Interface testing method and system
Through the manager, tester and monitor in the interface test system, the limitations of the secure container host-side interface testing are solved, and comprehensive monitoring and exception feedback of the target secure container and the interface to be tested are achieved.
Patent Information
- Application Number
- CN202311800303.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-25
- Publication Date
- 2025-07-01
AI Technical Summary
In the fuzzy test based on security containers, the host-side interface cannot be effectively tested, resulting in testing limitations.
Through the manager, target tester and target monitor in the interface test system, obtain the interface tasks to be tested, start the target security container and target tester, send test cases, monitor the running status and call status, and generate exception prompt information.
It realizes effective testing of the secure container host side interface, monitors and feedbacks abnormal situations, and improves the comprehensiveness and accuracy of the test.
Smart Images

Figure CN120234231A_ABST
Abstract
Description
Technical Field
[0001] The embodiments of this specification relate to the field of computer technology, and particularly to an interface testing method. Background Art
[0002] With the development of science and technology, more and more people begin to use various application software. However, in actual applications, various vulnerabilities may occur during the use of application software. To detect the vulnerabilities existing in the application software, relevant technical personnel usually implement them through fuzz testing technology.
[0003] In the relevant fuzz testing technology, due to the uncertainty of fuzz testing and for the convenience of observing test results, the test process of the application software or system generally needs to be carried out in a test sandbox (SandBox) to complete the test of the application software or system. However, in the fuzz testing technology based on a security container, if the test target is changed, that is, the application software or system is not tested, for example, the host-side interface is tested, the above test method will have certain limitations. Therefore, a method is needed to solve the above problems. Summary of the Invention
[0004] In view of this, the embodiments of this specification provide an interface testing method. One or more embodiments of this specification simultaneously relate to an interface testing device, an interface testing system, a computing device, a computer-readable storage medium, and a computer program to solve the technical defects existing in the prior art.
[0005] According to the first aspect of the embodiments of this specification, an interface testing method is provided, which is applied to a manager in an interface testing system. The method includes:
[0006] Obtain a to-be-tested interface task, where the to-be-tested interface task includes a target test case of the to-be-tested interface;
[0007] Start a target security container and a target tester corresponding to the to-be-tested interface task, and send the target test case to the target tester, so that the target tester sends test data to the target security container by calling the to-be-tested interface;
[0008] Create a target monitor, so that the target monitor monitors the running state of the target security container and the call situation of the to-be-tested interface, and obtains the test result of the to-be-tested interface task.
[0009] According to the second aspect of the embodiments of this specification, an interface testing device is provided, which is applied to a manager in an interface testing system. The device includes:
[0010] An acquisition module, configured to acquire an interface task to be tested, where the interface task to be tested includes a target test case for the interface to be tested;
[0011] A start module, configured to start a target security container and a target tester corresponding to the interface task to be tested, and send the target test case to the target tester, so that the target tester sends test data to the target security container by calling the interface to be tested;
[0012] A creation module, configured to create a target monitor, so that the target monitor monitors the running state of the target security container and the call situation of the interface to be tested, and obtains the test result of the interface task to be tested.
[0013] According to the third aspect of the embodiments of the present specification, another interface testing method is provided, which is applied to a tester in an interface testing system. The method includes:
[0014] Receiving a target test case for an interface task to be tested sent by a manager, where the target test case is sent through a communication connection between the manager and the tester;
[0015] Obtaining test data corresponding to the interface task to be tested;
[0016] Calling the interface to be tested corresponding to the target test case, and sending the test data to a target security container.
[0017] According to the fourth aspect of the embodiments of the present specification, another interface testing device is provided, which is applied to a tester in an interface testing system. The device includes:
[0018] A receiving module, configured to receive a target test case for an interface task to be tested sent by a manager, where the target test case is sent through a communication connection between the manager and the tester;
[0019] A data acquisition module, configured to acquire test data corresponding to the interface task to be tested;
[0020] A calling module, configured to call the interface to be tested corresponding to the target test case, and send the test data to a target security container.
[0021] According to the fifth aspect of the embodiments of the present specification, another interface testing method is provided, which is applied to a monitor in an interface testing system. The method includes:
[0022] Monitoring the running state of a target security container and the call situation of an interface to be tested;
[0023] Obtain the running result of the target secure container and the call result of the interface to be tested;
[0024] Generate an exception prompt message when there is an exception in the running result or the call result.
[0025] According to the sixth aspect of the embodiments of this specification, another interface testing device is provided, which is applied to a monitor in an interface testing system. The device includes:
[0026] A monitoring module, configured to monitor the running status of a target secure container and the call situation of an interface to be tested;
[0027] An obtaining module, configured to obtain the running result of the target secure container and the call result of the interface to be tested;
[0028] A generating module, configured to generate an exception prompt message when there is an exception in the running result or the call result.
[0029] According to the seventh aspect of the embodiments of this specification, an interface testing system is provided, including a manager, a target tester, and a target monitor;
[0030] The manager is configured to obtain an interface testing task to be tested, where the interface testing task to be tested includes target test cases of the interface to be tested, start a target secure container and a target tester corresponding to the interface testing task to be tested, and send the target test cases to the target tester;
[0031] The target tester is configured to receive the target test cases of the interface testing task to be tested sent by the manager, where the target test cases are sent through a communication connection between the manager and the target tester, obtain test data corresponding to the interface testing task to be tested, call the interface to be tested corresponding to the target test cases, and send the test data to the target secure container;
[0032] The manager is further configured to create a target monitor;
[0033] The target monitor is configured to monitor the running status of the target secure container and the call situation of the interface to be tested, and obtain the running result of the target secure container and the call result of the interface to be tested.
[0034] According to the eighth aspect of the embodiments of this specification, a computing device is provided, including:
[0035] A memory and a processor;
[0036] The memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions. When the computer-executable instructions are executed by the processor, the steps of the above interface test method are implemented.
[0037] According to the ninth aspect of the embodiments of the present specification, a computer-readable storage medium is provided, which stores computer-executable instructions. When the instructions are executed by a processor, the steps of the above interface test method are implemented.
[0038] According to the tenth aspect of the embodiments of the present specification, a computer program is provided. When the computer program is executed on a computer, the computer is made to execute the steps of the above interface test method.
[0039] An embodiment of the present specification realizes that a manager in an interface test system starts a target security container and a target tester corresponding to an interface task to be tested on a host, and enables the target tester to execute a target test case on the host by calling the interface to be tested, thereby realizing the call of the interface to be tested. And by creating a target monitor to monitor the running state of the target security container and the call situation of the interface to be tested, the test of the interface to be tested is realized. Description of the Drawings
[0040] Figure 1 is a framework flowchart of an interface test system provided by an embodiment of the present specification;
[0041] Figure 2 is a flowchart of an interface test method provided by an embodiment of the present specification;
[0042] Figure 3 is a processing procedure flowchart of an interface test method provided by an embodiment of the present specification;
[0043] Figure 4 is a structural schematic diagram of an interface test device provided by an embodiment of the present specification;
[0044] Figure 5 is a flowchart of another interface test method provided by an embodiment of the present specification;
[0045] Figure 6 is a structural schematic diagram of another interface test device provided by an embodiment of the present specification;
[0046] Figure 7 is a flowchart of yet another interface test method provided by an embodiment of the present specification;
[0047] Figure 8 is a structural schematic diagram of yet another interface test device provided by an embodiment of the present specification;
[0048] Figure 9 It is a structural block diagram of a computing device provided by an embodiment of this specification. Specific implementation manners
[0049] In the following description, many specific details are set forth in order to provide a thorough understanding of this specification. However, this specification can be implemented in many other ways different from those described herein, and those skilled in the art can make similar generalizations without departing from the connotation of this specification. Therefore, this specification is not limited by the specific implementations disclosed below.
[0050] The terms used in one or more embodiments of this specification are only for the purpose of describing specific embodiments, and are not intended to limit one or more embodiments of this specification. The singular forms "a", "the", and "said" used in one or more embodiments of this specification and the appended claims are also intended to include the plural forms, unless the context clearly indicates otherwise. It should also be understood that the term "and / or" used in one or more embodiments of this specification refers to and includes any or all possible combinations of one or more of the associated listed items.
[0051] It should be understood that although the terms first, second, etc. may be used in one or more embodiments of this specification to describe various information, such information should not be limited to these terms. These terms are only used to distinguish the same type of information from each other. For example, without departing from the scope of one or more embodiments of this specification, the first may also be referred to as the second, and similarly, the second may also be referred to as the first. Depending on the context, the word "if" as used herein may be interpreted as "when" or "while" or "in response to determining".
[0052] In addition, it should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in one or more embodiments of this specification are all information and data that have been authorized by the user or fully authorized by all parties, and the collection, use, and processing of the relevant data need to comply with the relevant laws, regulations, and standards of the relevant countries and regions, and corresponding operation entrances are provided for the user to select to authorize or reject.
[0053] First, the noun terms involved in one or more embodiments of this specification are explained.
[0054] Fuzzing: Fuzzing is a software testing technique. The core idea is to input automatically or semi-automatically generated random data into a program and monitor program anomalies such as crashes and assertion failures to discover possible program errors.
[0055] Container: A container is a sandbox technology. Its main purpose is to run applications in it, isolate them from the outside world, and facilitate the transfer of the sandbox to other host machines. In essence, it is a special process. Through namespace and control groups technology, resources, files, devices, status, and configuration are divided into an independent space.
[0056] Security Container: In public cloud scenarios, to solve the problem of more security risks caused by the low isolation level of container technology, a virtual machine is used to provide additional security protection performance, and container applications are created in the virtual machine. This type of container technology is called security container technology. Security containers provide virtualization-level protection performance through an additional virtualization layer.
[0057] rund: A lightweight secure container.
[0058] Host: A physical machine that runs a container or secure container.
[0059] Test case (Prog): A piece of test code that needs to be actually run in fuzz testing to try to trigger system errors. The fuzz tester discovers system vulnerabilities by continuously generating and executing test cases.
[0060] Fuzzer: One of the components of the fuzz testing framework, responsible for executing test cases.
[0061] Monitor: One of the components of the fuzz testing framework, responsible for monitoring whether the system enters an error state.
[0062] Manager: One of the components of the fuzz testing framework, responsible for controlling the test process and generating test cases.
[0063] Test Sandbox: Due to the uncertainty of fuzz testing, the convenience of observing test results and maintaining the consistency of the test environment, it is generally necessary to put the test execution process into a test sandbox to isolate it from the running environment of the test tool. Errors occurring in the test sandbox will not cause interruptions to the test process.
[0064] Corpus: A collection of test cases.
[0065] In practical applications, software or systems used by people may have various vulnerabilities. To detect these vulnerabilities in software or systems, relevant technical personnel usually use fuzz testing technology for detection. In relevant fuzz testing technology, due to the uncertainty of fuzz testing and for the convenience of observing test results, the testing process of software or systems generally needs to be carried out in a test sandbox to complete the testing of software or systems. However, in fuzz testing technology based on secure containers, it is also necessary to test the host-side interface of the secure container, and this method cannot achieve the testing of the host-side interface of the secure container.
[0066] In this specification, an interface testing method is provided. This specification also relates to an interface testing device and an interface testing system, a computing device, and a computer-readable storage medium, which will be described in detail one by one in the following embodiments.
[0067] An embodiment of the interface testing system provided in this specification is as follows:
[0068] The interface testing system includes a manager, a target tester, and a target monitor;
[0069] The manager is configured to obtain an interface task to be tested, where the interface task to be tested includes target test cases for the interface to be tested, start the target secure container and the target tester corresponding to the interface task to be tested, and send the target test cases to the target tester;
[0070] The target tester is configured to receive the target test cases for the interface task to be tested sent by the manager, where the target test cases are sent through the communication connection between the manager and the target tester, obtain the test data corresponding to the interface task to be tested, call the interface to be tested corresponding to the target test cases, and send the test data to the target secure container;
[0071] The manager is further configured to create a target monitor;
[0072] The target monitor is configured to monitor the running state of the target secure container and the call situation of the interface to be tested, and obtain the running result of the target secure container and the call result of the interface to be tested.
[0073] Among them, the manager is used to control the interface testing process and generate test cases corresponding to each interface task to be tested. The target tester refers to the tester used to execute the interface task to be tested; the target monitor refers to the monitor used to monitor the status of the target secure container and the interface to be tested corresponding to the interface task to be tested.
[0074] The interface task to be tested refers to the test task generated for the interface on the host side of the secure container that needs to be tested. The interface to be tested is the interface on the host side of the secure container that needs to be tested. The target test case refers to the test case corresponding to the interface to be tested, which can be specifically understood as the interface primitive of the interface to be tested and is used for the target tester to call the interface to be tested. The test data refers to the data used for functional testing of the interface to be tested. For example, if it is necessary to call the interface to be tested to perform an email login operation, the test data can be the email account and email password, etc.
[0075] Specifically, when testing the interface to be tested through the interface test system, the manager obtains the interface task to be tested and the target test case of the interface to be tested carried in the interface task to be tested. Based on the interface task to be tested, the corresponding target secure container and target tester of the interface task to be tested are started, and the obtained target test case is sent to the target tester. The target tester receives the target test case sent by the manager, obtains the test data corresponding to the interface task to be tested, and then, by calling the interface to be tested and sending the test data to the target secure container, the target test case is executed.
[0076] Furthermore, the manager creates a target monitor corresponding to the interface task to be tested. After the target monitor is created, the target monitor can monitor the running status of the target secure container and the call situation of the interface to be tested to determine whether the target secure container can run normally and whether there is an abnormality in the interface to be tested. If the target monitor detects an abnormality in the running status of the target secure container or an abnormality in the call situation of the interface to be tested, an abnormal error reporting process can be triggered, and the abnormal records generated during the running process of the target secure container and the abnormal records generated during the call process of the interface to be tested are collected, and an abnormal prompt message is generated according to the abnormal records.
[0077] The interface task to be tested can also carry a container configuration file for running the target secure container. After the manager obtains the container configuration file of the target secure container, the target secure container can be started according to the container configuration file.
[0078] Before the manager starts the target tester, in order to enable the target tester to call the interface to be tested to execute the target test case of the interface to be tested, a target working directory corresponding to the target secure container can be created on the host so that the target tester can run in the target working directory.
[0079] In an optional implementation manner provided by the embodiments of this specification, the interface task to be tested includes the binary file of the target tester;
[0080] The manager is further configured to:
[0081] Create a target working directory corresponding to the target secure container;
[0082] Copy the binary file to the target working directory and start the target tester in the target working directory based on the binary file.
[0083] Among them, the binary file is used to start the target tester in the target working directory. The target working directory refers to the path or folder where the target tester runs and can be used to read and store the working process of the target tester.
[0084] In practical applications, one target secure container is used to execute one interface task to be tested, and there is a one-to-one correspondence between the target working directory and the target secure container.
[0085] Specifically, the manager creates a target working directory corresponding to the target secure container on the host running the target secure container, obtains the binary file for starting the target tester carried in the interface task to be tested, copies the binary file of the target tester to the created target working directory, and starts the target tester in the target working directory according to the binary file of the target tester.
[0086] Since in practical applications, different secure containers correspond to different container identifiers, the working directory corresponding to the secure container can be created based on the container identifier of the secure container to improve the accuracy of creating the working directory.
[0087] In an optional implementation manner provided by the embodiments of this specification, the manager is further configured to:
[0088] Obtain the target container identifier of the target secure container and the test data for the interface task to be tested;
[0089] Create a target working directory corresponding to the target secure container according to the target container identifier;
[0090] Store the test data in the target working directory.
[0091] Among them, the target container identifier is the unique container identifier corresponding to the target secure container.
[0092] Specifically, after starting the target secure container, the manager obtains the target container identifier corresponding to the target secure container, and creates a target working directory corresponding to the target secure container according to the target container identifier. Further, the manager can also obtain the test data for executing the interface task to be tested, and store the test data in the target working directory after creating the target working directory for subsequent testing of the interface to be tested.
[0093] Since the manager and the target tester are two components in the interface test system, in order to achieve data interaction between the manager and the target tester, a communication connection also needs to be established between the manager and the target tester. Specifically, after the target tester is started, the target tester can initiate a request to establish a communication connection with the manager through remote invocation, so that the manager responds to the request and establishes a communication connection with the target tester. Furthermore, the manager and the target tester can perform data interaction through this communication connection. For example, the target test cases of the interface to be tested are transmitted, etc.
[0094] In practical applications, the target monitor monitors the running status of the target security container and the invocation situation of the interface to be tested. It may detect that the target security container is running abnormally or the interface to be tested is invoked abnormally. Based on this, it is necessary to give feedback on the above situations to facilitate subsequent relevant technical personnel to repair and handle the abnormal situations.
[0095] In an alternative implementation provided by the embodiments of this specification, the target monitor is further configured to:
[0096] Generate an exception prompt message when there is an abnormality in the running result or the invocation result.
[0097] Among them, the exception prompt message refers to a prompt message used to feedback that the target security container is running abnormally or the interface to be tested is invoked abnormally. The exception prompt message can be a prompt message only used to prompt relevant technical personnel that the target security container is running abnormally or the interface to be tested is invoked abnormally, or it can be an exception report recording the abnormal running of the target security container or the abnormal invocation of the interface to be tested.
[0098] Specifically, when the target monitor detects that the target security container has a running abnormality or the interface to be tested is invoked abnormally, it can collect the exception records generated during the running process of the target security container and the exception records generated during the invocation process of the interface to be tested, and generate an exception prompt message based on the exception records.
[0099] It should be noted that after the manager starts the target tester and the target monitor, it can also start the target tester and the target monitor corresponding to other interface test tasks to be tested based on other interface test tasks to be tested, so as to achieve concurrent execution of multiple interface test tasks to be tested.
[0100] See Figure 1 , Figure 1 shows a framework flowchart of an interface test system provided according to an embodiment of this specification. As Figure 1As shown in the figure, the interface test system includes a manager, a target tester, and a target monitor. First, the manager obtains the interface task to be tested, and obtains the target test cases, container configuration files, and binary files of the target tester carried in the interface task to be tested. The manager starts the target security container according to the container configuration file, creates a target working directory corresponding to the target container identifier on the host based on the target container identifier of the target security container, copies the binary file of the target tester to the target working directory, and starts the target tester in the target working directory.
[0101] Furthermore, after the target tester is started, it sends a communication connection request to establish a communication connection to the manager. After receiving the communication connection request, the manager establishes a communication connection with the target tester and sends the target test cases to the target tester through the communication connection. The target tester obtains the test data, calls the interface to be tested, and sends the test data to the target security container, so that the test data is executed in the target security container, thereby realizing the execution of the target test cases.
[0102] Further, the manager creates a target monitor, which monitors the running status of the target security container and the call situation of the interface to be tested. If it is detected that there is an abnormality in the running status of the target security container or an abnormality in the call of the interface to be tested, the target monitor can collect the exception records generated during the running of the target security container and the exception records generated during the call of the interface to be tested, and generate exception prompt information according to the exception records.
[0103] In practical applications, the target tester and the target monitor run asynchronously. After the manager starts a group of target testers and target monitors, it can also start the target testers and target monitors corresponding to other interface tasks to be tested based on other interface tasks to be tested, thereby realizing the concurrent execution of multiple interface tasks to be tested.
[0104] The interface test system provided in this specification creates a target working directory corresponding to the target security container (test sandbox) on the host running the target security container, and starts the target tester in the target working directory, so that the target tester runs outside the target security container, thereby realizing the call of the interface to be tested, and monitors the running status of the target security container and the call situation of the interface to be tested through the target monitor to determine whether the target security container can run normally and whether the interface to be tested can be called, so as to realize the test of the interface on the host side of the target security container.
[0105] See Figure 2 , Figure 2 shows a flowchart of an interface test method provided according to an embodiment of this specification, which specifically includes the following steps.
[0106] Step 202: Obtain the interface task to be tested, where the interface task to be tested includes the target test cases of the interface to be tested.
[0107] This interface testing method is applied to the manager in the interface testing system. In actual application, the test cases of each interface to be tested are stored in the corpus.
[0108] The interface task to be tested carries the target test cases of the interface to be tested. Therefore, after obtaining the interface task to be tested, the manager can obtain the target test cases of the interface to be tested from the interface task to be tested.
[0109] Step 204: Start the target security container and the target tester corresponding to the interface task to be tested, and send the target test cases to the target tester, so that the target tester sends the test data to the target security container by calling the interface to be tested.
[0110] After the manager obtains the interface task to be tested, it can start the corresponding target security container and target tester according to the interface task to be tested, and send the target test cases of the interface to be tested to the target tester. In actual application, the target security container can be started according to the container configuration file of the target security container, that is, the configuration item for starting the target security container.
[0111] In an optional implementation manner provided in the embodiments of this specification, the interface task to be tested includes the container configuration file of the target security container;
[0112] Starting the target security container corresponding to the interface task to be tested includes:
[0113] Start the target security container according to the container configuration file.
[0114] Specifically, the interface task to be tested further includes the container configuration file of the target security container. The manager can start the target security container according to the container configuration file, so as to use the target security container as the test sandbox in the interface testing process. In actual application, the rund security container can be started as the target security container.
[0115] Furthermore, in order to implement the call to the interface to be tested, a target working directory corresponding to the target security container can be created on the host, so that the target tester runs in the target working directory, and further, the interface to be tested can be called during the test process of the interface to be tested.
[0116] Based on this, in an optional implementation manner provided in the embodiments of this specification, the interface task to be tested includes the binary file of the target tester;
[0117] Start the target tester corresponding to the interface task to be tested, including:
[0118] Create a target working directory corresponding to the target security container;
[0119] Copy the binary file to the target working directory and start the target tester in the target working directory based on the binary file.
[0120] Specifically, the manager creates a target working directory corresponding to the target security container on the host running the target security container, obtains the binary file carried in the interface task to be tested for starting the target tester, copies the binary file of the target tester to the created target working directory, and starts the target tester in the target working directory according to the binary file of the target tester.
[0121] By creating a corresponding target working directory for the target security container and starting the target tester in the target working directory, a one-to-one correspondence between the target security container and the target working directory is achieved, and the independent operation of each security container is realized. Further, the implementation method of creating the target working directory is as follows:
[0122] In an optional implementation manner provided in the embodiments of this specification, creating the target working directory corresponding to the target security container includes:
[0123] Obtain the target container identifier of the target security container and the test data for the interface task to be tested;
[0124] Create a target working directory corresponding to the target security container according to the target container identifier;
[0125] Store the test data in the target working directory.
[0126] Specifically, after the manager starts the target security container, it obtains the target container identifier corresponding to the target security container, creates a target working directory corresponding to the target security container according to the target container identifier, so that each security container has a corresponding working directory to store corresponding test data. Further, the manager can also obtain the test data for executing the interface task to be tested, and after creating the target working directory, store the test data in the target working directory for subsequent testing of the interface to be tested.
[0127] Since the manager and the target tester are two components in the interface testing system, in order to implement data interaction between the manager and the target tester, after starting the target security container and the target tester corresponding to the interface task to be tested, it is also necessary to establish a communication connection between the manager and the target tester so that data interaction can occur between the manager and the target tester. The implementation method of establishing a communication connection between the manager and the target tester is as follows:
[0128] In an alternative implementation provided by an embodiment of this specification, after starting the target security container and the target tester corresponding to the interface task to be tested, the method further includes:
[0129] Receiving a communication connection request sent by the target tester;
[0130] In response to the communication connection request, establishing a communication connection with the target tester.
[0131] Among them, the communication connection request specifically refers to a request sent by the target tester for establishing a communication connection with the manager.
[0132] Specifically, the manager receives the communication connection request sent by the target tester and, in response to this communication connection request, establishes a communication connection with the target tester. By establishing a communication connection between the manager and the target tester, data transmission and data interaction between the manager and the target tester can be achieved.
[0133] In an alternative implementation provided by an embodiment of this specification, sending the target test case to the target tester includes:
[0134] Sending the target test case to the target tester based on the communication connection.
[0135] After establishing a communication connection between the manager and the target tester, the manager can send the target test case to the target tester through the communication connection.
[0136] It should be noted that since the target working directory is not created in the target security container but on the host, when the target tester executes the target test case corresponding to the interface to be tested, it is also executed in the host environment.
[0137] The interface testing method provided in this specification is applied to the manager in the interface testing system. It can start the target security container and the target tester corresponding to the interface task to be tested on the host and create the working directory corresponding to the target security container on the host, enabling the target tester to execute the target test case on the host by calling the interface to be tested instead of in the target security container, thereby realizing subsequent testing of the interface to be tested.
[0138] Step 206: Create a target monitor to monitor the running status of the target security container and the invocation of the interface to be tested, and obtain the test result of the interface task to be tested.
[0139] After the target tester executes the target test case, it is also necessary to monitor the running status of the target security container and the invocation of the interface to be tested, so as to implement the test of the interface to be tested.
[0140] Based on this, the manager also needs to create a target monitor corresponding to the interface task to be tested, and monitor the running status of the target security container and the invocation of the interface to be tested through the target monitor, and obtain the test result of this interface task to be tested, that is, obtain the running result of the target security container and the invocation result of the interface to be tested. Specifically, after the manager creates the target monitor, the target monitor monitors the running status of the target security container to determine whether the target security container can run normally. The target monitor also needs to monitor the invocation of the interface to be tested to determine whether there is an abnormality in the interface to be tested, that is, to determine whether the host can normally access the test data in the target security container through the interface to be tested. By monitoring the running status of the target security container and the invocation of the interface to be tested, the target monitor can obtain the running result of the target security container and the invocation result of the interface to be tested.
[0141] The interface test method provided in this specification is applied to the manager in the interface test system. The method includes: obtaining an interface task to be tested, where the interface task to be tested includes the target test case of the interface to be tested; starting the target security container and the target tester corresponding to the interface task to be tested, and sending the target test case to the target tester, so that the target tester sends the test data to the target security container by invoking the interface to be tested; creating a target monitor to monitor the running status of the target security container and the invocation of the interface to be tested, and obtaining the test result of the interface task to be tested.
[0142] An embodiment of this specification realizes that the manager starts the target security container and the target tester corresponding to the interface task to be tested on the host, and creates a working directory corresponding to the target security container on the host, so that the target tester runs outside the target security container, and there is no need to execute the target test case in the target security container, but to execute the target test case on the host by invoking the interface to be tested, so as to realize the invocation of the interface to be tested. And by creating a target monitor to monitor the running status of the target security container and the invocation of the interface to be tested, the test of the interface to be tested is realized.
[0143] The following, in conjunction with the appended Figure 3 , taking the application of the interface testing method provided in this specification in fuzz testing as an example, further describes the interface testing method. Among them, Figure 3 shows the process flow chart of an interface testing method provided by an embodiment of this specification. The method is applied to a manager in an interface testing system and specifically includes the following steps.
[0144] Step 302: Obtain the interface task to be tested. Among them, the interface task to be tested includes the target test cases of the interface to be tested, the container configuration file of the target security container, and the binary file of the target tester.
[0145] Step 304: Start the target security container according to the container configuration file.
[0146] Step 306: Obtain the target container identifier of the target security container and the test data for the interface task to be tested.
[0147] Step 308: Create a target working directory corresponding to the target security container according to the target container identifier, and store the test data in the target working directory.
[0148] Step 310: Copy the binary file to the target working directory, and start the target tester in the target working directory based on the binary file.
[0149] Step 312: Receive the communication connection request sent by the target tester, and in response to the communication connection request, establish a communication connection with the target tester.
[0150] Step 314: Send the target test cases to the target tester based on the communication connection, so that the target tester sends the test data to the target security container by calling the interface to be tested.
[0151] Step 316: Create a target monitor, so that the target monitor monitors the running state of the target security container and the call situation of the interface to be tested, and obtains the test result of the interface task to be tested.
[0152] In one embodiment of this specification, the manager in the interface test system starts the target security container and the target tester corresponding to the interface task to be tested, and creates a working directory corresponding to the target security container, so that the target tester runs outside the target security container. Instead of executing the target test case in the target security container, the target test case is executed on the host by calling the interface to be tested, thereby realizing the call of the interface to be tested. And by creating a target monitor to monitor the running state of the target security container and the call situation of the interface to be tested, the test of the interface to be tested is realized.
[0153] Corresponding to the above method embodiment, this specification also provides an embodiment of an interface test device. Figure 4 The structure diagram of an interface test device provided by an embodiment of this specification is shown. As Figure 4 shown, this device is applied to the manager in the interface test system, and this device includes:
[0154] An acquisition module 402, configured to acquire an interface task to be tested, where the interface task to be tested includes a target test case of the interface to be tested;
[0155] A start module 404, configured to start the target security container and the target tester corresponding to the interface task to be tested, and send the target test case to the target tester, so that the target tester sends test data to the target security container by calling the interface to be tested;
[0156] A creation module 406, configured to create a target monitor, so that the target monitor monitors the running state of the target security container and the call situation of the interface to be tested, and obtains the test result of the interface task to be tested.
[0157] Optionally, the interface task to be tested includes a container configuration file of the target security container;
[0158] The start module 404 is further configured to:
[0159] Start the target security container according to the container configuration file.
[0160] Optionally, the interface task to be tested includes a binary file of the target tester;
[0161] The start module 404 is further configured to:
[0162] Create a target working directory corresponding to the target security container;
[0163] Copy the binary file to the target working directory and start the target tester in the target working directory based on the binary file.
[0164] Optionally, the starting module 404 is further configured to:
[0165] Obtain the target container identifier of the target security container and test data for the interface task to be tested;
[0166] Create a target working directory corresponding to the target security container according to the target container identifier;
[0167] Store the test data in the target working directory.
[0168] Optionally, the device further includes:
[0169] A request receiving module, configured to receive a communication connection request sent by the target tester;
[0170] A establishing module, configured to establish a communication connection with the target tester in response to the communication connection request.
[0171] Optionally, the starting module 404 is further configured to:
[0172] Send the target test case to the target tester based on the communication connection.
[0173] The interface test device provided in this specification is applied to a manager in an interface test system. The device includes: an obtaining module, configured to obtain an interface task to be tested, where the interface task to be tested includes a target test case of an interface to be tested; a starting module, configured to start a target security container and a target tester corresponding to the interface task to be tested, and send the target test case to the target tester, so that the target tester sends test data to the target security container by calling the interface to be tested; a creating module, configured to create a target monitor, so that the target monitor monitors the running state of the target security container and the call situation of the interface to be tested, and obtains the test result of the interface task to be tested.
[0174] In one embodiment of this specification, the manager starts a target security container and a target tester corresponding to the interface task to be tested on the host, and creates a working directory corresponding to the target security container on the host, so that the target tester runs outside the target security container. Instead of executing the target test case in the target security container, the target test case is executed on the host by calling the interface to be tested, thereby realizing the call of the interface to be tested. And by creating a target monitor to monitor the running status of the target security container and the call situation of the interface to be tested, the test of the interface to be tested is realized.
[0175] The above is a schematic solution of an interface testing device according to this embodiment. It should be noted that the technical solution of this interface testing device and the technical solution of the above interface testing method belong to the same concept. For the details not described in the technical solution of the interface testing device, reference can be made to the description of the technical solution of the above interface testing method.
[0176] See Figure 5 , Figure 5 shows a flowchart of another interface testing method provided according to an embodiment of this specification, which specifically includes the following steps.
[0177] Step 502: Receive the target test case for the interface task to be tested sent by the manager, where the target test case is sent through the communication connection between the manager and the tester.
[0178] Step 504: Obtain the test data corresponding to the interface task to be tested.
[0179] Step 506: Call the interface to be tested corresponding to the target test case, and send the test data to the target security container.
[0180] This interface testing method is applied to the tester in the interface testing system. Specifically, the tester receives the target test case for the interface task to be tested sent by the manager based on the communication connection, and obtains the test data corresponding to the interface task to be tested. Furthermore, by calling the interface to be tested and sending the test data to the target security container, the target test case is executed.
[0181] In one embodiment of this specification, the tester runs outside the target security container, and realizes the call of the interface to be tested by calling the interface to be tested and executing the target test case on the host.
[0182] Corresponding to the above method embodiment, this specification also provides another embodiment of the interface testing device. Figure 6 shows a schematic structural diagram of another interface testing device provided according to an embodiment of this specification. As Figure 6As shown, the device is applied to a tester in an interface test system. The device includes:
[0183] A receiving module 602, configured to receive a target test case for an interface task to be tested sent by a manager, where the target test case is sent through a communication connection between the manager and the tester;
[0184] A data acquisition module 604, configured to acquire test data corresponding to the interface task to be tested;
[0185] An invocation module 606, configured to invoke an interface to be tested corresponding to the target test case and send the test data to a target security container.
[0186] In one embodiment of this specification, it is realized that the tester runs outside the target security container, and by invoking the interface to be tested, the target test case is executed on the host machine to realize the invocation of the interface to be tested.
[0187] The above is a schematic solution of another interface test device of this embodiment. It should be noted that the technical solution of this interface test device and the technical solution of the above interface test method belong to the same concept. For the details not described in the technical solution of the interface test device, reference can be made to the description of the technical solution of the above interface test method.
[0188] See Figure 7 , Figure 7 which shows a flowchart of another interface test method provided according to an embodiment of this specification, specifically including the following steps.
[0189] Step 702: Monitor the running status of the target security container and the invocation situation of the interface to be tested.
[0190] Step 704: Obtain the running result of the target security container and the invocation result of the interface to be tested.
[0191] Step 706: Generate an exception prompt message when an exception exists in the running result or the invocation result.
[0192] This interface test method is applied to a monitor in an interface test system. Since the target tester does not run in the target security container, monitoring the target tester cannot obtain the running status of the target security container.
[0193] Based on this, the monitor determines whether the target security container can operate normally and whether there are abnormalities in the to-be-tested interface by monitoring the running status of the target security container and the call situation of the to-be-tested interface. If the monitor detects an abnormality in the running status of the target security container or an abnormality in the call situation of the to-be-tested interface, it can trigger an exception reporting process, collect the exception records generated during the running of the target security container, and the exception records generated during the call of the to-be-tested interface, and generate exception prompt information based on the exception records. Further, the generated exception prompt information can be fed back to the terminals of relevant technical personnel so that the relevant technical personnel can handle the exception vulnerabilities in a timely manner.
[0194] An embodiment of this specification realizes monitoring the running status of a target security container and the call situation of a to-be-tested interface by using a monitor, obtaining a test result for the to-be-tested interface task, and if the test result is abnormal, generating corresponding exception prompt information to implement the test of the to-be-tested interface.
[0195] Corresponding to the above method embodiment, this specification also provides another embodiment of an interface testing device. Figure 8 The structure diagram of another interface testing device provided by an embodiment of this specification is shown. As Figure 8 shown, this device is applied to the monitor in the interface testing system, and this device includes:
[0196] A monitoring module 802, configured to monitor the running status of the target security container and the call situation of the to-be-tested interface;
[0197] An obtaining module 804, configured to obtain the running result of the target security container and the call result of the to-be-tested interface;
[0198] A generating module 806, configured to generate exception prompt information when there is an abnormality in the running result or the call result.
[0199] An embodiment of this specification realizes monitoring the running status of a target security container and the call situation of a to-be-tested interface by using a monitor, obtaining a test result for the to-be-tested interface task, and if the test result is abnormal, generating corresponding exception prompt information to implement the test of the to-be-tested interface.
[0200] The above is a schematic solution of another interface testing device of this embodiment. It should be noted that the technical solution of this interface testing device and the technical solution of the above interface testing method belong to the same concept. For the details not described in the technical solution of the interface testing device, reference can be made to the description of the technical solution of the above interface testing method.
[0201] Figure 9FIG. 0 shows a structural block diagram of a computing device 900 provided according to an embodiment of the present specification. The components of the computing device 900 include, but are not limited to, a memory 910 and a processor 920. The processor 920 is connected to the memory 910 via a bus 930, and a database 950 is used to store data.
[0202] The computing device 900 further includes an access device 940, which enables the computing device 900 to communicate via one or more networks 960. Examples of these networks include the Public Switched Telephone Network (PSTN), Local Area Network (LAN), Wide Area Network (WAN), Personal Area Network (PAN), or a combination of communication networks such as the Internet. The access device 940 may include one or more of any type of wired or wireless network interface (e.g., a network interface card (NIC)), such as an IEEE 802.11 Wireless Local Area Network (WLAN) wireless interface, a Worldwide Interoperability for Microwave Access (Wi-MAX) interface, an Ethernet interface, a Universal Serial Bus (USB) interface, a cellular network interface, a Bluetooth interface, a Near Field Communication (NFC).
[0203] In an embodiment of the present specification, the above components of the computing device 900 and Figure 9 other components not shown therein may also be connected to each other, for example, via a bus. It should be understood that Figure 9 the shown structural block diagram of the computing device is for illustrative purposes only and is not a limitation on the scope of the present specification. Those skilled in the art may add or replace other components as needed.
[0204] The computing device 900 can be any type of stationary or mobile computing device, including mobile computers or mobile computing devices (e.g., tablet computers, personal digital assistants, laptop computers, notebook computers, netbooks, etc.), mobile phones (e.g., smart phones), wearable computing devices (e.g., smart watches, smart glasses, etc.) or other types of mobile devices, or stationary computing devices such as desktop computers or personal computers (PCs). The computing device 900 can also be a mobile or stationary server.
[0205] Wherein, the processor 920 is configured to execute the following computer-executable instructions, and when the computer-executable instructions are executed by the processor, the steps of the above interface testing method are implemented.
[0206] The above is a schematic solution of a computing device according to this embodiment. It should be noted that the technical solution of the computing device and the technical solution of the above interface testing method belong to the same concept. For the details not described in detail in the technical solution of the computing device, reference can be made to the description of the technical solution of the above interface testing method.
[0207] An embodiment of this specification also provides a computer-readable storage medium, which stores computer-executable instructions, and when the computer-executable instructions are executed by a processor, the steps of the above interface testing method are implemented.
[0208] The above is a schematic solution of a computer-readable storage medium according to this embodiment. It should be noted that the technical solution of the storage medium and the technical solution of the above interface testing method belong to the same concept. For the details not described in detail in the technical solution of the storage medium, reference can be made to the description of the technical solution of the above interface testing method.
[0209] An embodiment of this specification also provides a computer program, wherein when the computer program is executed on a computer, the computer is made to execute the steps of the above interface testing method.
[0210] The above is a schematic solution of a computer program according to this embodiment. It should be noted that the technical solution of the computer program and the technical solution of the above interface testing method belong to the same concept. For the details not described in detail in the technical solution of the computer program, reference can be made to the description of the technical solution of the above interface testing method.
[0211] The above describes specific embodiments of this specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims may be performed in a different order than in the embodiments and still achieve the desired results. Additionally, the processes depicted in the figures do not necessarily require the particular order or sequential order shown to achieve the desired results. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0212] The computer instructions include computer program code, which may be in source code form, object code form, executable file, or some intermediate form, etc. The computer-readable medium may include: any entity or device capable of carrying the computer program code, recording medium, USB flash drive, removable hard disk, magnetic disk, optical disc, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signal, telecommunication signal, and software distribution medium, etc. It should be noted that the content included in the computer-readable medium may be appropriately increased or decreased according to the requirements of patent practice. For example, in some regions, according to patent practice, the computer-readable medium does not include electrical carrier signals and telecommunication signals.
[0213] It should be noted that for the foregoing method embodiments, for the sake of simplicity of description, they are all expressed as a series of action combinations. However, those skilled in the art should know that the embodiments of this specification are not limited by the described order of actions, because according to the embodiments of this specification, certain steps may be performed in other orders or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily essential to the embodiments of this specification.
[0214] In the above embodiments, the descriptions of the various embodiments have their own focuses. For the parts not detailed in a certain embodiment, reference may be made to the relevant descriptions of other embodiments.
[0215] The preferred embodiments of this specification disclosed above are only used to help explain this specification. The alternative embodiments do not elaborate on all the details and do not limit the invention to only the specific embodiments described. Obviously, based on the content of the embodiments of this specification, many modifications and changes can be made. This specification selects and specifically describes these embodiments to better explain the principles and practical applications of the embodiments of this specification, so that those skilled in the art can well understand and utilize this specification. This specification is only limited by the claims and their full scope and equivalents.
Claims
1. An interface testing method, applied to a manager in an interface testing system, the method comprising: Obtain an interface task to be tested, wherein the interface task to be tested includes target test cases of the interface to be tested; Start a target security container and a target tester corresponding to the interface task to be tested, and send the target test cases to the target tester, so that the target tester sends test data to the target security container by invoking the interface to be tested; Create a target monitor, so that the target monitor monitors the running status of the target security container and the invocation situation of the interface to be tested, and obtains the test result of the interface task to be tested.
2. The method according to claim 1, wherein the interface task to be tested includes a container configuration file of the target security container; Starting the target security container corresponding to the interface task to be tested includes: Starting the target security container according to the container configuration file.
3. The method according to claim 1, wherein the interface task to be tested includes a binary file of the target tester; Starting the target tester corresponding to the interface task to be tested includes: Create a target working directory corresponding to the target security container; Copy the binary file to the target working directory, and start the target tester in the target working directory based on the binary file.
4. The method according to claim 3, creating a target working directory corresponding to the target security container includes: Obtain the target container identifier of the target security container and test data for the interface task to be tested; Create a target working directory corresponding to the target security container according to the target container identifier; Store the test data in the target working directory.
5. The method according to claim 1, after starting the target security container and the target tester corresponding to the interface task to be tested, the method further includes: Receive a communication connection request sent by the target tester; In response to the communication connection request, establish a communication connection with the target tester.
6. The method according to claim 5, sending the target test cases to the target tester includes: Send the target test cases to the target tester based on the communication connection.
7. An interface testing method, applied to a tester in an interface testing system, the method comprising: Receive target test cases for an interface task to be tested sent by a manager, wherein the target test cases are sent through a communication connection between the manager and the tester; Obtain test data corresponding to the interface task to be tested; Invoke the interface to be tested corresponding to the target test cases, and send the test data to a target security container.
8. An interface testing method, applied to a monitor in an interface testing system, the method comprising: Monitor the running status of a target security container and the invocation situation of an interface to be tested; Obtain the running result of the target security container and the invocation result of the interface to be tested; Generate an exception prompt message when an exception exists in the running result or the invocation result.
9. An interface testing system, comprising a manager, a target tester, and a target monitor; The manager is configured to obtain an interface task to be tested, where The interface task to be tested includes target test cases for the interface to be tested. Start the target security container and the target tester corresponding to the interface task to be tested, and send the target test cases to the target tester; The target tester is configured to receive the target test cases for the interface task to be tested sent by the manager. Among them, the target test cases are sent through the communication connection between the manager and the target tester, obtain the test data corresponding to the interface task to be tested, call the interface to be tested corresponding to the target test cases, and send the test data to the target security container; The manager is further configured to create a target monitor; The target monitor is configured to monitor the running status of the target security container and the call situation of the interface to be tested, and obtain the running result of the target security container and the call result of the interface to be tested.
10. The system according to claim 9, wherein the interface task to be tested includes the binary file of the target tester; The manager is further configured to: Create a target working directory corresponding to the target security container; Copy the binary file to the target working directory, and start the target tester in the target working directory based on the binary file.
11. The system according to claim 10, wherein the manager is further configured to: Obtain the target container identifier of the target security container and the test data for the interface task to be tested; Create a target working directory corresponding to the target security container according to the target container identifier; Store the test data in the target working directory.
12. The system according to claim 9, wherein the target monitor is further configured to: Generate an exception prompt message when an exception exists in the running result or the call result.
13. A computing device, comprising: A memory and a processor; The memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions. When the computer-executable instructions are executed by the processor, the steps of the interface testing method according to any one of claims 1-6 or 7 or 8 are implemented.
14. A computer-readable storage medium, which stores computer-executable instructions. When the computer-executable instructions are executed by a processor, the steps of the interface testing method according to any one of claims 1-6 or 7 or 8 are implemented.