Automatic Web API authentication type vulnerability scanning method and system
Through the automated Web API authentication vulnerability scanning method, the authentication item mutation and identifier mutation technology are used to solve the problem of the inreliability of the Web API authentication mechanism, and efficient vulnerability scanning and security improvement are achieved.
Patent Information
- Application Number
- CN202510138903.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-08
- Publication Date
- 2025-06-03
AI Technical Summary
In the prior art, the authentication mechanism of the Web API is not reliable enough and is easily exploited by attackers, resulting in data breaches and enterprise losses.
It provides an automated web API authentication vulnerability scanning method, accesses the system to be tested through bypass mode, parses the authentication mechanism, parameter items and permission identification items, builds the API asset library, and uses authentication item mutation and identifier mutation technology to adaptively construct attack requests, perform vulnerability scanning tests and result judgments.
It significantly improves the automation level and efficiency of Web API authentication vulnerability scanning, enhances the security of Web API systems, shortens the security assessment cycle, and improves the response speed to security threats.
Smart Images

Figure CN120090821A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and particularly to an automated Web API authentication vulnerability scanning method and system. Background Art
[0002] Currently, Web Application Programming Interfaces (Web APIs) have become key components for data exchange and network services, and are also the core of enterprise digital assets. For this reason, Web APIs have become key targets for attackers to steal data. In this context, the Web API authentication mechanism responsible for verifying "what operations can the caller perform" is particularly crucial. In recent years, attackers have exploited Web API authentication vulnerabilities to steal a large amount of personal privacy information of users, resulting in significant financial losses and reputational damage to enterprises. The important reason for the existence of such security threats is that the Web API authentication mechanisms of manufacturers are not reliable enough. A sound authentication mechanism should be able to ensure that only authorized users or systems can access the specified API, effectively solve the problems of what permissions the Web API caller has, what operations can be performed, and what resources can be accessed, and prevent the API from being illegally called. However, in the prior art, many Web APIs have problems such as lax authentication, insufficient policy implementation, or easy bypass of the authentication mechanism, which have become the main breakthrough points for attackers to exploit Web APIs.
[0003] Ensuring the reliability of the Web API authentication mechanism has become a key link in ensuring API security and a necessary measure to safeguard the interests of enterprises and users. Existing tools mainly conduct research on the security of Web APIs from the perspective of code or specifications, but this perspective cannot effectively cover the scenario of detecting authentication-related business logic vulnerabilities. The detection of vulnerabilities in the authentication-related business logic scenario still highly relies on manual analysis or semi-automated tools at present. Therefore, how to achieve automatic scanning of Web API authentication vulnerabilities has become an urgent problem to be solved. Summary of the Invention
[0004] The present invention aims to at least solve one of the problems existing in the prior art, and provides an automated Web API authentication vulnerability scanning method and system.
[0005] In one aspect of the present invention, an automated Web API authentication vulnerability scanning method is provided. The method includes:
[0006] Access the system to be tested in a bypass mode, parse the authentication mechanism, authentication parameter items, and permission identification items used by the Web APIs of the system to be tested, collect the prerequisite information required for authentication vulnerability scanning, and construct an API asset library;
[0007] Based on the attack scheduling strategy, authentication item mutation and identifier mutation technologies are adopted. From the perspective of an attacker, authentication item attack requests and identifier mutation attack requests in different scenarios are adaptively constructed, and vulnerability scanning tests are initiated based on the authentication item attack requests and the identifier mutation attack requests;
[0008] According to the original request response given by the Web API, as well as the authentication item attack request response and the identifier mutation attack request response, based on the response feature recognition technology and the similarity detection technology, the vulnerability scanning result is determined, and a vulnerability scanning report is generated.
[0009] Optionally, access the system under test in a bypass mode, analyze the authentication mechanism, authentication parameter items, and permission identification items used by the Web API of the system under test, collect the prerequisite information required for authentication vulnerability scanning, and construct an API asset library, including:
[0010] Access the system under test in a bypass traffic proxy mode and filter non-API traffic;
[0011] Analyze the traffic characteristics of Web API requests and identify different framework types of the Web API; wherein, the traffic characteristics include the structure of Web API requests, the protocols used, and the data formats;
[0012] Adopt corresponding traffic preprocessing modes for the Web API of different framework types, and analyze the authentication mechanisms, authentication parameter items, and permission identification items corresponding to the Web API of each framework category;
[0013] Identify the permission levels and sensitivity levels of the Web API, and store the authentication mechanisms, the authentication parameter items, the permission identification items, the permission levels, and the sensitivity levels corresponding to the Web API of each framework category into the API asset library.
[0014] Optionally, the step of, based on the attack scheduling strategy, adopting authentication item mutation and identifier mutation technologies, adaptively constructing authentication item attack requests and identifier mutation attack requests in different scenarios from the perspective of an attacker, and initiating vulnerability scanning tests based on the authentication item attack requests and the identifier mutation attack requests includes:
[0015] According to the traffic characteristics of the Web API and the authentication mechanism, cut into the authentication vulnerability scanning from the perspective of the attacker, design an adaptive attack scheduling strategy, and manage and schedule different forms of authentication attack tests;
[0016] According to the attack scheduling strategy, construct the authentication item attack request and the identifier mutation attack request based on the authentication item mutation technology and the permission identifier mutation technology respectively in different scenarios; wherein, both the authentication item attack request and the identifier mutation attack request include attack request packets in three forms: unauthorized attack, horizontal privilege escalation attack, and vertical privilege escalation attack.
[0017] Optionally, based on the original request response given by the Web API, the authentication item attack request response, and the identifier mutation attack request response, determine the vulnerability scanning result based on the response feature recognition technology and the similarity detection technology, including:
[0018] Based on the result comprehensive determination strategy, according to the original request response, the authentication item attack request response, and the identifier mutation attack request response, combined with the API asset library, use the response feature recognition technology and the similarity detection technology to determine the attack results of the authentication item attack request and the identifier mutation attack request, discover vulnerabilities, and obtain the vulnerability scanning result.
[0019] Optionally, determining the attack results of the authentication item attack request and the identifier mutation attack request includes:
[0020] If the similarity of the response content between the authentication item attack request response and the original request response is higher than the first content threshold, it is determined that the authentication item attack request is successful.
[0021] If the characteristics of the identifier mutation attack request response are consistent with those of the original request response, the response structure similarity is higher than the structure threshold, and the response content similarity is lower than the second content threshold, it is determined that the identifier mutation attack request is successful.
[0022] Optionally, generating the vulnerability scanning report includes:
[0023] Record the attack results and generate the vulnerability scanning report including Web API endpoint information, detection result type, original request response, and attack request response.
[0024] Another aspect of the present invention provides an automated Web API authentication vulnerability scanning system, the system includes:
[0025] Web API traffic preprocessing module, used to access the system under test in a bypass mode, parse the authentication mechanism, authentication parameter items, and permission identification items used by the Web API of the system under test, collect the precondition information required for authentication vulnerability scanning, and construct an API asset library;
[0026] Web API Authentication Attack Request Automatic Construction Module, which is used to adaptively construct authentication item attack requests and identifier mutation attack requests in different scenarios from the perspective of an attacker based on an attack scheduling strategy, using authentication item mutation and identifier mutation technologies, and initiate vulnerability scanning tests based on the authentication item attack requests and the identifier mutation attack requests;
[0027] Web API Authentication Vulnerability Automatic Judgment Module, which is used to determine the vulnerability scanning results based on the response feature recognition technology and similarity detection technology according to the original request response given by the Web API, the authentication item attack request response, and the identifier mutation attack request response, and generate a vulnerability scanning report.
[0028] Another aspect of the present invention provides an electronic device, including:
[0029] At least one processor; and,
[0030] A memory communicatively connected to at least one processor; wherein,
[0031] The memory stores instructions executable by at least one processor. The instructions are executed by at least one processor so that at least one processor can execute the automated Web API authentication class vulnerability scanning method described above.
[0032] Another aspect of the present invention provides a computer-readable storage medium storing a computer program, and when the computer program is executed by a processor, it implements the automated Web API authentication class vulnerability scanning method described above.
[0033] Another aspect of the present invention provides a computer program product including a computer program, and when the computer program is executed by a processor, it implements the automated Web API authentication class vulnerability scanning method described above.
[0034] Compared with the prior art, the present invention has general vulnerability scanning adaptability to different Web API frameworks, can adaptively generate effective and diverse authentication attack test requests according to specific scenarios, automatically determine the existence of vulnerabilities based on various traffic characteristics, significantly improves the automation level and efficiency of Web API authentication class vulnerability scanning, enhances the security of the Web API system, shortens the security assessment cycle, and improves the response speed to security threats. BRIEF DESCRIPTION OF THE DRAWINGS
[0035] One or more embodiments are exemplarily illustrated by the pictures in the corresponding drawings. These exemplary illustrations do not constitute limitations on the embodiments. Elements with the same reference numerals in the drawings are represented as similar elements, unless otherwise stated, and the drawings in the drawings do not constitute a scale limitation.
[0036] Figure 1 Flow chart of an automated Web API authentication - type vulnerability scanning method provided by an embodiment of the present invention;
[0037] Figure 2 Schematic diagram of the automatic construction process of Web API authentication attack requests provided by another embodiment of the present invention;
[0038] Figure 3 Schematic diagram of the automatic determination process of Web API authentication vulnerabilities provided by another embodiment of the present invention;
[0039] Figure 4 Schematic diagram of the structure of an automated Web API authentication - type vulnerability scanning system provided by another embodiment of the present invention;
[0040] Figure 5 Schematic diagram of the structure of an electronic device provided by another embodiment of the present invention. Specific embodiments
[0041] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the embodiments of the present invention will be elaborated in detail below with reference to the accompanying drawings. However, those of ordinary skill in the art can understand that in the embodiments of the present invention, many technical details are provided for readers to better understand the present invention. However, even without these technical details and various changes and modifications based on the following embodiments, the technical solutions claimed by the present invention can still be implemented. The following division of each embodiment is for convenience of description and should not constitute any limitation to the specific implementation of the present invention. Each embodiment can be combined and cross - referenced with each other on the premise of no contradiction.
[0042] One embodiment of the present invention relates to an automated Web API authentication - type vulnerability scanning method, and its process is as Figure 1 shown, including steps S1 to S3.
[0043] Step S1, access the system to be tested in a bypass mode, analyze the authentication mechanism, authentication parameter items, and permission identification items used by the Web API of the system to be tested, collect the prerequisite information required for authentication vulnerability scanning, and construct an API asset library.
[0044] Step S1 may specifically include: accessing the system under test in the bypass traffic proxy mode to filter non-API traffic; analyzing the traffic characteristics of Web API requests to identify different framework types of Web APIs; adopting corresponding traffic preprocessing modes for Web APIs of different framework types, and parsing the authentication mechanisms, authentication parameter items, and permission identifier items respectively corresponding to each framework category of Web APIs; identifying the permission levels and sensitivity levels of Web APIs, and storing the authentication mechanisms, authentication parameter items, permission identifier items, permission levels, and sensitivity levels corresponding to each framework category of Web APIs in the API asset library.
[0045] Among them, the traffic characteristics of Web API requests include the structure of Web API requests, the protocols used, and the data formats. The framework types of Web APIs may include mainstream framework types such as REST, GraphQL, gRPC, and SOAP API.
[0046] When adopting corresponding traffic preprocessing modes for Web APIs of different framework types and parsing the authentication mechanisms, authentication parameter items, and permission identifier items respectively corresponding to each framework category of Web APIs, it is possible to analyze at positions such as the URL query, request header, request cookie, and request body of the Web API traffic of each framework category to fully parse information such as the authentication mechanisms, authentication parameter items, and permission identifier items used by the Web API.
[0047] The API asset library may store complete API data information such as the authentication mechanisms, authentication parameter items, permission identifier items, permission levels, and sensitivity levels corresponding to each framework category of Web APIs, so as to provide necessary and accurate pre-information for subsequent automated authentication vulnerability scanning.
[0048] Step S2, based on the attack scheduling strategy, adopt the authentication item mutation and identifier mutation technologies to adaptively construct authentication item attack requests and identifier mutation attack requests in different scenarios from the perspective of an attacker, and initiate vulnerability scanning tests based on the authentication item attack requests and identifier mutation attack requests.
[0049] Specifically, on the premise of personalized configuration of vulnerability scanning, step S2 can adopt the following attack scheduling strategy: If it is determined that the API to be tested does not belong to the public user privilege level, attack testing can be carried out based on the authentication item mutation technology; if there is no API with a higher privilege level of the same type in the API asset library, attack testing is carried out based on the identifier mutation technology. This is because when there are differences in the privilege levels of Web APIs, the authentication item mutation technology can well test vertical privilege escalation attacks, and when the privilege levels of Web APIs are the same, the identifier mutation technology is required to supplement the test for vertical privilege escalation attack scenarios. By setting the above attack scheduling strategy in this embodiment, the comprehensiveness of the attack surface test can be ensured, and at the same time, the corresponding attack testing technology can be used in specific scenarios, thereby improving the system efficiency. Among them, the API to be tested here can be any Web API in the system to be tested.
[0050] Specifically, step S2 may specifically include: According to the traffic characteristics and authentication mechanism of the Web API, starting from the perspective of an attacker to conduct authentication vulnerability scanning, designing an adaptive attack scheduling strategy, and managing and scheduling different forms of authentication attack testing; According to the attack scheduling strategy, construct an authentication item attack request and an identifier mutation attack request based on the authentication item mutation technology and the privilege identifier mutation technology respectively in different scenarios; among them, both the authentication item attack request and the identifier mutation attack request include attack request packets in three forms: unauthorized attack, horizontal privilege escalation attack, and vertical privilege escalation attack.
[0051] Specifically, step S2 mainly constructs Web API authentication attack requests automatically based on two major attack scheduling strategies: authentication item mutation and identifier mutation. The following combines Figure 2 to illustrate the specific process of automatically constructing Web API authentication attack requests.
[0052] Combined with Figure 2When automatically constructing Web API authentication attack requests based on authentication item mutations, the authentication item mutation strategy can be combined with specific situations to implement the construction of test request packets for unauthorized, horizontal privilege escalation, and vertical privilege escalation attacks, thereby obtaining attack request packets in three forms: unauthorized attacks, horizontal privilege escalation attacks, and vertical privilege escalation attacks. For the APIs to be tested at non-public privilege levels, according to the original request information of the API, while keeping other information unchanged, two unauthorized attack request packets are constructed with the authentication item being empty and the authentication item being a meaningless string of equal length. For the APIs to be tested at the ordinary privilege level, if there are APIs at the same privilege level in the API asset library, first determine the type of authentication item of the API to be tested, then count the APIs with the same type of authentication item at the same privilege level in the API asset library, extract the parameter value that appears most frequently in the same type of authentication item as the attack authentication item, and replace the API authentication item in the original request with this attack authentication item to obtain the horizontal privilege escalation attack request packet for accessing with the replaced authentication item. For the APIs to be tested at the high privilege level, if there are APIs at the ordinary privilege level in the API asset library, similarly first parse the authentication item of the API to be tested and determine the type of authentication item of the API to be tested, then count the APIs with the same type of authentication item at the ordinary privilege level in the API asset library, extract the parameter value that appears most frequently in the same type of authentication item as the attack authentication item, and replace the API authentication item in the original request with this attack authentication item to obtain the vertical privilege escalation attack request packet for accessing with the downgraded authentication item.
[0053] Combined with Figure 2When automatically constructing Web API authentication attack requests based on identifier mutation, the identifier mutation strategy can be combined with specific situations to implement the construction of test request packets for unauthorized, horizontal privilege escalation, and vertical privilege escalation attacks, thereby obtaining attack request packets in three forms: unauthorized attack, horizontal privilege escalation attack, and vertical privilege escalation attack. Based on the idea of unauthorized access beyond authentication items, for the API to be tested at the public permission level, if the API framework type is REST, the request verb is mutated according to the original request response information of the API. For example, three unauthorized attack request data packets of POST, PUT, and DELETE are constructed by mutating the data returned by the GET request; if the API framework type is GraphQL and it is a GET request, a POST unauthorized attack request data packet is mutated and constructed. Based on the idea of accessing by replacing resource identifiers, for the API to be tested at the normal permission level, if there is a corresponding API asset in the API asset library at the same permission level, it is replaced with different resource identifiers in the API in the asset library to obtain a horizontal privilege escalation attack request packet for accessing by replacing resource identifiers; for the API to be tested at the normal permission level, first extract the API permission identifier. If the permission identifier is successfully extracted, a vertical privilege escalation attack request packet based on accessing by replacing the permission identifier is constructed by upgrading and mutating the permission identifier according to the parameter value regular expression in the feature library; if the permission identifier is not successfully extracted and the API framework is REST or GraphQL, based on the idea of unauthorized access beyond authentication items, a vertical privilege escalation attack request packet with an upgraded request verb is constructed.
[0054] Step S3: Based on the original request response given by the Web API, as well as the authentication item attack request response and the identifier mutation attack request response, and using response feature recognition technology and similarity detection technology, determine the vulnerability scan result and generate a vulnerability scan report.
[0055] Specifically, in step S3, based on the original request response given by the Web API, as well as the authentication item attack request response and the identifier mutation attack request response, and using response feature recognition technology and similarity detection technology, determining the vulnerability scan result may include: Based on the result comprehensive determination strategy, according to the original request response, the authentication item attack request response, and the identifier mutation attack request response, combined with the API asset library, using response feature recognition technology and similarity detection technology, determine the attack results of the authentication item attack request and the identifier mutation attack request, discover vulnerabilities, and obtain the vulnerability scan result.
[0056] The following combines Figure 3 to specifically describe the process of determining the attack results of the authentication item attack request and the identifier mutation attack request.
[0057] When making a comprehensive determination of the attack results, different determination logics are adopted according to different attack techniques.
[0058] When the attack technique is authentication item mutation, the attack request is an authentication item attack request. The attack corresponding to the authentication item attack request uses an authentication item that does not belong to the caller of the API under test to execute the API call. Then, if the response of the authentication item attack request is the same as the original request response of the API under test, it proves that the attack is successful. Of course, there are also some scenarios where, although the API is successfully called, the responses before and after are not the same. For example, when using a POST-type API request to punch in, the original response is "{message:success}", and after modifying the authentication item and replaying the request, the attack response is "{message:already execute}". Therefore, response feature detection needs to be used for supplementary determination, and a two-way comparison, one white and one black, is performed based on the traffic characteristics of successful responses and failed responses to determine whether the API request is successfully called. The determination idea of the attack based on active defect testing is the same as the authentication item mutation path.
[0059] That is to say, as Figure 3 shown, if the similarity of the response content between the response of the authentication item attack request and the original request response is higher than the threshold (denote this threshold as the first content threshold), it is determined that the authentication item attack request is successful. Otherwise, a feature comparison is made between the response of the authentication item attack request and the original request response. If the feature comparison passes, that is, the features of the response of the authentication item attack request and the original request response are the same, it is determined that the authentication item attack request is successful. Otherwise, it is determined that the authentication item attack request fails.
[0060] When the attack technique is identifier mutation, the attack request is an identifier attack request. The attack corresponding to the identifier attack request uses its own authentication item to access a resource that does not belong to itself through the API under test. If the request call is successful, the responses before and after generally have structural consistency but not content consistency. Therefore, when determining the attack result, response feature comparison can be performed first, and then the attack result can be determined from two dimensions: response structure similarity and content similarity.
[0061] That is to say, as Figure 3 shown, determining the attack results of the authentication item attack request and the identifier mutation attack request includes: if the features of the response of the identifier mutation attack request are the same as those of the original request response, that is, the attack response feature comparison passes, and the response structure similarity is higher than the structure threshold, and at the same time the response content similarity is lower than the threshold (denote this threshold as the second content threshold), it is determined that the identifier mutation attack request is successful. Otherwise, if the attack response feature comparison fails, or the response structure similarity is not higher than the structure threshold, or the response content similarity is not lower than the second content threshold, it is determined that the identifier mutation attack request fails.
[0062] Exemplarily, a vulnerability scan report is generated, including: recording the attack results and generating a vulnerability scan report containing Web API endpoint information, detection result types, original request responses, and attack request responses.
[0063] Specifically, the recorded attack results can be stored in the API asset library to update the content of the API asset library, thereby avoiding repeated vulnerability scans for the same Web API. By generating a vulnerability scan report containing information such as Web API endpoint information, detection result types, original request responses, and attack request responses, the user review experience can also be improved.
[0064] The automated Web API authentication - related vulnerability scanning method provided by the embodiments of the present invention, compared with the prior art, has general vulnerability scanning adaptability for different Web API frameworks, can adaptively generate effective and diverse authentication attack test requests according to specific scenarios, automatically determine the existence of vulnerabilities based on multiple traffic characteristics, significantly improves the automation level and efficiency of Web API authentication - related vulnerability scanning, enhances the security of the Web API system, shortens the security assessment cycle, and improves the response speed to security threats.
[0065] Another embodiment of the present invention relates to an automated Web API authentication - related vulnerability scanning system, as Figure 4 shown, including a Web API traffic pre - processing module, a Web API authentication attack request automatic construction module, and a Web API authentication vulnerability automatic determination module.
[0066] The Web API traffic pre - processing module is used to access the system under test in a bypass mode, analyze the authentication mechanism, authentication parameter items, and permission identification items used by the Web API of the system under test, collect the pre - required information for authentication vulnerability scanning, and construct an API asset library.
[0067] Specifically, the Web API traffic pre - processing module can access the system through the traffic bypass proxy mode, identify the WebAPI framework and extract key parameter information, perform asset storage, construct an API asset library, and provide pre - required information for vulnerability scanning.
[0068] The Web API authentication attack request automatic construction module is used to adaptively construct authentication item attack requests and identifier mutation attack requests in different scenarios from the perspective of an attacker based on an attack scheduling strategy, using authentication item mutation and identifier mutation technologies, and initiate vulnerability scan tests based on the authentication item attack requests and identifier mutation attack requests.
[0069] Specifically, the Web API authentication attack request automatic construction module can simulate the behavior of attackers in different scenarios according to the attack scheduling strategy, and automatically construct test data packets of attack requests that meet the requirements of the current scenario based on the authentication item mutation technology and permission identifier mutation technology.
[0070] The Web API authentication vulnerability automatic determination module is used to determine the vulnerability scanning result and generate a vulnerability scanning report based on the original request response given by the Web API, the authentication item attack request response, and the identifier mutation attack request response, using response feature recognition technology and similarity detection technology.
[0071] Specifically, the Web API authentication vulnerability automatic determination module is used to automatically evaluate and determine whether the attack test is successful. By analyzing the original request response and the attack test request response, with response feature recognition and response similarity detection as the key technologies, it comprehensively determines whether the attack is successful, identifies possible authentication vulnerabilities, records the results, and automatically generates a vulnerability scanning report.
[0072] For the specific implementation method of the automated Web API authentication vulnerability scanning system provided by the embodiments of the present invention, reference can be made to the automated Web API authentication vulnerability scanning method provided by the embodiments of the present invention, which will not be elaborated here.
[0073] Compared with the prior art, the automated Web API authentication vulnerability scanning system provided by the embodiments of the present invention has general vulnerability scanning adaptability to different Web API frameworks, can adaptively generate effective and diverse authentication attack test requests according to specific scenarios, and automatically determines the existence of vulnerabilities based on various traffic characteristics, significantly improving the automation level and efficiency of Web API authentication vulnerability scanning, enhancing the security of the Web API system, shortening the security assessment cycle, and improving the response speed to security threats.
[0074] Another embodiment of the present invention relates to an electronic device, as Figure 5 shown, including:
[0075] At least one processor 501; and,
[0076] A memory 502 communicatively connected to the at least one processor 501; wherein,
[0077] The memory 502 stores instructions executable by the at least one processor 501, and the instructions are executed by the at least one processor 501 so that the at least one processor 501 can execute the automated Web API authentication vulnerability scanning method described in the above embodiments.
[0078] Among them, the memory and the processor are connected in a bus manner. The bus may include any number of interconnected buses and bridges, and the bus connects various circuits of one or more processors and memories together. The bus can also connect various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art, and thus will not be further described herein. The bus interface provides an interface between the bus and the transceiver. The transceiver can be a component or multiple components, such as multiple receivers and transmitters, and provides a unit for communicating with various other devices on the transmission medium. The data processed by the processor is transmitted on the wireless medium through the antenna. Further, the antenna also receives data and transmits the data to the processor.
[0079] The processor is responsible for managing the bus and general processing, and can also provide various functions, including timing, peripheral interface, voltage regulation, power management, and other control functions. The memory can be used to store the data used by the processor when executing operations.
[0080] Another embodiment of the present invention relates to a computer-readable storage medium storing a computer program, and when the computer program is executed by a processor, it implements the automated Web API authentication class vulnerability scanning method described in the above embodiment.
[0081] That is, those skilled in the art can understand that all or part of the steps in implementing the method described in the above embodiment can be completed by instructing relevant hardware through a program. This program is stored in a storage medium and includes several instructions to enable a device (which can be a single-chip microcomputer, a chip, etc.) or a processor to execute all or part of the steps of the method described in various embodiments of the present invention. The aforementioned storage medium includes: USB flash drives, mobile hard disks, read-only memories (ROMs), random access memories (RAMs), magnetic disks, or optical discs and other various media that can store program codes.
[0082] Another embodiment of the present invention relates to a computer program product including a computer program, and when the computer program is executed by a processor, it implements the automated Web API authentication class vulnerability scanning method described in the above embodiment.
[0083] Those of ordinary skill in the art can understand that the above embodiments are specific embodiments for implementing the present invention, and in practical applications, various changes can be made in form and details without departing from the spirit and scope of the present invention.
Claims
1. An automated Web API authentication vulnerability scanning method, characterized in that: The method comprises: Access the system to be tested in bypass mode, parse the authentication mechanism, authentication parameter items, and permission identification items used by the Web API of the system to be tested, collect the pre-information required for authentication vulnerability scanning, and build an API asset library; Based on the attack scheduling strategy, authentication item mutation and identifier mutation technology are adopted to adaptively construct authentication item attack requests and identifier mutation attack requests in different scenarios from the attacker's perspective, and initiate vulnerability scanning tests based on the authentication item attack requests and identifier mutation attack requests; According to the original request response given by the Web API, the authentication item attack request response, and the identifier mutation attack request response, based on the response feature recognition technology and the similarity detection technology, the vulnerability scanning result is determined and a vulnerability scanning report is generated.
2. The method according to claim 1, characterized in that The method of accessing the system to be tested in bypass mode, parsing the authentication mechanism, authentication parameter items, and permission identification items used by the Web API of the system to be tested, collecting the pre-information required for authentication vulnerability scanning, and building an API asset library includes: Access the system under test in bypass traffic proxy mode to filter non-API traffic; Analyze the traffic characteristics of the Web API request and identify different framework types of the Web API; wherein the traffic characteristics include the structure of the Web API request, the protocol used, and the data format; Adopt corresponding traffic preprocessing modes for the Web APIs of different framework types, and parse the authentication mechanisms, authentication parameter items, and permission identification items corresponding to the Web APIs of different framework types; Identify the permission level and sensitivity level of the Web API, and store the authentication mechanism, the authentication parameter item, the permission identification item, the permission level, and the sensitivity level corresponding to the Web API of each framework category in the API asset library.
3. The method according to claim 2, characterized in that The attack scheduling strategy is based on authentication item mutation and identifier mutation technology, authentication item attack requests and identifier mutation attack requests in different scenarios are adaptively constructed from the attacker's perspective, and vulnerability scanning tests are initiated based on the authentication item attack requests and the identifier mutation attack requests, including: According to the traffic characteristics of the Web API and the authentication mechanism, the authentication vulnerability scan is performed from the attacker's perspective, and an adaptive attack scheduling strategy is designed to manage and schedule different forms of authentication attack tests; According to the attack scheduling strategy, the authentication item attack request and the identifier mutation attack request are constructed respectively based on the authentication item mutation technology and the authority identifier mutation technology in different scenarios; wherein, the authentication item attack request and the identifier mutation attack request both include three forms of attack request packets: unauthorized attack, horizontal overauthority attack, and vertical overauthority attack.
4. The method according to claim 1, characterized in that The vulnerability scanning result is determined based on the original request response given by the Web API, the authentication item attack request response, and the identifier mutation attack request response, based on the response feature recognition technology and the similarity detection technology, including: Based on the comprehensive result judgment strategy, according to the original request response, the authentication item attack request response, and the identifier mutation attack request response, combined with the API asset library, using the response feature recognition technology and the similarity detection technology, the attack results of the authentication item attack request and the identifier mutation attack request are determined, the vulnerability is discovered, and the vulnerability scanning result is obtained.
5. The method according to claim 4, characterized in that The determining the attack results of the authentication item attack request and the identifier mutation attack request includes: If the similarity between the authentication item attack request response and the original request response is higher than a first content threshold, then determining that the authentication item attack request is successful; If the identifier mutation attack request response is consistent with the characteristics of the original request response, and the response structure similarity is higher than the structure threshold, and the response content similarity is lower than the second content threshold, then it is determined that the identifier mutation attack request attack is successful.
6. The method according to claim 4, characterized in that The generating of vulnerability scanning report includes: The attack results are recorded, and the vulnerability scanning report including Web API endpoint information, detection result type, original request response, and attack request response is generated.
7. An automated Web API authentication vulnerability scanning system, characterized in that: The system comprises: The Web API traffic preprocessing module is used to access the system under test in bypass mode, parse the authentication mechanism, authentication parameter items, and permission identification items used by the WebAPI of the system under test, collect the pre-information required for authentication vulnerability scanning, and build an API asset library; A Web API authentication attack request automatic construction module, which is used to adaptively construct authentication item attack requests and identifier mutation attack requests in different scenarios from the attacker's perspective based on the attack scheduling strategy and the authentication item mutation and identifier mutation technologies, and initiate a vulnerability scanning test based on the authentication item attack requests and the identifier mutation attack requests; The Web API authentication vulnerability automatic determination module is used to determine the vulnerability scanning results and generate a vulnerability scanning report based on the original request response given by the Web API, the authentication item attack request response, and the identifier mutation attack request response, based on the response feature recognition technology and the similarity detection technology.
8. An electronic device, characterized in that: include: at least one processor; as well as, a memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the method according to any one of claims 1 to 6.
9. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the method according to any one of claims 1 to 6 is implemented.
10. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the method according to any one of claims 1 to 6 is implemented.