RASP protection capability evaluation method and device
By generating tag information and using it in RASP evaluation, the problems of low efficiency and inaccurate results in the prior art are solved, and efficient and accurate RASP protection capability assessment is achieved, supporting large-scale continuous evaluation.
Patent Information
- Application Number
- CN202510113447.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-23
- Publication Date
- 2025-06-06
AI Technical Summary
The RASP evaluation method in the prior art is inefficient, difficult to support large-scale continuous evaluation, and lacks unified standards, resulting in poor accuracy and repeatability of evaluation results.
By determining the test code that needs to be executed in the evaluation script, a mark information corresponding to the tagging unique test code is generated, a test request is generated based on the tagging information and test code and sent to the application. The application generates class and method functions with tagging information based on the received tagging information and test code. When executing the test logic, a class and method functions with tagging information are added to the stack information during the execution of the test logic through the class and method functions with tagging information, and the evaluation results of RASP protection capabilities are obtained based on the test-related information obtained by the application.
It improves the efficiency of RASP evaluation, supports large-scale continuous evaluation, and automatically obtains evaluation results according to unified standards, improving the accuracy and repeatability of the evaluation, which is conducive to long-term tracking of changes in the protection capabilities of RASP products.
Smart Images

Figure CN120104472A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer technology, and in particular to a method and device for evaluating RASP protection capability. Background Art
[0002] With the development of Internet technology, Java Web (Java network application) applications have become an important part of enterprise-level software development. The Java language is widely used in many fields due to its cross-platform nature and security. However, the complexity of the network environment makes it difficult for traditional security measures such as firewalls and abnormal behavior detection systems to meet the security needs of modern Web applications. To this end, RASP (Runtime Application Self-Protection) came into being. It embeds the protection mechanism into the application, provides the ability to detect and block abnormal behavior in real time, and improves the level of security protection. Accurately evaluating the protection capabilities of RASP is crucial to identifying weak links in existing configurations, which helps to take targeted measures for optimization.
[0003] In the existing technology, RASP evaluation methods are mostly based on manual testing and semi-automated processes: security personnel first deploy vulnerable applications with RASP in the test environment, and then use scripts to batch execute manually constructed test codes for evaluation. However, manual testing and semi-automated testing are inefficient and difficult to support large-scale continuous evaluation; the log analysis process relies heavily on manual experience and is prone to subjective bias; there is a lack of effective correlation mechanism, making it difficult to accurately match specific test behaviors with the alarm records generated by RASP; the test process and results lack unified standards and poor repeatability, which is not conducive to long-term tracking of changes in the protection capabilities of RASP products. Summary of the invention
[0004] In view of this, the purpose of the embodiments of the present invention is to provide a method and device for evaluating the protection capability of RASP, which can improve the efficiency of RASP evaluation and support large-scale continuous evaluation. At the same time, the evaluation results can be automatically obtained according to unified standards, which can improve the accuracy and repeatability of RASP evaluation and facilitate long-term tracking of changes in the protection capability of RASP products.
[0005] In a first aspect, an embodiment of the present invention provides a method for evaluating RASP protection capability, the method comprising:
[0006] Identify the test code that needs to be executed in the evaluation script;
[0007] Generate marking information corresponding to the test code, where the marking information is used to mark a unique test code;
[0008] Generate a test request and send it to an application, wherein the test request includes the test code and the tag information;
[0009] Generate a class and method function with the tag information according to the tag information and the test code;
[0010] Execute the test logic according to the test code, class and method function through the application program to obtain test related information, wherein the class and method function are used to add marking information to the stack information during the execution of the test logic;
[0011] The evaluation result of the RASP protection capability is obtained according to the test related information.
[0012] In some embodiments, the method further comprises:
[0013] Receiving an evaluation script sent by the management platform, wherein the evaluation script includes at least one test code and a predetermined hash value;
[0014] Obtain the file lock corresponding to the evaluation script;
[0015] In response to successfully acquiring the file lock, detecting whether an application exists locally;
[0016] In response to the presence of an application, detecting whether the application matches a predetermined hash value in the evaluation script;
[0017] In response to the application matching a predetermined hash value in the evaluation script, a test environment is configured according to the application.
[0018] In some embodiments, the method further comprises:
[0019] In response to failure to successfully obtain the file lock, after waiting for a first predetermined period of time, obtain the file lock corresponding to the evaluation script.
[0020] In some embodiments, the method further comprises:
[0021] In response to the application not being present, or the application being present and the application not matching a predetermined hash value in the evaluation script, downloading the application;
[0022] Configure the test environment according to the application in question.
[0023] In some embodiments, configuring the test environment according to the application comprises:
[0024] detecting whether the application is already running;
[0025] In response to the application being run, obtaining a running time of the application;
[0026] In response to the running time being greater than or equal to a second predetermined time, configuring the test environment is completed, and the second predetermined time is determined according to the time required for RASP injection.
[0027] In some embodiments, configuring the test environment according to the application further comprises:
[0028] In response to the application not being running, launching the application;
[0029] Obtaining the running time of the application;
[0030] In response to the running time being greater than or equal to the second predetermined time, configuring the test environment is completed.
[0031] In some embodiments, the test-related information includes at least one of alarm and interception logs, context information of de-grouping and entry of alarm or interception points, and RASP version information.
[0032] In some embodiments, the evaluation results include at least one of the interception and alarm status of each test code, the RASP console alarm response time, the detection rate, the interception rate and the false alarm rate.
[0033] In some embodiments, the method further comprises:
[0034] The evaluation result is sent to the management platform so that the management platform generates a test report according to the evaluation result.
[0035] In a second aspect, an embodiment of the present invention provides a device for evaluating RASP protection capability, the device comprising:
[0036] A test code determination unit, used to determine the test code that needs to be executed in the evaluation script;
[0037] A marking information generating unit, used to generate marking information corresponding to the test code, wherein the marking information is used to mark a unique test code;
[0038] A test request sending unit, used for generating a test request and sending it to an application program, wherein the test request includes the test code and the marking information;
[0039] A data generation unit, used for generating a class and a method function with the tag information according to the tag information and the test code;
[0040] A test information acquisition unit, used to execute the test logic according to the test code, class and method function through the application program to obtain test related information, wherein the class and method function are used to add marking information to the stack information during the execution of the test logic;
[0041] The evaluation result acquisition unit is used to acquire the evaluation result of the RASP protection capability according to the test related information.
[0042] In a third aspect, an embodiment of the present invention provides an electronic device, comprising a memory and a processor, wherein the memory is used to store one or more computer program instructions, wherein the one or more computer program instructions are executed by the processor to implement the method described in the first aspect.
[0043] In a fourth aspect, an embodiment of the present invention provides a computer program product, wherein the computer program product includes a computer program. When the computer program runs on a computer, the computer executes the method described in the first aspect.
[0044] In a fifth aspect, an embodiment of the present invention provides a computer-readable storage medium on which computer program instructions are stored. When the computer program instructions are executed by a processor, the method described in the first aspect is implemented.
[0045] The technical solution of the embodiment of the present invention determines the test code that needs to be executed in the evaluation script, generates marking information corresponding to the unique test code, generates a test request based on the marking information and the test code and sends it to the application, and the application generates a class and method function with marking information based on the received marking information and the test code. When executing the test logic, the stack information in the execution process of the test logic is added with marking information through the class and method function with marking information, and the evaluation result of the RASP protection capability is obtained based on the test-related information obtained by the application. In this way, the efficiency of RASP evaluation can be improved, and large-scale continuous evaluation can be supported. At the same time, the evaluation results can be automatically obtained according to unified standards, which can improve the accuracy and repeatability of RASP evaluation, and is conducive to long-term tracking of changes in the protection capabilities of RASP products. BRIEF DESCRIPTION OF THE DRAWINGS
[0046] The above and other objects, features and advantages of the present invention will become more apparent through the following description of the embodiments of the present invention with reference to the accompanying drawings, in which:
[0047] Figure 1 is a schematic diagram of a RASP evaluation system according to an embodiment of the present invention;
[0048] Figure 2 is a flow chart of a method for evaluating RASP protection capability according to an embodiment of the present invention;
[0049] Figure 3 is a flow chart of a method for evaluating RASP protection capability according to another embodiment of the present invention;
[0050] Figure 4is a schematic diagram of a device for evaluating RASP protection capability according to an embodiment of the present invention;
[0051] Figure 5 is a schematic diagram of an electronic device according to an embodiment of the present invention. DETAILED DESCRIPTION
[0052] The present application is described below based on embodiments, but the present application is not limited to these embodiments. In the detailed description of the present application below, some specific details are described in detail. It is possible for those skilled in the art to fully understand the present application without the description of these details. In order to avoid confusing the essence of the present application, known methods, processes, flows, components and circuits are not described in detail.
[0053] In addition, persons of ordinary skill in the art will appreciate that the drawings provided herein are for illustration purposes and are not necessarily drawn to scale.
[0054] Unless the context clearly requires otherwise, the words "include", "comprising" and similar words throughout the application should be interpreted as including rather than exclusive or exhaustive; that is, the meaning is "including but not limited to".
[0055] In the description of this application, it should be understood that the terms "first", "second", etc. are only used for descriptive purposes and cannot be understood as indicating or implying relative importance. In addition, in the description of this application, unless otherwise specified, the meaning of "plurality" is two or more.
[0056] The solutions described in this specification and in the examples, if they involve the processing of personal information, will be processed on the premise of having a legal basis (such as obtaining the consent of the subject of personal information, or being necessary for the performance of a contract, etc.), and will only be processed within the scope of regulations or agreements. If a user refuses to process personal information other than the necessary information for basic functions, it will not affect the user's use of basic functions.
[0057] With the rapid development of Internet technology, Java Web applications have become an indispensable part of enterprise-level software development. With its cross-platform nature, stability, and strong ecosystem support, the Java language has taken a dominant position in building complex enterprise applications. Whether it is an e-commerce platform, a financial service system, or an internal management tool, Java Web applications play a vital role in ensuring the efficient operation of operational processes.
[0058] Java Web applications refer to applications developed using the Java programming language and its related technologies and frameworks that can run in a Web environment. Such applications are usually deployed on the server side and interact with the client (usually a browser) through the HTTP protocol to provide dynamic content and services. Java Web applications are a very important component of enterprise-level software development and are widely used in e-commerce, financial services, social media, online education and other fields.
[0059] However, with the increasing complexity of network environments and the continuous evolution of testing methods, traditional network security protection measures such as firewalls and intrusion detection systems can no longer fully meet the security needs of modern Web applications. These traditional methods often focus on protecting network boundaries and are unable to cope with application layer threats that come from within or through legal channels. Especially in the dynamically changing cloud computing and microservice architecture, security vulnerabilities at the application level have become new risk points.
[0060] In this context, RASP (Runtime Application Self-Protection) technology came into being, providing a more in-depth and efficient protection mechanism for Java Web applications. By embedding security functions directly into the application, RASP can achieve the ability to detect and prevent improper behavior in real time without affecting performance. It can not only detect and respond to potential threats during code execution, but also make intelligent judgments based on specific contexts, reduce false alarm rates, and provide effective defense against known and unknown types of abnormal behaviors.
[0061] RASP embeds security functions directly into the application, enabling real-time detection and blocking of potential threat behaviors, providing a more sophisticated and efficient protection mechanism. For enterprises that rely on the Java technology stack, deploying RASP has become one of the important means to improve the overall level of information security. However, large enterprises face many challenges in evaluating the actual protection effects of these products. Due to the lack of a systematic evaluation method, enterprises often encounter difficulties in selecting or optimizing RASP solutions: on the one hand, it is difficult to accurately measure the security effectiveness under the existing configuration; on the other hand, it is also difficult to discover and locate the weak links in it, and then take targeted measures to improve them. This not only affects the accuracy of the company's understanding of its own security situation, but may also lead to improper resource allocation and even miss better defense opportunities.
[0062] For enterprises that rely on the Java technology stack, deploying RASP has become one of the important means to improve their overall information security level. RASP can be tightly integrated into the existing Java development environment, using Java's unique reflection mechanism and other features to enhance the security of the application itself. At the same time, it also supports automatic updates of the rule base to adapt to the ever-changing security threat situation and ensure that the enterprise is always in a good defensive state. In this way, RASP not only strengthens the security barrier of Java Web applications, but also provides a solid guarantee for the digital transformation of enterprises.
[0063] Therefore, it is particularly urgent to develop a method specifically for comprehensive quantitative evaluation of Java RASP's protection capabilities. In the existing technology, RASP evaluation methods are mostly based on manual testing and semi-automated processes: security personnel first deploy vulnerable applications with RASP in the test environment, and then batch execute manually constructed test payloads through scripts for evaluation. Although this solution has achieved automation in some aspects, there are still significant problems: low test efficiency and difficulty in supporting large-scale continuous evaluation; the log analysis process relies heavily on manual experience and is prone to subjective bias; lack of effective correlation mechanism, it is difficult to accurately match specific test behaviors with alarm records generated by RASP; the test process and results lack unified standards and poor repeatability, which is not conducive to long-term tracking of changes in the protection capabilities of RASP products. Therefore, establishing a scientific and reasonable evaluation framework is crucial to improving the effectiveness and reliability of RASP technology.
[0064] Figure 1 Schematic diagram of a RASP evaluation system according to an embodiment of the present invention. Figure 1 As shown, the RASP evaluation system of the embodiment of the present invention includes a management platform 1 and a test device 2. The management platform 1 and the test device 2 are connected to each other in a wireless or wired manner to achieve data interaction.
[0065] Management platform 1 is responsible for distributing the designed evaluation scripts to the test equipment, collecting and analyzing the evaluation results sent by the test equipment, and generating the final test report.
[0066] The management platform 1 may be implemented by a server, and the server may be a separate server or a server cluster composed of multiple servers.
[0067] In an optional implementation, the management platform 1 can be built on a cloud server, using the powerful computing power and massive storage resources provided by the cloud infrastructure, which enables it to process data from a large number of test devices and quickly respond to complex test requirements. At the same time, the cloud server also has high availability and elastic scaling capabilities, and can automatically adjust resource configuration according to actual load to ensure stable operation of the system.
[0068] In another optional implementation, the management platform 1 can be built on a local server, which allows users to fully control their data and reduces the risks that may be caused by Internet transmission. At the same time, the local server can also optimize the internal network performance and reduce delays.
[0069] Furthermore, the management platform 1 may also integrate a user interface, allowing the user to intuitively view the test progress and adjust parameter settings, etc.
[0070] The test device 2 is used to simulate various application scenarios in a real environment. The test device can receive the evaluation script from the management platform, execute the corresponding test code by running a specific application, and obtain the evaluation result of the RASP protection capability.
[0071] The test device 2 may be implemented by a mobile phone, a tablet computer, a laptop computer, a desktop computer, a server, a virtual machine, an embedded system, an Internet of Things (IoT) device or other dedicated test equipment.
[0072] In this embodiment, the management platform 1 is composed of multiple subsystems that work together to ensure the efficiency and accuracy of the RASP evaluation process. In some embodiments, the management platform 1 includes a control center 11, a task manager 12, and a report generator 13, each of which is responsible for a specific task, and together realizes the automation and intelligence of the entire test process.
[0073] Among them, the control center 11 is the core component of the management platform 1, and the control center 11 comprehensively manages the test process of RASP. Specifically, the control center 11 is responsible for all activities related to test configuration, such as defining test parameters, setting up the test environment, and planning the test schedule. In addition, the control center 11 also plays the role of task allocation, accurately issuing specific test instructions to the corresponding test equipment 2. Through centralized management and scheduling, the control center ensures the orderly progress of the test process, and can obtain the status of each stage in real time, and adjust the strategy in time to deal with emergencies.
[0074] The task manager 12 is a bridge between the management platform 1 and the test device 2. Specifically, the task manager 12 receives task instructions from the control center 11, converts them into specific evaluation tasks, and sends these tasks together with necessary evaluation scripts to the designated test device 2.
[0075] After the test is completed, the test device 2 will feed back the obtained evaluation results to the management platform 1. After receiving the evaluation results, the report generator 13 uses the built-in data analysis algorithm to analyze the evaluation results and automatically generate a detailed test report to provide a comprehensive insight into the security of the application. The report can not only summarize the test findings, but also provide improvement suggestions to help the development team optimize the application in a targeted manner.
[0076] The control center 11, the task manager 12 and the report generator 13 may be dedicated modules on physical devices in the management platform or software programs, and may be implemented as physical components or software programs according to different actual application scenarios.
[0077] In this embodiment, the test device 2 includes a script processing module 21 and an application 22. The script processing module 21 is used to receive the evaluation script sent by the management platform 1, and generate a test request according to the evaluation script and send it to the application. The application 22 is used to execute the test logic according to the test request.
[0078] Specifically, the script processing module 21 includes a file lock manager 211 , an application manager 212 , an executor 213 , a request generation module 214 and a log analyzer 215 .
[0079] Among them, the file lock manager 211 is a mechanism for managing and coordinating the access of multiple processes or threads to the same file. After receiving the evaluation script, the file lock manager 211 creates a file lock for the process or thread corresponding to the execution of the evaluation script. The file lock mechanism can ensure that a single evaluation script runs. In other words, the management platform may send multiple evaluation scripts to the test device at the same time. If multiple evaluation scripts are executed in parallel, there will be conflicts and other problems. Therefore, the file lock mechanism ensures that only one evaluation script is running at a time. When an evaluation script wants to run, it will try to obtain the file lock from the file lock manager. If no other evaluation script holds the file lock, the current evaluation script can successfully obtain the file lock and continue testing. If another evaluation script already holds the file lock, the current evaluation script must wait until the file lock is released.
[0080] The application manager 212 is used to manage applications. Specifically, one or more applications for simulating various vulnerability scenarios are installed on the test device 2, and the application manager 212 is used to determine the application that matches the evaluation script according to the evaluation script. Specifically, the evaluation script includes at least one test code and a predetermined hash value. The application manager 212 parses the evaluation script to obtain the hash value, detects whether the application exists locally, and in response to the existence of the application, detects whether the application matches the predetermined hash value in the evaluation script. If it matches, the application is obtained. In response to the absence of the application, or the existence of the application and the application does not match the predetermined hash value in the evaluation script, the corresponding application is downloaded.
[0081] Furthermore, the application manager 212 is also used to configure the test environment according to the application after acquiring the application. Specifically, it is detected whether the application has been running, and in response to the application having been running, the running time of the application is obtained, and in response to the running time being greater than or equal to a second predetermined time, the test environment is configured, and the second predetermined time is determined according to the time required for RASP injection. In response to the application not being running, the application is started, the running time of the application is obtained, and in response to the running time being greater than or equal to the second predetermined time, the test environment is configured.
[0082] The executor 213 is used to execute the test codes in the evaluation script one by one after the test environment configuration is completed.
[0083] The request generation module 214 is used to generate a test request according to the test code to be executed, and send it to the application program.
[0084] The request generating module 214 includes a label generator 2141 , a request generator 2142 and a request module 2143 .
[0085] The tag generator 2141 generates tag information corresponding to the test code, and the tag information is used to mark a unique test code. The tag information is a color tag. The tag information is carried in the test request and sent to the application. The application generates a class and method function with the tag information, and when executing the test logic, the class and method function with the tag information are used to add tag information to the stack information in the execution process of the test logic.
[0086] The request generator 2142 is used to generate a test request according to the tag information, and the test request includes the test code and the tag information.
[0087] The request module 2143 is used to send a test request to the application 22 .
[0088] The log analyzer 215 is used to receive the test related information returned by the application program, and analyze the test related information to obtain the evaluation result.
[0089] The application 22 is used to execute the test code and obtain the execution result. The application 22 includes a receiving module 221, a stack processor 222, a security module 223 and a processing module 224.
[0090] The receiving module 221 is used to receive the test request sent by the request generating module 214 .
[0091] The stack processor 222 is used to generate a class and a method function with the tag information according to the tag information.
[0092] The security module 223 is a program for implementing various vulnerability scenarios in the application program.
[0093] The processing module 224 is used to execute the test logic according to the test code, class and method function through the application to obtain test related information, and the class and method function are used to add tag information to the stack information during the execution of the test logic. Whether the test related information exists at least one of the alarm and interception log, the context information of the de-grouping and entry of the alarm or interception point, and the RASP version information.
[0094] Further, the processing module 224 sends the test related information to the log analyzer 215. The log analyzer 215 analyzes the test related information returned by the application to obtain an evaluation result. The evaluation result includes at least one of the interception and alarm conditions of each test code, the RASP console alarm response time, the detection rate, the interception rate and the false alarm rate.
[0095] Furthermore, after obtaining the evaluation result, the log analyzer 215 sends the evaluation result to the report generator 13, and the report generator 3 generates a test report according to the evaluation result.
[0096] The test report includes but is not limited to charts, tables, and other forms that intuitively display various indicators, as well as a summary and suggestions on the test results.
[0097] The embodiment of the present invention determines the test code that needs to be executed in the evaluation script, generates tag information corresponding to the unique test code, generates a test request based on the tag information and the test code and sends it to the application, and the application generates a class and method function with the tag information based on the received tag information and the test code. When executing the test logic, the class and method function with the tag information are used to add tag information to the stack information in the execution process of the test logic, and the evaluation result of the RASP protection capability is obtained based on the test-related information obtained by the application. In this way, the efficiency of the RASP evaluation can be improved, and large-scale continuous evaluation can be supported. At the same time, the evaluation results can be automatically obtained according to unified standards, which can improve the accuracy and repeatability of the RASP evaluation, and is conducive to long-term tracking of changes in the protection capabilities of RASP products.
[0098] Figure 2 The figure is a flow chart of a method for evaluating RASP protection capability according to an embodiment of the present invention. Figure 2 The RASP protection capability evaluation method shown is performed by a test device and specifically includes the following steps:
[0099] Step S101: Receive an evaluation script.
[0100] In this embodiment, when the user needs to evaluate the protection capability of RASP (Runtime Application Self-Protection), the management platform will first be triggered to send an evaluation script to the test device. This process is the starting point of the entire evaluation process, ensuring that subsequent test tasks can be accurately executed according to the preset standards and conditions.
[0101] The evaluation script is a key file used to instruct the test device on how to simulate abnormal behavior to verify the security protection capability of the application at runtime. The evaluation script can be obtained by manual writing by the user or automatic generation.
[0102] In some embodiments, the evaluation script includes at least one test code and a predetermined hash value.
[0103] Among them, the test code is the core part of the evaluation script. It specifically instructs the test equipment on how to simulate abnormal behavior to test the security protection capabilities of the application at runtime. Each test code represents an independent test case. The functions of each test code can be the same or different. Specifically, when evaluating the protection capabilities of RASP, the role of the test code is to simulate actual security event scenarios. The test code is designed to test the RASP system's ability to identify and respond to potential risks to ensure that it can provide effective protection in a real environment. The security event scenarios include abnormal SQL injection, remote code execution, etc.
[0104] The predetermined hash value is a fixed value associated with the test code, which can be calculated by the management platform according to a specific algorithm. The predetermined hash value is used to obtain the application matching the test code in the subsequent process. Specifically, the management platform generates a unique hash value based on the specific version or other parameters of the application. This hash value is embedded in the evaluation script as a predetermined value and sent to the test device along with the script.
[0105] Step S102: Acquire the file lock.
[0106] In this embodiment, after receiving the evaluation script, the file lock manager creates a file lock for the process or thread that executes the evaluation script. Specifically, if no other evaluation script holds the file lock, the current evaluation script can successfully obtain the file lock and continue with subsequent tests. If another evaluation script already holds the file lock, the current evaluation script must wait until the file lock is released.
[0107] In response to failure to successfully acquire the file lock (file lock acquisition failure), the process proceeds to step S103.
[0108] In response to successfully acquiring the file lock, the process proceeds to step S104.
[0109] Step S103: Wait for a first predetermined time period.
[0110] In this embodiment, in response to failure to obtain the file lock, after waiting for a first predetermined time, step S102 is re-executed until the file lock is successfully obtained. The first predetermined time can be set according to actual application scenarios.
[0111] Step S104: an application exists.
[0112] In this embodiment, the test device may be installed with one or more applications for simulating various vulnerability scenarios. After successfully acquiring the file lock, the application manager detects whether the application exists locally.
[0113] In response to the existence of the application, the process proceeds to step S105.
[0114] In response to the absence of an application, the process proceeds to step S106.
[0115] Step S105: Hash value matching.
[0116] In this embodiment, in response to the existence of an application, it is detected whether the application matches a predetermined hash value in the evaluation script.
[0117] Specifically, if the application exists this time, the hash value of the local application is calculated. The calculation method of the hash value is consistent with the method of calculating the hash value of the management platform. A unique hash value can be generated based on the specific version or other parameters of the application. Check whether the hash value in the evaluation script is the same as the hash value of the local application.
[0118] In response to the application matching the predetermined hash value in the evaluation script, the process proceeds to step S107.
[0119] In response to the application not matching the predetermined hash value in the evaluation script, the process proceeds to step S106.
[0120] Step S106: download the application.
[0121] In this embodiment, in response to the application not existing, or the application existing and not matching the hash value predetermined in the evaluation script, the application is downloaded.
[0122] Specifically, a download request may be sent to the management platform according to a predetermined hash value in the evaluation script, the download request including the predetermined hash value. The management platform determines the corresponding application according to the hash value in the download request, and sends the application to the test device.
[0123] Step S107: The application is running.
[0124] In this embodiment, in response to the application matching a predetermined hash value in the evaluation script, or after the application is downloaded and installed, the test environment is configured according to the application, and first, it is detected whether the application is running.
[0125] In response to the application being already running, the application startup process is skipped and the process proceeds to step S109.
[0126] In response to the application not being run, the process proceeds to step S108.
[0127] Step S108: Start the application.
[0128] In this embodiment, in response to the application not being running, the application is started.
[0129] Step S109: greater than or equal to t2.
[0130] In this embodiment, in response to the application being run, or after the application is started, the running time of the application is obtained, and it is detected whether the running time is greater than or equal to a second predetermined time. Wherein, the second predetermined time t2 is determined according to the time required for RASP injection. RASP injection refers to directly embedding the security protection mechanism into the runtime environment of the application, so that the application can protect itself during operation, detect and defend against potential security threats in real time.
[0131] Specifically, the second predetermined time duration t2 is greater than or equal to the time required for RASP injection.
[0132] In response to the running time being greater than or equal to the second predetermined time, it indicates that the RASP injection is completed, that is, the configuration of the test environment is completed, and the process proceeds to step S111.
[0133] In response to the running time being less than the second predetermined time, it indicates that the RASP injection is not completed, and the process goes to step S110.
[0134] Step S110, waiting for RASP injection to be completed.
[0135] In this embodiment, in response to the running time being less than the second predetermined time, it indicates that the RASP injection is not completed, and the RASP injection is waited to be completed.
[0136] In some embodiments, waiting for the RASP injection to be completed specifically includes: obtaining a time difference between the second predetermined time duration and the running time duration, and when the waiting time is greater than or equal to the time difference, it indicates that the RASP injection is completed.
[0137] Step S111: Determine the test code.
[0138] In this embodiment, in response to the completion of RASP injection, it indicates that the configuration of the test environment is completed and the test process begins to be executed. First, according to a predetermined selection method, a test code to be executed is selected in the evaluation script.
[0139] Among them, the predetermined selection method can be random selection, sequential selection, etc.
[0140] Step S112: Generate marking information.
[0141] In this embodiment, marking information corresponding to the test code is generated, and the marking information is used to mark a unique test code.
[0142] Specifically, the embodiment of the present invention generates a dyeing label, i.e., marking information, corresponding to the test code through the Java stack dyeing technology. Java stack dyeing technology is a technology used to debug and analyze Java applications. By modifying or extending the behavior of the Java virtual machine (JVM), specific metadata (i.e., "color" or marking information) is associated with these objects or method stack frames when the object is created or the method is called. This technology can help developers track the source of objects, understand the execution path of the program, detect memory leaks and other problems. Among them, to generate the marking information corresponding to the test code, it is necessary to determine the generation rules of the dyeing label, that is, to determine the information encoded as the dyeing label, which includes one or more of timestamp, thread ID, class name, method name, etc.
[0143] Step S113: Generate a test request and send it to the application.
[0144] In this embodiment, a test request is generated according to the test code and the tag information, and the test request is sent to the application program, wherein the test parameters include the test code and the tag information.
[0145] In some embodiments, the test request is an HTTP (Hypertext Transfer Protocol) request.
[0146] Step S114: Generate a class and method function with tag information.
[0147] In this embodiment, the test request is parsed to obtain the test code and tag information, the class template and method signature for dynamic construction are obtained, and based on the extracted tag information, a new Java class is dynamically created at runtime using the Javassist library according to the tag information, and method functions containing tag information are added to the class. It is ensured that these method functions can propagate the coloring tags and can record stack trace information during execution. The newly constructed class is loaded into the JVM so that it can be referenced by subsequent operations.
[0148] Step S115: Execute the test logic to obtain test related information.
[0149] In this embodiment, the test logic is executed by the application according to the test code, class and method function to obtain test related information, and the class and method function are used to add tag information to the stack information during the execution of the test logic.
[0150] The class objects (from the above step S114) and test codes loaded into the JVM call the classes loaded in step S114 to execute the corresponding test logic according to the received request path and test code. Since these classes have been marked with unique tag information, the stack information during the entire execution process will contain this tag information, which is convenient for tracking and analysis.
[0151] Specifically, the request path refers to the portion of the URL (uniform resource locator) in the HTTP request, which specifies the resource location on the server or the service endpoint to be called. The request path is used to determine which test logic or handler should be executed to respond to the test request.
[0152] In the context of RASP assessment, the request path can help identify which specific API endpoint or function is targeted by the test code. Therefore, the application will decide which specific test logic or processing function to call based on the path information in the received HTTP request, and then execute the test code in that context to simulate abnormal behavior and perform analysis.
[0153] Furthermore, when the application receives a test request with tag information, it parses the request path and selects the correct test logic or handler to handle the request based on the request path. If the request path points to an API endpoint with a known security vulnerability, then in the test environment, it will allow the execution of the code snippet related to the test, while tracking the execution process through the previously constructed method with tag information.
[0154] The test related information includes at least one of alarm and interception logs, context information of de-grouping and entry of alarm or interception points, and RASP version information.
[0155] Step S116, execution completed.
[0156] In this embodiment, as described above, the evaluation script includes multiple test codes, and the process of one test code is completed through the above steps S111-S115. Therefore, it is determined whether all the test codes in the evaluation script have been executed.
[0157] In response to the execution not being completed, the process returns to step S111 , determines the next test code, and executes steps S111 - S115 .
[0158] In response to all being executed, the process proceeds to step S116.
[0159] Step S117: Generate evaluation results.
[0160] In this embodiment, in response to the test codes in the evaluation script being all executed, an evaluation result corresponding to the evaluation script is generated according to the test related information. The evaluation result is obtained by analyzing the test related information returned by the application. The evaluation result includes at least one of the interception and alarm conditions of each test code, the alarm response time of the RASP console, the detection rate, the interception rate and the false alarm rate.
[0161] Specifically, as described above, during the execution of the test logic, tag information is added to the stack information during the execution of the test logic through classes and method functions with tag information. Thus, the logs of the RASP system when potential abnormal behavior is detected can be collected based on the tag information. The log information includes information such as type, occurrence time, source IP, target resource, whether to intercept, etc. Ensure that data from different sources has a unified format to facilitate subsequent analysis, for example, convert all timestamps to a unified time format. Parse the RASP log file, extract relevant fields such as event ID, timestamp, type, whether to intercept, etc., and then analyze based on the test-related information to obtain the evaluation results.
[0162] Among them, the interception and alarm status of the test code includes information such as whether RASP intercepts or alarms the test code.
[0163] The RASP console alarm response time is the time interval from initiating a test request to the time when RASP generates an alarm.
[0164] The detection rate is the probability that a test request is correctly identified, and may be the ratio of the number of correctly identified test requests to the total number of test requests.
[0165] The interception rate is the probability that a test request is intercepted, which may be the ratio of the number of intercepted test requests to the number of correctly identified test requests.
[0166] The false positive rate is the ratio of the number of normal requests during the test period that are mistakenly identified as abnormal behavior by RASP to the total number of test requests.
[0167] Step S118: Release the file lock.
[0168] In this embodiment, after the evaluation result is generated, the file lock corresponding to the current evaluation script is released to avoid affecting other tests.
[0169] The embodiment of the present invention determines the test code that needs to be executed in the evaluation script, generates tag information corresponding to the unique test code, generates a test request based on the tag information and the test code and sends it to the application, and the application generates a class and method function with the tag information based on the received tag information and the test code. When executing the test logic, the class and method function with the tag information are used to add tag information to the stack information in the execution process of the test logic, and the evaluation result of the RASP protection capability is obtained based on the test-related information obtained by the application. In this way, the efficiency of the RASP evaluation can be improved, and large-scale continuous evaluation can be supported. At the same time, the evaluation results can be automatically obtained according to unified standards, which can improve the accuracy and repeatability of the RASP evaluation, and is conducive to long-term tracking of changes in the protection capabilities of RASP products.
[0170] Figure 3 FIG. 4 is a flow chart of a method for evaluating RASP protection capability according to another embodiment of the present invention. Figure 3 As shown, the RASP protection capability evaluation method of the embodiment of the present invention includes the following steps:
[0171] Step S210: Determine the test code that needs to be executed in the evaluation script.
[0172] Step S220: Generate marking information corresponding to the test code, where the marking information is used to mark a unique test code;
[0173] Step S230: Generate a test request and send it to the application, wherein the test request includes the test code and the marking information;
[0174] Step S240: Generate a class and method function with the tag information according to the tag information and the test code;
[0175] Step S250: executing the test logic according to the test code, class and method function through the application program to obtain test related information, wherein the class and method function are used to add tag information to the stack information during the execution of the test logic;
[0176] Step S260: Obtain an evaluation result of the RASP protection capability according to the test related information.
[0177] In some embodiments, the method further comprises:
[0178] Receiving an evaluation script sent by the management platform, wherein the evaluation script includes at least one test code and a predetermined hash value;
[0179] Obtain the file lock corresponding to the evaluation script;
[0180] In response to successfully acquiring the file lock, detecting whether an application exists locally;
[0181] In response to the presence of an application, detecting whether the application matches a predetermined hash value in the evaluation script;
[0182] In response to the application matching a predetermined hash value in the evaluation script, a test environment is configured according to the application.
[0183] In some embodiments, the method further comprises:
[0184] In response to failure to successfully obtain the file lock, after waiting for a first predetermined period of time, obtain the file lock corresponding to the evaluation script.
[0185] In some embodiments, the method further comprises:
[0186] In response to the application not being present, or the application being present and the application not matching a predetermined hash value in the evaluation script, downloading the application;
[0187] Configure the test environment according to the application in question.
[0188] In some embodiments, configuring the test environment according to the application comprises:
[0189] detecting whether the application is already running;
[0190] In response to the application being run, obtaining a running time of the application;
[0191] In response to the running time being greater than or equal to a second predetermined time, configuring the test environment is completed, and the second predetermined time is determined according to the time required for RASP injection.
[0192] In some embodiments, configuring the test environment according to the application further comprises:
[0193] In response to the application not being running, launching the application;
[0194] Obtaining the running time of the application;
[0195] In response to the running time being greater than or equal to the second predetermined time, configuring the test environment is completed.
[0196] In some embodiments, the test-related information includes at least one of alarm and interception logs, context information of de-grouping and entry of alarm or interception points, and RASP version information.
[0197] In some embodiments, the evaluation results include at least one of the interception and alarm status of each test code, the RASP console alarm response time, the detection rate, the interception rate and the false alarm rate.
[0198] In some embodiments, the method further comprises:
[0199] The evaluation result is sent to the management platform so that the management platform generates a test report according to the evaluation result.
[0200] The embodiment of the present invention determines the test code that needs to be executed in the evaluation script, generates tag information corresponding to the unique test code, generates a test request based on the tag information and the test code and sends it to the application, and the application generates a class and method function with the tag information based on the received tag information and the test code. When executing the test logic, the class and method function with the tag information are used to add tag information to the stack information in the execution process of the test logic, and the evaluation result of the RASP protection capability is obtained based on the test-related information obtained by the application. In this way, the efficiency of the RASP evaluation can be improved, and large-scale continuous evaluation can be supported. At the same time, the evaluation results can be automatically obtained according to unified standards, which can improve the accuracy and repeatability of the RASP evaluation, and is conducive to long-term tracking of changes in the protection capabilities of RASP products.
[0201] Figure 4 Schematic diagram of a device for evaluating the RASP protection capability according to an embodiment of the present invention. Figure 4 As shown, the RASP protection capability evaluation device of the embodiment of the present invention includes a test code determination unit 41, a tag information generation unit 42, a test request sending unit 43, a data generation unit 44, a test information acquisition unit 45, and an evaluation result acquisition unit 46. Among them, the test code determination unit 41 is used to determine the test code that needs to be executed in the evaluation script. The tag information generation unit 42 is used to generate tag information corresponding to the test code, and the tag information is used to mark the unique test code. The test request sending unit 43 is used to generate a test request and send it to an application, and the test request includes the test code and the tag information. The data generation unit 44 is used to generate a class and method function with the tag information according to the tag information and the test code. The test information acquisition unit 45 is used to execute the test logic according to the test code, class and method function through the application to obtain test related information, and the class and method function are used to add tag information to the stack information during the execution of the test logic. The evaluation result acquisition unit 46 is used to obtain the evaluation result of the RASP protection capability according to the test related information.
[0202] The embodiment of the present invention determines the test code that needs to be executed in the evaluation script, generates tag information corresponding to the unique test code, generates a test request based on the tag information and the test code and sends it to the application, and the application generates a class and method function with the tag information based on the received tag information and the test code. When executing the test logic, the class and method function with the tag information are used to add tag information to the stack information in the execution process of the test logic, and the evaluation result of the RASP protection capability is obtained based on the test-related information obtained by the application. In this way, the efficiency of the RASP evaluation can be improved, and large-scale continuous evaluation can be supported. At the same time, the evaluation results can be automatically obtained according to unified standards, which can improve the accuracy and repeatability of the RASP evaluation, and is conducive to long-term tracking of changes in the protection capabilities of RASP products.
[0203] Figure 5 Schematic diagram of an electronic device according to an embodiment of the present invention. In this embodiment, the electronic device 5 includes a server, a terminal, etc. Figure 5 As shown, the electronic device 5 includes: at least one processor 51; a memory 52 connected to the at least one processor 51 for communication; and a communication component 53 connected to the scanning device for communication, the communication component 53 receives and sends data under the control of the processor 51; wherein the memory 52 stores instructions executable by at least one processor 51, and the instructions are executed by at least one processor 51 to implement the above-mentioned RASP protection capability evaluation method.
[0204] Specifically, the electronic device includes: one or more processors 51 and a memory 52, Figure 5 A processor 51 is taken as an example. The processor 51 and the memory 52 may be connected via a bus or other means. Figure 5 In the example, the bus connection is used. The memory 52 is a non-volatile computer-readable storage medium that can be used to store non-volatile software programs, non-volatile computer executable programs and modules. The processor 51 executes various functional applications and data processing of the device by running the non-volatile software programs, instructions and modules stored in the memory 52, that is, the above-mentioned RASP protection capability evaluation method is realized.
[0205] The memory 52 may include a program storage area and a data storage area, wherein the program storage area may store an operating system and applications required for at least one function; the data storage area may store a list of options, etc. In addition, the memory 52 may include a high-speed random access memory, and may also include a non-volatile memory, such as at least one disk storage device, a flash memory device, or other non-volatile solid-state storage device. In some embodiments, the memory 52 may optionally include a memory remotely arranged relative to the processor 51, and these remote memories may be connected to an external device via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0206] One or more modules are stored in the memory 52, and when executed by one or more processors 51, the RASP protection capability evaluation method in any of the above method embodiments is executed.
[0207] The above-mentioned product can execute the method provided in the embodiment of the present application, and has the functional modules and beneficial effects corresponding to the execution method. For technical details not fully described in this embodiment, please refer to the method provided in the embodiment of the present application.
[0208] The embodiment of the present invention determines the test code that needs to be executed in the evaluation script, generates tag information corresponding to the unique test code, generates a test request based on the tag information and the test code and sends it to the application, and the application generates a class and method function with the tag information based on the received tag information and the test code. When executing the test logic, the class and method function with the tag information are used to add tag information to the stack information in the execution process of the test logic, and the evaluation result of the RASP protection capability is obtained based on the test-related information obtained by the application. In this way, the efficiency of the RASP evaluation can be improved, and large-scale continuous evaluation can be supported. At the same time, the evaluation results can be automatically obtained according to unified standards, which can improve the accuracy and repeatability of the RASP evaluation, and is conducive to long-term tracking of changes in the protection capabilities of RASP products.
[0209] Another embodiment of the present invention relates to a non-volatile storage medium for storing a computer-readable program, wherein the computer-readable program is used for a computer to execute part or all of the above method embodiments.
[0210] That is, those skilled in the art can understand that all or part of the steps in the above-mentioned embodiment method can be completed by instructing the relevant hardware through a program, and the program is stored in a storage medium, including a number of instructions to enable a device (which can be a single-chip microcomputer, chip, etc.) or a processor to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), disk or optical disk and other media that can store program codes.
[0211] The above description is only a preferred embodiment of the present application and is not intended to limit the present application. For those skilled in the art, the present application may have various modifications and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application.
Claims
1. A method for evaluating RASP protection capability, characterized in that: The method comprises: Identify the test code that needs to be executed in the evaluation script; Generate marking information corresponding to the test code, where the marking information is used to mark a unique test code; Generate a test request and send it to an application, wherein the test request includes the test code and the tag information; Generate a class and method function with the tag information according to the tag information and the test code; Execute the test logic according to the test code, class and method function through the application program to obtain test related information, wherein the class and method function are used to add marking information to the stack information during the execution of the test logic; The evaluation result of the RASP protection capability is obtained according to the test related information.
2. The method according to claim 1, characterized in that The method further comprises: Receiving an evaluation script sent by a management platform, wherein the evaluation script includes at least one test code and a predetermined hash value; Obtain the file lock corresponding to the evaluation script; In response to successfully acquiring the file lock, detecting whether an application exists locally; In response to the presence of an application, detecting whether the application matches a predetermined hash value in the evaluation script; In response to the application matching a predetermined hash value in the evaluation script, a test environment is configured according to the application.
3. The method according to claim 2, characterized in that The method further comprises: In response to failure to successfully obtain the file lock, after waiting for a first predetermined period of time, obtain the file lock corresponding to the evaluation script.
4. The method according to claim 2, characterized in that: The method further comprises: In response to the application not being present, or the application being present and the application not matching a predetermined hash value in the evaluation script, downloading the application; Configure the test environment according to the application in question.
5. The method according to claim 2 or 4, characterized in that: Configuring the test environment according to the application comprises: detecting whether the application is already running; In response to the application being run, obtaining a running time of the application; In response to the running time being greater than or equal to a second predetermined time, configuring the test environment is completed, and the second predetermined time is determined according to the time required for RASP injection.
6. The method according to claim 5, characterized in that Configuring the test environment according to the application further includes: In response to the application not being running, launching the application; Obtaining the running time of the application; In response to the running time being greater than or equal to the second predetermined time, configuring the test environment is completed.
7. The method according to claim 1, characterized in that The test related information includes at least one of alarm and interception logs, context information of de-grouping and entry of alarm or interception points, and RASP version information.
8. The method according to claim 1, characterized in that The evaluation results include at least one of the interception and alarm conditions of each test code, the RASP console alarm response time, the detection rate, the interception rate and the false alarm rate.
9. The method according to claim 1, characterized in that: The method further comprises: The evaluation result is sent to a management platform so that the management platform generates a test report according to the evaluation result.
10. A device for evaluating RASP protection capability, characterized in that: The device comprises: A test code determination unit, used to determine the test code that needs to be executed in the evaluation script; A marking information generating unit, used to generate marking information corresponding to the test code, wherein the marking information is used to mark a unique test code; A test request sending unit, used for generating a test request and sending it to an application program, wherein the test request includes the test code and the marking information; A data generation unit, used for generating a class and a method function with the tag information according to the tag information and the test code; A test information acquisition unit, used to execute the test logic according to the test code, class and method function through the application program to obtain test related information, wherein the class and method function are used to add marking information to the stack information during the execution of the test logic; The evaluation result acquisition unit is used to acquire the evaluation result of the RASP protection capability according to the test related information.
11. An electronic device comprising a memory and a processor, characterized in that: The memory is used to store one or more computer program instructions, wherein the one or more computer program instructions are executed by the processor to implement the method according to any one of claims 1 to 9.
12. A computer program product, comprising a computer program, characterized in that: When the computer program is executed on a computer, the computer executes the method according to any one of claims 1 to 9.
13. A computer-readable storage medium storing computer program instructions, characterized in that: The computer program instructions, when executed by a processor, implement the method according to any one of claims 1 to 9.