Unauthorized detection method and device, equipment and medium

By traversing multiple functions of the web application and counting messages, identifying important functions and performing overright detection, the problem of lack of focus and priority in the detection process in the prior art is solved, and efficient overright vulnerability detection is achieved.

CN120090819APending Publication Date: 2025-06-03JINAN INSPUR DATA TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510070028.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-15
Publication Date
2025-06-03

AI Technical Summary

Technical Problem

The existing unauthorized vulnerability detection methods cannot effectively deal with complex web applications, resulting in the lack of focus and priority of the detection process and the inability to effectively identify high-risk functions.

Method used

The client of the first tested role traverses the multiple functions of the target application, issues multiple request messages with data, and counts these request messages, determines the target data whose occurrences are greater than the preset threshold, thereby identifying important functions and performing overprivileged detection.

Benefits of technology

It achieves comprehensive coverage of web applications, ensures the breadth and depth of overright detection, optimizes the allocation of security resources, improves the efficiency and flexibility of overright detection, and can effectively identify and prioritize functions with higher risks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120090819A_ABST
    Figure CN120090819A_ABST
Patent Text Reader

Abstract

The invention provides an unauthorized detection method and device, equipment and a medium, and relates to the technical field of network security, and the method comprises the steps: carrying out the traversal of a plurality of functions of a target application through a client of a first tested role, and transmitting a plurality of request messages with data to the plurality of traversed functions; multiple request messages sent by the client of the first tested role in the process of traversing multiple functions of the target application are counted, multiple target data are determined, and the target data are data with the total occurrence frequency larger than a first preset occurrence frequency threshold value in the data carried by the multiple request messages; determining a plurality of target functions from the plurality of functions based on the plurality of target data; and performing unauthorized detection on the plurality of target functions, thereby determining the priority and the emphasis of the unauthorized detection, and improving the efficiency and the flexibility of the unauthorized detection.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security technologies, and in particular, to a method, apparatus, device, and medium for detecting unauthorized access. Background Art

[0002] With the development of big data, cloud computing, and artificial intelligence technologies, Web applications developed by major Internet companies have been continuously iterated and have more comprehensive functions. The "paperless" business process has also become the most obvious trend. On the other hand, more and more functions of Web applications require a more refined user role management mechanism for matching. Different role users are only allowed to operate resources within the scope permitted by their roles. With the current major Internet manufacturers having successively developed Web applications with more complex functions and a greater variety of user roles, accompanied by this, there are more easily exposed unauthorized access vulnerabilities. Since the exploitation methods of unauthorized access vulnerabilities are simple and the actual harm is relatively large, especially in attack scenarios such as confidential data leakage, denial of service, and system downtime, which directly affect the normal operation of information systems, they have always been the types of vulnerabilities that are key concerns in the field of network security.

[0003] Traditional methods for detecting unauthorized access vulnerabilities cannot cope with the large number of functions included in Web applications. The Web applications developed by current major Internet manufacturers have more and more functions and more complex user roles. If the HTTP requests corresponding to each function are used to detect unauthorized access by replacing the session identifier, it is easy to have false negatives, and there is no focus and priority in the detection process. Often, too many security penetration testing resources are consumed on Web application functions with lower risks, but the Web application functions with higher risks cannot be identified as the key points. Summary of the Invention

[0004] In view of this, embodiments of this application provide a method, apparatus, device, and medium for detecting unauthorized access to overcome or at least partially solve the above problems.

[0005] The first aspect of the embodiments of this application provides a method for detecting unauthorized access, and the method includes: Traverse multiple functions of a target application through a client of a first tested role, and send multiple request messages with data for the traversed multiple functions; Statistically analyze the multiple request messages sent by the client of the first tested role during the process of traversing the multiple functions of the target application, and determine multiple target data, where the target data is data whose total occurrence times in the data carried by the multiple request messages is greater than a first preset occurrence times threshold; Based on the multiple target data, determine multiple target functions from the multiple functions; Perform unauthorized access detection on the multiple target functions.

[0006] Optionally, during the process of traversing multiple functions of the target application by the client of the first tested role, statistics are performed on multiple request messages with data, and multiple target data are determined, including: Taking the data in the query string and the request body included in the multiple request messages as data to be analyzed; For each request message among the multiple request messages, counting the first occurrence times of the data to be analyzed included in the request message; Summarizing the first occurrence times of the data to be analyzed in each request message to determine the total occurrence times of each data to be analyzed in the multiple request messages; Taking the data to be analyzed with the total occurrence times greater than the first preset occurrence times threshold as the target data.

[0007] Optionally, it further includes: Taking the data to be analyzed with the total occurrence times greater than the first preset occurrence times threshold as candidate data, and in combination with the actual business requirements of the target application and the requirements of security penetration testing, determining the second occurrence times of each candidate data in the usage information database of the target application, where the usage information database of the target application includes at least one of the following: the front-end page display information of the target application, the product user manual of the target application, the product installation manual of the target application; Filtering out the candidate data with the second occurrence times lower than the second preset occurrence times threshold; Taking the data to be analyzed with the total occurrence times greater than the first preset occurrence times threshold as the target data, including: Taking the remaining candidate data after filtering as the target data.

[0008] Optionally, determining multiple target functions from the multiple functions based on the multiple target data includes: Based on the target data, performing reverse tracing in the multiple request messages to determine the multiple request messages where each target data is located; Taking the multiple functions corresponding to the multiple request messages where the multiple target data are located as the multiple target functions.

[0009] Optionally, the privilege escalation detection for the multiple target functions includes: Taking the multiple request messages corresponding to the multiple target functions as multiple target request messages; Determining the current detection target request message for privilege escalation detection from the multiple target request messages; Selecting any role other than the first tested role as the second tested role; Replace the value of the target data included in the target request message corresponding to the current detection target request message with the value of the second tested role to obtain the replaced target data; Generate a new target request message based on the replaced target data, and send the new target request message to the target application; Determine the detection results of privilege escalation detection for each target function according to the response result of the server of the target application for the new target request message; After determining that the privilege escalation detection of the current detection target request message is completed, reselect the second tested role, and re-determine the next current detection target request message from the multiple target request messages, and execute the above privilege escalation detection process until the privilege escalation detection of all the multiple target functions is completed.

[0010] Optionally, the privilege escalation detection for the multiple target functions includes: For each target function, respectively select multiple second tested roles with the same and different levels as the level of the first tested role; When the level of the second tested role is the same as the level of the first tested role, perform horizontal privilege escalation detection on the target application; when the response result of the horizontal privilege escalation detection indicates that the target application returns a normal response, determine that the detection result is that the target function has a horizontal privilege escalation vulnerability; When the level of the second tested role is higher than the level of the first tested role, perform vertical privilege escalation detection on the target application; when the response result of the vertical privilege escalation detection indicates that the target application returns a normal response, determine that the detection result is that the target function has a vertical privilege escalation vulnerability.

[0011] Optionally, the traversing of multiple functions of a target application by the client of the first tested role and sending multiple request messages with data to the traversed multiple functions includes: Select any role of any user as the first tested role through the page automation tool of the target application, traverse multiple functions of the target application, and send a request message to each traversed function; Intercept and save the multiple request messages corresponding to the multiple functions covered by the first tested role through the packet capture tool of the target application.

[0012] A second aspect of the embodiments of the present application provides a privilege escalation detection device, and the device includes: A function traversal module, configured to traverse multiple functions of a target application through the client of the first tested role, and send multiple request messages with data to the traversed multiple functions; A data statistics module, configured to count multiple request messages sent by the client of the first tested role during traversing multiple functions of the target application, and determine multiple target data, where the target data is data with a total occurrence times greater than a first preset occurrence times threshold among the data carried by the multiple request messages; A target function determination module, configured to determine multiple target functions from the multiple functions based on the multiple target data; An over - privilege detection module, configured to perform over - privilege detection on the multiple target functions.

[0013] In a third aspect of the embodiments of the present application, an electronic device is provided, including a memory, a processor, and a computer program stored on the memory. Wherein, the processor executes the computer program to implement the method as described in the first aspect.

[0014] In a fourth aspect of the embodiments of the present application, a computer program product is provided, including a computer program, which when executed by a processor, implements the method as described in the first aspect.

[0015] In a fifth aspect of the embodiments of the present application, a computer - readable storage medium is provided, on which a computer program is stored. Wherein, the computer program when executed by a processor implements the method as described in the first aspect.

[0016] Advantages of the present application: The embodiments of the present application provide an over - privilege detection method, device, equipment, and medium, including: traversing multiple functions of a target application through a client of a first tested role, and sending multiple request messages with data for the traversed multiple functions; counting multiple request messages sent by the client of the first tested role during traversing the multiple functions of the target application, and determining multiple target data, where the target data is data with a total occurrence times greater than a first preset occurrence times threshold among the data carried by the multiple request messages; determining multiple target functions from the multiple functions based on the multiple target data; and performing over - privilege detection on the multiple target functions.

[0017] Through the technical solution of the present application, it is possible to traverse multiple functions of the target application through the client operation of the first tested role and send multiple request messages with data, which can comprehensively cover all functions of the target application, ensure the breadth and depth of privilege escalation detection, and provide a comprehensive data basis for subsequent security analysis. Then, statistical analysis is performed on these request messages to determine the target data whose total occurrence times exceed the first preset occurrence threshold, and the corresponding function is reversely determined based on the target data as the target function, so that it is possible to determine which functions are important and need to be preferentially detected for privilege escalation among the multiple functions included in the target application, thereby optimizing the allocation of security resources, determining the priority and focus of privilege escalation detection, and improving the efficiency and flexibility of privilege escalation detection. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] The drawings constituting a part of this application are used to provide a further understanding of this application. The schematic embodiments and descriptions thereof of this application are used to explain this application and do not constitute an improper limitation to this application.

[0019] In order to more clearly illustrate the technical solution of this application, the drawings required to be used in the description of this application will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of this application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0020] Figure 1 It is a schematic flowchart of a privilege escalation detection method shown in an embodiment of this application; Figure 2 It is a schematic flowchart of a permission detection method shown in another embodiment of this application; Figure 3 It is a schematic framework diagram of a privilege escalation detection device shown in an embodiment of this application; Figure 4 It is a schematic diagram of an electronic device provided by an embodiment of this application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0021] It should be noted that, without conflict, the embodiments in this application and the features in the embodiments can be combined with each other.

[0022] Next, the technical solutions in the embodiments of this application will be clearly and completely described in conjunction with the drawings in the embodiments of this application. Obviously, the described embodiments are some, rather than all, of the embodiments of this application. Based on the embodiments in this application, all other embodiments obtained by those of ordinary skill in the art without creative efforts fall within the scope of protection of this application.

[0023] Web application: It is an application program that can be accessed through the Web. The greatest advantage is that users can easily access the application program. All they need is a browser, without the need to install other software. Application programs have two modes: C / S and B / S. C / S is a client / server program, which means that such programs generally run independently. While B / S is a browser / server application program, and such application programs generally run with the help of browsers such as IE. Web application programs generally use the B / S mode. A Web application program is first of all an "application program", and there is no essential difference from a program written in standard programming languages such as C and C++. A Web application program is composed of various Web components that complete specific tasks and presents services to the outside world through the Web. In practical applications, a Web application program is composed of multiple Servlets, JSP pages, HTML files, and image files, etc. All these components coordinate with each other to provide a complete set of services for users.

[0024] Web front-end: It refers to using computer languages such as HTML, CSS, and JavaScript to create an interface that can run on a browser and is visible to users, such as website web pages, APP software interfaces, Web application interfaces, etc.

[0025] Web back-end: It is the content that users cannot view and interact with in the browser, responsible for storing and processing data, and ensuring the normal operation of the Web application.

[0026] Page automation: A tool that can read test suites, execute tests, and record test results, simulating the operations of real users, including operations such as browsing pages, clicking links, entering text, submitting forms, and triggering mouse events, and can also verify various page results. That is to say, as long as the expected user behaviors and results are described in the test cases, we can obtain a functional test suite that can run automatically.

[0027] Web packet capture tool: A packet capture tool is software that intercepts and views the content of network packets. By analyzing the captured packets, useful information can be obtained. Our computers transmit data in the network by uploading and downloading some packets from the network. The packet capture tool can help us save these packets. If these packets are transmitted in plain text or we know their encryption methods, then we can analyze the content of these packets and their uses.

[0028] Unauthorized access vulnerability: It is one of the common business logic vulnerabilities in Web applications. It is caused by the server over-trusting the data operation request made by the client and ignoring the determination of the user's operation authority; or the R&D personnel only designed the authority verification on the Web front end, but the attacker can still send an unauthorized request on the back end to achieve his goal. The attacker can use a legitimate user to perform illegal operations on other users' data with unauthorized access vulnerabilities, such as query, insert, delete, modify and other regular database commands.

[0029] HTTP request: HTTP (HyperText Transfer Protocol) is based on the client / server (C / S) architecture model. It exchanges information through a reliable link and is a stateless request / response protocol. HTTP messages are the basis of communication between clients and servers. They consist of a series of text lines and follow a specific format and structure. HTTP messages are divided into two types: request messages and response messages. HTTP requests refer to request messages from the client to the server. It includes request URL (Uniform Resource Locator), request method, request header, request body and other parts. In actual Web application development, the business data of user roles is mainly stored in the request URL and request body. The request URL refers to the resource path of the request, which usually includes the host name, port number, path and query string.

[0030] Role: The type of user. Users with different roles have different permissions. Users with the same role have the same permissions. When creating a new user, you must specify the role to which it belongs. For example, super administrator, domain administrator, ordinary user, etc. are all roles.

[0031] Horizontal privilege escalation: This refers to an attacker trying to access the resources of a user at the same level as him. For example, a low-level attacker uses the role of a normal user to change the password of another user with the same role as a normal user. Vertical privilege escalation: refers to a low-level attacker trying to access the resources of a high-level user. For example, a low-level attacker uses the role of an ordinary user to successfully obtain a large amount of confidential data through a network attack. However, under normal circumstances, confidential data can only be viewed by the highest-level super administrator role.

[0032] The present application will be described in detail below with reference to the accompanying drawings and in combination with embodiments.

[0033] refer to Figure 1 , Figure 1 FIG. 1 is a flow chart of an unauthorized detection method shown in an embodiment of the present application. Figure 1As shown in the figure, a privilege escalation detection method provided by an embodiment of the present application includes steps S11 to S14: Step S11: Through the client of the first role under test, traverse multiple functions of the target application, and send multiple request messages with data to the traversed multiple functions.

[0034] In this embodiment, first, any one or more roles under test need to be selected. Different roles under test represent different user privilege levels, which are referred to as the first role under test here. The first role under test is any role including a super administrator, so it can traverse all functions of the target application and the requests corresponding to the functions.

[0035] Among them, the first role under test can be an ordinary user, a VIP user, and a super administrator. The target application can be any type of network application, such as a Web application, the network background of a mobile application, etc. "Function" refers to a specific operation or service in the target application, such as login, query, edit, etc.

[0036] Furthermore, after selecting the first role under test, through the client of the first role under test, such as a browser, traverse each of the multiple functions included in the target application in sequence. Automation scripts or tools (such as Selenium, Postman, etc.) can be used to simulate the behavior of the first role under test in the target application, including clicking buttons, filling out forms, uploading files, querying information, modifying and deleting, etc. In this process, in order to request multiple functions of the target application, the client of the first role under test will initiate request messages corresponding to the multiple functions to the target application. The request messages carry data, such as HTTP requests. These request messages will be sent to the server of the target application for further processing.

[0037] Step S12: Statistically analyze the multiple request messages sent by the client of the first role under test during the process of traversing the multiple functions of the target application, and determine multiple target data. The target data is the data in the data carried by the multiple request messages whose total occurrence times are greater than the first preset occurrence times threshold.

[0038] In this embodiment, during the process of traversing multiple functions, it is necessary to collect multiple request messages with data sent by the client of the first tested role, and analyze and statistically process the data in all the collected request messages to determine the target data. Among them, the target data is the data whose total occurrence times in all the data included in the multiple request messages is greater than the first preset occurrence threshold. That is to say, for each data carried in the multiple request messages, by counting the occurrence times of each data in each request message and summing up the occurrence times of this data in each request message, the total occurrence times of each data in the multiple request messages are obtained, and the total occurrence times of each data are compared with the first preset occurrence threshold. If the total occurrence times of a certain data exceed the first preset occurrence threshold, it is marked as the target data.

[0039] The first preset occurrence threshold is a standard in the privilege escalation detection method to determine which data appears frequently enough to be considered critical or sensitive data, and then identify the target data.

[0040] Optionally, the first preset occurrence threshold can be set based on historical data analysis, understanding of business logic, or suggestions from security experts.

[0041] Step S13: Determine multiple target functions from the multiple functions based on the multiple target data.

[0042] In this embodiment, after determining the target data, according to the identified target data, the functions corresponding to the target applications of the target data are determined in reverse, and these functions corresponding to the target data are determined as the target functions. Specifically, first list all the request messages containing the target data, and then analyze the functions corresponding to these request messages to determine the target functions. For example, if the target data is a specific resource ID, it is necessary to find all the request messages involving this resource ID, and then determine the target functions.

[0043] Step S14: Perform privilege escalation detection on the multiple target functions.

[0044] In this embodiment, the determined multiple target functions illustrate which functions among the multiple functions included in the target application are more important and which functions need to be preferentially subjected to privilege escalation detection. Then, actual privilege escalation detection is performed on the determined target functions to verify whether there are security vulnerabilities in each target function.

[0045] Through the technical solution shown in this embodiment, it is possible to traverse multiple functions of the target application and send request messages through the client operation of the first tested role, which can comprehensively cover all functions of the target application, ensure the breadth and depth of privilege escalation detection, and provide a comprehensive data basis for subsequent security analysis. Then, statistical analysis is performed on these request messages to determine the target data whose occurrence times exceed the first preset occurrence threshold, and the target function is reversely determined based on the target data, so that it is possible to determine which functions are important and need to be preferentially detected for privilege escalation among the multiple functions included in the target application, thereby optimizing the allocation of security resources and improving the efficiency and flexibility of privilege escalation detection.

[0046] This avoids the defect mentioned in the background art that there is no focus and priority during the detection process, excessive security penetration testing resources are consumed for functions with lower risks, but functions with higher risks cannot be identified as the key points.

[0047] Combined with the above embodiments, in one implementation manner, the embodiment of the present application also provides a permission detection method. Specifically, in the method of this embodiment, the step of "statistically analyzing the multiple request messages with data sent by the client of the first tested role during the process of traversing the multiple functions of the target application to determine multiple target data" in step S12 specifically includes steps S12-1 to S12-4: Step S12-1: Take the data in the query string and request body included in the multiple request messages as the data to be analyzed.

[0048] In this embodiment, for the data in the request message, taking the HTTP request as an example, it is necessary to identify and extract the key parts of the HTTP request, that is, the data in the query string and request body of the request message, and these data are regarded as the data to be analyzed. The query string is the query string of the request URL, which is the part after the "?" in the request URL. The request URL refers to the resource path of the request, usually including the host name, port number, path, and query string, and the request body is usually included in the POST or PUT request.

[0049] Exemplarily, the following is a GET-type request message:

[0050] Among them, the query string is: dir=desc&field=createTime&page=1&pageSze=15, dir=desc, where dir is the target data and desc is the value.

[0051] Exemplarily, the following is a request message of the POST type. The data in the black box is the data in the request body. For example, "isInitial": "false", where isInitial is the target data and false is the value.

[0052]

[0053] Step S12-2: For each of the multiple request messages, count the first occurrence times of the data to be analyzed included in the request message.

[0054] In this embodiment, count the data to be analyzed in each request message to determine the occurrence times of each piece of data to be analyzed in a single request message, that is, the first occurrence times, so as to identify the data to be analyzed that frequently appears in a single request message.

[0055] Step S12-3: Aggregate the first occurrence times of the data to be analyzed in each request message to determine the total occurrence times of each piece of data to be analyzed in the multiple request messages.

[0056] In this embodiment, not only focus on the first occurrence times of the data to be analyzed in a single request message, but also accumulate the occurrence times of each piece of data to be analyzed in all request messages to obtain the total occurrence times of each piece of data to be analyzed in all request messages. This total occurrence times is the key to determining whether the data to be analyzed is "target data".

[0057] Step S12-4: Determine the data to be analyzed whose total occurrence times is greater than the first preset occurrence times threshold as the target data.

[0058] In this embodiment, based on the comparison between the total occurrence times and the first preset occurrence times threshold, identify the data to be analyzed that frequently appears and may be related to the risk of unauthorized access. These data to be analyzed are marked as "target data" for subsequent unauthorized access detection steps.

[0059] Exemplarily, taking the target application as a Web application, the request message as an HTTP request, and the data to be analyzed including username (user name), uid (user ID), resourceid (resource ID), filepath (file path) as an example for illustration, Table 1 is a statistical table of the occurrence times of the data to be analyzed in each request message, as shown in Table 1.

[0060] First, parse the collected HTTP requests, extract the request URL query string and the data in the request body as target data, count the first occurrence times and the total occurrence times, and perform summarization and sorting. The following table shows an example result of the target data statistics. Among them, the target data "username" appears 3 times in HTTP request ③ and a total of 15 times in the HTTP requests initiated by the first tested role; the target data "resourceid" appears 1 time in HTTP request ④ and a total of 9 times in the HTTP requests initiated by the first tested role. Take the data to be analyzed whose total (i.e., the total occurrence times) in the sorting result in Table 1 is greater than the first preset occurrence threshold as the target data.

[0061] Table 1

[0062] Through the technical solution shown in this embodiment, taking the data in the query string and the request body as the data to be analyzed can more accurately capture the key information related to the behavior of the first tested role. Through summarization and statistics, it is determined which data to be analyzed are commonly and frequently used in the entire application. The functions corresponding to these data to be analyzed may be related to the key business processes. Therefore, special attention needs to be paid to the permission security of these functions. By screening out the data to be analyzed that are most likely related to the risk of unauthorized access, it provides a clear target for the focus and priority of subsequent unauthorized access detection for multiple functions, thereby improving the efficiency and accuracy of detection.

[0063] Combined with the above embodiments, in one implementation manner, the embodiment of the present application further provides an unauthorized access detection method. Specifically, in the method of this embodiment, in addition to the above steps, it may further include step S21 and step S22, and step S12-4 includes step S12-4-1.

[0064] Step S21: Take the data to be analyzed whose total occurrence times are greater than the first preset occurrence threshold as candidate data, and in combination with the actual business requirements of the target application and the requirements of security penetration testing, determine the second occurrence times of each candidate data in the usage information database of the target application. The usage information database of the target application includes at least one of the following: the front-end page display information of the target application, the product user manual of the target application, and the product installation manual of the target application.

[0065] In this embodiment, data items whose occurrence frequencies exceed the first preset threshold we set are screened out from all the data to be analyzed. These data items are considered candidate data, and these candidate data appear frequently and are associated with the key behaviors of the first tested role. For example, if "username" appears frequently in multiple request messages, it indicates that this candidate data is related to the key activities of the first tested role, such as login, data access, etc.

[0066] Furthermore, for the determined candidate data, in combination with the actual business requirements of the target application and the requirements of security penetration testing, the number of occurrences in the usage information database corresponding to the target application is analyzed. To distinguish the first number of occurrences, the number of occurrences in the usage information database corresponding to the target application is called the second number of occurrences.

[0067] Among them, the usage information database includes front-end page display information, product user manuals, product installation manuals, etc. By adopting such a method, the importance and sensitivity of each candidate data can be further verified according to the second number of occurrences. For example, if "resourceid" not only appears frequently in HTTP requests but is also mentioned multiple times in the user manual, that is, the first number of occurrences is greater than the first preset number of occurrences threshold, and the second number of occurrences is greater than the second preset number of occurrences threshold, it indicates that "resourceid" is closely related to the core business process of the target application, so it is used as the target data.

[0068] Step S22: Filter out the candidate data whose second number of occurrences is lower than the second preset number of occurrences threshold; In this embodiment, a second preset occurrence frequency threshold is set to exclude those candidate data with relatively low numbers of occurrences in the front-end page display information, product user manuals, and product installation manuals from the candidate data. These candidate data with relatively low numbers of occurrences are low-risk or non-critical data to be analyzed, or data to be analyzed that does not involve sensitive operations. Therefore, these candidate data with relatively low numbers of occurrences can be filtered out to reduce the scope of subsequent privilege escalation detection. For example, if "filepath" appears frequently in request messages but is rarely mentioned in business documents, that is, the first number of occurrences is greater than the first preset number of occurrences threshold, but the second number of occurrences is not greater than the second preset number of occurrences threshold, then "filepath" needs to be filtered out.

[0069] The step S12-4 includes: S12-4-1: Determine the remaining candidate data after filtering as the target data.

[0070] In this embodiment, after the above-mentioned screening process of candidate data, the remaining candidate data is officially determined as target data. These data items show a high frequency of occurrence in the request message, front-end page display information, product user manual, and product installation manual, indicating that these remaining candidate data are critical and sensitive and need to be particularly concerned about in privilege escalation detection. Therefore, they are used as the final target data.

[0071] Through the technical solution shown in this embodiment, on the basis of the previous embodiment, the number of occurrences of candidate data in the usage information database, that is, the second number of occurrences, is further considered, and based on the second number of occurrences, further screening of the candidate data is realized, so that data items that frequently appear in the target application and are closely related to the business process and security requirements, that is, target data, can be accurately identified. This not only provides a clear target and basis for privilege escalation detection, but also can reduce unnecessary security detections, avoid wasting resources on low-risk data, and thus improve the pertinence and efficiency of privilege escalation detection. In addition, it can also improve the security of the target application and the protection level of the business process.

[0072] Combined with the above embodiments, in one implementation manner, the embodiment of the present application further provides a privilege detection method. Specifically, in the method of this embodiment, the "determining a plurality of target functions from the plurality of functions based on the plurality of target data" in step S13 specifically includes step S13-1 and step S13-2.

[0073] Step S13-1: Based on the target data, perform reverse tracing in the plurality of request messages to determine the plurality of request messages where each target data is located.

[0074] In this embodiment, after determining a plurality of target data, use the target data as a clue to trace back the usage of these data in all request messages. The target data is the data to be analyzed that was identified as having a high frequency of occurrence and being possibly associated with critical functions in the previous steps, such as `username`, `uid`, `resourceid`, etc. Reverse tracing means finding the occurrence positions of these target data in all collected request messages and determining which request messages they specifically appear in.

[0075] During the reverse tracing process, record the request messages in which each target data appears. This includes recording the detailed information of the request, such as the request URL, method (GET, POST, etc.), request headers, and request body. The purpose of this step is to construct a request message library containing the target data, and the plurality of request messages in the request message library will be used for subsequent privilege escalation detection.

[0076] Step S13-2: Determine the multiple functions corresponding to the multiple request messages where the multiple target data are located as the multiple target functions.

[0077] In this embodiment, based on the request messages containing target data, determine which functions of the target application corresponding to these request messages. For example, if `resourceid` appears in the request, the corresponding functions may be the functions of viewing, editing, or deleting resources. This step involves analyzing the correspondence between the request messages and the functions of the target application to determine which functions need to be detected for privilege escalation. The functions corresponding to the request messages containing target data in the target application are determined as the target functions.

[0078] The technical solution shown in this embodiment is capable of accurately identifying the specific functions associated with the target data among the multiple functions of the target application. These functions have a great risk of privilege escalation and need to be preferentially and securely detected for privilege escalation to ensure that the focus of the privilege escalation detection is concentrated on those functions that are most likely to have security vulnerabilities, can be carried out more targeted, reduce the detection of non-critical functions, and thus optimize the entire privilege escalation detection process.

[0079] Combined with the above embodiments, in one implementation manner, the embodiments of the present application further provide a privilege detection method. Specifically, in the method of this embodiment, the "performing privilege escalation detection on the multiple target functions" in step S14 specifically includes steps S14-1 to S14-7. Figure 2 It is a schematic flowchart of a privilege detection method shown in another embodiment of the present application.

[0080] Step S14-1: Determine the multiple request messages corresponding to the multiple target functions as multiple target request messages.

[0081] In this embodiment, in this step, the request messages that have been identified as involving target data are determined as the target request messages, and there are corresponding target functions for the target request messages.

[0082] Step S14-2: Determine the current detection target request message for performing privilege escalation detection from the multiple target request messages.

[0083] In this embodiment, the target functions are the functions that need to be detected for privilege escalation using the process. For these multiple target functions, it is necessary to continue the privilege escalation detection in sequence. Therefore, first select one from all the target request messages as the current detection target, that is, the current detection target request message.

[0084] The process of selecting the current detection target request message can determine which target function to detect first based on the priority of the total occurrence times of the request message, the importance of the business logic, or the statistical data of historical security events. For example, if a request involves access to major sensitive data, it will be preferentially selected for privilege escalation detection.

[0085] Step S14-3: Select any role other than the first tested role as the second tested role.

[0086] In this embodiment, in this step, a role different from the first tested role (such as a super administrator) (i.e., the second tested role), such as a domain administrator or a VIP user, is selected to simulate the process of privilege escalation.

[0087] Step S14-4: Replace the value of the target data included in the target request message corresponding to the current detection target request message with the value of the second tested role from the value of the first tested role to obtain the replaced target data.

[0088] In this embodiment, the process of privilege escalation detection specifically involves a data replacement operation, that is, replacing the value of the target data (such as user ID) in the target request message from the value of the first tested role to the value of the second tested role. For example, the value of the target data username corresponding to the first tested role is test, while the value corresponding to the second tested role is admin. Here, it is necessary to replace the value test of the tested data username with admin.

[0089] Step S14-5: Generate a new target request message based on the replaced target data and send the new target request message to the target application.

[0090] In this embodiment, after the value replacement of the target data is completed, a new request message can be generated according to the replaced target data. This request message contains the value of the replaced target data and, through the first tested role, sends this new request message to the target application. Thus, it simulates the first tested role's actual privilege escalation attack behavior with the value of the second tested role to test whether the target application can identify and prevent this unauthorized access to the target function.

[0091] Step S14-6: Determine the detection result of the privilege escalation detection for each target function according to the response result of the server of the target application to the new target request message.

[0092] In this embodiment, the result of privilege escalation detection is further determined according to the response of the server of the target application to the new request message. When the server returns a successful response, it indicates that there is a privilege escalation vulnerability in the target function corresponding to the currently detected target request message; when a failure or rejection response is returned, it indicates that the privilege escalation attempt has been correctly blocked.

[0093] Step S14-7: After determining that the privilege escalation detection of the currently detected target request message is completed, reselect the second tested role, and re-determine the next currently detected target request message from the multiple target request messages, and execute the above privilege escalation detection process until the privilege escalation detection of all the multiple target functions is completed.

[0094] In this embodiment, after the privilege escalation detection of a target request message is completed, we will continue to select a new second tested role and a new target request message, and repeat the detection process of steps S14-1 to S14-6 above until the privilege escalation detection of all target functions is completed. This step ensures the comprehensiveness of the privilege escalation detection and covers all privilege escalation scenarios.

[0095] It should be noted that the detection of the target request message in this article is equivalent to the detection of the target function, and the target request message and the target function are in one-to-one correspondence.

[0096] Through the technical solution shown in this embodiment, all target functions are traversed and privilege escalation detection is performed, ensuring the comprehensiveness of the detection and not missing any possible privilege escalation risk points. By precisely replacing the target data and simulating privilege escalation attempts between different roles, the accuracy of the detection result is improved, and false positives and false negatives are reduced. The automated privilege escalation detection process reduces manual intervention, improves the detection efficiency, and at the same time reduces the detection errors caused by human factors. By sending request messages in real time and analyzing the response results, privilege escalation vulnerabilities can be discovered and responded to in a timely manner, enhancing the real-time protection ability of the system. By identifying and fixing privilege escalation vulnerabilities, the security of the target application is significantly improved, protecting user data and business processes from unauthorized access.

[0097] Combined with the above embodiments, in one implementation, the embodiment of the present application further provides a privilege detection method. Specifically, in the method of this embodiment, "performing privilege escalation detection on the multiple target functions" in step S14 further specifically includes steps S14-8 to S14-10: Step S14-8: For each target function, respectively select multiple second tested roles with the same and different levels as the first tested role.

[0098] In this embodiment, the first tested role is the attacker, and the second tested role is the victim. For the selection of the second tested role, in order to fully cover the comprehensiveness of the privilege escalation detection process, not only roles with different privilege levels from the first tested role need to be selected, but also roles with the same privilege level need to be selected, so as to comprehensively test the impact of roles with different privilege levels on the target function, including horizontal privilege escalation (privilege escalation between users of the same level) and vertical privilege escalation (privilege escalation between users of different levels).

[0099] Step S14-9: When the level of the second tested role is the same as that of the first tested role, perform horizontal privilege escalation detection on the target application; when the response result of the horizontal privilege escalation detection indicates that the target application returns a normal response, determine that the detection result is that there is a horizontal privilege escalation vulnerability in the target function.

[0100] In this embodiment, performing privilege escalation detection between two roles with the same privilege level is called horizontal privilege escalation detection. For example, both of the two tested roles are ordinary users, but the first tested role attempts to access or modify the personal data of the second tested role, which belongs to horizontal privilege escalation. Therefore, in this step, it is possible to detect whether a tested role at the same level can access or modify the protected data or privilege function of another tested role. When the target application returns a normal response in the horizontal privilege escalation detection, it means that the first tested role can achieve privilege escalation operation on the target function of the second tested role, indicating the existence of a horizontal privilege escalation vulnerability.

[0101] Step S14-10: When the level of the second tested role is higher than that of the first tested role, perform vertical privilege escalation detection on the target application; when the response result of the vertical privilege escalation detection indicates that the target application returns a normal response, determine that the detection result is that there is a vertical privilege escalation vulnerability in the target function.

[0102] In this embodiment, performing privilege escalation detection between two roles with different privilege levels is called vertical privilege escalation detection. For example, the first tested role is an ordinary user, and the second tested role is an administrator. If an ordinary user attempts to perform an administrator-level operation, it is necessary to replace the value of the target data of the first tested role with the value of the target data of the second tested role to achieve the privilege escalation behavior, which belongs to vertical privilege escalation. When the target application returns a normal response in the vertical privilege escalation detection, it means that a user with a low privilege level (i.e., the first tested role) can successfully execute the protected data or privilege function of a user with a high privilege level (i.e., the second tested role), indicating the existence of a vertical privilege escalation vulnerability.

[0103] Through the technical solution shown in this embodiment, it is possible to detect horizontal and vertical privilege escalation simultaneously, ensuring comprehensive privilege escalation detection for users with different privilege levels, and improving the comprehensiveness of detection. In this process, by simulating privilege escalation behaviors between roles with different privilege levels, horizontal and vertical privilege escalation vulnerabilities can be accurately identified, improving the accuracy of detection results, helping the target application meet relevant security compliance requirements, and reducing risks caused by security vulnerabilities.

[0104] Combined with the above embodiments, in one implementation, the embodiments of the present application further provide a privilege detection method. Specifically, in the method of this embodiment, the step of "traversing multiple functions of the target application through the client of the first tested role and sending multiple request messages with data to the traversed multiple functions" in step S11 specifically includes step S11-1 and step S11-2.

[0105] Step S11-1: Through the page automation tool of the target application, select any role of any user as the first tested role, traverse multiple functions of the target application, and send a request message to each traversed function.

[0106] In this embodiment, for the traversal process of multiple functions of the target application, automation tools such as Selenium or Puppeteer can be used to simulate the behavior of the first tested role. These tools can automatically perform operations such as clicking, filling out forms, and submitting data, thereby traversing various functions of the target application. In this process, the automation tool will act as the first tested role, that is, the set test user, which can be an ordinary user, an administrator, or any other predefined role. Traversing functions means accessing all pages and functions of the application to trigger the generation of request messages, such as HTTP requests.

[0107] Step S11-2: Through the packet capture tool of the target application, intercept and save the multiple request messages corresponding to the multiple functions covered by the first tested role.

[0108] In this embodiment, while the automation tool simulates the operations of the first tested role, a packet capture tool such as Wireshark or Fiddler is used to intercept the sent request messages and response messages. These request messages are then saved for subsequent data analysis and privilege escalation detection. The saved request messages include information such as the URL, request method, request headers, query string, and request body.

[0109] Through the technical solution shown in this embodiment, the combined use of automation tools and packet capture tools provides a comprehensive, accurate, and efficient test and data collection basis for privilege escalation detection, thereby improving the security of the target application and the efficiency of the privilege escalation detection process.

[0110] In an alternative embodiment, in combination with the above embodiments, in step S11, during the process of automatically traversing all functions of the target application, the behaviors of multiple historical roles can be analyzed, and then traversal can be performed using the client of the first tested role, so as to simulate more realistic user operations and increase the diversity and authenticity of request messages. Specifically, in this process, machine learning techniques such as clustering analysis can be used to perform pattern recognition on the behaviors of multiple historical roles. By analyzing the behaviors of historical roles, these behaviors include: page residence time, mouse movement trajectory, click pattern, page access order, operation frequency, etc., to learn the behavior habits of historical roles in the target application. Finally, a baseline model of the role behavior pattern is established, and based on the identified behavior pattern, an automated test script is developed to simulate the behavior operations of the role to traverse each function point of the target application.

[0111] In addition, to further achieve the convenience of automatically traversing all functions of the target application, request message templates corresponding to the request operations of different types of first tested roles can be created, including necessary request headers, query parameters, and request bodies, and parameterized scripts can be developed to dynamically generate the data in the request messages to simulate the input and real-time data changes of the first tested role. Then, an automated tool is used to send these dynamically generated request messages to test the processing of the target application for different inputs.

[0112] Through the above embodiments, the privilege escalation detection scheme can be more in line with the actual situation, effectively identify and preferentially detect potential security vulnerabilities in the target application, and improve the security and efficiency of each function of the entire target application.

[0113] Based on the same inventive concept, another embodiment of the present application further provides a privilege escalation detection device. Figure 3 It is a framework schematic diagram of a privilege escalation detection device shown in an embodiment of the present application, as Figure 3 shown. The device includes: A function traversal module 11, configured to traverse multiple functions of the target application through the client of the first tested role, and send multiple request messages with data to the multiple functions traversed; A data statistics module 12, configured to count the multiple request messages sent by the client of the first tested role during the process of traversing the multiple functions of the target application, and determine multiple target data, where the target data is the data whose total occurrence times in the data carried by the multiple request messages is greater than the first preset occurrence times threshold; A target function determination module 13, configured to determine multiple target functions from the multiple functions based on the multiple target data; A privilege escalation detection module 14, configured to perform privilege escalation detection on the multiple target functions.

[0114] Optionally, the data statistics module 12 includes: A to-be-analyzed data determination unit, configured to use the query string and the data in the request body included in the multiple request messages as the to-be-analyzed data; A first occurrence count unit, configured to, for each of the multiple request messages, count the first occurrence count of the to-be-analyzed data included in the request message; A total occurrence count unit, configured to summarize the first occurrence counts of the to-be-analyzed data in each request message, and determine the total occurrence count of each to-be-analyzed data in the multiple request messages; A target data determination unit, configured to determine the to-be-analyzed data with a total occurrence count greater than a first preset occurrence count threshold as the target data.

[0115] Optionally, the apparatus further includes: A candidate data determination unit, configured to use the to-be-analyzed data with a total occurrence count greater than a first preset occurrence count threshold as candidate data, and in combination with the actual business requirements of the target application and the requirements of security penetration testing, determine the second occurrence count of each candidate data in the usage information database of the target application, where the usage information database of the target application includes at least one of the following: the front-end page display information of the target application, the product user manual of the target application, and the product installation manual of the target application; A filtering unit, configured to filter out the candidate data with a second occurrence count lower than a second preset occurrence count threshold; The target data determination unit includes: A target data determination subunit, configured to determine the remaining candidate data after filtering as the target data.

[0116] Optionally, the target function determination module 13 includes: A reverse tracing unit, configured to perform reverse tracing in the multiple request messages based on the target data, and determine the multiple request messages where each target data is located; A target function determination unit, configured to determine the multiple functions corresponding to the multiple request messages where the multiple target data are located as the multiple target functions.

[0117] Optionally, the privilege escalation detection module 14 includes: A target request message determination unit, configured to determine the multiple request messages corresponding to the multiple target functions as multiple target request messages; A current detection target request message determination unit, configured to determine a current detection target request message for privilege escalation detection from the multiple target request messages; The second tested role selects a first unit to select any role other than the first tested role as the second tested role; A replacement unit is used to replace the value of the target data included in the target request message corresponding to the current detection target request message with the value of the second tested role from the value of the first tested role, to obtain the replaced target data; A target request message sending unit is used to generate a new target request message based on the replaced target data, and send the new target request message to the target application; A detection result determination unit is used to determine the detection result of the privilege escalation detection for each target function according to the response result of the server of the target application for the new target request message; A loop unit is used to, after determining that the privilege escalation detection of the current detection target request message is completed, re-select the second tested role, and re-determine the next current detection target request message from the multiple target request messages, and execute the above process of the privilege escalation detection until the privilege escalation detection of all the multiple target functions is completed.

[0118] Optionally, the privilege escalation detection module 14 includes: A second tested role selection second unit is used to, for each target function, respectively select multiple second tested roles with the same and different levels as the first tested role; A horizontal privilege escalation detection unit is used to perform horizontal privilege escalation detection on the target application when the level of the second tested role is the same as the level of the first tested role; when the response result of the horizontal privilege escalation detection indicates that the target application returns a normal response, determine that the detection result is that the target function has a horizontal privilege escalation vulnerability; A vertical privilege escalation detection unit is used to perform vertical privilege escalation detection on the target application when the level of the second tested role is higher than the level of the first tested role; when the response result of the vertical privilege escalation detection indicates that the target application returns a normal response, determine that the detection result is that the target function has a vertical privilege escalation vulnerability.

[0119] Optionally, the function traversal module 11 includes: A traversal unit is used to, through the page automation tool of the target application, select any role of any user as the first tested role, traverse multiple functions of the target application, and send request messages to each traversed function; A collection unit is used to, through the packet capture tool of the target application, intercept and save the multiple request messages corresponding to the multiple functions covered by the first tested role.

[0120] Based on the same inventive concept, another embodiment of the present application further provides an electronic device, including a memory, a processor, and a computer program stored on the memory. Wherein, the processor executes the computer program to implement the unauthorized access detection method as described in any of the above embodiments.

[0121] Among them, the electronic device refers to Figure 4 , Figure 4 which is a schematic diagram of an electronic device provided by an embodiment of the present application. As Figure 4 shown, the electronic device 400 includes: a memory 410 and a processor 420. The memory 410 and the processor 420 are communicatively connected via a bus. A computer program is stored in the memory 410, and the computer program can run on the processor 420, thereby implementing the steps in the unauthorized access detection method disclosed in the above embodiments of the present application.

[0122] Based on the same inventive concept, another embodiment of the present application further provides a computer program product, including a computer program, and the computer program is executed by a processor to implement the unauthorized access detection method as described in any of the above embodiments.

[0123] Based on the same inventive concept, another embodiment of the present application further provides a computer-readable storage medium, on which a computer program is stored. Wherein, when the program is executed by a processor, it implements the unauthorized access detection method as described in any of the above embodiments.

[0124] For the device, since it is basically similar to the method embodiment, the description is relatively simple. For the relevant parts, refer to the partial description of the method embodiment.

[0125] Each embodiment in this specification is described in a progressive manner. The key point of each embodiment is to illustrate the differences from other embodiments. For the same or similar parts among the embodiments, reference can be made to each other.

[0126] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a device, or a computer program product. Therefore, the embodiments of the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the embodiments of the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memories, CD-ROMs, optical memories, etc.) containing computer-usable program codes.

[0127] Embodiments of the present application are described with reference to the flowcharts and / or block diagrams of methods, terminal devices (systems), and computer program products according to embodiments of the present application. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing terminal devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing terminal devices generate a device for implementing the functions specified in one process Figure 1 one process or multiple processes and / or blocks Figure 1 or a device for implementing the functions specified in multiple blocks

[0128] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing terminal device to work in a specific manner, such that the instructions stored in the computer-readable memory generate a manufactured article including an instruction device, and the instruction device implements the functions specified in one process Figure 1 one process or multiple processes and / or blocks Figure 1 or the functions specified in multiple blocks

[0129] These computer program instructions can also be loaded onto a computer or other programmable data processing terminal device, such that a series of operation steps are executed on the computer or other programmable terminal device to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable terminal device provide steps for implementing the functions specified in one process Figure 1 one process or multiple processes and / or blocks Figure 1 or the functions specified in multiple blocks

[0130] Although the preferred embodiments of the embodiments of the present application have been described, those skilled in the art can make additional changes and modifications to these embodiments once they know the basic creative concepts. Therefore, the appended claims are intended to be construed as including the preferred embodiments and all changes and modifications that fall within the scope of the embodiments of the present application

[0131] Finally, it should also be noted that in this text, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or terminal device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or elements inherent to such process, method, article or terminal device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, article or terminal device comprising the element.

[0132] The above has introduced in detail a privilege violation detection method, apparatus, device and medium provided by the present application. Specific examples are used in this text to elaborate on the principle and implementation manner of the present application. The description of the above embodiments is only used to help understand the method and its core idea of the present application; at the same time, for those of ordinary skill in the art, according to the idea of the present application, there will be changes in the specific implementation manner and application scope. In summary, the content of this specification should not be construed as a limitation to the present application.

Claims

1. A method for detecting unauthorized access, characterized in that: The method comprises: Through the client of the first tested role, multiple functions of the target application are traversed, and multiple request messages with data are sent to the traversed multiple functions; Counting multiple request messages sent by the client of the first tested role in the process of traversing multiple functions of the target application, and determining multiple target data, where the target data is data with a total occurrence count greater than a first preset occurrence count threshold in the data carried by the multiple request messages; Based on the plurality of target data, determining a plurality of target functions from the plurality of functions; An unauthorized detection is performed on the multiple target functions.

2. The unauthorized detection method according to claim 1, characterized in that: The step of counting multiple request messages with data sent by the client of the first tested role in the process of traversing multiple functions of the target application to determine multiple target data includes: Using the query strings and the data in the request bodies contained in the multiple request messages as data to be analyzed; For each request message among the multiple request messages, counting the first occurrence number of the data to be analyzed contained in the request message; Summarizing the first occurrence number of the data to be analyzed in each request message to determine the total occurrence number of each data to be analyzed in the multiple request messages; The data to be analyzed whose total occurrence times are greater than a first preset occurrence times threshold are determined as the target data.

3. The unauthorized detection method according to claim 2, characterized in that: Also includes: The data to be analyzed whose total number of occurrences is greater than the first preset number of occurrences threshold is used as candidate data, and a second number of occurrences of each candidate data in a usage information database of the target application is determined in combination with the actual business needs of the target application and the requirements of the security penetration test, wherein the usage information database of the target application includes at least one of the following: front-end page display information of the target application, a product user manual of the target application, and a product installation manual of the target application; Filter out candidate data whose second occurrence count is lower than a second preset occurrence count threshold; Determining the data to be analyzed whose total number of occurrences is greater than a first preset number of occurrences threshold as the target data includes: The candidate data remaining after filtering is determined as the target data.

4. The unauthorized detection method according to claim 1, characterized in that: The determining of a plurality of target functions from the plurality of functions based on the plurality of target data comprises: Based on the target data, reverse tracing is performed in the multiple request messages to determine the multiple request messages where each target data is located; The multiple functions corresponding to the multiple request messages where the multiple target data are located are determined as the multiple target functions.

5. The unauthorized detection method according to claim 1, characterized in that: The performing unauthorized detection on the multiple target functions includes: Determine the multiple request messages corresponding to the multiple target functions as multiple target request messages; Determining a current detection target request message for performing unauthorized detection from the multiple target request messages; Selecting any role other than the first tested role as the second tested role; Replacing the value of the target data contained in the target request message corresponding to the current target detection request message by the value of the first measured role with the value of the second measured role, to obtain the replaced target data; generating a new target request message based on the replaced target data, and sending the new target request message to the target application; Determine, according to the response result of the server of the target application to the new target request message, the detection result of the unauthorized detection for each target function; After determining that the unauthorized detection of the current detection target request message is completed, reselect the second role to be tested, and re-determine the next current detection target request message from the multiple target request messages, and perform the above-mentioned unauthorized detection process until the unauthorized detection of the multiple target functions is completed.

6. The unauthorized detection method according to claim 5, characterized in that: The performing unauthorized detection on the multiple target functions includes: For each target function, selecting a plurality of second tested roles having the same or different levels as the first tested role respectively; When the level of the second tested role is the same as the level of the first tested role, a lateral privilege escalation detection is performed on the target application; when the response result of the lateral privilege escalation detection indicates that the target application returns a normal response, it is determined that the detection result is that the target function has a lateral privilege escalation vulnerability; When the level of the second tested role is higher than the level of the first tested role, a vertical unauthorized access detection is performed on the target application; when the response result of the vertical unauthorized access detection indicates that the target application returns a normal response, it is determined that the detection result is that the target function has a vertical unauthorized access vulnerability.

7. The unauthorized detection method according to any one of claims 1 to 6, characterized in that: The method of traversing multiple functions of the target application through the client of the first tested role and sending multiple request messages with data to the traversed multiple functions includes: By using the page automation tool of the target application, any role of any user is selected as the first tested role, multiple functions of the target application are traversed, and a request message is sent to each traversed function; A plurality of request messages corresponding to a plurality of functions covered by the first tested role are intercepted and saved through a packet capture tool of the target application.

8. An unauthorized detection device, characterized in that: The device comprises: A function traversal module, used to traverse multiple functions of the target application through the client of the first tested role, and send multiple request messages with data to the traversed multiple functions; A data statistics module, used to count multiple request messages sent by the client of the first tested role in the process of traversing multiple functions of the target application, and determine multiple target data, where the target data is data with a total occurrence count greater than a first preset occurrence count threshold in the data carried by the multiple request messages; a target function determination module, configured to determine a plurality of target functions from the plurality of functions based on the plurality of target data; The unauthorized detection module is used to perform unauthorized detection on the multiple target functions.

9. An electronic device, characterized in that: The system comprises a memory, a processor and a computer program stored in the memory, wherein the processor executes the computer program to implement the unauthorized detection method according to any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that: A computer program is stored thereon, wherein when the computer program is executed by a processor, the unauthorized detection method according to any one of claims 1 to 7 is implemented.