other second service data packets that have not been tampered with during the test are used as the multiple test data packets.

3. The method according to claim 1, characterized in that The step of screening out a plurality of second service data packets related to the service to be tested from the first service data packet according to the service to be tested comprises: Determining the service type of the service to be tested; The plurality of second service data packets having the same service type as the first service data packet are screened out according to the service type.

4. The method according to claim 1, characterized in that: The step of screening out a plurality of second service data packets related to the service to be tested from the first service data packet according to the service to be tested comprises: Determining a plurality of test parameters included in the service to be tested; The plurality of second service data packets related to the plurality of test parameters are screened out from the first service data packets.

5. The method according to claim 4, characterized in that The generating a plurality of test data packets based on the test items of the service to be tested and the second service data comprises: Determine a first test parameter from the plurality of test parameters according to the item to be tested; Performing a test replacement process on the first test parameter to obtain a target test parameter; The target test parameters and the test parameters that have not been processed by the test replacement are used as the multiple test data packets.

6. The method according to claim 5, characterized in that After performing test replacement processing on the first test parameter to obtain a target test parameter, the method further includes: The target test parameter is marked.

7. The method according to claim 6, characterized in that The sending the multiple test data packets to the server to be tested includes: Performing mark detection on the multiple test data packets; Encryption coding is performed on the marked test data packets, and after encryption coding, the multiple test data packets are sent to the server to be tested.

8. A safety testing device, characterized in that: The device comprises: An acquisition module, used for acquiring first service data packets of multiple different services sent by the client to the server to be tested during the execution of the service; A first execution module, configured to filter out a plurality of second service data packets related to the service to be tested from the first service data packet according to the service to be tested, and generate a plurality of test data packets based on the test items of the service to be tested and the second service data packets; The second execution module is used to send the multiple test data packets to the server to be tested, receive test response data returned by the server to be tested, and obtain the test result corresponding to the test item according to the test response data.

9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 7 are implemented.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.