A Fuzzy Testing Method and System for Restful API Based on Tree Structure Generation Parameters
Through the method of generating parameters based on tree structure, the limitations of the existing Restful API fuzz testing method when dealing with complex parameter structures are solved, efficient detection of nested data structures and complex parameter dependencies is achieved, and the coverage and detection efficiency of fuzz testing are improved.
Patent Information
- Application Number
- CN202510559169.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-30
- Publication Date
- 2025-07-04
- Estimated Expiration
- 2045-04-30
AI Technical Summary
The existing Restful API fuzz testing methods have limitations when dealing with complex parameter structures, especially the difficulty in effectively identifying and mutating parameter structures with multi-level nesting or complex dependencies, resulting in limited testing depth and breadth, and the vulnerabilities of deep-level parameter dependencies and nested data structures cannot be discovered in time.
The method of generating parameters based on the tree structure is adopted, and by obtaining Restful API document data and parsing and identifying it, a parameter tree is constructed, and a parameter value generation function is used to calculate parameter values and structure variations are generated, and parameter trees with rich parameter variants are finally requested and verified, and a vulnerability report is output.
It realizes efficient processing of complex parameter structures, especially suitable for nested data structures and complex parameter dependencies, improves the detection efficiency and coverage of fuzzy testing, and can fully and efficiently discover potential security vulnerabilities.
Smart Images

Figure CN120086108B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of Web security technologies, and in particular, to a method and system for fuzz testing Restful APIs based on generating parameters using a tree structure. Background Art
[0002] As a simple and efficient communication protocol, Restful API has become a widely used standard interface in modern Web services. With the increase in application complexity, more and more security risks have emerged in Restful APIs. To address these security risks, fuzz testing, as an effective security testing technology, has been widely applied. Existing Restful API fuzz testing methods usually perform tests by randomly mutating the parameters in Restful API requests. However, these methods have some limitations in practical applications. On the one hand, many security vulnerabilities are not only reflected in parameter values. Different changes in parameter structures may also lead to different system behaviors and even expose security vulnerabilities. Existing Restful API fuzz testing methods mainly rely on randomly mutating the values of request parameters to simulate possible attack scenarios by changing the input values. However, this method is usually limited to simple random mutations of parameter values and fails to fully consider the structural characteristics of request parameters. For complex nested parameter structures, simple mutation methods only targeting parameter values are difficult to effectively cover, resulting in limited depth and breadth of Restful API fuzz testing. On the other hand, existing Restful API fuzz testing methods usually can only handle simple parameter structures, and for parameters with multi-level nesting or complex dependencies (such as nested JSON objects, arrays, or Base64-encoded data, etc.), these methods are often difficult to effectively identify and mutate complex parameter structures, ignoring issues such as dependencies between parameters and encoding conversions. This makes it impossible to timely discover and effectively detect some vulnerabilities involving deep parameter dependencies, nested data structures, or special encoding methods. Summary of the Invention
[0003] In order to solve the above technical problems, the object of the present invention is to provide a method and system for fuzz testing Restful APIs based on generating parameters using a tree structure, which can efficiently handle complex parameter structures, especially applicable to nested data structures and complex parameter dependencies, so as to achieve comprehensive and efficient fuzz testing of Restful APIs.
[0004] The first technical solution adopted by the present invention is: A method for fuzz testing Restful APIs based on generating parameters using a tree structure, comprising the following steps:
[0005] Obtain Restful API document data, parse and identify it, and generate a Restful API request sequence;
[0006] Perform mapping processing on the request parameters in the Restful API request sequence to construct a parameter tree, where the nodes of the parameter tree represent the various parameters in the Restful API request, and the edges of the parameter tree represent the parent-child relationships between the parameters;
[0007] Calculate the parameter values of the nodes in the parameter tree through a parameter value generation function to obtain the parameter values of the parameter tree nodes;
[0008] Perform parameter structure mutation based on the parameter values of the parameter tree nodes to obtain a parameter tree with rich parameter variants. The parameter structure mutation includes tree structure mutation and tree node mutation;
[0009] Perform requests and validations on the parameter tree with rich parameter variants, output a vulnerability report, and complete the fuzz testing of the Restful API.
[0010] Furthermore, the step of obtaining Restful API document data, parsing and identifying it, and generating a Restful API request sequence specifically includes:
[0011] Obtain Restful API document data, where the Restful API document data includes the definition information of the Restful API interface;
[0012] Perform identification processing on the definition information of the Restful API interface to obtain the components of the Restful API request. The components of the Restful API request include the request method, request path, request parameters, and the corresponding constraint conditions of the request parameters;
[0013] Parse according to the components of the Restful API request and the corresponding Restful API request operations to obtain the dependency relationship between the Restful API operations and the parameters;
[0014] Generate a Restful API request sequence according to the dependency relationship between the Restful API operations and the parameters.
[0015] Furthermore, the step of performing mapping processing on the request parameters in the Restful API request sequence to construct a parameter tree specifically includes:
[0016] Perform format standardization processing on the request parameters in the Restful API request sequence through the StandardizeData function to obtain request parameters in a unified format;
[0017] Initialize an empty parameter tree and call the ParseNode function to parse according to the data type of the request parameters in a unified format;
[0018] If the current node represents a complex data type, add it as a child node to the parameter tree. If the current node represents a basic data type, directly extract its value and store it in the node, and then set the node attributes to construct the root node of the parameter tree;
[0019] Perform recursive decoding on the root node of the parameter tree through the RecursiveDecode function;
[0020] If the value of the target node is nested structured data, perform decoding and parse it into a subtree to construct the parameter tree.
[0021] Furthermore, the expression of the parameter tree is specifically as follows:
[0022]
[0023] In the above formula, represents the parameter tree, represents the set of all nodes in the parameter tree, represents the set of all edges in the parameter tree, represents the set of data types of the parameter tree, which provides a type basis for the generation and mutation rules of parameters, represents the data type function of the parameter tree, which is used to identify the value type and its structural characteristics of the node, represents the set of high-value parameters of the parameter tree, which is used to identify parameter nodes with relatively high value or priority in vulnerability detection.
[0024] Furthermore, the formal definition of the node of the parameter tree is a seven-tuple, and its expression is specifically as follows:
[0025]
[0026] In the above formula, represents the node of the parameter tree, represents the identifier, represents the data type of the node, represents the direct parent node of the current node, represents the set of direct child nodes of the current node, represents that the value of the node provides additional restrictive conditions, represents the encoding method of the node value, represents the actual value stored in the node.
[0027] Furthermore, the expression of the parameter value generation function is:
[0028]
[0029] In the above formula, represents the parameter value generating function, Represents a collection of data types. represents a set of node constraints, represents a set of parameter generation strategies, which includes static mapping, random strategy, example strategy based on specification document, dynamic strategy learned from previous response, reuse strategy learned from previous request and strategy based on predefined attack payload, Represents the set of possible parameter values that can be generated.
[0030] Furthermore, the step of performing parameter structure variation based on parameter values of parameter tree nodes to obtain a parameter tree with rich parameter variants specifically includes:
[0031] Based on the parameter values of the parameter tree nodes, the parameter tree is subjected to tree structure mutation to obtain parameter trees with different structural characteristics, wherein the tree structure mutation includes single node mutation, path mutation and global mutation;
[0032] Tree node mutation is performed on parameter trees with different structural characteristics to obtain parameter trees with rich parameter variants, wherein the tree node mutation includes deletion, retention, duplication and type change.
[0033] Furthermore, the step of requesting and verifying the parameter tree with rich parameter variations, outputting a vulnerability report, and completing the RESTful API fuzz testing specifically includes:
[0034] Construct HTTP requests through the HTTP client library and send them to a parameter tree with rich parameter variations, receive and store response information for each request, the response information including HTTP status code, response header and response body;
[0035] Analyze the response information of each request, identify abnormal response patterns, detect potential security vulnerabilities based on preset security rules, output vulnerability reports, and complete Restful API fuzz testing.
[0036] The second technical solution adopted by the present invention is: a RESTful API fuzzy testing system based on tree structure-based parameter generation, comprising:
[0037] The first module is used to obtain the Restful API document data and perform parsing and identification processing to generate a Restful API request sequence;
[0038] The second module is used to perform mapping processing on the request parameters in the Restful API request sequence and construct a parameter tree. The nodes of the parameter tree represent the various parameters in the Restful API request, and the edges of the parameter tree represent the parent-child relationships between the parameters;
[0039] The third module is used to calculate the parameter values of the nodes in the parameter tree through a parameter value generation function to obtain the parameter values of the parameter tree nodes;
[0040] The fourth module is used to perform parameter structure mutation based on the parameter values of the parameter tree nodes to obtain a parameter tree with rich parameter variants. The parameter structure mutation includes tree structure mutation and tree node mutation;
[0041] The fifth module is used to perform requests and validations on the parameter tree with rich parameter variants, output a vulnerability report, and complete the fuzz testing of the Restful API.
[0042] The beneficial effects of the method and system of the present invention are as follows: By obtaining and parsing the Restful API document data, the present invention generates a Restful API request sequence, further performs mapping processing on the request parameters in the Restful API request sequence, constructs a parameter tree, maps complex request parameters into a tree structure, and effectively identifies the data relationships and dependencies at each level through recursive parsing. The parameter values of the nodes in the parameter tree are calculated through a parameter value generation function to obtain the parameter values of the parameter tree nodes. Furthermore, based on the parameter values of the parameter tree nodes, parameter structure mutation is performed to obtain a parameter tree with rich parameter variants, realizing systematic mutation processing of the parameter structure. It can not only mutate single parameter values but also flexibly adjust the hierarchical structure of the parameters. Finally, requests and validations are performed on the parameter tree with rich parameter variants, and a vulnerability report is output, which can efficiently process complex parameter structures, especially suitable for nested data structures and complex parameter dependency relationships, thereby realizing comprehensive and efficient fuzz testing of the Restful API. Description of the Drawings
[0043] Figure 1 is the flowchart of the steps of a method for fuzz testing Restful API based on generating parameters using a tree structure according to the present invention;
[0044] Figure 2 is the block diagram of the structure of a system for fuzz testing Restful API based on generating parameters using a tree structure according to the present invention;
[0045] Figure 3 is the schematic diagram of the framework of fuzz testing Restful API provided by a specific embodiment of the present invention. Detailed Embodiments
[0046] The present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments. For the step numbers in the following embodiments, they are only set for the convenience of explanation and illustration, and no limitation is imposed on the order between steps. The execution order of each step in the embodiments can be adaptively adjusted according to the understanding of those skilled in the art.
[0047] First of all, it should be noted that as a simple and efficient communication protocol, the Restful API has become a widely used standard interface in modern web services. Its design concept is centered around resources, emphasizing statelessness and a unified interface, enabling different systems to interact efficiently through the HTTP protocol. Due to this flexibility and scalability, the Restful API is widely used in various Internet services and platforms, including but not limited to e-commerce, social networks, fintech, and the Internet of Things, etc., and has become an important tool for promoting digital transformation. However, with the increase in application complexity, more and more security risks have emerged in the Restful API. Especially in aspects such as identity authentication, input validation, and access control of the Restful API, there are still relatively large security risks, and these risks may lead to serious consequences such as unauthorized access, sensitive data leakage, and service interruption. To address these security risks, fuzz testing, as an effective security testing technology, is widely used. Fuzz testing helps identify potential vulnerabilities in the system under abnormal inputs by sending a large amount of random or malformed data to the target Restful API interface, simulating the input data formats that attackers may exploit.
[0048] Based on this, the embodiments of the present invention first parse and identify the Restful API document data, then generate a request sequence, construct a parameter tree for the generated requests, further generate parameter values according to the tree structure and mutate the parameter structure according to the tree structure, and finally send requests, collect response information, and output a vulnerability report. By adopting the method of generating parameters based on the tree structure, it can effectively solve the limitations of the existing Restful API fuzz testing methods in dealing with complex parameter structures, especially the general limitation to the mutation of parameter values, resulting in low test efficiency and limited coverage; in addition, the embodiments of the present invention can also support the generation and mutation of parameters with complex nested data structures through recursive parsing and mutation processing, thereby improving the detection efficiency and effectiveness of Restful API fuzz testing.
[0049] Referring to Figure 1 , the present invention provides a Restful API fuzz testing method based on generating parameters with a tree structure, and this method includes the following steps:
[0050] S100. Obtain the Restful API document data, parse and identify it, and generate a Restful API document data request sequence;
[0051] S110. Obtain the Restful API document data, where the Restful API document data includes the definition information of the Restful API interface;
[0052] Specifically, receive the input Restful API document data, which is usually in the OpenAPI or other similar format. This document data contains the definition information of the Restful API interface, such as the request method, request path, request parameters and their data types, format requirements, etc.
[0053] S120. Identify and process the definition information of the Restful API interface to obtain the components of the Restful API request. The components of the Restful API request include the request method, request path, request parameters, and the corresponding constraint conditions for the request parameters;
[0054] Specifically, identify each component of the Restful API request, including the request method (such as GET, POST, etc.), request path, and the parameters required for each request. In this process, not only the type of each parameter (such as string, integer, boolean, etc.) needs to be identified, but also the constraint conditions of each parameter need to be extracted, such as the value range, whether it is a required parameter, format requirements, etc.
[0055] S130. Parse according to the components of the Restful API request and the corresponding Restful API request operations to obtain the dependency relationship between the Restful API operations and parameters;
[0056] Specifically, identify the dependency relationship between the Restful API operations and parameters, especially the mutual dependency between some parameters. For example, the existence of some parameters may depend on the values of other parameters. This information will provide a necessary basis for subsequent request generation and mutation processing.
[0057] S140. Generate a Restful API request sequence according to the dependency relationship between the Restful API operations and parameters.
[0058] In this embodiment, after parsing and identifying the Restful API document data, a request sequence is generated based on the operations of the Restful API interface and the dependency relationship of its parameters . The requests in each request sequence are arranged in the order of Restful API operations, and each request It includes interface operations and corresponding parameter information, ensuring that the filling of parameters complies with the specification requirements and considering the dependencies between parameters. For example, if some parameters depend on the values of other parameters, ensure that these dependency conditions are satisfied first when generating the request.
[0059] S200. Perform mapping processing on the request parameters in the Restful API request sequence to construct a parameter tree. The nodes of the parameter tree represent each parameter in the Restful API request, and the edges of the parameter tree represent the parent-child relationships between parameters.
[0060] Specifically, perform format standardization processing on the input data requestData through the StandardizeData function to obtain request parameters in a unified format; initialize an empty parameter tree and call the ParseNode function to parse according to the data type of the request parameters in the unified format; if the current node represents a complex data type, add it as a child node to the parameter tree, and if the current node represents a basic data type, directly extract its value and store it in the node, and then set the node attributes to construct the root node of the parameter tree; perform recursive decoding on the root node of the parameter tree through the RecursiveDecode function; if the value of the target node is nested structured data, perform decoding and parse it into a subtree to construct the parameter tree.
[0061] First of all, it should be noted that in the embodiments of the present invention, the request parameters will be mapped to a parameter tree. The nodes of the parameter tree represent each parameter in the Restful API request, and the edges of the parameter tree represent the parent-child relationships between parameters. This parameter tree structure facilitates flexible operations in the subsequent mutation stage and can clearly show the hierarchical relationships between parameters.
[0062] The nodes of the parameter tree are divided into non-leaf nodes and leaf nodes. Among them, the object and array types are non-leaf nodes, and the fields of basic data types (such as string, boolean, integer) are leaf nodes. Based on this, the formal definition of the parameter tree is as follows:
[0063]
[0064] Among them, the node set represents all nodes in the parameter tree, and each node corresponds to an attribute field or element in the request and constitutes the basic unit of the parameter; the edge set , where , each element in is an ordered pair Both of the two elements in , represents a node is the parent node of node , while node is the child node of node ; the data type set contains the supported data type set. For example, , which provides a type basis for the generation and mutation rules of parameters; the data type function maps each node to an element in the data type set , that is, , where , which is used to identify the value type and its structural characteristics of the node; the high-value parameter set is used to identify the parameter nodes with higher value or priority in vulnerability detection, that is, , where is a boolean function used to determine whether the node is a high-value parameter. The high-value parameter set can be dynamically updated and adjusted according to actual needs.
[0065] Each node in the parameter tree is the basic unit that constitutes the tree structure. The formal definition of the node is a seven-tuple, and its expression is:
[0066]
[0067] Among them, the identifier is used to uniquely identify the node, usually corresponding to the parameter name to distinguish different nodes; the type represents the data type of the node, and through the data type function it is mapped to the specific type in the data type set ; the parent node represents the direct parent node of the current node. If it is the root node, its parent node is ; the child node set represents the set of direct child nodes of the current node, which is applicable to composite data type nodes. For leaf nodes, this set is empty; the constraint condition represents providing additional limiting conditions for the value of the node, which is used to define the valid range, length, or format of the node value. For example, an integer node may have a value range, and a string node may be attached with a regular expression constraint; the encoding method represents the encoding method of the node value, so as to process parameters with complex multi-level nesting or dependency relationships. For example, processing parameters encoded in XML, JSON, Base64, etc., which is often used for fields that need to be converted or nested; the node value Represents the actual value stored in a node, usually applicable to leaf nodes. The values of non-leaf nodes are usually empty or , as their role is limited to organizing child nodes.
[0068] Furthermore, in this embodiment, first, the algorithm receives the input data requestData and standardizes it into a unified format (e.g., converting key-value pairs into JSON format) through the StandardizeData function. Then, an empty parameter tree parameterTree is initialized, and the ParseNode function is called to start parsing the data, thereby constructing the root node of the tree. In the ParseNode function, each node is parsed according to the data type. If the current node is a complex data type (e.g., object or array), the algorithm recursively processes its child elements and adds them as child nodes to the parameter tree; if it is a basic data type (e.g., string, integer, etc.), its value is directly extracted and stored in the node. During this process, the algorithm also sets attributes for each node, including type, constraint conditions, encoding method, etc., and marks high-value parameters that may be of great significance in vulnerability detection through the IdentifyHighValueParams function. In addition, the algorithm uses the RecursiveDecode function to recursively decode each node in the parameter tree. If the value of a node is nested structured data (e.g., Base64-encoded JSON), the algorithm decodes it and further parses it into a subtree to ensure that the nested data can be correctly integrated into the parameter tree. Finally, the algorithm returns the constructed parameterTree, which contains all the parsed parameter nodes and their attributes and relationships.
[0069] S300. Calculate the parameter values of the nodes in the parameter tree through the parameter value generation function to obtain the parameter values of the parameter tree nodes;
[0070] Specifically, generate parameter values according to the tree structure. In the embodiment of the present invention, through the constructed parameter tree , use the parameter value generation function to generate parameter values for each node, where represents the set of data types, represents the set of node constraint conditions, represents the set of possible generated parameter values, the set of parameter generation strategies .
[0071] It should be further noted that contains six parameter value generation strategies, specifically including:
[0072] 1) Static mapping With random strategy , through static "type-value" mapping, each data type is mapped to a fixed value. For example, a string is mapped to "fuzzstring", an integer is 0, a Boolean value is false, and an array is When static mapping cannot meet the needs, a random strategy is used , randomly generate parameter values according to parameter types and constraints (such as value ranges or regular expressions) to improve input diversity.
[0073] 2) Example policy based on specification document If example values, default values, or enumeration values are provided in the Restful API document data, these values are used first to assign parameter values. These values can usually improve the effectiveness and rationality of the request.
[0074] 3) Dynamic policies learned from previous responses , using parameter values extracted from previous responses, storing them in a resource pool and reusing responses of successful requests to ensure the dynamic adaptability of the test environment. This strategy is divided into conservative mode and aggressive mode, specifically:
[0075] Conservative mode: This value is selected only when the path of the request where the target parameter is located completely matches the path in the resource pool. This mode reduces the risk of false matching and ensures the accuracy of the test.
[0076] Aggressive mode only compares parameter names. As long as the parameter names match, the value in the resource pool is selected. This mode can expand test scenarios and increase flexibility and exploration scope.
[0077] 4) Reuse strategy learned from previous requests ,Previously successful requests and their parameter values will be stored in the resource pool and used first for subsequent request generation.,By moderately mutating the reused parameters, the diversity of,mutations can be increased and excessive repetition can be avoided.
[0078] 5) Based on predefined attack payload strategies , use the attack payload in the existing vulnerability testing library to replace or inject parameter values to detect the security performance of the Restful API when facing malicious input and help discover potential security vulnerabilities. (Its data type and constraints ), the resulting parameter value is ,in .
[0079] S400. Mutate the parameter structure based on the parameter values of the parameter tree nodes to obtain a parameter tree with rich parameter variants. The parameter structure mutation includes tree structure mutation and tree node mutation;
[0080] Specifically, according to the tree structure mutation parameter structure, by adjusting the overall structure and local nodes of the parameter tree, various possible input situations are simulated. The mutation rules of the parameter structure include tree structure mutation and tree node mutation.
[0081] S410. Based on the parameter values of the parameter tree nodes, perform tree structure mutation on the parameter tree to obtain a parameter tree with different structural characteristics. The tree structure mutation includes single node mutation, path mutation, and global mutation;
[0082] In this embodiment, for tree structure mutation, the structure mutation rules of the parameter tree are divided into three categories: single node mutation, path mutation, and global mutation. Specifically:
[0083] 1) Single node mutation. Denote the single node mutation as , which means modifying a single node in the tree while keeping the rest of the nodes unchanged. This method is applicable to testing the impact of the change of a single parameter on the behavior of the Restful API;
[0084] 2) Path mutation. Select a path in the parameter tree and denote the path mutation as , that is, synchronously mutate all nodes on the path to explore the impact of the combined change of multi-level nodes on the overall request;
[0085] 3) Global mutation. Apply mutation rules to multiple nodes in the tree (possibly distributed on different paths) simultaneously to generate a parameter tree with completely different structures.
[0086] S420. Perform tree node mutation on the parameter tree with different structural characteristics to obtain a parameter tree with rich parameter variants. The tree node mutation includes deletion, retention, replication, and type change.
[0087] In this embodiment, for tree node mutation, for any node expression , there are four categories of node mutation rules for the parameter tree, namely deletion, retention, replication, and type change. Specifically:
[0088] 1) Deletion. Define the deletion operation as , which means completely removing the node and its subtree to simulate the situation of parameter missing.
[0089] 2) Retention. Define the retention operation as , where Indicates to retain only part of the child nodes, delete other nodes at the same level, and test the processing ability when minimizing the input.
[0090] 3) Copy, the expression defining the copy operation is:
[0091]
[0092] where is the copy of, indicating to copy the node and its subtree, simulating redundant data input, is a new identifier to ensure uniqueness.
[0093] 4) Type change, the expression defining the type change operation is:
[0094]
[0095] where is the new data type, and is the function to convert the original value to the new type indicating to change the data type of the node, such as changing a string to an array or an object, and testing the response of the Restful API to data type mismatches.
[0096] In summary, by combining the use of tree structure mutation and tree node mutation rules, more abundant parameter variants can be obtained. For example, the overall parameter tree can be mutated by path or globally first to generate a set of parameter trees with different structural characteristics, and then local mutations such as deletion, retention, copying, or type change can be applied to key nodes to further refine the test cases.
[0097] S500. Send requests and perform validations on the parameter tree with rich parameter variants, output vulnerability reports, and complete the fuzz testing of the Restful API.
[0098] S510. Construct an HTTP request through the HTTP client library and send it to the parameter tree with rich parameter variants, receive and store the response information of each request, where the response information includes the HTTP status code, response headers, and response body;
[0099] In this embodiment, send a request, use the HTTP client library to construct an HTTP request, and send the request through the function to ensure the correctness and integrity of the request, which is formally represented as where is the HTTP response object, further collect the response information, receive and store the response information of each request, and define the received HTTP response object as , including HTTP status codes , response headers and response bodies , the storage operation is formalized as .
[0100] S520. Analyze the response information for each request, identify abnormal response patterns, detect potential security vulnerabilities based on preset security rules, output a vulnerability report, and complete the fuzz testing of the Restful API.
[0101] In this embodiment, output a vulnerability report, analyze the collected response information, identify abnormal response patterns, such as status code 500, abnormal error messages, etc., and detect potential security vulnerabilities based on predefined security rules, and finally generate a detailed vulnerability report , the content includes the vulnerability type , vulnerability description , affected API operations and their request sequences , facilitating subsequent repair by developers.
[0102] In summary, as Figure 3 shown, the embodiment of the present invention parses the existing RESTful API document data, extracts information such as request methods, request paths, request parameters, and request examples, and then converts this information into a series of request sequences or request lists, providing an input basis for subsequent parameter tree construction and mutation. Furthermore, the obtained request data is processed in a tree-like structure, and a parameter tree is generated through recursive parsing and standardization operations. Each tree node carries descriptive information about the parameter, such as identifier , type , parent node , child node set , constraint conditions , encoding method , node value This module lays the data foundation for the subsequent parameter value generation and structural mutation. According to different test requirements, the system adopts a variety of parameter value strategies for each parameter node, including static mapping and random strategies, example strategies based on specification documents, dynamic strategies learned from previous responses, dynamic strategies learned from previous attacks, reuse strategies learned from previous requests, and strategies based on predefined attack payloads. Further, it is divided into tree structure mutation and tree node mutation. Tree structure mutation includes single node mutation, path mutation and global mutation; tree node mutation includes node deletion, retention, replication and type change. After completing the mutation operation, the system will use recursive encoding to re-inject the mutated parameter data into the request, and finally send the request generated or mutated by the above module to the server to execute the actual Restful API call. Subsequently, the response results are analyzed through corresponding vulnerability detection or verification means to identify possible security vulnerabilities or functional defects, and finally output vulnerability reports, realizing a Restful API fuzz testing system that efficiently constructs complex parameter structures, generates diversified parameter values and flexibly mutates parameter trees, thereby improving the coverage and detection efficiency of Restful API fuzz testing.
[0103] Therefore, compared with the prior art, the embodiments of the present invention have the following advantages:
[0104] 1) Through the recursive mutation method based on the tree structure, the systematic mutation processing of the parameter structure is realized, which can not only mutate the single parameter value, but also flexibly adjust the hierarchical structure of the parameter. For example, the present invention generates diversified test cases by modifying the nested hierarchy of parameters, dynamically adding or deleting nodes, adjusting the order of nodes, etc. These mutation operations expand the coverage of Restful API fuzz testing from simple parameter values to deep adjustment of parameter structures, effectively simulating and detecting potential vulnerabilities caused by improper parameter structures. Compared with traditional methods, the present invention not only focuses on the randomized variation of parameter values, but also attaches importance to the diversity of parameter structures, which enables the Restful API fuzzy testing method to effectively discover vulnerabilities in the face of more complex scenarios, thereby improving the test coverage and vulnerability discovery efficiency.
[0105] 2) Through the parameter generation and recursive parsing method based on the tree structure, it is possible to accurately handle multi-layer nesting and complex parameter dependencies. Specifically, the present invention maps complex request parameters into a tree structure, and ensures that the data relationships and dependencies at each level are effectively identified through recursive parsing. This method ensures that whether it is a simple flat structure or a complex multi-layer nesting, the hierarchy and relationship between parameters are correctly parsed and effectively mutated. The present invention greatly improves the depth and accuracy of Restful API fuzz testing, making the test more comprehensive.
[0106] Reference Figure 2 , a Restful API fuzz testing system for generating parameters based on a tree structure, comprising:
[0107] The first module 201 is used to obtain Restful API document data, perform parsing and recognition processing, and generate a Restful API request sequence;
[0108] The second module 202 is used to perform mapping processing on the request parameters in the Restful API request sequence, construct a parameter tree, where the nodes of the parameter tree represent the respective parameters in the Restful API request, and the edges of the parameter tree represent the parent-child relationships between the parameters;
[0109] The third module 203 is used to calculate the parameter values of the nodes in the parameter tree through a parameter value generation function to obtain the parameter values of the parameter tree nodes;
[0110] The fourth module 204 is used to perform parameter structure mutation based on the parameter values of the parameter tree nodes to obtain a parameter tree with rich parameter variants, and the parameter structure mutation includes tree structure mutation and tree node mutation;
[0111] The fifth module 205 is used to perform requests and validations on the parameter tree with rich parameter variants, output a vulnerability report, and complete the Restful API fuzz testing.
[0112] The content in the above method embodiments is applicable to the system embodiments of the present invention. The functions specifically implemented by the system embodiments of the present invention are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those of the above method embodiments.
[0113] The above has specifically described the preferred embodiments of the present invention, but the present invention is not limited to the described embodiments. Those skilled in the art can make various equivalent deformations or substitutions without departing from the spirit of the present invention, and these equivalent deformations or substitutions are all included within the scope defined by the claims of this application.
Claims
1. A fuzzy testing method for Restful APIs based on generating parameters using a tree structure, characterized in that, It includes the following steps: Obtain Restful API document data, perform parsing and recognition processing, and generate a Restful API request sequence; Perform mapping processing on the Restful API request sequence to construct a parameter tree. The nodes of the parameter tree represent each parameter in the Restful API request, and the edges of the parameter tree represent the parent-child relationships between the parameters, including: Perform format standardization processing on the request parameters in the Restful API request sequence through the StandardizeData function to obtain request parameters in a unified format; Initialize an empty parameter tree and call the ParseNode function to parse according to the data types of the request parameters in the unified format; If the current node represents a complex data type, add it as a child node to the parameter tree. If the current node represents a basic data type, directly extract its value and store it in the node, and then set the node attributes to construct the root node of the parameter tree; Perform recursive decoding on the root node of the parameter tree through the RecursiveDecode function; If the value of the target node is nested structured data, perform decoding and parse it into a subtree to construct a parameter tree; Perform parameter value calculation on the nodes in the parameter tree through the parameter value generation function to obtain the parameter values of the parameter tree nodes; Perform parameter structure mutation based on the parameter values of the parameter tree nodes to obtain a parameter tree with rich parameter variants. The parameter structure mutation includes tree structure mutation and tree node mutation, including: Based on the parameter values of the parameter tree nodes, perform tree structure mutation on the parameter tree to obtain parameter trees with different structural characteristics. The tree structure mutation includes single node mutation, path mutation, and global mutation; Perform tree node mutation on the parameter trees with different structural characteristics to obtain a parameter tree with rich parameter variants. The tree node mutation includes deletion, retention, copying, and type change; Perform requests and validations on the parameter tree with rich parameter variants, output a vulnerability report, and complete the Restful API fuzz testing.
2. The Restful API fuzz testing method for generating parameters based on a tree structure according to claim 1, wherein The step of obtaining Restful API document data, performing parsing and recognition processing, and generating a Restful API request sequence specifically includes: Obtain Restful API document data, where the Restful API document data includes the definition information of the Restful API interface; Perform recognition processing on the definition information of the Restful API interface to obtain the components of the Restful API request. The components of the Restful API request include the request method, request path, request parameters, and the constraint conditions corresponding to the request parameters; Parse according to the components of the Restful API request and the corresponding Restful API request operations to obtain the dependency relationship between the Restful API operations and the parameters; Generate a Restful API request sequence according to the dependency relationship between the Restful API operations and the parameters.
3. The Restful API fuzz testing method for generating parameters based on a tree structure according to claim 2, characterized in that, The expression of the parameter tree is specifically as follows: T=(V, E, Γ, L, H) In the above formula, T represents the parameter tree, V represents the set of all nodes in the parameter tree, E represents the set of all edges in the parameter tree, Γ represents the set of data types of the parameter tree, which is used to provide a type basis for the generation and mutation rules of parameters, L represents the data type function of the parameter tree, which is used to identify the value type and its structural characteristics of the nodes, and H represents the set of high-value parameters of the parameter tree, which is used to identify the parameter nodes with higher value or priority in vulnerability detection.
4. The Restful API fuzz testing method for generating parameters based on a tree structure according to claim 3, wherein The node of the parameter tree is formally defined as a seven-tuple, and its expression is specifically as follows: N = (Id, Type, Parent, Children, Constraints, Encode, Value) In the above formula, N represents the node of the parameter tree, Id represents the identifier, Type represents the data type of the node, Parent represents the direct parent node of the current node, Children represents the set of direct child nodes of the current node, Constraints represents the additional limiting conditions provided by the value of the node, Encode represents the encoding method of the node value, and Value represents the actual value stored in the node.
5. The Restful API fuzz testing method for generating parameters based on a tree structure according to claim 4, characterized in that The expression of the parameter value generation function is: In the above formula, f gen represents the parameter value generating function, Γ represents the data type set, represents a set of node constraints, S represents a set of parameter generation strategies, which includes static mapping, random strategy, example strategy based on specification document, dynamic strategy learned from previous response, reuse strategy learned from previous request and strategy based on predefined attack payload, and U represents a set of parameter values that may be generated.
6. The Restful API fuzz testing method for generating parameters based on a tree structure according to claim 5, characterized in that, Request and verify the parameter tree with rich parameter variants, and output a vulnerability report to complete the step of Restful API fuzz testing, which specifically includes: Construct an HTTP request through the HTTP client library and send it to the parameter tree with rich parameter variants, and receive and store the response information of each request. The response information includes the HTTP status code, response headers, and response body; Analyze the response information of each request, identify abnormal response patterns, and detect potential security vulnerabilities based on preset security rules, and output a vulnerability report to complete the Restful API fuzz testing.
7. A fuzzy testing system for Restful API that generates parameters based on a tree structure, characterized in that, It includes the following modules: The first module is used to obtain the Restful API document data and perform parsing and identification processing to generate a Restful API request sequence; The second module is used to perform mapping processing on the Restful API request sequence to construct a parameter tree. The nodes of the parameter tree represent the various parameters in the Restful API request, and the edges of the parameter tree represent the parent-child relationships between the parameters, including: Standardize the format of the request parameters in the Restful API request sequence through the StandardizeData function to obtain request parameters in a unified format; Initialize an empty parameter tree and call the ParseNode function to parse according to the data type of the request parameters in the unified format; If the current node represents a complex data type, add it as a child node to the parameter tree. If the current node represents a basic data type, directly extract its value and store it in the node, and then set the node attributes to construct the root node of the parameter tree; Recursively decode the root node of the parameter tree through the RecursiveDecode function; If the value of the target node is nested structured data, decode and parse it into a subtree to construct a parameter tree; The third module is used to calculate the parameter values of the nodes in the parameter tree through a parameter value generation function to obtain the parameter values of the parameter tree nodes; The fourth module is used to perform parameter structure mutation based on the parameter values of the parameter tree nodes to obtain a parameter tree with rich parameter variants. The parameter structure mutation includes tree structure mutation and tree node mutation, including: Based on the parameter values of the parameter tree nodes, perform tree structure mutation on the parameter tree to obtain parameter trees with different structural characteristics. The tree structure mutation includes single node mutation, path mutation, and global mutation; Perform tree node mutation on the parameter trees with different structural characteristics to obtain a parameter tree with rich parameter variants. The tree node mutation includes deletion, retention, copying, and type change; The fifth module is used to perform requests and validations on the parameter tree with rich parameter variants, output vulnerability reports, and complete the fuzz testing of the Restful API.
Citation Information
Patent Citations
Fuzzy testing method for RestFul API (Application Program Interface)
CN118672930A
Intelligently fuzzing data to exercise a service
US20210216435A1