Unauthorized test method and system
By using accounts with different permissions to test the interface and determining the overright test results based on reconstruction and comparison of response data, the existing overright test methods are solved, and more efficient and accurate overright test detection is achieved.
Patent Information
- Application Number
- CN202510142523.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-08
- Publication Date
- 2025-05-30
AI Technical Summary
The existing overprivileged testing methods require testers to invest a lot of time and energy, are inefficient, and the test results are inaccurate.
By sequentially using accounts with different permissions to initiate access requests to the test interface, obtain response data, and reconstruct the response data based on the form of preset response data, and calculate data errors to determine the overright test results.
This method can comprehensively detect the behavior of the interface under different permissions, improve the accuracy of detecting overprivileged behaviors, automate the testing process, reduce manual intervention, and improve testing efficiency.
Smart Images

Figure CN120068087A_ABST
Abstract
Description
Technical Field
[0001] This application belongs to the field of testing technology, and particularly relates to a method and system for cross-authorization testing. Background Art
[0002] Cross-authorization testing is a security testing method used to detect whether there are privilege escalation vulnerabilities in an application. Cross-authorization testing can help discover and fix potential security risks, thereby effectively preventing attackers from using these vulnerabilities to obtain higher privileges. Currently, there are mainly two methods for cross-authorization testing. One is manual testing, that is, testers directly operate on the application and observe and record the behavior performance under different privileges; the other is automated testing with the help of tools. The tool simulates operations such as clicking on the page to capture data packets, and then the tester manually compares and analyzes the captured return results to determine whether there is a privilege escalation vulnerability. However, both of the above methods require testers to invest a lot of time and effort, with low efficiency and inaccurate test results. Summary of the Invention
[0003] The embodiments of this application provide a method and system for cross-authorization testing, which can solve the technical problems that the existing cross-authorization testing methods require testers to invest a lot of time and effort, with low efficiency and inaccurate test results.
[0004] In a first aspect, the embodiments of this application provide a method for cross-authorization testing, including:
[0005] Initiate access requests to the interface to be tested in sequence using accounts with different privileges, and obtain response data;
[0006] Reconstruct the response data based on the form of the preset response data to obtain reconstructed data;
[0007] Compare the reconstructed data with the preset response data to determine the data error;
[0008] Determine the cross-authorization test result based on the data error.
[0009] In a possible implementation manner of the first aspect, the reconstructing the response data based on the form of the preset response data to obtain reconstructed data includes:
[0010] Obtain the data type of the response data;
[0011] Reconstruct the response data based on the form of the preset response data and the data type of the response data to obtain the reconstructed data.
[0012] In a possible implementation of the first aspect, the form of the preset response data includes an image form or a text form; the data type of the response data includes a text type, a file type, a JSON type, an XML type, or a picture type; the reconstruction data includes text reconstruction data or image reconstruction data;
[0013] Reconstructing the response data based on the form of the preset response data and the data type of the response data to obtain the reconstruction data includes:
[0014] If the data type of the response data is any one of the text type, the file type, the JSON type, and the XML type, and the form of the preset response data is the text form, perform feature extraction and transformation on the response data to obtain a text feature vector;
[0015] Reconstruct the text feature vector to obtain the text reconstruction data;
[0016] If the data type of the response data is the picture type and the form of the preset response data is the image form, perform feature extraction and transformation on the response data to obtain an image feature vector;
[0017] Reconstruct the image feature vector to obtain the image reconstruction data.
[0018] In a possible implementation of the first aspect, performing feature extraction and transformation on the response data to obtain a text feature vector includes:
[0019] If the data type of the response data is the text type, perform text feature extraction on the response data to obtain the text feature vector;
[0020] If the data type of the response data is the JSON type, parse the response data, extract key-value pairs, and convert the key-value pairs into the text feature vector;
[0021] If the data type of the response data is the XML type, parse the response data, extract tags and attributes, and convert the tags and attributes into the text feature vector;
[0022] If the data type of the response data is the file type, open the response data, read the data in the file, and obtain the text feature vector based on the data type of the data in the file.
[0023] In a possible implementation of the first aspect, determining the over-authorization test result based on the data error includes:
[0024] If the data error is greater than a preset data error threshold, determine that the unauthorized test result is an unauthorized act;
[0025] If the data error is less than or equal to the preset data error threshold, determine that the unauthorized test result is a non-unauthorized act.
[0026] In a possible implementation manner of the first aspect, the method further includes:
[0027] Determine the unauthorized test result based on any combination of the following unauthorized test judgment conditions;
[0028] Unauthorized test judgment condition one: Based on the data error, determine the unauthorized test result;
[0029] Unauthorized test judgment condition two: Based on whether the response data contains a preset parameter, determine the unauthorized test result;
[0030] Unauthorized test judgment condition three: Based on the preset parameter included in the response data and the weight factor of the preset parameter, determine the unauthorized test result.
[0031] In a second aspect, an embodiment of the present application provides an unauthorized test system, including:
[0032] An acquisition module, configured to sequentially use accounts with different permissions to initiate access requests to the interface to be tested and obtain response data;
[0033] A reconstruction module, configured to reconstruct the response data based on the form of the preset response data to obtain reconstructed data;
[0034] A comparison module, configured to compare the reconstructed data with the preset response data to determine a data error;
[0035] A determination module, configured to determine an unauthorized test result based on the data error.
[0036] In a third aspect, an embodiment of the present application provides a computer device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the unauthorized test method described in any item of the first aspect is implemented.
[0037] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, where the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the unauthorized test method described in any item of the first aspect is implemented.
[0038] In a fifth aspect, an embodiment of the present application provides a computer program product. When the computer program product runs on a computer device, it causes the computer device to execute the privilege escalation testing method described in any one of the above first aspects.
[0039] In the embodiments of the present application, by sequentially using accounts with different permissions to initiate access requests to the interface to be tested and obtaining response data, the behavior of the interface under different permissions can be comprehensively detected, ensuring that the test covers multiple permission scenarios and improving the accuracy of detecting privilege escalation behavior. Reconstructing the response data based on the form of the preset response data and comparing the reconstructed data with the preset response data to calculate the data error can quantify the difference between the data returned by the interface and the expected data, thereby more accurately determining whether there is a privilege escalation behavior. In addition, this method can automatically perform privilege escalation testing, reducing manual intervention, improving the testing efficiency, and saving testing time and resources.
[0040] It can be understood that the beneficial effects of the above second to fifth aspects can be referred to the relevant descriptions in the above first aspect and will not be elaborated here. BRIEF DESCRIPTION OF THE DRAWINGS
[0041] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings required for use in the embodiments or the description of the prior art. Obviously, the following drawings are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0042] Figure 1 is a schematic flowchart of a privilege escalation testing method provided by an embodiment of the present application;
[0043] Figure 2 is a schematic flowchart of the detailed steps of S102 in the privilege escalation testing method provided by an embodiment of the present application;
[0044] Figure 3 is a schematic structural diagram of a privilege escalation testing system provided by an embodiment of the present application;
[0045] Figure 4 is a schematic structural diagram of a computer device provided by an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0046] In the following description, specific details such as specific system structures and technologies are proposed for the purpose of illustration rather than limitation, so as to thoroughly understand the embodiments of the present application. However, those skilled in the art should clearly understand that the present application can also be implemented in other embodiments without these specific details. In other cases, detailed descriptions of well-known systems, devices, circuits, and methods are omitted to avoid unnecessary details from interfering with the description of the present application.
[0047] It should be understood that when used in the specification of the present application and the appended claims, the term "comprising" indicates the presence of the described features, wholes, steps, operations, elements and / or components, but does not exclude the presence or addition of one or more other features, wholes, steps, operations, elements, components and / or their combinations.
[0048] It should also be understood that the term "and / or" used in the specification of the present application and the appended claims refers to any combination and all possible combinations of one or more of the associated listed items, and includes these combinations.
[0049] As used in the specification of the present application and the appended claims, the term "if" can be interpreted as "when", "once", "in response to determining", or "in response to detecting" according to the context. Similarly, the phrase "if determined" or "if [the described condition or event] is detected" can be interpreted as meaning "once determined", "in response to determining", "once [the described condition or event] is detected", or "in response to detecting [the described condition or event]" according to the context.
[0050] In addition, in the description of the specification of the present application and the appended claims, the terms "first", "second", "third", etc. are only used for differential description and cannot be understood as indicating or implying relative importance.
[0051] Referring to "one embodiment" or "some embodiments" described in the specification of the present application means that in one or more embodiments of the present application, the specific features, structures or characteristics described in combination with the embodiment are included. Thus, statements such as "in one embodiment", "in some embodiments", "in other some embodiments", "in still other embodiments", etc. that appear in different places in this specification do not necessarily all refer to the same embodiment, but mean "one or more but not all embodiments", unless otherwise specifically emphasized in other ways. The terms "comprising", "including", "having" and their variants all mean "including but not limited to", unless otherwise specifically emphasized in other ways.
[0052] Figure 1 A schematic flowchart of an over - privilege testing method provided by an embodiment of the present application is shown.
[0053] S101, initiate access requests to the interface to be tested in sequence using accounts with different permissions, and obtain response data.
[0054] Among them, a plurality of accounts with different permissions and account information are pre - configured. For each account, the over - privilege testing system initiates access requests to the interface to be tested in sequence using accounts with different permissions according to the configured interface to be tested or the path of the interface to be tested.
[0055] Optionally, before initiating an access request, for each account, the privilege escalation testing system obtains authentication information (such as a token or session ID) through the login interface or authentication service and stores it in the cache.
[0056] In an embodiment of the present application, when using accounts with different privileges to initiate an access request to the interface under test, the privilege escalation testing system automatically assembles the message header, including authentication information, and assembles the request body according to the configured input parameters. For each access request, the privilege escalation testing system will receive and record the response data returned by the server, including the status code, response header, and response body.
[0057] Among them, assembling the request body with input parameters means organizing the parameters required for the request into a part of the request body according to a predetermined format to ensure that the interface receives a request with the correct format and content.
[0058] In an optional embodiment, before successively using accounts with different privileges to initiate an access request to the interface under test and obtain response data, it is necessary to pre-configure accounts, account information, interface parameters, public parameters, etc. Specifically:
[0059] Step a, configure account information with different privileges.
[0060] Among them, the account information with different privileges can be configured through a yaml file. The account information includes, but is not limited to: user type, username, password, and environment.
[0061] Step b, configure interface parameters.
[0062] Among them, the interface parameter configuration can be implemented through an interface configuration file (such as a yaml file). The interface parameters include, but are not limited to: the interface path of the privilege escalation testing interface, input parameters (request parameters), output parameters (corresponding response data configured according to different privileges), request methods (get, post, put, delete, etc.), result assignment, and matching algorithms.
[0063] Among them, the output parameters are configured with corresponding response formats according to different privileges, using the account type as the keyword. The input parameters and output parameters can be configured as variables in the ${variable} format.
[0064] Among them, the result assignment can extract variable values from the interface return value automatically in the way of variable configuration and assign them to the specified variables. In this way, the subsequent interface calls can use these variables, thus realizing data transfer and sharing. This method is applicable to the privilege escalation test of interfaces that cannot be requested independently and need to rely on the return results of the previous interfaces. Specifically, the extraction rules of variables can be defined in the YAML file, such as specifying to obtain variable values from the returned JSON path and assign them to variables, so as to use the variables as input parameters in the subsequent test steps to complete the entire test process.
[0065] Among them, the matching algorithm configuration is used to define the algorithms based on which this interface conducts the privilege escalation test and the parameters required by these algorithms, including single algorithm configuration and combined algorithm configuration. For the single algorithm configuration, each algorithm has its specific parameters and thresholds, which are used to define the behavior and judgment criteria of the algorithm. When multiple algorithms need to be configured, the combined algorithm is used. The combined algorithm allows multiple single algorithms to be combined together and sets a comprehensive threshold to judge the overall test result.
[0066] Step c, configure the common parameters.
[0067] Among them, the common parameters can be configured through the yaml file. These parameters can be used to automatically replace the variables with the same name in the interface configuration file, thus realizing the parametric configuration of variables. The specific configuration items include parameter names and parameter values. In the YAML file, the name and corresponding value of each parameter will be listed. In this way, when these parameters are referenced in the interface configuration file, they can be dynamically replaced with the corresponding values according to actual needs, improving the flexibility and maintainability of the configuration.
[0068] Among them, in step b, the input parameters and output parameters in the interface configuration file can be configured as variables in the format of ${variable}. These variables need to be replaced with specific values in the actual request. For example, username in the input parameter can be configured as ${username}, and token in the output parameter can be configured as ${token}. In step c, the common parameters configured through the YAML file include parameter names and parameter values. Among them, the parameter name is the name of the variable, such as username, token, etc. The parameter value is the specific value of the variable, such as user123, abc123, etc. These parameter names and parameter values are used to dynamically replace the variables in the format of ${variable} in the interface configuration file.
[0069] Step d, after completing the above configuration, the privilege escalation test system automatically assembles the parameters. Specifically: the privilege escalation test system obtains the authentication information corresponding to the permissions through different account passwords and stores them in the cache. According to the interface parameters in step b, it automatically assembles the message header, input parameters, etc.
[0070] In step e, the unauthorized test system uses account information with different permissions to initiate access requests to the interface to be tested and obtain response data.
[0071] S102, reconstructing the response data based on a preset response data format to obtain reconstructed data.
[0072] The preset response data may be in the form of an image or text.
[0073] The reconstructed data includes text reconstruction data or image reconstruction data.
[0074] The above reconstruction process involves converting the actual response data obtained from the interface into a predefined format. For example, if the format of the response data is JSON type, the response data of JSON type is converted into text form to obtain text reconstruction data. For example, if the format of the response data is picture type, the response data of picture type is converted into image form to obtain image reconstruction data.
[0075] Optionally, the response data may be reconstructed using a decoder to obtain reconstructed data.
[0076] S103, comparing the reconstructed data with the preset response data to determine a data error.
[0077] The data error can be determined in the following manner.
[0078] Method 1: compare each field of the reconstructed data with the preset response data one by one to check whether there is any difference.
[0079] Method 2: Use a hash algorithm to generate a hash value for the data and compare the hash values to determine whether the data is consistent.
[0080] Method 3, calculates the similarity between the reconstructed data and the preset response data, such as cosine similarity, Jaccard similarity, etc., quantifies the similarity between the data, and determines the data error.
[0081] Method 4: Use image processing technology (such as structural similarity index, perceptual hash algorithm, etc.) to compare the similarity of images.
[0082] Method 5: Use machine learning models (such as classifiers, clustering algorithms, etc.) to identify anomalies or inconsistencies in the data.
[0083] In the embodiments of the present application, image processing technology, machine learning models and other methods can be used to determine the results of unauthorized testing, thereby enhancing the effectiveness and adaptability of unauthorized detection. This method not only relies on predefined rules, but also uses machine learning algorithms to identify and determine unauthorized behavior, thereby providing a more convenient and accurate detection method.
[0084] S104, determine the unauthorized test result based on the data error.
[0085] In an embodiment of the present application, if the data error is greater than a preset data error threshold, it is determined that the unauthorized test result is an unauthorized act. If the data error is less than or equal to the preset data error threshold, it is determined that the unauthorized test result is a non-unauthorized act.
[0086] Among them, the preset data error threshold is a quantitative standard used in the unauthorized test system to determine whether an unauthorized act has occurred. It is a predefined value representing the maximum acceptable error range. If the data error between the reconstructed data and the preset response data exceeds this threshold, it is determined that an unauthorized act has occurred, that is, a low-privilege user has accessed high-privilege data. On the contrary, if the data error is less than or equal to this threshold, it is determined as a non-unauthorized act.
[0087] Among them, the definition of the preset data error threshold needs to consider multiple factors, including the type of data, the complexity of the test scenario, business requirements, and the sensitivity to security, etc.
[0088] Among them, the unauthorized test result can be determined and an unauthorized test report can be generated. The unauthorized test report is a more formal document that details the process, method, discovered unauthorized acts, unauthorized test results, and any reasons for failure of the unauthorized test. The unauthorized test report can include input parameters, output parameters, return values of accounts with different privileges, unauthorized test results, reasons for test failure, suggestions, and fixes. The unauthorized test report can be in the Comma-Separated Values (CSV) format for easy recording and analysis. At the same time, it is necessary to log all interface call records and error information details.
[0089] In the embodiment of the present application, by successively using accounts with different privileges to initiate access requests to the interface to be tested and obtaining response data, the behavior of the interface under different privileges can be comprehensively detected, ensuring that the test covers multiple privilege scenarios and improving the accuracy of detecting unauthorized acts. Reconstructing the response data based on the form of the preset response data and comparing the reconstructed data with the preset response data to calculate the data error can quantify the difference between the interface return data and the expected data, thereby more accurately determining whether there is an unauthorized act. In addition, this method can automatically perform unauthorized tests, reducing manual intervention, improving test efficiency, and saving test time and resources.
[0090] In an optional embodiment, as Figure 2 shown, it is a schematic flowchart of the detailed steps of S102 for reconstructing the response data based on the form of the preset response data to obtain the reconstructed data.
[0091] S1021, obtain the data type of the response data.
[0092] Among them, the data type of the response data includes text type, file type, JSON type, XML type or image type.
[0093] Among them, the data type of the response data can be determined by the Content-Type field in the returned HTTP header.
[0094] S1022, reconstruct the response data based on the form of the preset response data and the data type of the response data to obtain the reconstructed data.
[0095] In the embodiments of the present application, if the data type of the response data is any one of the text type, file type, JSON type, and XML type, and the form of the preset response data is text form, then feature extraction and conversion are performed on the response data to obtain a text feature vector, and then the text feature vector is reconstructed to obtain the text reconstruction data. If the data type of the response data is the image type, and the form of the preset response data is image form, then feature extraction and conversion are performed on the response data to obtain an image feature vector, and then the image feature vector is reconstructed to obtain the image reconstruction data.
[0096] Generally, the data type of the response data and the form of the preset response data should be consistent.
[0097] Optionally, performing feature extraction and conversion on the response data to obtain a text feature vector includes the following situations.
[0098] Situation 1, if the data type of the response data is the text type, then perform text feature extraction on the response data to obtain the text feature vector. Among them, methods such as word embedding can be used for text feature extraction.
[0099] Situation 2, if the data type of the response data is the JSON type, then parse the response data, extract key-value pairs, and convert the key-value pairs into the text feature vector. Specifically: for the response data of the JSON type, parse the JSON-formatted string into an operable data structure, such as a dictionary in Python. Extract all the keys (parameter names) and values (parameter values) from the parsed data structure, form key-value pairs (parameter name: parameter value), arrange these key-value pairs in a certain format to form a text format that is easy to read and process, and further obtain the text feature vector. The advantage of doing this is that the data can be simplified and made easier to compare and analyze.
[0100] In Case 3, if the data type of the response data is the XML type, parse the response data, extract tags and attributes, and convert the tags and attributes into the text feature vector. Specifically: Use an XML parser to convert the XML document into a tree structure, traverse the tree structure and obtain the values of specific tags and attributes. Convert the extracted tag-attributes into text format, and apply text feature extraction techniques such as word embedding to the data in the converted text format to obtain a text feature vector that can be used for comparison.
[0101] In Case 4, if the data type of the response data is the file type, open the response data, read the data in the file, and obtain the text feature vector based on the data type of the data in the file.
[0102] Among them, opening the response data and reading the data in the file includes: Reading a CSV file based on the pandas library, based on the standard file operation methods in Python, etc. Among them, the data in the file can be of JSON type, XML type or text type. If the data in the file is of JSON type, the method in Case 2 is used to obtain the text feature vector. If the data in the file is of XML type, the method in Case 3 is used to obtain the text feature vector. If the data in the file is of text type, the method in Case 1 is used to obtain the text feature vector.
[0103] Generally speaking, the data type of the response data is mostly non-text types such as JSON, so all response data except for the picture type can be assembled and processed into text type. This text type is a pure text type.
[0104] In the embodiments of the present application, the forms of different response data are inconsistent and need to be converted. To ensure data consistency, so as to facilitate effective comparison and analysis. The purpose of the conversion is to make all types of response data be able to adapt to the preset response data format in the over-privilege test, and then perform accurate over-privilege detection.
[0105] In an optional embodiment, aiming at the limitations existing in the traditional over-privilege test, the present application designs a single or combined over-privilege test result determination method, aiming to provide a more convenient and accurate method to detect and determine over-privilege behaviors. Specifically, determine the over-privilege test result based on any combination of the following over-privilege test judgment conditions.
[0106] Over-privilege test judgment condition ①: Determine the over-privilege test result based on the data error.
[0107] Over-privilege test judgment condition ②: Determine the over-privilege test result based on whether the response data contains preset parameters.
[0108] Over - authority test judgment condition ③: Determine the over - authority test result based on the preset parameters included in the response data and the weight factors of the preset parameters.
[0109] Over - authority test judgment condition ④: Determine the over - authority test result by pairwise comparing whether the return values of different - permission accounts are exactly the same.
[0110] Among them, for over - authority test judgment condition ①, calculate the data error between the actual response data and the preset response data, such as using indicators like mean - square error, cosine similarity, etc. If the data error exceeds the preset data - error threshold, it is determined as an over - authority behavior.
[0111] For over - authority test judgment condition ②, check whether the response data contains preset parameters, which may be key business identifiers or security marks. If the response data contains these preset parameters, it may indicate that a low - permission user has accessed high - permission data, thus determining it as an over - authority behavior.
[0112] For over - authority test judgment condition ③, based on the preset parameters and their weight factors, not only check whether the response data contains the preset parameters, but also consider the weight factors of these parameters to reflect their importance or influence. By calculating the weighted value of the included preset parameters (i.e., multiplying by its weight factor when the parameter exists), if the total weighted value exceeds a certain threshold, it is determined as an over - authority behavior. This method can more finely control which parameters have a greater impact on over - authority determination.
[0113] For over - authority test judgment condition ④, determine whether there is an over - authority behavior by pairwise comparing whether the return values of different - permission accounts are exactly the same. If the return values are exactly the same, it is determined as an over - authority behavior.
[0114] Among them, according to different test scenarios and requirements, single or combined judgment conditions can be flexibly selected. By combining multiple judgment conditions, the existence of over - authority behavior can be evaluated from multiple perspectives, improving the accuracy of determination.
[0115] Among them, for the combined over - authority result determination method, the over - authority behavior can be determined in the following two ways:
[0116] Configured hit count: Set a threshold. If the number of over - authority test judgment conditions hit exceeds this threshold, it is determined that the interface has over - authority.
[0117] Configure weight settings: Set weights for each over - privilege test judgment condition. If an over - privilege test judgment condition is met, it is recorded as 1; if not, it is recorded as 0. For example, if over - privilege test judgment condition ① is met, over - privilege test judgment condition ② is not met, over - privilege test judgment condition ③ is met, and over - privilege test judgment condition ④ is not met, the total weight calculation formula is: Total weight = 1 * weight of ①+0 * weight of ② + 1 * weight of ③+0 * weight of ④. If the total weight is greater than or equal to the preset threshold, the overall result is met, indicating that there is an over - privilege risk for this interface.
[0118] Among them, multiple thresholds are mentioned above. For each threshold, it can be set and adjusted according to actual needs.
[0119] In the embodiments of this application, through the combined application of multiple criterion conditions (which can also be called algorithms), potential over - privilege behaviors can be evaluated from different perspectives, reducing errors caused by misjudgment or missed judgment of a single condition. By setting weights for over - privilege test judgment conditions and configuring the number of hit conditions, the decision - making process of over - privilege determination can be more finely controlled, enhancing the reliability of the results. By comprehensively considering multiple over - privilege test judgment conditions and setting reasonable thresholds, false positives (wrongly judging over - privilege behaviors) and false negatives (failing to identify real over - privilege behaviors) can be effectively reduced.
[0120] It should be understood that the magnitudes of the sequence numbers of the steps in the above embodiments do not mean the order of execution. The execution order of each process should be determined according to its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of this application.
[0121] Corresponding to the over - privilege test method described in the above embodiments, Figure 3 The structural block diagram of the over - privilege test system provided by the embodiments of this application is shown. For the sake of convenience of description, only the parts related to the embodiments of this application are shown.
[0122] Refer to Figure 3 , the over - privilege test system includes:
[0123] An acquisition module, configured to initiate access requests to the interface to be tested in sequence using accounts with different permissions and obtain response data;
[0124] A reconstruction module, configured to reconstruct the response data based on the form of preset response data to obtain reconstructed data;
[0125] A comparison module, configured to compare the reconstructed data with the preset response data to determine the data error;
[0126] A determination module, configured to determine the over - privilege test result based on the data error.
[0127] In a possible implementation manner, the reconstruction module is configured to:
[0128] Obtain the data type of the response data;
[0129] Reconstruct the response data based on the form of the preset response data and the data type of the response data to obtain the reconstructed data.
[0130] In a possible implementation manner, the reconstruction module is used for:
[0131] If the data type of the response data is any one of the text type, file type, JSON type, and XML type, and the form of the preset response data is the text form, perform feature extraction and conversion on the response data to obtain a text feature vector;
[0132] Reconstruct the text feature vector to obtain the text reconstruction data;
[0133] If the data type of the response data is the picture type, and the form of the preset response data is the image form, perform feature extraction and conversion on the response data to obtain an image feature vector;
[0134] Reconstruct the image feature vector to obtain the image reconstruction data.
[0135] In a possible implementation manner, the reconstruction module is used for:
[0136] If the data type of the response data is the text type, perform text feature extraction on the response data to obtain the text feature vector;
[0137] If the data type of the response data is the JSON type, parse the response data, extract key-value pairs, and convert the key-value pairs into the text feature vector;
[0138] If the data type of the response data is the XML type, parse the response data, extract tags and attributes, and convert the tags and attributes into the text feature vector;
[0139] If the data type of the response data is the file type, open the response data, read the data in the file, and obtain the text feature vector based on the data type of the data in the file.
[0140] In a possible implementation manner, the determination module is used for:
[0141] If the data error is greater than the preset data error threshold, determine that the over-authorization test result is an over-authorization behavior;
[0142] If the data error is less than or equal to the preset data error threshold, it is determined that the unauthorized test result is a non-unauthorized behavior.
[0143] In a possible implementation, the determining module is further configured to:
[0144] Determine the unauthorized test result based on any combination of the following unauthorized test judgment conditions;
[0145] Unauthorized test judgment condition 1: Determine the unauthorized test result based on the data error;
[0146] Unauthorized test judgment condition 2: Determine the unauthorized test result based on whether the response data contains a preset parameter;
[0147] Unauthorized test judgment condition 3: Determine the unauthorized test result based on the preset parameter included in the response data and the weight factor of the preset parameter.
[0148] It should be noted that for the information interaction, execution process, etc. between the above modules, since they are based on the same concept as the method embodiments of the present application, their specific functions and the technical effects brought about can be specifically referred to in the method embodiment part, and will not be elaborated here.
[0149] Those skilled in the art can clearly understand that for the convenience and simplicity of description, only the above division of each functional unit and module is used as an example. In actual applications, the above functions can be allocated to different functional units and modules according to needs, that is, the internal structure of the device is divided into different functional units or modules to complete all or part of the functions described above. Each functional unit and module in the embodiment can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above integrated unit can be implemented in the form of hardware or in the form of a software functional unit. In addition, the specific names of the functional units and modules are only for the convenience of mutual distinction and do not limit the protection scope of the present application. The specific working process of the units and modules in the above system can refer to the corresponding process in the foregoing method embodiments and will not be elaborated here.
[0150] The embodiment of the present application further provides a computer device, which includes: at least one processor, a memory, and a computer program stored in the memory and executable on the at least one processor. When the processor executes the computer program, the steps in any of the foregoing method embodiments are implemented.
[0151] The embodiment of the present application also provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, the steps in the above-mentioned method embodiments can be implemented.
[0152] The embodiment of the present application provides a computer program product. When the computer program product runs on a computer device, the computer device can implement the steps in the above-mentioned method embodiments when executed.
[0153] Figure 4 It is a schematic structural diagram of a computer device provided by an embodiment of the present application. As Figure 4 shown, the computer device in this embodiment includes: at least one processor 20 ( Figure 4 only one is shown in the figure), a memory 21, and a computer program 22 stored in the memory 21 and executable on the at least one processor 20. When the processor 20 executes the computer program 22, the steps in any of the above-mentioned privilege escalation test method embodiments can be implemented.
[0154] The computer device may include, but is not limited to, a processor 20 and a memory 21. Those skilled in the art can understand that Figure 4 this is only an example of a computer device and does not constitute a limitation on the computer device. It may include more or fewer components than shown in the figure, or combine certain components, or different components. For example, it may also include input / output devices, network access devices, etc.
[0155] The so-called processor 20 may be a central processing unit (CPU). The processor 20 may also be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.
[0156] In some embodiments, the memory 21 may be an internal storage unit of the computer device, such as a hard disk or memory of the computer device. In other embodiments, the memory 21 may also be an external storage device of the computer device, such as a plug-in hard disk, a Smart Media Card (SMC), a Secure Digital (SD) card, a Flash Card, etc. equipped on the computer device. Further, the memory 21 may also include both the internal storage unit and the external storage device of the computer device. The memory 21 is used to store an operating system, application programs, a BootLoader, data, and other programs, such as program codes of the computer program. The memory 21 may also be used to temporarily store data that has been output or is to be output.
[0157] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, to implement all or part of the processes in the above-described embodiment methods of the present application, a computer program can be used to instruct relevant hardware to complete. The computer program can be stored in a computer-readable storage medium. When the computer program is executed by a processor, the steps of the above-described method embodiments can be implemented. Among them, the computer program includes computer program code, and the computer program code can be in the form of source code, object code, an executable file, or some intermediate form, etc. The computer-readable medium can at least include: any entity or device that can carry the computer program code to the device / computer device, a recording medium, a computer memory, a read-only memory (ROM), a random access memory (RAM), an electrical carrier signal, a telecommunication signal, and a software distribution medium. For example, a USB flash drive, a mobile hard disk, a magnetic disk, or an optical disc, etc. In some jurisdictions, according to legislation and patent practice, the computer-readable medium cannot be an electrical carrier signal and a telecommunication signal.
[0158] In the above embodiments, the descriptions of the various embodiments have their own focuses. For parts not detailed or recorded in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0159] Those of ordinary skill in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods for each specific application to implement the described functions, but such implementation should not be considered to exceed the scope of this application.
[0160] In the embodiments provided in this application, it should be understood that the disclosed device / computer equipment and method can be implemented in other ways. For example, the device / computer equipment embodiments described above are only illustrative. For example, the division of the modules or units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection between each other can be through some interfaces. The indirect coupling or communication connection of the device or unit can be in an electrical, mechanical or other form.
[0161] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place, or can be distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0162] The above-described embodiments are only used to illustrate the technical solutions of this application, rather than to limit them; although this application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application, and should all be included in the protection scope of this application.
Claims
1. An unauthorized testing method, characterized in that: include: Use accounts with different permissions to initiate access requests to the interface to be tested and obtain response data; Reconstructing the response data based on a preset response data format to obtain reconstructed data; Comparing the reconstructed data with the preset response data to determine a data error; An override test result is determined based on the data error.
2. The unauthorized testing method according to claim 1, characterized in that: The step of reconstructing the response data based on the preset response data to obtain the reconstructed data includes: Get the data type of the response data; Based on the preset response data format and the data type of the response data, the response data is reconstructed to obtain the reconstructed data.
3. The unauthorized testing method according to claim 2, characterized in that: The form of the preset response data includes an image form or a text form; the data type of the response data includes a text type, a file type, a JSON type, an XML type or a picture type; the reconstructed data includes text reconstructed data or image reconstructed data; The reconstructing the response data based on the preset response data format and the data type of the response data to obtain the reconstructed data includes: If the data type of the response data is any one of the text type, file type, JSON type, and XML type, and the format of the preset response data is text format, then feature extraction and conversion are performed on the response data to obtain a text feature vector; Reconstructing the text feature vector to obtain the text reconstruction data; If the data type of the response data is the picture type, and the format of the preset response data is an image format, performing feature extraction and conversion on the response data to obtain an image feature vector; The image feature vector is reconstructed to obtain the image reconstruction data.
4. The unauthorized testing method according to claim 3, characterized in that: The feature extraction and conversion of the response data to obtain a text feature vector includes: If the data type of the response data is the text type, performing text feature extraction on the response data to obtain the text feature vector; If the data type of the response data is the JSON type, parsing the response data, extracting key-value pairs, and converting the key-value pairs into the text feature vector; If the data type of the response data is the XML type, parsing the response data, extracting tags and attributes, and converting the tags and attributes into the text feature vector; If the data type of the response data is the file type, the response data is opened, the data in the file is read, and the text feature vector is obtained based on the data type of the data in the file.
5. The unauthorized testing method according to any one of claims 1 to 4, characterized in that: The determining of the over-authorization test result based on the data error comprises: If the data error is greater than a preset data error threshold, determining that the unauthorized test result is an unauthorized behavior; If the data error is less than or equal to the preset data error threshold, the unauthorized test result is determined to be a non-unauthorized behavior.
6. The unauthorized testing method according to any one of claims 1 to 4, characterized in that: The method further comprises: Determine the unauthorized test result based on any combination of the following unauthorized test judgment conditions; Unauthorized test judgment condition 1: determining the unauthorized test result based on the data error; Unauthorized test judgment condition 2: determining the unauthorized test result based on whether the response data contains preset parameters; Unauthorized test judgment condition three: determining the unauthorized test result based on the preset parameters included in the response data and the weight factors of the preset parameters.
7. An unauthorized testing system, characterized in that: include: The acquisition module is used to use accounts with different permissions to initiate access requests to the interface to be tested and obtain response data; A reconstruction module, used to reconstruct the response data based on a preset response data format to obtain reconstructed data; A comparison module, used for comparing the reconstructed data with the preset response data to determine a data error; A determination module is used to determine an unauthorized test result based on the data error.
8. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the method according to any one of claims 1 to 6 is implemented.
9. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the method according to any one of claims 1 to 6 is implemented.
10. A computer program product, characterized in that When the computer program product is executed on a computer device, the computer device is caused to execute the method according to any one of claims 1 to 6.