Restful API fuzz testing method and system based on tree structure generation parameters
Through the tree structure-based generation method, the limitations of the existing Restful API fuzz testing method when dealing with complex parameter structures are solved, and efficient processing and comprehensive testing of complex parameter structures are realized.
Patent Information
- Application Number
- CN202510559169.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-30
- Publication Date
- 2025-06-03
- Estimated Expiration
- 2045-04-30
AI Technical Summary
The existing Restful API fuzz testing methods have limitations when dealing with complex parameter structures, and it is difficult to effectively cover complex nested parameter structures and parameter dependencies, resulting in limited testing depth and breadth.
The parameter generation method based on the tree structure is adopted, and by obtaining Restful API document data and parsing and identifying, a request sequence is generated, a parameter tree is constructed, parameter values are calculated through parameter value generation functions, and parameter structure variation is performed to generate a parameter tree with rich parameter variants, and finally request and verification are performed, and vulnerability reports are output.
It realizes efficient processing of complex parameter structures, especially suitable for nested data structures and complex parameter dependencies, improves the depth and breadth of Restful API fuzz testing, and ensures comprehensive and efficient testing.
Smart Images

Figure CN120086108A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of Web security technology, and in particular, to a method and system for fuzz testing Restful APIs based on generating parameters using a tree structure. Background Art
[0002] As a simple and efficient communication protocol, Restful API has become a widely used standard interface in modern Web services. With the increase in application complexity, more and more security risks have emerged in Restful APIs. To address these security risks, fuzz testing, as an effective security testing technology, has been widely applied. Existing Restful API fuzz testing methods usually perform tests by randomly mutating the parameters in Restful API requests. However, these methods have some limitations in practical applications. On the one hand, many security vulnerabilities are not only reflected in parameter values. Different changes in parameter structures may also lead to different system behaviors and even expose security vulnerabilities. Existing Restful API fuzz testing methods mainly rely on randomly mutating the values of request parameters to simulate possible attack scenarios by changing the input values. However, this method is usually limited to simple random mutations of parameter values and fails to fully consider the structural characteristics of request parameters. For complex nested parameter structures, simple mutation methods only targeting parameter values are difficult to effectively cover, resulting in limited depth and breadth of Restful API fuzz testing. On the other hand, existing Restful API fuzz testing methods can usually only handle simple parameter structures. For parameters with multi-level nesting or complex dependencies (such as nested JSON objects, arrays, or Base64-encoded data, etc.), these methods are often difficult to effectively identify and mutate complex parameter structures, ignoring issues such as dependencies between parameters and encoding conversions. This makes it impossible to timely discover and effectively detect some vulnerabilities involving deep parameter dependencies, nested data structures, or special encoding methods. Summary of the Invention
[0003] To solve the above technical problems, the object of the present invention is to provide a method and system for fuzz testing Restful APIs based on generating parameters using a tree structure, which can efficiently handle complex parameter structures, especially suitable for nested data structures and complex parameter dependencies, thereby achieving comprehensive and efficient fuzz testing of Restful APIs.
[0004] The first technical solution adopted by the present invention is: A method for fuzz testing Restful APIs based on generating parameters using a tree structure, comprising the following steps: Obtain Restful API document data and perform parsing and recognition processing to generate a Restful API request sequence; Map the request parameters in the Restful API request sequence, construct a parameter tree, where the nodes of the parameter tree represent the respective parameters in the Restful API request, and the edges of the parameter tree represent the parent-child relationships between the parameters; Calculate the parameter values of the nodes in the parameter tree through a parameter value generation function to obtain the parameter values of the parameter tree nodes; Perform parameter structure mutation based on the parameter tree node parameter values to obtain a parameter tree with rich parameter variants, where the parameter structure mutation includes tree structure mutation and tree node mutation; Perform requests and validations on the parameter tree with rich parameter variants, output a vulnerability report, and complete the fuzz testing of the Restful API.
[0005] Furthermore, the step of obtaining the Restful API document data and performing parsing and recognition processing to generate a Restful API request sequence specifically includes: Obtain the Restful API document data, where the Restful API document data includes the definition information of the Restful API interfaces; Perform recognition processing on the definition information of the Restful API interfaces to obtain the components of the Restful API request, where the components of the Restful API request include the request method, request path, request parameters, and the constraint conditions corresponding to the request parameters; Parse according to the components of the Restful API request and the corresponding Restful API request operations to obtain the dependency relationship between the Restful API operations and the parameters; Generate a Restful API request sequence according to the dependency relationship between the Restful API operations and the parameters.
[0006] Furthermore, the step of mapping the request parameters in the Restful API request sequence and constructing a parameter tree specifically includes: Standardize the format of the request parameters in the Restful API request sequence through the StandardizeData function to obtain request parameters in a unified format; Initialize an empty parameter tree and call the ParseNode function to parse according to the data types of the request parameters in the unified format; If the current node represents a complex data type, add it as a child node to the parameter tree. If the current node represents a basic data type, directly extract its value and store it in the node, and then set the node attributes to construct the root node of the parameter tree; Recursively decode the root node of the parameter tree through the RecursiveDecode function; If the value of the target node is nested structured data, it is decoded and parsed into subtrees to build a parameter tree.
[0007] Furthermore, the expression of the parameter tree is specifically as follows:
[0008] In the above formula, Represents the parameter tree, Represents the set of all nodes in the parameter tree, represents the set of all edges in the parameter tree, A data type set representing a parameter tree, used to provide a type basis for parameter generation and mutation rules. The data type function representing the parameter tree is used to identify the value type of the node and its structural characteristics. Represents a collection of high-value parameters in a parameter tree, used to identify parameter nodes with higher value or priority in vulnerability detection.
[0009] Furthermore, the nodes of the parameter tree are formally defined as seven-tuples, and their expressions are specifically as follows:
[0010] In the above formula, represents a node of the parameter tree, Represents an identifier, Indicates the data type of the node, Indicates the direct parent node of the current node. Represents the direct child node set of the current node. Indicates that the value of the node provides additional constraints. Indicates the encoding method of the node value. Represents the actual value stored in the node.
[0011] Furthermore, the expression of the parameter value generating function is:
[0012] In the above formula, represents the parameter value generating function, Represents a collection of data types. represents a set of node constraints, represents a set of parameter generation strategies, which includes static mapping, random strategy, example strategy based on specification document, dynamic strategy learned from previous response, reuse strategy learned from previous request and strategy based on predefined attack payload, Represents the set of possible generated parameter values.
[0013] Further, the step of performing parameter structure mutation based on the parameter values of the parameter tree nodes to obtain a parameter tree with rich parameter variants specifically includes: Based on the parameter values of the parameter tree nodes, perform tree structure mutation on the parameter tree to obtain parameter trees with different structural characteristics. The tree structure mutation includes single-node mutation, path mutation, and global mutation; Perform tree node mutation on the parameter trees with different structural characteristics to obtain a parameter tree with rich parameter variants. The tree node mutation includes deletion, retention, copying, and type change.
[0014] Further, the step of making requests and validating the parameter tree with rich parameter variants, outputting a vulnerability report, and completing the fuzz testing of the Restful API specifically includes: Construct an HTTP request through an HTTP client library and send it to the parameter tree with rich parameter variants, receive and store the response information of each request. The response information includes the HTTP status code, response headers, and response body; Analyze the response information of each request, identify abnormal response patterns, and detect potential security vulnerabilities based on preset security rules, output a vulnerability report, and complete the fuzz testing of the Restful API.
[0015] The second technical solution adopted by the present invention is: a Restful API fuzz testing system for generating parameters based on a tree structure, including: The first module is used to obtain Restful API document data and perform parsing and recognition processing to generate a Restful API request sequence; The second module is used to perform mapping processing on the request parameters in the Restful API request sequence to construct a parameter tree. The nodes of the parameter tree represent the respective parameters in the Restful API request, and the edges of the parameter tree represent the parent-child relationships between the parameters; The third module is used to calculate the parameter values of the nodes in the parameter tree through a parameter value generation function to obtain the parameter values of the parameter tree nodes; The fourth module is used to perform parameter structure mutation based on the parameter values of the parameter tree nodes to obtain a parameter tree with rich parameter variants. The parameter structure mutation includes tree structure mutation and tree node mutation; The fifth module is used to make requests and validate the parameter tree with rich parameter variants, output a vulnerability report, and complete the fuzz testing of the Restful API.
[0016] The beneficial effects of the method and system of the present invention are as follows: By obtaining and parsing and identifying Restful API document data, the present invention generates a Restful API request sequence, further performs mapping processing on the request parameters in the Restful API request sequence, constructs a parameter tree, maps complex request parameters into a tree structure, and effectively identifies the data relationships and dependencies at each level through recursive parsing. The parameter values of the nodes in the parameter tree are calculated through a parameter value generation function to obtain the parameter values of the parameter tree nodes. Furthermore, parameter structure mutation is performed based on the parameter values of the parameter tree nodes to obtain a parameter tree with rich parameter variants, realizing systematic mutation processing of the parameter structure. It can not only mutate a single parameter value but also flexibly adjust the hierarchical structure of the parameters. Finally, requests and validations are performed on the parameter tree with rich parameter variants, and a vulnerability report is output, which can efficiently process complex parameter structures, especially suitable for nested data structures and complex parameter dependency relationships, thereby realizing comprehensive and efficient Restful API fuzz testing. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] Figure 1 is a flowchart of the steps of a Restful API fuzz testing method based on tree structure parameter generation according to the present invention; Figure 2 is a block diagram of the structure of a Restful API fuzz testing system based on tree structure parameter generation according to the present invention; Figure 3 is a schematic diagram of the framework of Restful API fuzz testing provided by a specific embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0018] The present invention will be further described in detail below with reference to the drawings and specific embodiments. For the step numbers in the following embodiments, they are only set for the convenience of description and explanation, and no limitation is imposed on the order between the steps. The execution order of each step in the embodiments can be adaptively adjusted according to the understanding of those skilled in the art.
[0019] First of all, it should be noted that as a simple and efficient communication protocol, the Restful API has become a widely used standard interface in modern web services. Its design concept is centered around resources, emphasizing statelessness and unified interfaces, enabling different systems to interact efficiently through the HTTP protocol. Due to this flexibility and scalability, the Restful API is widely used in various Internet services and platforms, including but not limited to e-commerce, social networks, fintech, and the Internet of Things, etc., and has become an important tool for promoting digital transformation. However, with the increase in application complexity, more and more security risks have emerged in the Restful API. Especially in aspects such as identity authentication, input validation, and access control of the Restful API, there are still relatively large security risks, which may lead to serious consequences such as unauthorized access, sensitive data leakage, and service interruption. To address these security risks, fuzz testing, as an effective security testing technology, is widely used. Fuzz testing helps identify vulnerabilities that may occur in the system under abnormal inputs by inputting a large amount of random or malformed data into the target Restful API interface and simulating the input data formats that attackers may exploit.
[0020] Based on this, the embodiments of the present invention first parse and identify the Restful API document data, then generate a request sequence, construct a parameter tree for the generated requests, further generate parameter values according to the tree structure and mutate the parameter structure according to the tree structure, and finally send requests, collect response information, and output a vulnerability report. By adopting the method of generating parameters based on the tree structure, it can effectively solve the limitations of the existing Restful API fuzz testing methods in dealing with complex parameter structures, especially the general limitation to the mutation of parameter values, resulting in low test efficiency and limited coverage; in addition, the embodiments of the present invention can also support the generation and mutation of parameters with complex nested data structures through recursive parsing and mutation processing, thereby improving the detection efficiency and effectiveness of Restful API fuzz testing.
[0021] Refer to Figure 1 , the present invention provides a Restful API fuzz testing method based on generating parameters with a tree structure, and this method includes the following steps: S100. Obtain the Restful API document data and perform parsing and identification processing to generate a Restful API document data request sequence; S110. Obtain the Restful API document data, and the Restful API document data includes the definition information of the Restful API interface; Specifically, receive the input Restful API document data, which is usually in the OpenAPI or other similar formats. This document data contains the definition information of the Restful API interfaces, such as the request method, request path, request parameters and their data types, format requirements, etc.
[0022] S120. Identify and process the definition information of the Restful API interfaces to obtain the components of the Restful API requests. The components of the Restful API requests include the request method, request path, request parameters, and the corresponding constraint conditions of the request parameters. Specifically, identify each component of the Restful API requests, including the request method (such as GET, POST, etc.), request path, and the parameters required for each request. In this process, not only the type of each parameter (such as string, integer, boolean, etc.) needs to be identified, but also the constraint conditions of each parameter need to be extracted, such as the value range, whether it is a required parameter, format requirements, etc.
[0023] S130. Parse according to the components of the Restful API requests and the corresponding Restful API request operations to obtain the dependency relationship between the Restful API operations and the parameters. Specifically, identify the dependency relationship between the Restful API operations and the parameters, especially the mutual dependency between some parameters. For example, the existence of some parameters may depend on the values of other parameters. This information will provide a necessary basis for subsequent request generation and mutation processing.
[0024] S140. Generate a Restful API request sequence according to the dependency relationship between the Restful API operations and the parameters.
[0025] In this embodiment, after parsing and identifying the Restful API document data, a request sequence is generated based on the operations of the Restful API interfaces and the dependency relationship of their parameters. The requests in each request sequence are arranged in the order of the Restful API operations. Each request contains the interface operation and the corresponding parameter information, ensuring that the filling of the parameters meets the specification requirements and considering the dependency relationship between the parameters. For example, if some parameters depend on the values of other parameters, ensure that these dependency conditions are met first when generating the requests.
[0026] S200. Map the request parameters in the Restful API request sequence, construct a parameter tree, where the nodes of the parameter tree represent the respective parameters in the Restful API request, and the edges of the parameter tree represent the parent-child relationships between the parameters; Specifically, perform format standardization processing on the input data requestData through the StandardizeData function to obtain request parameters in a unified format; initialize an empty parameter tree, and call the ParseNode function to parse according to the data type of the request parameters in the unified format; if the current node represents a complex data type, add it as a child node to the parameter tree, if the current node represents a basic data type, directly extract its value and store it in the node, and then set the node attributes to construct the root node of the parameter tree; perform recursive decoding on the root node of the parameter tree through the RecursiveDecode function; if the value of the target node is nested structured data, perform decoding and parse it into a subtree to construct the parameter tree.
[0027] First of all, it should be noted that in the embodiments of the present invention, the request parameters will be mapped to a parameter tree. The nodes of this parameter tree represent the respective parameters in the Restful API request, while the edges of the parameter tree represent the parent-child relationships between the parameters. This parameter tree structure facilitates flexible operations in the subsequent mutation stage and can clearly show the hierarchical relationships between the parameters.
[0028] The nodes of the parameter tree are divided into non-leaf nodes and leaf nodes. Among them, the object and array types are non-leaf nodes, and the fields of the basic data types (such as string, boolean, integer) are leaf nodes. Based on this, the formal definition of the parameter tree is:
[0029] Among them, the node set represents all the nodes in the parameter tree. Each node corresponds to an attribute field or element in the request and constitutes the basic unit of the parameter; the edge set , where , each element in is an ordered pair , and both elements in the ordered pair belong to , represents that the node is the parent node of the node , and the node is the child node of the node ; the data type set contains the supported data type set, for example , provides a type basis for the generation and mutation rules of parameters; data type function maps each node to an element in the data type set ; that is , namely , where , is used to identify the value type and its structural characteristics of the node; high-value parameter set is used to identify parameter nodes with relatively high value or priority in vulnerability detection, that is , where is a boolean function used to determine whether the node is a high-value parameter. The high-value parameter set can be dynamically updated and adjusted according to actual needs.
[0030] Each node in the parameter tree is the basic unit that constitutes the tree structure. The formal definition of a node is a seven-tuple, and its expression is:
[0031] Among them, the identifier is used to uniquely identify the node, usually corresponding to the parameter name to distinguish different nodes; the type represents the data type of the node, and is mapped to a specific type in the data type set through the data type function ; the parent node represents the direct parent node of the current node. If it is the root node, its parent node is ; the set of child nodes represents the set of direct child nodes of the current node, which is applicable to composite data type nodes. For leaf nodes, this set is empty; the constraint condition represents providing additional restrictive conditions for the value of the node, used to define the valid range, length or format of the node value. For example, an integer node may have a value range, and a string node may be attached with a regular expression constraint; the encoding method represents the encoding method of the node value to handle parameters with complex multi-level nesting or dependencies. For example, processing parameters encoded in XML, JSON, Base64, etc., is often used for fields that need to be converted or nested; the node value represents the actual value stored in the node, usually applicable to leaf nodes, and the values of non-leaf nodes are usually empty or , because their role is only limited to organizing child nodes.
[0032] Further, in this embodiment, first, the algorithm receives the input data requestData and standardizes it into a unified format through the StandardizeData function (for example, converting the key-value pair form into the JSON form). Then, an empty parameter tree parameterTree is initialized, and the ParseNode function is called to start parsing the data, thereby constructing the root node of the tree. In the ParseNode function, each node is parsed according to the data type. If the current node is a complex data type (such as object or array), the algorithm recursively processes its child elements and adds them as child nodes to the parameter tree; if it is a basic data type (such as string, integer, etc.), its value is directly extracted and stored in the node. During this process, the algorithm also sets attributes for each node, including type, constraint conditions, encoding method, etc., and marks high-value parameters that may be of great significance in vulnerability detection through the IdentifyHighValueParams function. In addition, the algorithm uses the RecursiveDecode function to recursively decode each node in the parameter tree. If the value of a certain node is nested structured data (such as Base64-encoded JSON), the algorithm decodes it and further parses it into a subtree to ensure that the nested data can be correctly integrated into the parameter tree. Finally, the algorithm returns the constructed parameterTree, which contains all the parsed parameter nodes and their attributes and relationships.
[0033] S300. Calculate the parameter values of the nodes in the parameter tree through the parameter value generation function to obtain the parameter values of the parameter tree nodes; Specifically, generate parameter values according to the tree structure. In the embodiment of the present invention, through the constructed parameter tree , use the parameter value generation function to generate parameter values for each node, where represents the set of data types, represents the set of node constraint conditions, represents the set of possible generated parameter values, the set of parameter generation strategies .
[0034] It should be further noted that contains six parameter value generation strategies, specifically including: 1) Static mapping and the random strategy , through the static "type-value" mapping, map each data type to a fixed value. For example, a string is mapped to "fuzzstring", an integer is 0, a boolean value is false, and an array is . When the static mapping cannot meet the requirements, the random strategy is adopted , randomly generate parameter values according to parameter types and constraints (such as value ranges or regular expressions) to improve input diversity.
[0035] 2) Example policy based on specification document If example values, default values, or enumeration values are provided in the Restful API document data, these values are used first to assign parameter values. These values can usually improve the effectiveness and rationality of the request.
[0036] 3) Dynamic policies learned from previous responses , using parameter values extracted from previous responses, storing them in a resource pool and reusing responses of successful requests to ensure the dynamic adaptability of the test environment. This strategy is divided into conservative mode and aggressive mode, specifically: Conservative mode: This value is selected only when the path of the request where the target parameter is located completely matches the path in the resource pool. This mode reduces the risk of false matching and ensures the accuracy of the test. Aggressive mode only compares parameter names. As long as the parameter names match, the value in the resource pool is selected. This mode can expand test scenarios and increase flexibility and exploration scope.
[0037] 4) Reuse strategy learned from previous requests ,Previously successful requests and their parameter values will be stored in the resource pool and used first for subsequent request generation.,By moderately mutating the reused parameters, the diversity of,mutations can be increased and excessive repetition can be avoided.
[0038] 5) Based on predefined attack payload strategy , use the attack payload in the existing vulnerability testing library to replace or inject parameter values to detect the security performance of the Restful API when facing malicious input and help discover potential security vulnerabilities. (Its data type and constraints ), the resulting parameter value is ,in .
[0039] S400, performing parameter structure variation based on parameter values of parameter tree nodes to obtain a parameter tree with rich parameter variants, wherein the parameter structure variation includes tree structure variation and tree node variation; Specifically, according to the tree structure variation parameter structure, by adjusting the overall structure and local nodes of the parameter tree, a variety of possible input situations are simulated, and the variation rules of the parameter structure include tree structure variation and tree node variation.
[0040] S410. Based on the parameter values of the parameter tree nodes, perform tree structure mutation on the parameter tree to obtain parameter trees with different structural characteristics. The tree structure mutation includes single-node mutation, path mutation, and global mutation. In this embodiment, for the tree structure mutation, the structure mutation rules of the parameter tree are divided into three categories: single-node mutation, path mutation, and global mutation. Specifically: 1) Single-node mutation. Denote the single-node mutation as , which means modifying a single node in the tree while keeping the other nodes unchanged. This method is applicable to testing the impact of the change of a single parameter on the behavior of the Restful API. 2) Path mutation. Select a path in the parameter tree, and denote the path mutation as , that is, synchronously mutate all the nodes on the path to explore the impact of the combined changes of multi-level nodes on the overall request. 3) Global mutation. Apply the mutation rules to multiple nodes (possibly distributed on different paths) in the tree simultaneously, thereby generating parameter trees with completely different structures.
[0041] S420. Perform tree node mutation on the parameter trees with different structural characteristics to obtain parameter trees with rich parameter variants. The tree node mutation includes deletion, retention, replication, and type change.
[0042] In this embodiment, for the tree node mutation, for the expression of any node, , the node mutation rules of the parameter tree are divided into four categories: deletion, retention, replication, and type change. Specifically: 1) Deletion. Define the deletion operation as , which means completely removing the node and its subtree, simulating the situation of parameter absence.
[0043] 2) Retention. Define the retention operation as , where means only retaining some child nodes of and deleting other sibling nodes to test the processing ability when the input is minimized.
[0044] 3) Replication. The expression defining the replication operation is:
[0045] where is the replication of , indicating replicating the node and its subtree, simulating redundant data input, being a new identifier to ensure uniqueness.
[0046] 4) Type change. The expression defining the type change operation is:
[0047] where is the new data type, and is the function to convert the original value to the new type , indicating changing the data type of the node. For example, changing a string to an array or an object, and testing the response of the Restful API to data type mismatches.
[0048] In summary, by combining the use of tree structure mutation and tree node mutation rules, more abundant parameter variants can be obtained. For example, the parameter tree as a whole can be mutated by path or globally first to generate a set of parameter trees with different structural characteristics, and then local mutations such as deletion, retention, copying, or type change can be performed on key nodes to further refine the test cases.
[0049] S500. Send requests to the parameter tree with abundant parameter variants and verify, output a vulnerability report, and complete the fuzz testing of the Restful API.
[0050] S510. Construct an HTTP request through the HTTP client library and send it to the parameter tree with abundant parameter variants, receive and store the response information of each request. The response information includes the HTTP status code, response headers, and response body; In this embodiment, when sending a request, use the HTTP client library to construct an HTTP request, and send the request through the function to ensure the correctness and integrity of the request. It is formally represented as , where is the HTTP response object. Further collect the response information, receive and store the response information of each request, and define the received HTTP response object as , which includes the HTTP status code , response headers and response body . The storage operation is formally represented as .
[0051] S520. Analyze the response information of each request, identify abnormal response patterns, and detect potential security vulnerabilities based on preset security rules, output a vulnerability report, and complete the fuzz testing of the Restful API.
[0052] In this embodiment, output a vulnerability report, analyze the collected response information, identify abnormal response patterns, such as status code 500, abnormal error messages, etc., and detect potential security vulnerabilities based on predefined security rules, and finally generate a detailed vulnerability report , the content includes the vulnerability type , Vulnerability Description , Affected API operations and its request sequence , which makes it easier for developers to make subsequent repairs.
[0053] In summary, if Figure 3 As shown, the embodiment of the present invention parses the existing RESTful API document data, extracts the request method, request path, request parameters, request examples and other information, and then converts this information into a series of request sequences or request lists to provide input basis for subsequent parameter tree construction and mutation, and then performs tree-structured processing on the obtained request data, and generates a parameter tree through recursive parsing and standardization operations. Each tree node Carrying description information of the parameter, such as identifier ,type , parent node , child node collection , Constraints , encoding method , Node Value This module lays the data foundation for the subsequent parameter value generation and structural mutation. According to different test requirements, the system adopts a variety of parameter value strategies for each parameter node, including static mapping and random strategies, example strategies based on specification documents, dynamic strategies learned from previous responses, dynamic strategies learned from previous attacks, reuse strategies learned from previous requests, and strategies based on predefined attack payloads. Further, it is divided into tree structure mutation and tree node mutation. Tree structure mutation includes single node mutation, path mutation and global mutation; tree node mutation includes node deletion, retention, replication and type change. After completing the mutation operation, the system will use recursive encoding to re-inject the mutated parameter data into the request, and finally send the request generated or mutated by the above module to the server to execute the actual Restful API call. Subsequently, the response results are analyzed through corresponding vulnerability detection or verification means to identify possible security vulnerabilities or functional defects, and finally output vulnerability reports, realizing a Restful API fuzz testing system that efficiently constructs complex parameter structures, generates diversified parameter values and flexibly mutates parameter trees, thereby improving the coverage and detection efficiency of Restful API fuzz testing.
[0054] Therefore, compared with the prior art, the embodiments of the present invention have the following advantages: 1) By means of a recursive mutation method based on a tree structure, systematic mutation processing of the parameter structure is achieved. It can not only mutate a single parameter value but also flexibly adjust the hierarchical structure of the parameters. For example, in the present invention, diverse test cases are generated by modifying the nested levels of the parameters, dynamically adding or deleting nodes, adjusting the node order, etc. These mutation operations expand the coverage of Restful API fuzz testing from simple parameter values to in-depth adjustment of the parameter structure, effectively simulating and detecting potential vulnerabilities caused by improper parameter structures. Compared with traditional methods, the present invention not only focuses on the random mutation of parameter values but also attaches importance to the diversity of the parameter structure, enabling the Restful API fuzz testing method to effectively discover vulnerabilities in the face of more complex scenarios, thus improving the test coverage rate and vulnerability discovery efficiency.
[0055] 2) Through a parameter generation and recursive parsing method based on a tree structure, multi-level nested and complex parameter dependency relationships can be accurately processed. Specifically, in the present invention, complex request parameters are mapped into a tree structure, and the data relationships and dependencies at each level are effectively identified through recursive parsing. This method ensures that whether it is a simple flat structure or a complex multi-level nested structure, the hierarchy and relationships between parameters are correctly parsed and effectively mutated. The present invention greatly improves the depth and accuracy of Restful API fuzz testing, making the test more comprehensive.
[0056] Refer to Figure 2 , a Restful API fuzz testing system for generating parameters based on a tree structure, comprising: A first module 201, configured to obtain Restful API document data and perform parsing and recognition processing to generate a Restful API request sequence; A second module 202, configured to perform mapping processing on the request parameters in the Restful API request sequence to construct a parameter tree, where the nodes of the parameter tree represent each parameter in the Restful API request, and the edges of the parameter tree represent the parent-child relationships between the parameters; A third module 203, configured to calculate the parameter values of the nodes in the parameter tree through a parameter value generation function to obtain the parameter values of the parameter tree nodes; A fourth module 204, configured to perform parameter structure mutation based on the parameter values of the parameter tree nodes to obtain a parameter tree with rich parameter variants, where the parameter structure mutation includes tree structure mutation and tree node mutation; A fifth module 205, configured to perform requests and validations on the parameter tree with rich parameter variants, output a vulnerability report, and complete the Restful API fuzz testing.
[0057] The content in the above method embodiments is applicable to the system embodiments of the present invention. The functions specifically implemented in the system embodiments of the present invention are the same as those in the above method embodiments, and the beneficial effects achieved are also the same as those in the above method embodiments.
[0058] The above is a specific description of the preferred embodiments of the present invention, but the present invention is not limited to the described embodiments. Those skilled in the art can make various equivalent deformations or substitutions without departing from the spirit of the present invention, and these equivalent deformations or substitutions are all included within the scope defined by the claims of this application.
Claims
1. A RESTful API fuzz testing method based on tree structure parameter generation, characterized in that: The following steps are involved: Obtain the Restful API document data and perform parsing and identification processing to generate the Restful API request sequence; Mapping the Restful API request sequence to construct a parameter tree, where the nodes of the parameter tree represent the parameters in the Restful API request, and the edges of the parameter tree represent the parent-child relationship between the parameters; Calculate the parameter values of the nodes in the parameter tree through the parameter value generation function to obtain the parameter values of the parameter tree nodes; Performing parameter structure variation based on parameter values of parameter tree nodes to obtain a parameter tree with rich parameter variants, wherein the parameter structure variation includes tree structure variation and tree node variation; Request and verify parameter trees with rich parameter variations, output vulnerability reports, and complete Restful API fuzz testing.
2. According to claim 1, a RESTful API fuzzy testing method based on tree structure generation parameters is characterized in that: The step of obtaining the Restful API document data and performing parsing and identification processing to generate the Restful API request sequence specifically includes: Acquire RESTful API document data, where the RESTful API document data includes definition information of a RESTful API interface; Identify and process the definition information of the Restful API interface to obtain components of the Restful API request, where the components of the Restful API request include a request method, a request path, request parameters, and constraints corresponding to the request parameters; Parse the components of the Restful API request and the corresponding Restful API request operations to obtain the dependency relationship between the Restful API operations and parameters; Generate a Restful API request sequence based on the dependencies between Restful API operations and parameters.
3. According to claim 2, a RESTful API fuzzy testing method based on tree structure generation parameters is characterized in that: The step of mapping the request parameters in the Restful API request sequence and constructing a parameter tree specifically includes: Use the StandardizeData function to standardize the format of the request parameters in the Restful API request sequence to obtain request parameters in a unified format. Initialize an empty parameter tree and call the ParseNode function to parse the data type of the request parameter in a unified format; If the current node represents a complex data type, it is added as a child node to the parameter tree. If the current node represents a basic data type, its value is directly extracted and stored in the node, and then the node attributes are set to construct the root node of the parameter tree. Recursively decode the root node of the parameter tree through the RecursiveDecode function; If the value of the target node is nested structured data, it is decoded and parsed into subtrees to build a parameter tree.
4. According to claim 3, a RESTful API fuzzy testing method based on tree structure generation parameters is characterized in that: The expression of the parameter tree is specifically as follows: In the above formula, Represents the parameter tree, Represents the set of all nodes in the parameter tree, represents the set of all edges in the parameter tree, A data type set representing a parameter tree, used to provide a type basis for parameter generation and mutation rules. The data type function representing the parameter tree is used to identify the value type of the node and its structural characteristics. Represents a collection of high-value parameters in a parameter tree, used to identify parameter nodes with higher value or priority in vulnerability detection.
5. According to claim 4, a RESTful API fuzzy testing method based on tree structure generation parameters is characterized in that: The nodes of the parameter tree are formally defined as seven-tuples, and their expressions are as follows: In the above formula, represents a node of the parameter tree, Represents an identifier, Indicates the data type of the node, Indicates the direct parent node of the current node. Represents the direct child node set of the current node. Indicates that the value of the node provides additional constraints. Indicates the encoding method of the node value. Represents the actual value stored in the node.
6. According to claim 5, a RESTful API fuzzy testing method based on tree structure generation parameters is characterized in that: The expression of the parameter value generating function is: In the above formula, represents the parameter value generating function, Represents a collection of data types. represents a set of node constraints, represents a set of parameter generation strategies, which includes static mapping, random strategy, example strategy based on specification document, dynamic strategy learned from previous response, reuse strategy learned from previous request and strategy based on predefined attack payload, Represents the set of possible parameter values that can be generated.
7. According to claim 6, a Restful API fuzzy testing method based on tree structure generation parameters is characterized in that: The step of performing parameter structure variation based on parameter values of parameter tree nodes to obtain a parameter tree with rich parameter variants specifically includes: Based on the parameter values of the parameter tree nodes, the parameter tree is subjected to tree structure mutation to obtain parameter trees with different structural characteristics, wherein the tree structure mutation includes single node mutation, path mutation and global mutation; Tree node mutation is performed on parameter trees with different structural characteristics to obtain parameter trees with rich parameter variants, wherein the tree node mutation includes deletion, retention, duplication and type change.
8. According to claim 7, a RESTful API fuzzy testing method based on tree structure generation parameters is characterized in that: The step of requesting and verifying the parameter tree with rich parameter variations, outputting a vulnerability report, and completing the RestfulAPI fuzz testing specifically includes: Construct HTTP requests through the HTTP client library and send them to a parameter tree with rich parameter variations, receive and store response information for each request, the response information including HTTP status code, response header and response body; Analyze the response information of each request, identify abnormal response patterns, detect potential security vulnerabilities based on preset security rules, output vulnerability reports, and complete Restful API fuzz testing.
9. A RESTful API fuzzy testing system based on tree structure parameter generation, characterized in that: Includes the following modules: The first module is used to obtain the Restful API document data and perform parsing and identification processing to generate a Restful API request sequence; The second module is used to map the request parameters in the Restful API request sequence and construct a parameter tree, wherein the nodes of the parameter tree represent the parameters in the Restful API request and the edges of the parameter tree represent the parent-child relationship between the parameters; The third module is used to calculate the parameter values of the nodes in the parameter tree through the parameter value generation function to obtain the parameter values of the parameter tree nodes; The fourth module is used to perform parameter structure variation based on the parameter values of the parameter tree nodes to obtain a parameter tree with rich parameter variants, wherein the parameter structure variation includes tree structure variation and tree node variation; The fifth module is used to request and verify parameter trees with rich parameter variations, output vulnerability reports, and complete Restful API fuzz testing.
Citation Information
Patent Citations
Fuzzy testing method for RestFul API (Application Program Interface)
CN118672930A
Intelligently fuzzing data to exercise a service
US20210216435A1
Cited By
Method and equipment for automatically generating debugging request message based on API (Application Program Interface) metadata
CN120849470A
Method and device for automatically generating a debugging request message based on API metadata
CN120849470B