Horizontal unauthorized vulnerability repairing method and device, equipment and medium

By determining the authentication inspection section in the web application, obtaining and judging business requests, and intercepting requests that meet the horizontal overright characteristics, the problem of low efficiency in the current technology of horizontal overright vulnerability repair is solved, and efficient and low-coupled vulnerability repair is achieved.

CN120180436APending Publication Date: 2025-06-20NETSUNION CLEARING CORP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311744244.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-12-18
Publication Date
2025-06-20

AI Technical Summary

Technical Problem

The existing technology is less efficient when repairing level-out privilege vulnerabilities, and requires a thorough transformation of the underlying engineering of web applications, which is a lot of work.

Method used

By determining the authentication and inspection section corresponding to the business module with horizontal overriding vulnerability, the service request for the business module is obtained, and whether it meets the horizontal overriding feature, and intercept the request if it meets the feature.

Benefits of technology

It effectively intercepts business requests that meet the characteristics of horizontal overright, repairs horizontal overright vulnerabilities, and has low coupling between the repair method and the source code, high code readability, small workload, and high repair efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120180436A_ABST
    Figure CN120180436A_ABST
Patent Text Reader

Abstract

The invention discloses a horizontal unauthorized vulnerability repairing method and device, equipment and a medium, and belongs to the technical field of Internet. The horizontal unauthorized vulnerability repair method comprises the following steps: determining an authentication check section corresponding to a service module with a horizontal unauthorized vulnerability; obtaining a service request for the service module based on the authentication check aspect; judging whether the service request conforms to a horizontal unauthorized feature or not; and intercepting the service request under the condition that the service request conforms to the level unauthorized feature. Through the scheme disclosed by the invention, the service request conforming to the horizontal unauthorized feature can be effectively intercepted, and the horizontal unauthorized vulnerability can be repaired. Moreover, the coupling degree between the repairing mode and the source code corresponding to the business module is low, the code readability is high, the vulnerability repairing workload is small, and the method has relatively high level unauthorized vulnerability repairing efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application belongs to the field of Internet technologies, and particularly relates to a method, apparatus, device, and medium for repairing horizontal privilege escalation vulnerabilities. Background Art

[0002] With the development of Internet technologies and software technologies, there are more and more Web application programs.

[0003] Privilege escalation vulnerabilities are common security vulnerabilities in Web application programs. Privilege escalation vulnerabilities include horizontal privilege escalation vulnerabilities and vertical privilege escalation vulnerabilities. Horizontal privilege escalation means that an attacker attempts to access user resources with the same permissions as him; vertical privilege escalation means that a low-level attacker attempts to access high-level user resources or a high-level user attempts to access low-level user resources.

[0004] In related technologies, when repairing horizontal privilege escalation vulnerabilities, it is usually: transferring the control of permissions to the data interface layer, and requiring the web layer to additionally provide user identification when calling the interfaces of the data interface layer. However, by using this method to repair horizontal privilege escalation vulnerabilities, it is necessary to completely transform the underlying project of the Web application program, which has a large workload and low repair efficiency. Summary of the Invention

[0005] The purpose of the embodiments of this application is to provide a method, apparatus, device, and medium for repairing horizontal privilege escalation vulnerabilities, which can solve the problem of low repair efficiency of horizontal privilege escalation vulnerabilities.

[0006] In a first aspect, the embodiments of this application provide a method for repairing horizontal privilege escalation vulnerabilities, including:

[0007] Determine an authentication check aspect corresponding to a service module with a horizontal privilege escalation vulnerability;

[0008] Based on the authentication check aspect, obtain a service request for the service module;

[0009] Determine whether the service request conforms to the characteristics of horizontal privilege escalation;

[0010] In the case where the service request conforms to the characteristics of horizontal privilege escalation, intercept the service request.

[0011] In a second aspect, the embodiments of this application provide a device for repairing horizontal privilege escalation vulnerabilities, including:

[0012] A determination module, configured to determine an authentication check aspect corresponding to a service module with a horizontal privilege escalation vulnerability;

[0013] An obtaining module, configured to obtain a service request for the service module based on the authentication check aspect;

[0014] A judgment module, configured to determine whether the service request conforms to the characteristics of horizontal privilege escalation;

[0015] An interception module, configured to intercept a service request when the service request conforms to the horizontal privilege escalation feature.

[0016] In a third aspect, an embodiment of the present application provides an electronic device, including a processor and a memory, where the memory stores a program or instruction that can run on the processor, and when the program or instruction is executed by the processor, the steps of the horizontal privilege escalation vulnerability repair method provided in the first aspect of the embodiment of the present application are implemented.

[0017] In a fourth aspect, an embodiment of the present application provides a readable storage medium, on which a program or instruction is stored, and when the program or instruction is executed by a processor, the steps of the horizontal privilege escalation vulnerability repair method provided in the first aspect of the embodiment of the present application are implemented.

[0018] In a fifth aspect, an embodiment of the present application provides a chip, including a processor and a communication interface, the communication interface is coupled to the processor, and the processor is configured to run a program or instruction to implement the steps of the horizontal privilege escalation vulnerability repair method provided in the first aspect of the embodiment of the present application.

[0019] In a sixth aspect, an embodiment of the present application provides a computer program product, which is stored in a storage medium, and the program product is executed by at least one processor to implement the steps of the horizontal privilege escalation vulnerability repair method provided in the first aspect of the embodiment of the present application.

[0020] In the embodiment of the present application, by determining an authentication check section corresponding to a service module with a horizontal privilege escalation vulnerability; based on the authentication check section, obtaining a service request for the service module; determining whether the service request conforms to the horizontal privilege escalation feature; and intercepting the service request when the service request conforms to the horizontal privilege escalation feature. Through the solution of the present application, service requests conforming to the horizontal privilege escalation feature can be effectively intercepted, and the horizontal privilege escalation vulnerability can be repaired. Moreover, this repair method has a low coupling degree with the source code corresponding to the service module, high code readability, small vulnerability repair workload, and high horizontal privilege escalation vulnerability repair efficiency. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings required to be used in the embodiments of the present application. For those of ordinary skill in the art, other drawings can also be obtained based on these drawings without creative efforts.

[0022] Figure 1 is a schematic flowchart of the horizontal privilege escalation vulnerability repair method provided in the embodiment of the present application;

[0023] Figure 2 is a schematic diagram of the process of repairing the horizontal privilege escalation vulnerability provided in the embodiment of the present application;

[0024] Figure 3 is a schematic structural diagram of a horizontal privilege escalation vulnerability repair device provided by an embodiment of the present application;

[0025] Figure 4 is a schematic structural diagram of an electronic device provided by an embodiment of the present application;

[0026] Figure 5 is a schematic hardware structure diagram of an electronic device for implementing an embodiment of the present application. Detailed implementation manners

[0027] Next, the technical solutions in the embodiments of the present application will be clearly described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art belong to the scope of protection of the present application.

[0028] The terms "first", "second", etc. in the specification and claims of the present application are used to distinguish similar objects, rather than to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of the present application can be implemented in an order other than those illustrated or described herein, and the objects distinguished by "first", "second", etc. are generally of the same type, and the number of objects is not limited. For example, the first object can be one or multiple. In addition, "and / or" in the specification and claims means at least one of the connected objects, and the character " / " generally means that the associated objects before and after are in an "or" relationship.

[0029] Next, in conjunction with the accompanying drawings, the horizontal privilege escalation vulnerability repair method, device, equipment and medium provided by the embodiments of the present application will be described in detail through specific embodiments and their application scenarios.

[0030] Figure 1 is a schematic flowchart of a horizontal privilege escalation vulnerability repair method provided by an embodiment of the present application. As Figure 1 shown, the horizontal privilege escalation vulnerability repair method may include:

[0031] S110: Determine an authentication check section corresponding to a service module with a horizontal privilege escalation vulnerability;

[0032] S120: Obtain a service request for the service module based on the authentication check section;

[0033] S130: Determine whether the service request conforms to the horizontal privilege escalation feature;

[0034] S140: Intercept the service request when the service request conforms to the horizontal privilege escalation feature.

[0035] The specific implementation manners of the above steps will be described in detail below.

[0036] In the embodiment of the present application, an authentication check aspect is set through aspect technology, and a service request for a service module is obtained through the authentication check aspect corresponding to the service module with a horizontal privilege escalation vulnerability, and it is determined whether the service request conforms to the horizontal privilege escalation feature, which has little impact on the source code; in the case where the service request conforms to the horizontal privilege escalation feature, the service request is intercepted. Through the solution of the present application, service requests conforming to the horizontal privilege escalation feature can be effectively intercepted, and the horizontal privilege escalation vulnerability can be repaired. Moreover, this repair method has a low coupling degree with the source code corresponding to the service module, high code readability, small vulnerability repair workload, and high horizontal privilege escalation vulnerability repair efficiency.

[0037] In some possible implementations of the embodiment of the present application, in S110, an authentication check aspect corresponding to the sending of the service request of the service module with a horizontal privilege escalation vulnerability can be determined. In some other possible implementations of the embodiment of the present application, in S110, an authentication check aspect corresponding to the receiving of the service request of the service module with a horizontal privilege escalation vulnerability can also be determined.

[0038] In some possible implementations of the embodiment of the present application, the service request may be a request sent by a Web client for a service module on the server side. For the server side, it is necessary to determine whether the service request conforms to the horizontal privilege escalation feature before returning a response result to the Web client. Then, there are at least two ways to set the authentication check aspect:

[0039] One way is to determine an authentication check aspect corresponding to the sending of the service request of the service module with a horizontal privilege escalation vulnerability. In this way, the authentication check aspect can be set in the Web client and is correspondingly set with the service request sending function of the Web client to perform authentication check on the service request before the Web client sends out the service request.

[0040] Another way is to determine an authentication check aspect corresponding to the receiving of the service request of the service module with a horizontal privilege escalation vulnerability. In this way, the authentication check aspect can be set on the server side and is correspondingly set with the service request receiving function or processing function of the server side. Considering that the client is also at risk of being attacked during the process of transmitting the request to the server side, setting the authentication check aspect on the server side is a relatively better way.

[0041] In some possible implementations of the embodiments of the present application, the authentication check aspect in the embodiments of the present application may be an aspect for performing authentication checks developed based on Aspect Oriented Programming (AOP). Among them, the aspect includes a pointcut and an advice. The pointcut is the entry point for executing the aspect, and the advice is used to implement the aspect logic.

[0042] In some possible implementations of the embodiments of the present application, S130 may include: if the attribute information of the service request is recorded in the first request configuration table, then the service request conforms to the horizontal privilege escalation feature; where the first request configuration table includes service requests that are prohibited from accessing the service module.

[0043] It can be understood that the first configuration request table is similar to a blacklist, and the first request configuration table includes service requests that are prohibited from accessing the service module. Exemplarily, the service module with a horizontal privilege escalation vulnerability is service module M, and the first request configuration table includes three service requests that are prohibited from accessing service module M, and the three service requests that are prohibited from accessing service module M are respectively: the access request of user X to service module M, the access request of user Y to service module M, and the access request of user Z to service module M.

[0044] When the access request of user Y to service module M is obtained, at this time, the access request of user Y to service module M exists in the first request configuration table, and this service request conforms to the horizontal privilege escalation feature. At this time, horizontal privilege escalation occurs, and then the access request of user Y to service module M is intercepted, and user Y is prohibited from accessing service module M.

[0045] In some possible implementations of the embodiments of the present application, S120 may include: if the attribute information of the service request is recorded in the second request configuration table, then the service request does not conform to the horizontal privilege escalation feature; where the second request configuration table includes service requests that are allowed to access the service module.

[0046] It can be understood that the second configuration request table is similar to a white list, and the second request configuration table includes service requests that are allowed to access the service module. Exemplarily, the service module with a horizontal privilege escalation vulnerability is service module M, and the second request configuration table includes a service request that is allowed to access service module M, and this access request is the access request of user X to service module M.

[0047] When the access request of user Y to service module M is obtained, at this time, the access request of user Y to the service module does not exist in the second request configuration table, and this service request conforms to the horizontal privilege escalation feature. At this time, horizontal privilege escalation occurs, and then the access request of user Y to service module M is intercepted, and user Y is prohibited from accessing service module M.

[0048] When an access request from user X for business module M is obtained, at this time, the access request from user X for business module M exists in the second request configuration table. Since this business request does not conform to the horizontal privilege escalation feature and the access to business module M is a normal access, the access request from user X for business module M is released, allowing user X to access business module M.

[0049] In some possible implementations of the embodiments of the present application, the attribute information of a business request may include: the business identifier of the business to which the business request belongs.

[0050] In some possible implementations of the embodiments of the present application, S130 may include: when the number of times the business request triggers an alarm is greater than or equal to the threshold number of times, then the business request conforms to the horizontal privilege escalation feature.

[0051] Exemplarily, it is assumed that an access request from user X for business module M is obtained, and the threshold number of times is 5 times.

[0052] When the number of times the access request from user X for business module M triggers an alarm is greater than or equal to 5 times, then the access request from user X for business module M conforms to the horizontal privilege escalation feature, and the access request from user X for business module M is intercepted, prohibiting user X from accessing business module M.

[0053] In some possible implementations of the embodiments of the present application, the method for repairing horizontal privilege escalation vulnerabilities provided by the embodiments of the present application further includes: when the number of alarm times is less than the threshold number of times, performing a horizontal privilege escalation alarm operation.

[0054] Exemplarily, it is assumed that an access request from user X for business module M is obtained, and the threshold number of times is 5 times.

[0055] When the number of times the access request from user X for business module M triggers an alarm is less than 5 times, at this time, a horizontal privilege escalation alarm operation can be performed. For example, sending a text message, an email or displaying a prompt message to the operation and maintenance personnel of the Web application, etc., to prompt that a horizontal privilege escalation occurs when user X accesses business module M.

[0056] After seeing the prompt message, the operation and maintenance personnel can verify whether user X's access to business module M belongs to horizontal privilege escalation.

[0057] When the operation and maintenance personnel verify that user X's access to business module M does indeed belong to horizontal privilege escalation, the above-mentioned threshold number of times can be reduced, so that when an access request from user X for business module M is obtained subsequently, the access request from user X for business module M can be directly intercepted without performing the alarm operation again, which can improve the efficiency of repairing horizontal privilege escalation vulnerabilities.

[0058] When the operation and maintenance personnel verify that user X's access to business module M does not constitute horizontal unauthorized access, the above request configuration table can be modified to release subsequent user X's access requests to business module M, thereby avoiding the generation of false interception and affecting user X's normal access to business module M.

[0059] In an embodiment of the present application, when the number of times a service request triggers an alarm is less than a threshold number, a horizontal overauthorization alarm operation is performed, so that operation and maintenance personnel can verify the service request to avoid the occurrence of erroneous interception.

[0060] In some possible implementations of the embodiments of the present application, when the number of service request triggering alarms is less than the number threshold, an access report can also be generated for operation and maintenance personnel to review to verify whether the user's access to the service module constitutes horizontal unauthorized access.

[0061] Figure 2 It is a schematic diagram of the process of repairing horizontal unauthorized access vulnerabilities provided in an embodiment of the present application.

[0062] exist Figure 2 In the example, user M initiates an access request i to a certain service module (eg, service module n) through a browser in the electronic device used by the user.

[0063] Call the request configuration table, and determine whether the service request i meets the horizontal unauthorized feature according to the access request i and the request configuration table;

[0064] When the service request i does not meet the horizontal unauthorized feature, the access request i is released to perform subsequent normal access to the service module n.

[0065] When the service request i meets the horizontal overriding feature, the number of horizontal overriding occurrences corresponding to the access request i is increased by 1;

[0066] Determine whether the number of horizontal unauthorized occurrences corresponding to the access request i is greater than or equal to a number threshold;

[0067] When the number of horizontal unauthorized access corresponding to the access request i is less than the number threshold, a horizontal unauthorized access alarm operation is performed and the access request i is released.

[0068] When the operation and maintenance personnel verify that the access request i does not constitute horizontal unauthorized access, the request configuration table can be modified to release the subsequent access request i to avoid erroneous interception of the access request i.

[0069] When the operation and maintenance personnel verify that the access request i is a horizontal unauthorized access, the above-mentioned number threshold can be lowered so that when the access request i is obtained again in the future, the access request i can be directly intercepted without performing the horizontal unauthorized access alarm operation, which can improve the efficiency of repairing the horizontal unauthorized access vulnerability.

[0070] When the operation and maintenance personnel confirm that the access request i belongs to horizontal privilege escalation or when the operation and maintenance personnel do not confirm in time whether the access request i belongs to horizontal privilege escalation, when the number of occurrences of horizontal privilege escalation corresponding to the access request i is greater than or equal to the threshold number of times, intercept the access request i.

[0071] It should be noted that for the horizontal privilege escalation vulnerability repair method provided in the embodiments of the present application, the execution subject may be a horizontal privilege escalation vulnerability repair device. In the embodiments of the present application, taking the horizontal privilege escalation vulnerability repair device executing the horizontal privilege escalation vulnerability repair method as an example, the horizontal privilege escalation vulnerability repair device provided in the embodiments of the present application is described.

[0072] Figure 3 It is a schematic structural diagram of the horizontal privilege escalation vulnerability repair device provided in the embodiments of the present application. As Figure 3 shown, the horizontal privilege escalation vulnerability repair device 300 may include:

[0073] A determination module 301, configured to determine an authentication check section corresponding to a service module with a horizontal privilege escalation vulnerability;

[0074] An acquisition module 302, configured to acquire a service request for the service module based on the authentication check section;

[0075] A judgment module 303, configured to judge whether the service request conforms to the horizontal privilege escalation feature;

[0076] An interception module 304, configured to intercept the service request when the service request conforms to the horizontal privilege escalation feature.

[0077] In the embodiments of the present application, by using the aspect technology to set the authentication check section, acquiring the service request for the service module through the authentication check section corresponding to the service module with a horizontal privilege escalation vulnerability, judging whether the service request conforms to the horizontal privilege escalation feature, the impact on the source code is small; when the service request conforms to the horizontal privilege escalation feature, intercept the service request. Through the solution of the present application, it is possible to effectively intercept the service requests that conform to the horizontal privilege escalation feature and repair the horizontal privilege escalation vulnerability. Moreover, this repair method has a low coupling degree with the source code corresponding to the service module, high code readability, small vulnerability repair workload, and high horizontal privilege escalation vulnerability repair efficiency.

[0078] In some possible implementations of the embodiments of the present application, the determination module 301 may specifically be configured to:

[0079] Determine the authentication check section corresponding to the sending of the service request;

[0080] And / or,

[0081] Determine the authentication check section corresponding to the reception of the service request.

[0082] In some possible implementations of the embodiments of the present application, the determination module 303 may specifically be configured to:

[0083] If the attribute information of the service request is recorded in the first request configuration table, then the service request conforms to the horizontal privilege escalation feature; wherein, the first request configuration table includes service requests that are prohibited from accessing the service module.

[0084] In some possible implementations of the embodiments of the present application, the determination module 303 may specifically be configured to:

[0085] If the attribute information of the service request is recorded in the second request configuration table, then the service request does not conform to the horizontal privilege escalation feature; wherein, the second request configuration table includes service requests that are allowed to access the service module.

[0086] In some possible implementations of the embodiments of the present application, the attribute information of the service request may include:

[0087] The service identifier of the service to which the service request belongs.

[0088] In some possible implementations of the embodiments of the present application, the determination module 303 may specifically be configured to:

[0089] In the case where the number of times the service request triggers an alarm is greater than or equal to the number threshold, then the service request conforms to the horizontal privilege escalation feature.

[0090] In some possible implementations of the embodiments of the present application, the horizontal privilege escalation vulnerability repair device 300 further includes:

[0091] An alarm module, configured to perform a horizontal privilege escalation alarm operation in the case where the number of alarm times is less than the number threshold.

[0092] In the embodiments of the present application, when the number of times the service request triggers an alarm is less than the number threshold, a horizontal privilege escalation alarm operation is performed, so that the operation and maintenance personnel can verify the service request and avoid the occurrence of misinterception.

[0093] The horizontal privilege escalation vulnerability repair device in the embodiments of the present application may be an electronic device or a component in an electronic device, such as an integrated circuit or a chip. The electronic device may be a terminal or other devices other than terminals. Exemplarily, the electronic device may be a mobile phone, a tablet computer, a laptop computer, a handheld computer, a vehicle-mounted electronic device, a Mobile Internet Device (MID), an augmented reality (AR) / virtual reality (VR) device, a robot, a wearable device, an ultra-mobile personal computer (UMPC), a netbook, or a personal digital assistant (PDA), etc. It may also be a server, a Network Attached Storage (NAS), a personal computer (PC), a television (TV), a teller machine, or a self-service machine, etc. The embodiments of the present application do not make specific limitations.

[0094] The horizontal privilege escalation vulnerability repair device in the embodiments of the present application may be a device with an operating system. The operating system may be an Android operating system, an iOS operating system, or other possible operating systems. The embodiments of the present application do not make specific limitations.

[0095] The horizontal privilege escalation vulnerability repair device provided in the embodiments of the present application can implement Figures 1 to 2 each process in the horizontal privilege escalation vulnerability repair method embodiments. To avoid repetition, it will not be elaborated here.

[0096] Optionally, as Figure 4 shown, the embodiments of the present application further provide an electronic device 400, including a processor 401 and a memory 402. The memory 402 stores a program or instruction that can run on the processor 401. When the program or instruction is executed by the processor 401, it implements each step of the above-mentioned horizontal privilege escalation vulnerability repair method embodiments and can achieve the same technical effect. To avoid repetition, it will not be elaborated here.

[0097] In some possible implementations of the embodiments of the present application, the processor 401 may include a central processing unit (CPU), or an Application Specific Integrated Circuit (ASIC), or may be configured as one or more integrated circuits implementing the embodiments of the present application.

[0098] In some possible implementations of the embodiments of the present application, the memory 402 may include a read-only memory (ROM), a random access memory (RAM), a magnetic disk storage medium device, an optical storage medium device, a flash memory device, an electrical, optical, or other physical / tangible memory storage device. Therefore, generally, the memory 402 includes one or more tangible (non-transitory) computer-readable storage media (e.g., memory devices) encoded with software including computer-executable instructions, and when the software is executed (e.g., by one or more processors), it is operable to perform the operations described with reference to the method for fixing horizontal privilege escalation vulnerabilities according to the embodiments of the present application.

[0099] Figure 5 It is a schematic diagram of the hardware structure of the electronic device implementing the embodiments of the present application.

[0100] The electronic device 500 includes, but is not limited to: a radio frequency unit 501, a network module 502, an audio output unit 503, an input unit 504, a sensor 505, a display unit 506, a user input unit 507, an interface unit 508, a memory 509, and a processor 510, and other components.

[0101] Those skilled in the art can understand that the electronic device 500 may further include a power source (such as a battery) for supplying power to each component. The power source may be logically connected to the processor 510 through a power management system, so as to implement functions such as management of charging, discharging, and power consumption management through the power management system. Figure 5 The structure of the electronic device shown in does not constitute a limitation on the electronic device. The electronic device may include more or fewer components than shown in the figure, or combine certain components, or have different component arrangements, which will not be elaborated here.

[0102] Among them, the processor 510 is used to: determine an authentication check aspect corresponding to the service module with a horizontal privilege escalation vulnerability; obtain a service request for the service module based on the authentication check aspect; determine whether the service request conforms to the horizontal privilege escalation feature; and intercept the service request if the service request conforms to the horizontal privilege escalation feature.

[0103] In the embodiments of the present application, an authentication check aspect is set through aspect technology, and a business request for a business module is obtained through the authentication check aspect corresponding to the business module with a horizontal privilege escalation vulnerability, and it is determined whether the business request conforms to the horizontal privilege escalation feature, which has less impact on the source code; in the case where the business request conforms to the horizontal privilege escalation feature, the business request is intercepted. Through the solution of the present application, business requests that conform to the horizontal privilege escalation feature can be effectively intercepted, and horizontal privilege escalation vulnerabilities can be repaired. Moreover, this repair method has a low coupling degree with the source code corresponding to the business module, high code readability, small vulnerability repair workload, and high horizontal privilege escalation vulnerability repair efficiency.

[0104] In some possible implementations of the embodiments of the present application, the processor 510 may specifically be used for:

[0105] Determine the authentication check aspect corresponding to the sending of the business request;

[0106] And / or,

[0107] Determine the authentication check aspect corresponding to the reception of the business request.

[0108] In some possible implementations of the embodiments of the present application, the processor 510 may specifically be used for:

[0109] If the attribute information of the business request is recorded in the first request configuration table, then the business request conforms to the horizontal privilege escalation feature; wherein, the first request configuration table includes business requests that are prohibited from accessing the business module.

[0110] In some possible implementations of the embodiments of the present application, the processor 510 may specifically be used for:

[0111] If the attribute information of the business request is recorded in the second request configuration table, then the business request does not conform to the horizontal privilege escalation feature; wherein, the second request configuration table includes business requests that are allowed to access the business module.

[0112] In some possible implementations of the embodiments of the present application, the attribute information of the business request may include:

[0113] The business identifier of the business to which the business request belongs.

[0114] In some possible implementations of the embodiments of the present application, the processor 510 may specifically be used for:

[0115] In the case where the number of warning times triggered by the business request is greater than or equal to the number threshold, then the business request conforms to the horizontal privilege escalation feature.

[0116] In some possible implementations of the embodiments of the present application, the processor 510 may further be used for:

[0117] When the number of alarms is less than the threshold number of times, perform a horizontal privilege escalation alarm operation.

[0118] In the embodiment of the present application, when the number of alarms triggered by a service request is less than the threshold number of times, a horizontal privilege escalation alarm operation is performed, enabling the operation and maintenance personnel to verify the service request and avoid misinterception.

[0119] It should be understood that in the embodiment of the present application, the input unit 504 may include a Graphics Processing Unit (GPU) 5041 and a microphone 5042. The graphics processor 5041 processes the image data of static pictures or videos obtained by an image capture device (such as a camera) in a video capture mode or an image capture mode. The display unit 506 may include a display panel 5061, and the display panel 5061 may be configured in the form of a liquid crystal display, an organic light-emitting diode, etc. The user input unit 507 includes at least one of a touch panel 5071 and other input devices 5072. The touch panel 5071 is also referred to as a touch screen. The touch panel 5071 may include two parts: a touch detection device and a touch controller. The other input devices 5072 may include, but are not limited to, a physical keyboard, function keys (such as volume control keys, switch keys, etc.), a trackball, a mouse, and a joystick, which will not be elaborated here.

[0120] The memory 509 can be used to store software programs and various data. The memory 509 may mainly include a first storage area for storing programs or instructions and a second storage area for storing data. Among them, the first storage area may store an operating system, application programs or instructions required for at least one function (such as a sound playback function, an image playback function, etc.). In addition, the memory 509 may include a volatile memory or a non-volatile memory, or the memory 509 may include both a volatile memory and a non-volatile memory. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), a static random access memory (SRAM), a dynamic random access memory (DRAM), a synchronous dynamic random access memory (SDRAM), a double data rate synchronous dynamic random access memory (DDR SDRAM), an enhanced synchronous dynamic random access memory (ESDRAM), a synch link dynamic random access memory (SLDRAM), and a direct rambus random access memory (DRRAM). The memory 509 in the embodiments of the present application includes, but is not limited to, these and any other suitable types of memories.

[0121] The processor 510 may include one or more processing units; optionally, the processor 510 integrates an application processor and a modem processor. Among them, the application processor mainly processes operations related to the operating system, user interface, and application programs, etc., and the modem processor mainly processes wireless communication signals, such as a baseband processor. It can be understood that the above modem processor may not be integrated into the processor 510 either.

[0122] The embodiments of the present application also provide a readable storage medium, on which a program or instruction is stored. When the program or instruction is executed by a processor, it implements each process of the above embodiment of the horizontal privilege escalation vulnerability repair method and can achieve the same technical effect. To avoid repetition, it will not be elaborated here.

[0123] Among them, the processor is the processor in the electronic device in the above-mentioned embodiment. The readable storage medium includes a computer-readable storage medium. Examples of the computer-readable storage medium include non-transitory computer-readable storage media, such as ROM, RAM, magnetic disks, or optical discs, etc.

[0124] An embodiment of the present application further provides a chip, including a processor and a communication interface. The communication interface is coupled to the processor. The processor is used to run programs or instructions to implement each process of the above-mentioned embodiment of the horizontal privilege escalation vulnerability repair method, and can achieve the same technical effect. To avoid repetition, it will not be elaborated here.

[0125] It should be understood that the chip mentioned in the embodiment of the present application may also be referred to as a system-on-chip, system chip, chip system, or system-on-chip, etc.

[0126] An embodiment of the present application provides a computer program product. The program product is stored in a storage medium. The program product is executed by at least one processor to implement each process of the above-mentioned embodiment of the horizontal privilege escalation vulnerability repair method, and can achieve the same technical effect. To avoid repetition, it will not be elaborated here.

[0127] It should be noted that in this article, the term "including", "comprising", or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article, or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed, or further includes elements inherent to such process, method, article, or device. Without further limitations, an element defined by the statement "including a..." does not exclude the existence of additional identical elements in the process, method, article, or device including that element. In addition, it should be pointed out that the scope of the methods and devices in the embodiments of the present application is not limited to performing functions in the order shown or discussed. It may also include performing functions in a substantially simultaneous manner or in the reverse order according to the functions involved. For example, the described methods may be performed in an order different from that described, and various steps may be added, omitted, or combined. Additionally, the features described with reference to certain examples may be combined in other examples.

[0128] Through the description of the above embodiments, those skilled in the art can clearly understand that the above-described embodiment methods can be implemented by means of software plus a necessary general hardware platform. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the related technology, can be embodied in the form of a computer software product. The computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions for causing a terminal (which can be a mobile phone, computer, server, or network device, etc.) to execute the methods described in various embodiments of the present application.

[0129] The embodiments of the present application have been described above in conjunction with the accompanying drawings. However, the present application is not limited to the above specific implementation manners. The above specific implementation manners are merely illustrative rather than restrictive. Under the inspiration of the present application, those of ordinary skill in the art can also make many forms without departing from the purpose of the present application and the scope protected by the claims, and all of them belong to the protection scope of the present application.

Claims

1. A method for fixing horizontal privilege escalation vulnerabilities, characterized in that The method includes: Determining an authentication check aspect corresponding to a service module with a horizontal privilege escalation vulnerability; Obtaining a service request for the service module based on the authentication check aspect; Determining whether the service request conforms to the horizontal privilege escalation feature; Intercepting the service request if the service request conforms to the horizontal privilege escalation feature.

2. The method according to claim 1, characterized in that The determining an authentication check aspect corresponding to a service module with a horizontal privilege escalation vulnerability includes: Determining an authentication check aspect corresponding to the sending of the service request; And / or Determining an authentication check aspect corresponding to the receiving of the service request.

3. The method according to claim 1, characterized in that The determining whether the service request conforms to the horizontal privilege escalation feature includes: If the attribute information of the service request is recorded in a first request configuration table, the service request conforms to the horizontal privilege escalation feature; wherein, the first request configuration table includes service requests that are prohibited from accessing the service module.

4. The method according to claim 1, characterized in that The determining whether the service request conforms to the horizontal privilege escalation feature includes: If the attribute information of the service request is recorded in a second request configuration table, the service request does not conform to the horizontal privilege escalation feature; wherein, the second request configuration table includes service requests that are allowed to access the service module.

5. The method according to claim 3 or 4, characterized in that The attribute information includes: The service identifier of the service to which the service request belongs.

6. The method according to claim 1, characterized in that The determining whether the service request conforms to the horizontal privilege escalation feature includes: If the number of warning times triggered by the service request is greater than or equal to a threshold number of times, the service request conforms to the horizontal privilege escalation feature.

7. The method according to claim 6, characterized in that The method further includes: Performing a horizontal privilege escalation warning operation if the number of warning times is less than the threshold number of times.

8. A device for fixing horizontal privilege escalation vulnerabilities, characterized in that The device includes: A determination module for determining an authentication check aspect corresponding to a service module with a horizontal privilege escalation vulnerability; An acquisition module for obtaining a service request for the service module based on the authentication check aspect; A judgment module for determining whether the service request conforms to the horizontal privilege escalation feature; An interception module for intercepting the service request if the service request conforms to the horizontal privilege escalation feature.

9. An electronic device, characterized in that Including: A processor and a memory, the memory stores a program or instruction that can run on the processor, and when the program or instruction is executed by the processor, the steps of the horizontal privilege escalation vulnerability repair method according to any one of claims 1 to 7 are implemented.

10. A readable storage medium, characterized in that A program or instruction is stored on the readable storage medium, and when the program or instruction is executed by a processor, the steps of the horizontal privilege escalation vulnerability repair method according to any one of claims 1 to 7 are implemented.