Network vulnerability testing method, electronic equipment and computer readable medium
By building a preset vulnerability knowledge base and proxy tools to collect full data and generate a targeted test case set, the problem of insufficient effectiveness of existing network vulnerability scanning tools is solved, and efficient and accurate vulnerability detection and rapid repair are achieved.
Patent Information
- Application Number
- CN202311826153.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-27
- Publication Date
- 2025-06-27
AI Technical Summary
The existing network vulnerability scanning tools are insufficient in test cases, and are prone to vulnerability false positives, and cannot fully detect vulnerabilities in the network system.
By building a preset vulnerability knowledge base, the vulnerability type is determined based on the tested data of the tested network system, a targeted test case set is generated, and a proxy tool is used to collect all data and perform intelligent analysis to generate test case units to achieve flexible orchestration and accurate detection.
It reduces the probability of vulnerability false alarms, improves the accuracy and efficiency of vulnerability detection, ensures that the detection results are in line with the actual business scenarios, and can quickly discover and fix new vulnerabilities.
Smart Images

Figure CN120223340A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of network security technology, and particularly to a method for testing network vulnerabilities, an electronic device, and a computer-readable medium. Background Art
[0002] Current various web (World Wide Web) vulnerability scanning tools, such as AWVS (Acunetix Web Vulnerability Scanner), WebInspect (a web application security scanning tool), etc., their scanning principle is mainly to utilize the system's enumeration and crawling functions of web interfaces to obtain api (Application Programming Interface) interface information, and then perform static matching and attempts of vulnerabilities based on the api interface information to discover security vulnerabilities of the web system.
[0003] However, during the vulnerability scanning process, the test cases for testing the same api interface are often fixed and ambiguous, resulting in insufficient effectiveness of the test cases and prone to false positives of vulnerabilities. Summary of the Invention
[0004] Embodiments of the present disclosure provide a method for testing network vulnerabilities, an electronic device, and a computer-readable medium.
[0005] In a first aspect, embodiments of the present disclosure provide a method for testing network vulnerabilities, which includes:
[0006] Determine the vulnerability type corresponding to the test data in the network system to be tested based on a preset vulnerability knowledge base;
[0007] Obtain the test case set corresponding to the test data from the vulnerability knowledge base based on the vulnerability type corresponding to the test data;
[0008] Execute the test case set corresponding to the test data based on the test data to obtain the detection result of the network system to be tested.
[0009] In a second aspect, embodiments of the present disclosure provide an electronic device, including:
[0010] One or more processors;
[0011] A memory storing one or more programs, when the one or more programs are executed by the one or more processors, enabling the one or more processors to implement the method for testing network vulnerabilities described in the first aspect of the embodiments of the present disclosure.
[0012] In a third aspect, embodiments of the present disclosure provide a computer-readable medium having a computer program stored thereon, and when the program is executed by a processor, the method for testing network vulnerabilities described in the first aspect of the embodiments of the present disclosure is implemented.
[0013] The method for testing network vulnerabilities provided by the embodiments of the present disclosure matches test data in a preset vulnerability knowledge base to determine the vulnerability type corresponding to the data to be tested, and generates a test case set according to the vulnerability type corresponding to the data to be tested and the data mapping rules stored in the preset vulnerability knowledge base. The test case set is generated for the vulnerability type corresponding to the data to be tested, realizing flexible arrangement of test cases, thereby reducing the probability of false positives of vulnerabilities and ensuring the accuracy of detection results. BRIEF DESCRIPTION OF THE DRAWINGS
[0014] Figure 1 It is a flowchart of a method for testing network vulnerabilities provided by an embodiment of the present disclosure;
[0015] Figure 2 It is a flowchart of a specific implementation method of step S1 in an embodiment of the present disclosure;
[0016] Figure 3 It is a flowchart of a specific implementation method of step S2 in an embodiment of the present disclosure;
[0017] Figure 4 It is a flowchart of a specific implementation method of step S23 in an embodiment of the present disclosure;
[0018] Figure 5 It is a flowchart of a specific implementation method of step S3 in an embodiment of the present disclosure;
[0019] Figure 6 It is a schematic structural diagram of an electronic device provided by an embodiment of the present disclosure;
[0020] Figure 7 It is a schematic structural diagram of a computer-readable medium provided by an embodiment of the present disclosure;
[0021] Figure 8 It is a schematic diagram of an application environment in the method for testing network vulnerabilities provided by an embodiment of the present disclosure;
[0022] Figure 9 It is a schematic structural diagram of a test system for network vulnerabilities provided by an embodiment of the present disclosure;
[0023] Figure 10 It is a schematic flowchart of a method for testing network vulnerabilities provided by an embodiment of the present disclosure. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0024] To enable those skilled in the art to better understand the technical solutions of the present disclosure, the control method, electronic device, and computer-readable medium of the control provided by the present disclosure will be described in detail below with reference to the accompanying drawings.
[0025] Hereinafter, example embodiments will be described more fully with reference to the accompanying drawings, but the example embodiments may be embodied in different forms and should not be construed as limited to the embodiments set forth herein. On the contrary, these embodiments are provided so that this disclosure will be thorough and complete, and will fully convey the scope of the disclosure to those skilled in the art.
[0026] In the case of no conflict, the embodiments of the present disclosure and the features in the embodiments may be combined with each other.
[0027] As used herein, the term "and / or" includes any and all combinations of one or more of the associated listed items.
[0028] The terms used herein are only for describing specific embodiments and are not intended to limit the present disclosure. As used herein, the singular forms "a" and "the" are also intended to include the plural forms unless the context clearly indicates otherwise. It will also be understood that when the terms "comprises" and / or "consists of" are used in this specification, the specified features, wholes, steps, operations, elements, and / or components are present, but do not preclude the presence or addition of one or more other features, wholes, steps, operations, elements, components, and / or groups thereof.
[0029] Unless otherwise defined, all terms (including technical and scientific terms) used herein have the same meaning as commonly understood by one of ordinary skill in the art. It will also be understood that terms such as those defined in commonly used dictionaries should be interpreted as having a meaning consistent with their meaning in the context of the relevant art and the present disclosure, and will not be interpreted as having an idealized or overly formal meaning unless expressly so defined herein.
[0030] Figure 1 It is a flowchart of a method for testing network vulnerabilities provided for an embodiment of the present disclosure. In a first aspect, referring to Figure 1 , an embodiment of the present disclosure provides a method for testing network vulnerabilities, including:
[0031] S1. Determine the vulnerability type corresponding to the data to be tested in the network system to be tested based on a preset vulnerability knowledge base.
[0032] S2. Obtain the test case set corresponding to the data to be tested from the vulnerability knowledge base based on the vulnerability type corresponding to the data to be tested.
[0033] S3. Execute the test case set corresponding to the data to be tested based on the data to be tested to obtain the detection result of the network system to be tested.
[0034] Embodiments of the present disclosure determine the vulnerability type corresponding to the test data of the network system under test through a preset vulnerability knowledge base. After determining the vulnerability type of the test data, a test case set corresponding to the vulnerability type can be generated through the preset vulnerability knowledge base, and the test case set is executed to obtain the detection result corresponding to the test data, realizing flexible arrangement of test cases, thereby reducing the probability of false vulnerability reports and ensuring the accuracy of the detection result.
[0035] Among them, the network system under test is the object to be tested, and its performance, security, functions, etc. are evaluated for whether there are security vulnerabilities in all aspects. Embodiments of the present disclosure do not limit the network system under test, and it can be a website, a web application or service, etc.
[0036] In some embodiments, the network system under test is in a stable environment. Among them, the stable environment may refer to that the hardware such as servers and network devices works normally without failures or other factors that may affect system stability, or it may refer to that the software such as the operating system, database, and web server is configured correctly and runs stably without serious bugs or other problems that may cause crashes, etc. The present disclosure is not limited thereto.
[0037] Among them, the preset vulnerability knowledge base stores relevant data information of vulnerabilities whose vulnerability types are known, and may include at least one of various vulnerability types, vulnerability metadata, processing method data, vulnerability feature data, processing method metadata, and data mapping rules.
[0038] Correspondingly, in some embodiments, the construction method of the preset vulnerability knowledge base is as follows:
[0039] Obtain vulnerability historical data, and describe the vulnerability historical data according to the vulnerabilities to obtain vulnerability metadata;
[0040] Determine the data mapping rules between the vulnerability type of the vulnerability historical data, the vulnerability metadata, the vulnerability feature data corresponding to the vulnerability metadata, the processing method data corresponding to the vulnerability metadata, and the processing method metadata corresponding to the vulnerability metadata;
[0041] Based on the vulnerability type of the vulnerability historical data, the vulnerability metadata, the vulnerability feature data corresponding to the vulnerability metadata, the processing method data corresponding to the vulnerability metadata, the processing method metadata corresponding to the vulnerability metadata, and the data mapping rules, construct the vulnerability knowledge base.
[0042] In the embodiments of the present disclosure, the vulnerabilities in the vulnerability historical data and the vulnerability types corresponding to the vulnerabilities are known. Embodiments of the present disclosure do not make special limitations on the source of the vulnerability historical data.
[0043] In some embodiments, vulnerability historical data is obtained from vulnerability sites such as CVE, CNNVD, and CNVD.
[0044] In some embodiments, before determining the data mapping rules among the vulnerability type of the vulnerability historical data, the vulnerability metadata, the vulnerability feature data corresponding to the vulnerability metadata, the processing method data corresponding to the vulnerability metadata, and the processing method metadata corresponding to the vulnerability metadata, the following steps are further included:
[0045] According to the vulnerability metadata, extract the processing method data of each vulnerability type in the vulnerability metadata to obtain the processing method data corresponding to the vulnerability metadata;
[0046] Perform feature extraction on each vulnerability in the vulnerability metadata to obtain the vulnerability feature data corresponding to the vulnerability metadata, and describe the processing method data according to the vulnerability type to obtain the processing method metadata corresponding to the processing method data.
[0047] In this embodiment, the vulnerability historical data is described according to the vulnerability to obtain the description data of the vulnerability of the vulnerability historical data (i.e., vulnerability metadata). At the same time, the processing method data of each vulnerability type in the vulnerability metadata is extracted; feature extraction is performed on each vulnerability corresponding to the vulnerability metadata to obtain the vulnerability feature data of the vulnerability. At the same time, the processing method data is described according to the vulnerability type to obtain the processing method metadata of the processing method data corresponding to the vulnerability type;
[0048] Therefore, through the processing of the vulnerability historical data and its related data, the vulnerability type, vulnerability metadata, processing method data, vulnerability feature data, processing method metadata, and data mapping rules corresponding to the vulnerability historical data are obtained, and a preset vulnerability knowledge base is constructed. In some embodiments, the vulnerability feature data is stored in the tested data feature database corresponding to the preset vulnerability knowledge base, and the vulnerability type, vulnerability metadata, processing method data, processing method metadata, and data mapping rules are the vulnerability information knowledge data of the vulnerability feature data corresponding to the vulnerability.
[0049] It should be noted that the preset vulnerability knowledge base is a database for storing the vulnerability feature data and its vulnerability information knowledge data of known vulnerability types. The preset vulnerability knowledge base also provides corresponding extension interfaces for maintaining and adding the vulnerability feature data and its vulnerability information knowledge data of new vulnerability types.
[0050] In some embodiments, when the tested network system is tested for network vulnerabilities multiple times, the tested metadata of each network vulnerability test can also be stored in the preset vulnerability knowledge base.
[0051] The following describes the various data included in the preset vulnerability knowledge base:
[0052] The vulnerability type refers to the type of the vulnerability corresponding to the security vulnerability.
[0053] Vulnerability metadata is the description data of a vulnerability in the vulnerability historical data. During the testing process of network vulnerabilities, the vulnerability historical data corresponds to the tested data, and the vulnerability metadata corresponds to the tested metadata of the tested data. The tested metadata is the description data of the vulnerability regarding the tested data. Therefore, the content of the vulnerability metadata can be the same as or different from the tested metadata. This disclosure is not limited thereto and can be determined according to actual situations such as business types and transmission protocols. In some embodiments, the tested metadata includes at least one of: communication transmission protocol method, communication transmission protocol type, application programming interface data, parameter information, communication transmission protocol header information, and communication transmission protocol message body information.
[0054] The processing method data is the data regarding the processing method for solving or mitigating the problems caused by this vulnerability type.
[0055] The vulnerability feature data is the feature description of the vulnerability corresponding to this vulnerability type, which is used to uniquely identify and distinguish vulnerabilities. In some embodiments, the vulnerability feature data includes at least one of vulnerability number, vulnerability name, vulnerability level, vulnerability description, vulnerability test attack payload request, vulnerability features, and response feature data.
[0056] The processing method metadata is the description data of the processing method data. In some embodiments, the processing method metadata includes at least one of vulnerability repair suggestions and vulnerability test methods.
[0057] In some embodiments, the data mapping rules among the vulnerability type, the vulnerability metadata, the vulnerability feature data corresponding to the vulnerability metadata, the processing method data corresponding to the vulnerability metadata, and the processing method metadata corresponding to the vulnerability metadata of the vulnerability historical data include:
[0058] According to the vulnerability type corresponding to at least one vulnerability in the vulnerability historical data, determine the first data mapping rule between the vulnerability type and the vulnerability metadata corresponding to the vulnerability;
[0059] According to the vulnerability metadata corresponding to at least one vulnerability in the vulnerability historical data, determine the second data mapping rule between the vulnerability metadata and the vulnerability feature data corresponding to the vulnerability;
[0060] According to the first data mapping rule and the second data mapping rule, determine the data mapping rule.
[0061] In this embodiment, the data mapping rules include a first data mapping rule and a second data mapping rule. Among them, the first data mapping rule describes the mapping relationship between vulnerability metadata and vulnerability types, and the second data mapping rule describes the mapping relationship between vulnerability metadata and vulnerability characteristic data. During the testing process of network vulnerabilities, the first data mapping rule and the second data mapping rule can be used to locate the corresponding vulnerability types for the metadata to be tested. In some related technologies, the test cases for the same API interface are fixed, so it is impossible to provide corresponding test case sets for different vulnerability types. In the embodiments of the present disclosure, the number of vulnerability types and vulnerabilities corresponding to the data to be tested can both be one or more, and the present disclosure is not limited thereto, so as to achieve targeted security vulnerability detection for the data to be tested.
[0062] In some embodiments, the data mapping rules may further include: a third data mapping rule. Among them, according to at least one vulnerability in the vulnerability history data, a third data mapping rule between the vulnerability metadata corresponding to the vulnerability, the processing method data, and the processing method metadata is determined.
[0063] In some embodiments, the process of obtaining the data mapping rules may also be: determining the data mapping rules according to the first data mapping rule, the second data mapping rule, and the third data mapping rule.
[0064] Among them, during the testing process of network vulnerabilities, the second data mapping rule (the mapping relationship between vulnerability metadata and vulnerability characteristic data) and the third data mapping rule (the mapping relationship between vulnerability metadata, processing method data, and processing method metadata) can be used to provide corresponding processing method metadata for the data to be tested.
[0065] Correspondingly, in some embodiments, before S1, it further includes:
[0066] Obtain all data information of the network system under test during the testing process as the data to be tested through a proxy tool;
[0067] Describe the data to be tested to obtain the metadata to be tested;
[0068] Associate and store the metadata to be tested and the category label corresponding to the metadata to be tested in the detection system database.
[0069] In the embodiments of the present disclosure, all the data to be tested is obtained through a proxy tool deployed between the network browser (which can also be called the user browser or web browser) and the network system under test. Among them, the network browser is used to execute all business functions of the network system under test, that is, the network browser is a tool for users to interact with the network system under test.
[0070] Obtain the test data of all services triggered during the interaction between the network system under test and the web browser through a proxy tool, describe the full volume of the test data, and extract at least one of the communication transmission protocol method, communication transmission protocol type, application programming interface data, parameter information, communication transmission protocol header information, and communication transmission protocol message body information from the test data, so as to obtain the description data (i.e., the test metadata) of the test data. Analyze according to the specific type of the test metadata, assign a category label to the test metadata, and store the test metadata and the corresponding category label in the detection system database.
[0071] Among them, in some embodiments, the communication transmission protocol header information and the communication transmission protocol message body information can be further split into the smallest granularity metadata information.
[0072] In some embodiments, the test metadata in the detection system database can be stored in the detection system database according to the analysis results of the relevant information of the api interface corresponding to the test metadata and its service logic relationship.
[0073] The present disclosure does not make special restrictions on the communication transmission protocol in the test metadata, and it can be HTTP (Hypertext Transfer Protocol). In one example, according to the HTTP protocol, the full volume of the test data is described, so as to obtain at least one of the HTTP method, HTTP protocol type, api interface data, parameter information in the URL, HTTP request header information, HTTP request body information, HTTP response header information, and HTTP response body information.
[0074] It should be noted that in some related technologies, the amount of api information of the network system under test is huge, and the test data is collected by data crawling for the api interfaces in the network system. It is impossible to obtain the full volume of api interface data (i.e., the test data), and due to the insufficient automatic analysis ability for the scanned vulnerabilities, it is impossible to comprehensively detect the network system vulnerabilities. Subsequent tests also need to rely on manual analysis and supplementary tests, etc., which are prone to omissions. In the embodiments of the present disclosure, the full volume of the test data can be collected through the proxy tools deployed in the web browser and the network system under test, and the test data and its category label are stored in the detection system database. The vulnerability detection process for the web system under test is a detection for the full volume of the test data, effectively avoiding the problem of missed detection and improving the accuracy of vulnerability detection.
[0075] In some related technologies, the test API interfaces crawled by the system are not stored. Every time a test task is created, it is necessary to re-crawl the API interfaces for testing, which reduces the detection efficiency of newly added vulnerabilities. However, the embodiments of the present disclosure create a preset vulnerability knowledge base, which can maintain and add vulnerability feature data and vulnerability information knowledge data of new vulnerability types, thereby improving the vulnerability discovery efficiency when detecting new vulnerability types, achieving the effects of rapid detection and rapid repair.
[0076] In some embodiments, using the existing tested data in the detection system database, each API interface is quickly analyzed to identify response risks, and test cases are automatically generated and scanned for detection. For the newly added vulnerability types, according to the newly added vulnerability types, vulnerability metadata, processing method data, vulnerability feature data, processing method metadata, and data mapping rules, through the extended interface of the network system under test, it is updated to the preset vulnerability knowledge base; then, using the updated preset vulnerability knowledge base, vulnerability identification is performed on the full volume of tested data and business logic stored in the preset vulnerability knowledge base to quickly discover the security risks existing in the network system under test and accurately generate a test case set, realizing a quick scan of the network system under test, so that the identified security vulnerabilities can be repaired as soon as possible, improving the efficiency of vulnerability detection and repair.
[0077] Figure 2 This is a flowchart of a specific implementation method for step S1 in the embodiments of the present disclosure. Refer to Figure 2 , in some embodiments, S1 includes:
[0078] S11. Split the tested metadata of the tested data to obtain target vulnerability feature data.
[0079] S12. Based on a preset similarity threshold and the target vulnerability feature data, determine the vulnerability type corresponding to the tested data from the vulnerability knowledge base.
[0080] Embodiments of the present disclosure do not impose special limitations on the value of the preset similarity threshold. In some embodiments, the preset similarity threshold is used to compare with the similarity value between the target vulnerability feature data and the vulnerability feature data stored in the preset vulnerability knowledge base. Embodiments of the present disclosure do not impose special limitations on the similarity matching method. In some embodiments, the vulnerability feature data with the similarity value meeting the conditions is determined to match the target vulnerability feature data, and the association relationship between the target vulnerability feature data and the vulnerability feature data is established. Then, according to the second data mapping rule in the data mapping rule, the vulnerability metadata mapped thereto is determined through the vulnerability feature data. Furthermore, according to the first data mapping rule in the data mapping rule, the vulnerability type mapped thereto is determined through the vulnerability metadata, and the vulnerability type obtained by mapping the vulnerability feature data is determined as the vulnerability type corresponding to the test data.
[0081] Figure 3 It is a flowchart of a specific implementation method for step S2 in an embodiment of the present disclosure. Refer to Figure 3 , in some embodiments, S2 includes:
[0082] S21. According to the data mapping rule in the vulnerability knowledge base for the vulnerability type corresponding to the test data, determine the vulnerability feature data corresponding to the vulnerability type.
[0083] S22. Extract the vulnerability feature data to determine the test case unit of the test data.
[0084] S23. According to the test case unit of the test data, determine the test case set corresponding to the test data.
[0085] In some embodiments, the mapping relationship between the vulnerability type and the vulnerability metadata can be determined through the first data mapping rule, and the mapping relationship between the vulnerability metadata and the vulnerability feature data can be determined through the second data mapping rule. Therefore, through the data mapping rule in the preset vulnerability knowledge base, the vulnerability feature data corresponding to the vulnerability type can be determined. Thus, the vulnerability test payload request and response feature data can be extracted from the vulnerability feature data as the test case unit corresponding to the test data.
[0086] It should be noted that the test case set can be composed of the test case units of the test data, or can be composed of the test case units of the test data and its related interaction data. The present disclosure is not limited thereto, and the test case set can be generated according to actual test requirements.
[0087] Figure 4 It is a flowchart of a specific implementation method for step S23 in an embodiment of the present disclosure. Refer to Figure 4 , in some embodiments, S23 includes:
[0088] S231. Obtain the interaction data corresponding to the data to be tested according to the business logic of the data to be tested.
[0089] S232. Permute and combine the test case units of the interaction data and the test case units of the data to be tested to obtain the test case set corresponding to the data to be tested.
[0090] In the embodiments of the present disclosure, the interaction data may refer to context interaction data related to the business logic of the data to be tested. In some embodiments, it further includes analyzing the interaction message correlation of the metadata of the interaction data, and extracting the associated interaction data group, that is, each interaction data group is composed of associated interaction data. Among them, the metadata of the interaction data is the data obtained by describing the interaction data.
[0091] Permute and combine the test case units of the interaction data and the data to be tested to obtain the test case set corresponding to the data to be tested; in some embodiments, taking the group as a unit, permute and combine according to the test case units corresponding to the interaction data within the interaction data group to generate the test case set corresponding to the arranged data to be tested.
[0092] In some embodiments, it further includes analyzing and removing the conflicting test case units in the test case set, so as to generate the corresponding test case set.
[0093] In some related technologies, for the test of the same api interface, its test cases are often fixed and ambiguous, without referring to the response data of the real business, resulting in insufficient effectiveness of the test cases. In the embodiments of the present disclosure, the business logic of the data to be tested is fully considered, and the security vulnerability knowledge base (i.e., the preset vulnerability knowledge base) is used to realize intelligent analysis and processing through the generation and arrangement execution of the test case units, increase the coverage of the business scenario, reduce the probability of false positives of vulnerabilities, and ensure the accuracy of the vulnerability scan results.
[0094] In some embodiments, the test case set includes test case units, and each test case unit includes: a vulnerability test payload request and response feature data;
[0095] Figure 5 This is a flowchart of a specific implementation method for step S3 in the embodiments of the present disclosure. Refer to Figure 5 , where S3 includes:
[0096] S31. Receive the test response data fed back by the network system under test based on the vulnerability test payload request.
[0097] S32. Perform meta - data analysis on the test response data to obtain test response meta - data.
[0098] S33. Compare the test response meta - data with the response feature data in the test case unit to obtain a detection result. Among them, when the matching degree value between the test response meta - data and the response feature data in the test case unit is within a preset matching degree range, the detection result is that there is a network security vulnerability.
[0099] In the embodiments of the present disclosure, during the detection process, the vulnerability - testing payload requests of each test case unit in the test case set are sent to the network system under test, the test response data fed back by the network system under test is received, and meta - data analysis is performed on each test response data to obtain the corresponding test response meta - data. The test response meta - data is compared with the response feature data in the test case unit to obtain a detection result. In some embodiments, this comparison process may be to calculate the matching degree value between the test response meta - data and the response feature data, and compare this matching degree value with the preset matching degree range. When the matching degree value is within the preset matching degree range, it indicates that the test response meta - data is the same as or similar to the response feature data. When the matching degree value is not within the preset matching degree range, it indicates that the test response meta - data is different from the response feature data. When the matching degree value between the test response meta - data and the response feature data in the test case unit is within the preset matching degree range, it is determined that the detection result is that there is a network security vulnerability, that is, there is a security vulnerability in the corresponding api interface in the network system under test, so as to accurately detect the security vulnerabilities in the network system under test and reduce and eliminate false positives of vulnerabilities.
[0100] Among them, the api interface corresponding to the data under test refers to the network application interface of the network system under test, which has a wide range of functions. Through the api interface, the network application can achieve capabilities such as storage services, message services, and computing services, and powerful web applications can be developed using these capabilities.
[0101] In some embodiments, when the detection result is that there is a network security vulnerability, after S3, it further includes:
[0102] Determine the processing method data corresponding to the response feature data according to the response feature data in the test case unit and the preset vulnerability knowledge base;
[0103] Export and display the processing method data.
[0104] In an embodiment of the present disclosure, the response feature data is a type of vulnerability feature data. Therefore, according to the second data mapping rule, the vulnerability metadata mapped by the response feature data is determined. Furthermore, according to the third data mapping rule, the processing method data mapped by the vulnerability metadata is determined, where the processing method data is the solution method, repair suggestions, etc. for the security vulnerability corresponding to the vulnerability metadata. And the processing method data is exported and displayed to enable the accurate provision of the function of exporting the vulnerability scan report to the user.
[0105] In an embodiment of the present disclosure, by collecting all the test data in the network system to be tested and according to the test data and its business logic relationship, the accuracy, completeness of the vulnerability scan object and its compliance with the actual business usage scenario of the test data are ensured. At the same time, using the preset vulnerability knowledge base, fully considering the business logic of the test data, and using the security vulnerability knowledge base, through the generation and arrangement execution of test case units, intelligent analysis and processing are realized, the coverage of the business scenario is increased, the probability of false vulnerability reports is reduced, and the accuracy of the vulnerability scan result is ensured. In addition, all the test data collected in the network system to be tested is stored in the detection system database for a long time, which can not only be reused multiple times, but also, when a new security vulnerability is identified, differential analysis of the network system to be tested can be realized, improving the detection efficiency of new vulnerabilities and the effectiveness of overall system vulnerability detection.
[0106] Figure 6 It is a schematic structural diagram of an electronic device provided by an embodiment of the present disclosure. Referring to Figure 6 , an embodiment of the present disclosure provides an electronic device, which includes:
[0107] One or more processors 601;
[0108] A memory 602, on which one or more programs are stored. When the one or more programs are executed by the one or more processors, the one or more processors implement the test method for network vulnerabilities in any of the above items;
[0109] One or more I / O interfaces 603, connected between the processor and the memory, configured to realize the information interaction between the processor and the memory.
[0110] Among them, the processor 601 is a device with data processing capabilities, including but not limited to a central processing unit (CPU), etc.; the memory 602 is a device with data storage capabilities, including but not limited to a random access memory (RAM, more specifically such as SDRAM, DDR, etc.), a read-only memory (ROM), an electrically erasable programmable read-only memory (EEPROM), a flash memory (FLASH); the I / O interface (read / write interface) 603 is connected between the processor 601 and the memory 602, and can realize the information interaction between the processor 601 and the memory 602, including but not limited to a data bus (Bus), etc.
[0111] Figure 7 Schematic diagram of the structure of a computer-readable medium provided by an embodiment of the present disclosure. Refer to Figure 7 An embodiment of the present disclosure provides a computer-readable medium, on which a computer program is stored, and when the program is executed by a processor, the above-mentioned test method for any network vulnerability is implemented.
[0112] In order to enable those skilled in the art to more clearly understand the technical solutions provided by the embodiments of the present disclosure, the following uses specific embodiments to describe in detail the technical solutions provided by the embodiments of the present disclosure:
[0113] Embodiment 1: Figure 8 Schematic diagram of the application environment in the test method for network vulnerabilities provided by an embodiment of the present disclosure. Refer to Figure 8 In this case, the network system to be tested is a web system to be tested. In the operating environment of vulnerability scanning of the web system to be tested, a proxy tool is deployed between the web system to be tested and the web browser used on the user side.
[0114] Among them, the web system to be tested includes different functional modules (i.e., modules A, B, and C), and each functional module has multiple api interfaces (i.e., api1, api2,..., apiN) according to the business scenario, and the relationships between the api interfaces are intricate.
[0115] The proxy tool is used to collect and process the test data and business logic of all api interfaces in the web system to be tested, and store them in the detection system database. Combining with the preset vulnerability knowledge base created for the web system to be tested, the vulnerability types corresponding to the test data that may exist in the test data are matched and analyzed, and test case units are generated according to the vulnerability types and business logic corresponding to the test data, and after the test case units are arranged and executed, a detection result is obtained.
[0116] Among them, for the newly added security vulnerability types, the test data stored in the detection system database is used to quickly identify the vulnerability types corresponding to the test data in the web system to be tested, generate test case units and execute them, thereby improving the detection efficiency for the newly added vulnerability types.
[0117] Example Two: Figure 9 It is a schematic structural diagram of the network vulnerability testing system provided by the embodiments of the present disclosure. Refer to Figure 9 , based on software development, the network system to be tested is the web system to be tested. By using the proxy tool deployed between the web system to be tested and the web browser used on the user side, all test data corresponding to the business logic in the actual business scenario is collected, and the web system to be tested is detected by combining the collected test data with the preset vulnerability knowledge base. The software architecture of the network vulnerability testing system includes: proxy tool, preset vulnerability knowledge base, detection system database, intelligent analysis module, detection result display module, etc.
[0118] Among them, the proxy tool is deployed between the web system to be tested and the web browser, and is used for all the test data corresponding to the business logic in the actual business scenario, and reports the data to the network vulnerability testing system.
[0119] The preset vulnerability knowledge base is used to manage vulnerability metadata, vulnerability feature data, processing method data, data mapping rules, etc. of different vulnerability types, and at the same time provides an extension interface for the web system to be tested to manage the relevant data of newly added vulnerability types.
[0120] The detection system database is used to store all the test data reported by the proxy tool.
[0121] The intelligent analysis module is used to analyze the test data collected by the proxy tool, combine the actual business scenario and business logic, store the analysis result in the detection system database; analyze the test data, associate and match the vulnerability types and processing method data in the preset vulnerability knowledge base, generate customized test case units, and after arranging the test case units, detect the web system to be tested, and store the detected detection results and processing method data in the scan results.
[0122] The detection result display module is used to use the display component to display the data in the detection result on the web browser, and at the same time provides the function of exporting the vulnerability scan report.
[0123] Example Three: Figure 10 It is a schematic flow diagram of a network vulnerability testing method provided by the embodiments of the present disclosure. Refer to Figure 10 , the network vulnerability testing method includes:
[0124] Step 1001, deploy the proxy tool. That is, by deploying the proxy tool in the operating environment where the network system to be tested is located, and this proxy tool is specifically deployed between the network system to be tested and the network browser used on the user side. The proxy tool is used to collect all the test data during the operation of the network system to be tested.
[0125] Step 1002: Collection and storage of the data to be tested. That is, the data to be tested of the network system to be tested collected in Step 1001 is classified and labeled according to the HTTP protocol for all the collected data to be tested.
[0126] Among them, the data to be tested is described to obtain the metadata to be tested, including: HTTP method, HTTP protocol type, api interface data, parameter information in the URL, HTTP request header information, HTTP request body information, HTTP response header information, and HTTP response body information. Among them, the header information and the message body information are split into metadata information with the smallest granularity. The generated metadata to be tested is stored in the detection system database.
[0127] Step 1003: Analysis of the data to be tested. Using the intelligent analysis module, the target vulnerability feature data corresponding to the metadata to be tested is matched with the vulnerability feature data stored in the preset vulnerability knowledge base to obtain a similarity value. The similarity value is compared with the preset similarity threshold. When the similarity value is less than or equal to the preset similarity threshold, according to the first data mapping rule and the second data mapping rule, the vulnerability type corresponding to the vulnerability feature data in the preset vulnerability knowledge base is determined as the vulnerability type corresponding to the data to be tested. The vulnerability test payload request and response feature data in the vulnerability feature data corresponding to the vulnerability type of the data to be tested are extracted from the preset vulnerability knowledge base. Each group of vulnerability test payload request and response feature data is a test case unit, so as to determine the test case unit corresponding to the data to be tested.
[0128] Step 1004: Execution of the test case set. According to the interaction data analyzed from the data to be tested reported by the proxy tool, the relevance of the interaction messages is analyzed for the metadata of the interaction data in the context, and the associated interaction data groups are extracted; according to the interaction data and the test case unit corresponding to the data to be tested, permutations and combinations are performed to generate a test case set. In addition, the conflicting test case units are analyzed and removed, so as to generate the corresponding test case set, and then the security vulnerability test is carried out.
[0129] Step 1005: Judgment of the detection result. That is, in the process of testing network vulnerabilities, the metadata of each interactive data to be tested is analyzed, and the test response metadata is compared with the response feature data in the test case unit, and then it is decided whether there are network security vulnerabilities in the corresponding api interface, so as to reduce and eliminate false alarms of network security vulnerabilities. At the same time, the vulnerability detection result and the vulnerability repair suggestion can also be output.
[0130] Step 1006, display of detection results. For the detection results of network security vulnerabilities, use a display component to display the data in the detection results on a web browser and provide a function to export test reports at the same time.
[0131] In the above-mentioned first, second, and third embodiments of the present disclosure, without the support of hardware basic devices, by matching the data to be tested in a preset vulnerability knowledge base, the vulnerability type corresponding to the data to be tested is determined, and a test case set is generated according to the vulnerability type corresponding to the data to be tested and the data mapping rules stored in the preset vulnerability knowledge base. The test case set is generated for the vulnerability type corresponding to the data to be tested, realizing flexible arrangement of test cases, thereby reducing the probability of false positives of vulnerabilities and ensuring the accuracy of detection results.
[0132] Those of ordinary skill in the art can understand that all or some of the steps in the methods disclosed above, and the functional modules / units in the systems and devices, can be implemented as software, firmware, hardware, and their appropriate combinations. In the hardware implementation, the division between the functional modules / units mentioned above does not necessarily correspond to the division of physical components; for example, a physical component may have multiple functions, or a function or step may be executed by several physical components in cooperation. Some or all physical components may be implemented as software executed by a processor, such as a central processing unit, a digital signal processor, or a microprocessor, or may be implemented as hardware, or may be implemented as an integrated circuit, such as an application-specific integrated circuit. Such software can be distributed on a computer-readable medium, which may include a computer storage medium (or non-transitory medium) and a communication medium (or transitory medium). As is well known to those of ordinary skill in the art, the term computer storage medium includes volatile and non-volatile, removable and non-removable media implemented in any method or technology for storing information, such as computer-readable instructions, data structures, program modules, or other data. Computer storage media include, but are not limited to, RAM, ROM, EEPROM, flash memory or other memory technologies, CD-ROM, digital versatile disk (DVD) or other optical disk storage, magnetic cassette, tape, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to store the desired information and can be accessed by a computer. In addition, as is well known to those of ordinary skill in the art, a communication medium typically includes computer-readable instructions, data structures, program modules, or other data in a modulated data signal such as a carrier wave or other transmission mechanism, and may include any information delivery medium.
[0133] Example embodiments have been disclosed herein, and although specific terms are employed, they are used only and should be interpreted only as general descriptive meanings and not for the purpose of limitation. In some instances, it will be apparent to those skilled in the art that, unless otherwise expressly specified, features, characteristics, and / or elements described in connection with a particular embodiment may be used singly or in combination with features, characteristics, and / or elements described in connection with other embodiments. Accordingly, those skilled in the art will understand that various forms and details may be changed without departing from the scope of the present disclosure as set forth by the appended claims.
Claims
1. A method for testing network vulnerabilities, characterized in that, Including: Determine the vulnerability type corresponding to the tested data in the network system to be tested based on a preset vulnerability knowledge base; Obtain the test case set corresponding to the tested data from the vulnerability knowledge base based on the vulnerability type corresponding to the tested data; Execute the test case set corresponding to the tested data based on the tested data to obtain the detection result of the network system to be tested.
2. The testing method for network vulnerabilities according to claim 1, wherein The construction method of the preset vulnerability knowledge base is as follows: Obtain vulnerability historical data, and describe the vulnerability historical data according to vulnerabilities to obtain vulnerability metadata; Determine the data mapping rules between the vulnerability type of the vulnerability historical data, the vulnerability metadata, the vulnerability feature data corresponding to the vulnerability metadata, the processing method data corresponding to the vulnerability metadata, and the processing method metadata corresponding to the vulnerability metadata; Construct the vulnerability knowledge base based on the vulnerability type of the vulnerability historical data, the vulnerability metadata, the vulnerability feature data corresponding to the vulnerability metadata, the processing method data corresponding to the vulnerability metadata, the processing method metadata corresponding to the vulnerability metadata, and the data mapping rules.
3. The test method for network vulnerabilities according to claim 2, characterized in that, Before determining the data mapping rules between the vulnerability type of the vulnerability historical data, the vulnerability metadata, the vulnerability feature data corresponding to the vulnerability metadata, the processing method data corresponding to the vulnerability metadata, and the processing method metadata corresponding to the vulnerability metadata, it further includes: Extract the processing method data of each vulnerability type in the vulnerability metadata according to the vulnerability metadata to obtain the processing method data corresponding to the vulnerability metadata; Extract the features of each vulnerability in the vulnerability metadata to obtain the vulnerability feature data corresponding to the vulnerability metadata, and describe the processing method data according to the vulnerability type to obtain the processing method metadata corresponding to the processing method data.
4. The test method for network vulnerabilities according to claim 2, characterized in that Determining the data mapping rules between the vulnerability type of the vulnerability historical data, the vulnerability metadata, the vulnerability feature data corresponding to the vulnerability metadata, the processing method data corresponding to the vulnerability metadata, and the processing method metadata corresponding to the vulnerability metadata includes: Determine the first data mapping rule between the vulnerability type and the vulnerability metadata corresponding to the vulnerability according to the vulnerability type corresponding to at least one vulnerability in the vulnerability historical data; Determine the second data mapping rule between the vulnerability metadata and the vulnerability feature data corresponding to the vulnerability according to the vulnerability metadata corresponding to at least one vulnerability in the vulnerability historical data; Determine the data mapping rule according to the first data mapping rule and the second data mapping rule.
5. The test method for network vulnerabilities according to claim 1, characterized in that Before determining the vulnerability type corresponding to the tested data in the network system to be tested based on the preset vulnerability knowledge base, it further includes: Obtain all data information during the test of the network system to be tested through a proxy tool as the tested data; Describe the tested data to obtain tested metadata; Associate and store the tested metadata and the category label corresponding to the tested metadata in the detection system database.
6. The method for testing network vulnerabilities according to claim 1, wherein Determining the vulnerability type corresponding to the test data in the network system under test based on a preset vulnerability knowledge base includes: Splitting the test metadata of the test data to obtain target vulnerability feature data; Determining the vulnerability type corresponding to the test data from the vulnerability knowledge base based on a preset similarity threshold and the target vulnerability feature data.
7. The test method for network vulnerabilities according to claim 1, wherein Obtaining the test case set corresponding to the test data from the vulnerability knowledge base based on the vulnerability type corresponding to the test data includes: Determining the vulnerability feature data corresponding to the vulnerability type according to the data mapping rule of the vulnerability type corresponding to the test data in the vulnerability knowledge base; Extracting the vulnerability feature data to determine the test case unit of the test data; Determining the test case set corresponding to the test data according to the test case unit of the test data.
8. The test method for network vulnerabilities according to claim 7, characterized in that, The determining the test case set corresponding to the test data according to the test case unit of the test data includes: Obtaining the interaction data corresponding to the test data according to the business logic of the test data; Performing permutation and combination on the test case unit of the interaction data and the test case unit of the test data to obtain the test case set corresponding to the test data.
9. The test method for network vulnerabilities according to claim 1, wherein The test case set includes test case units, and each test case unit includes: a vulnerability test payload request and response feature data; Executing the test case set corresponding to the test data based on the test data to obtain the detection result of the network system under test includes: Receiving the test response data fed back by the network system under test based on the vulnerability test payload request; Performing metadata analysis on the test response data to obtain test response metadata; Comparing the test response metadata with the response feature data in the test case unit to obtain a detection result; wherein, when the matching degree value between the test response metadata and the response feature data in the test case unit is within a preset matching degree range, the detection result is that there is a network security vulnerability.
10. An electronic device, characterized in that, Including: One or more processors; A memory storing one or more programs, which when executed by the one or more processors, cause the one or more processors to implement the network vulnerability test method according to any one of claims 1 to 9.
11. A computer-readable medium, characterized in that, Storing a computer program thereon, and the program when executed by a processor implements the network vulnerability test method according to any one of claims 1 to 9.