Bluetooth security test method and device, electronic equipment and storage medium
By loading a type-specific security testing policy library for Bluetooth modules and performing a multi-dimensional testing process, the problem of inability to adapt to different Bluetooth types and lack of systematic evaluation in the existing technology is solved, and a comprehensive security assessment of Bluetooth modules is achieved.
Patent Information
- Application Number
- CN202510646885.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-20
- Publication Date
- 2025-07-08
AI Technical Summary
Existing Bluetooth security testing solutions cannot automatically adapt to different Bluetooth types, and are mostly limited to a single security defect or specific scenarios, making it difficult to comprehensively evaluate the security status of Bluetooth modules in the device.
Provide a Bluetooth security testing method, by determining the type of Bluetooth module, loading the corresponding security testing policy library, performing testing processes for projects including authentication, data transmission, protocol stack attacks and vulnerability scanning, and evaluable scanning, and evaluable status of the module.
Intelligent and automated testing of different Bluetooth types is realized, the compatibility and reliability of the test solutions are improved, and the security of the Bluetooth module can be comprehensively evaluated.
Smart Images

Figure CN120282200A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the technical field of Bluetooth communication security, for example, to a Bluetooth security testing method, apparatus, electronic device, and storage medium. Background Art
[0002] With the rapid development of wireless communication technologies, Bluetooth technology has been widely applied in fields such as vehicle-mounted systems, smart homes, wearable devices, and industrial automation due to its low power consumption, low cost, and wide compatibility. However, while the Bluetooth protocol is open and convenient, it also faces many security threats, such as unauthorized device access, data tampering, malicious attacks, and security vulnerabilities. Therefore, it is particularly necessary to perform security testing and evaluation on devices using Bluetooth communication.
[0003] Currently, devices using Bluetooth communication usually configure Bluetooth modules of different Bluetooth types. For example, some vehicle-mounted terminals integrate classic Bluetooth and low-power Bluetooth modules at the same time. Since there are significant differences in protocol implementation, security mechanisms, and application scenarios among different Bluetooth types, the Bluetooth security testing solutions provided in the related technologies are often designed only for a specific Bluetooth type and cannot automatically load corresponding test strategies according to the Bluetooth type used by the actual device.
[0004] It should be noted that the information disclosed in the above background art section is only used to enhance the understanding of the background of the present disclosure, and thus may include information that does not constitute the prior art known to those of ordinary skill in the art. Summary of the Invention
[0005] To provide a basic understanding of some aspects of the disclosed embodiments, a simple summary is given below. This summary is not an extensive review nor is it intended to identify key / important elements or delineate the scope of protection of these embodiments, but rather serves as a preamble to the detailed description that follows.
[0006] Embodiments of the present disclosure provide a Bluetooth security testing method, apparatus, electronic device, and storage medium, which can be applicable to the security testing requirements of different Bluetooth types.
[0007] According to a first aspect of the present disclosure, a Bluetooth security testing method is provided, including:
[0008] Determine the Bluetooth type of the Bluetooth module to be tested, where the Bluetooth type includes classic Bluetooth and low-power Bluetooth;
[0009] Load a security testing policy library corresponding to the Bluetooth type, where the security testing policy library includes at least one piece of security testing item information, and the security testing item information includes a test script and a determination criterion;
[0010] Execute corresponding test processes based on the information of each security test item, and evaluate the security status of the Bluetooth module according to the test results.
[0011] In some embodiments, the security test item information is any one of the following: authentication item information, transmitted data item information, protocol stack attack item information, and vulnerability scanning item information.
[0012] In some embodiments, executing corresponding test processes based on the information of each security test item, and evaluating the security status of the Bluetooth module according to the test results, includes: controlling an unauthorized device to pair with and interact with the Bluetooth module based on the authentication item information, and evaluating the authentication ability of the Bluetooth module based on the interaction results.
[0013] In some embodiments, controlling an unauthorized device to pair with and interact with the Bluetooth module based on the authentication item information, and evaluating the authentication ability of the Bluetooth module based on the interaction results, includes:
[0014] Controlling the Bluetooth module to broadcast based on the authentication item information, and controlling an unauthorized device to send a pairing request to the Bluetooth module;
[0015] In the case of unsuccessful pairing, controlling the unauthorized device to send a control instruction to the Bluetooth module;
[0016] When the Bluetooth module refuses to execute the control instruction, determining that the authentication ability of the Bluetooth module is qualified;
[0017] When the Bluetooth module accepts and executes the control instruction, determining that the authentication ability of the Bluetooth module is unqualified.
[0018] In some embodiments, executing corresponding test processes based on the information of each security test item, and evaluating the security status of the Bluetooth module according to the test results, includes:
[0019] Obtaining the data packet sent to the Bluetooth module based on the transmitted data item information;
[0020] Performing at least one security verification process on the data packet to obtain the verification result of each security verification;
[0021] Evaluating the transmitted data protection ability of the Bluetooth module based on the verification result of each security verification.
[0022] In some embodiments, the security verification is any one of the following: encryption security verification, identity security verification, protocol security verification, and data integrity verification.
[0023] In some embodiments, evaluating the transmitted data protection ability of the Bluetooth module based on the verification result of each security verification, includes:
[0024] When the verification result of each security verification is successful, it is determined that the transmission data protection ability of the Bluetooth module is qualified; and when the verification result of any security verification is failed, it is determined that the transmission data protection ability of the Bluetooth module is unqualified.
[0025] In some embodiments, corresponding test processes are executed based on each security test item information, and the security status of the Bluetooth module is evaluated according to the test results, including:
[0026] Generate an attack payload based on the protocol stack attack item information;
[0027] Send the attack payload to the Bluetooth module and monitor the running state of the Bluetooth module;
[0028] Evaluate the anti-attack ability of the Bluetooth module based on the running state of the Bluetooth module.
[0029] In some embodiments, the anti-attack ability of the Bluetooth module is evaluated based on the running state of the Bluetooth module, including: when the running state of the Bluetooth module is normal, it is determined that the anti-attack ability of the Bluetooth module is qualified; when the running state of the Bluetooth module is abnormal, it is determined that the anti-attack ability of the Bluetooth module is unqualified.
[0030] In some embodiments, corresponding test processes are executed based on each security test item information, and the security status of the Bluetooth module is evaluated according to the test results, including:
[0031] Based on the vulnerability scanning item information, attempt to trigger potential vulnerabilities of the Bluetooth module;
[0032] Monitor the running state of the Bluetooth module and whether the device to which the Bluetooth module belongs appears in an alarm state;
[0033] Determine the vulnerability protection ability of the Bluetooth module based on the running state of the Bluetooth module and the occurrence of the alarm state of the device to which the Bluetooth module belongs.
[0034] In some embodiments, the vulnerability protection ability of the Bluetooth module is determined based on the running state of the Bluetooth module and the occurrence of the alarm state of the device to which the Bluetooth module belongs, including:
[0035] When the running state of the Bluetooth module is normal and the device to which the Bluetooth module belongs does not appear in an alarm state, it is determined that the vulnerability protection ability of the Bluetooth module is qualified;
[0036] When the running state of the Bluetooth module is abnormal or the device to which the Bluetooth module belongs appears in an alarm state, it is determined that the vulnerability protection ability of the Bluetooth module is unqualified.
[0037] According to the second aspect of the present disclosure, there is provided a Bluetooth security test device, including:
[0038] A Bluetooth identification module, configured to: determine the Bluetooth type of the Bluetooth module to be tested, where the Bluetooth type includes classic Bluetooth and low-power Bluetooth;
[0039] A policy loading module, configured to: load a security test policy library corresponding to the Bluetooth type, where the security test policy library includes at least one piece of security test item information, and the security test item information includes a test script and a determination criterion;
[0040] A security test module, configured to: execute a corresponding test process based on each piece of security test item information, and evaluate the security status of the Bluetooth module according to the test results.
[0041] According to a third aspect of the present disclosure, there is provided an electronic device, including a processor and a memory storing program instructions, characterized in that the processor is configured to execute the Bluetooth security test method provided in the second aspect of the present disclosure when running the program instructions.
[0042] According to a fourth aspect of the present disclosure, there is provided a storage medium storing computer program instructions, and when the computer program instructions are run by a processor, the Bluetooth security test method provided in the second aspect of the present disclosure is executed.
[0043] The Bluetooth security test method, device, electronic device and storage medium provided by the embodiments of the present disclosure can achieve the following technical effects:
[0044] The Bluetooth security test method provided by the embodiments of the present disclosure pre-configures a security test policy library corresponding to different Bluetooth types. Each policy library customizes and designs security test item information including test scripts and determination criteria according to the protocol implementation and security mechanism characteristics of the corresponding Bluetooth type. During the test, first determine the type of the Bluetooth module to be tested, and automatically load the matching security test policy library, so as to accurately select the appropriate test content and automatically execute the test process. This method realizes the intelligence and automation of the test process, improves the compatibility of the test scheme with multiple Bluetooth types, can be applied to the security test requirements of different Bluetooth types, effectively avoids the limitation of the traditional scheme that only supports a single Bluetooth type, and provides a more comprehensive, efficient and reliable means for Bluetooth security evaluation.
[0045] The above general description and the following description are only exemplary and explanatory, and are not used to limit the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS
[0046] One or more embodiments are exemplarily illustrated by corresponding drawings. These exemplary illustrations and the drawings do not constitute limitations on the embodiments. Elements with the same reference numerals in the drawings are shown as similar elements. The drawings do not constitute a scale limitation, and in which:
[0047] Figure 1 It is a schematic diagram of a Bluetooth security test scenario provided by an embodiment of the present disclosure;
[0048] Figure 2 It is a schematic diagram of another Bluetooth security test scenario provided by an embodiment of the present disclosure;
[0049] Figure 3 It is a schematic flowchart of a Bluetooth security test method provided by an embodiment of the present disclosure;
[0050] Figure 4 It is a schematic flowchart of another Bluetooth security test method provided by an embodiment of the present disclosure;
[0051] Figure 5 It is a schematic flowchart of another Bluetooth security test method provided by an embodiment of the present disclosure;
[0052] Figure 6 It is a schematic flowchart of another Bluetooth security test method provided by an embodiment of the present disclosure;
[0053] Figure 7 It is a schematic flowchart of another Bluetooth security test method provided by an embodiment of the present disclosure;
[0054] Figure 8 It is a schematic structural diagram of a Bluetooth security test device provided by an embodiment of the present disclosure;
[0055] Figure 9 It is a schematic structural diagram of an electronic device provided by an embodiment of the present disclosure. Detailed implementation manners
[0056] In order to be able to understand the features and technical content of the embodiments of the present disclosure in more detail, the implementation of the embodiments of the present disclosure will be described in detail below with reference to the accompanying drawings. The accompanying drawings are only for reference and explanation purposes and are not used to limit the embodiments of the present disclosure. In the following technical description, for the convenience of explanation, a sufficient understanding of the disclosed embodiments is provided through multiple details. However, one or more embodiments can still be implemented without these details. In other cases, well-known structures and devices can be shown in a simplified manner.
[0057] Terms such as "first", "second", etc. in the specification, claims and above-mentioned drawings of the embodiments of the present disclosure are used to distinguish similar objects and do not have to be used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances so as to implement the embodiments of the present disclosure described herein. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion.
[0058] Unless otherwise stated, the term "plurality" means two or more.
[0059] In the embodiments of the present disclosure, the character " / " indicates that the front and rear objects have an "or" relationship. For example, A / B means: A or B.
[0060] The term "and / or" is an associative relationship describing an object, indicating that three relationships can exist. For example, A and / or B means: A or B, or, A and B, these three relationships.
[0061] The term "corresponding" may refer to an associative relationship or a binding relationship. A corresponding to B means that there is an associative relationship or a binding relationship between A and B.
[0062] With the rapid development of wireless communication technology, Bluetooth technology has been widely used in in-vehicle systems, smart homes, wearable devices, industrial automation and other fields due to its low power consumption, low cost and wide compatibility. However, while the Bluetooth protocol is open and convenient, it also faces many security threats, such as unauthorized device access, data tampering, malicious attacks and security vulnerabilities. Therefore, it is particularly necessary to conduct security testing and evaluation on devices using Bluetooth communication.
[0063] Currently, devices using Bluetooth communication are usually configured with Bluetooth modules of different Bluetooth types. For example, some in-vehicle terminals will integrate classic Bluetooth and low-power Bluetooth modules at the same time. Since there are significant differences in protocol implementation, security mechanisms and application scenarios among different Bluetooth types, the Bluetooth security testing solutions provided in the related technologies are often designed only for a specific Bluetooth type and cannot automatically load the corresponding test strategies according to the Bluetooth type used by the actual device. In addition, existing Bluetooth security testing solutions are mostly point-to-point tests for single security defects or specific scenarios, lacking systematic coverage of multiple security dimensions involved in Bluetooth communication and making it difficult to comprehensively evaluate the security status of the Bluetooth module in the device.
[0064] Existing Bluetooth security testing solutions fail to automatically adapt to different Bluetooth types, and are mostly limited to testing single security defects or specific scenarios, lacking systematic coverage of multiple security dimensions of Bluetooth communication, resulting in difficulty in comprehensively evaluating the security of the Bluetooth module.
[0065] Embodiments of the present disclosure provide a Bluetooth security testing method. The Bluetooth security testing method can be executed by a testing device to perform security testing on Bluetooth modules of different Bluetooth types in the testing device. Here, the Bluetooth types include classic Bluetooth and low-power Bluetooth. Classic Bluetooth generally refers to the original Bluetooth technical standard, which supports a relatively high data transmission rate and is suitable for application scenarios that require continuous data transmission. Classic Bluetooth is mainly used for tasks that require relatively high bandwidth, such as audio streaming and file transfer. For example, it is widely used in file transfer between wireless headphones, speakers, computers, and mobile phones. Low-power Bluetooth is a version of Bluetooth technology designed to meet low-power requirements, aiming to significantly reduce power consumption and cost while maintaining a communication range similar to traditional Bluetooth. It is particularly suitable for application scenarios that do not require continuous data transmission but need to run for a long time and have limited battery power.
[0066] As shown in Figure 1 , the Bluetooth module using classic Bluetooth technology is named as the classic Bluetooth module, and the Bluetooth module using low-power Bluetooth technology is named as the low-power Bluetooth module. The testing device can interact with the classic Bluetooth module and the low-power Bluetooth module to carry out corresponding security testing.
[0067] As shown in Figure 2 , some terminal devices with Bluetooth communication functions can be configured with both a classic Bluetooth module and a low-power Bluetooth module at the same time. The testing device can interact with the classic Bluetooth module and the low-power Bluetooth module in the terminal device to carry out corresponding security testing. Taking the terminal device as a vehicle terminal (such as an in-vehicle computer) as an example, in the vehicle terminal, the classic Bluetooth module is mainly used to support functions such as voice communication and audio playback. In normal application scenarios, the classic Bluetooth module can interact with a user terminal (such as a smart phone), and its typical application scenarios include Bluetooth calls, music streaming, etc. The low-power Bluetooth module can be applied to scenarios such as vehicle key control. In normal application scenarios, the low-power Bluetooth module can interact with a Bluetooth key to implement functions such as unlocking the vehicle door and starting the engine. The testing device can interact with the classic Bluetooth module and the low-power Bluetooth module in the vehicle terminal to carry out corresponding security testing. During this process, the user terminal and the Bluetooth key can also interact with the testing device, and their interaction behaviors can be used in the security testing process of the Bluetooth module.
[0068] As shown in Figure 1 and Figure 2 , during the security testing process, unauthorized devices can also be introduced for testing. The unauthorized devices can interact with the testing device, and their interaction behaviors can also be used in the security testing process of the Bluetooth module. Specifically, such unauthorized devices do not have legitimate access rights to the Bluetooth module, and by simulating the behaviors of potential attackers, they assist in evaluating the security protection capabilities of the Bluetooth module.
[0069] Combined Figure 3 As shown, embodiments of the present disclosure provide a Bluetooth security testing method, and the Bluetooth security testing method includes:
[0070] S301, the testing device determines the Bluetooth type of the Bluetooth module to be tested.
[0071] In the embodiments of the present disclosure, the Bluetooth type includes classic Bluetooth and low-power Bluetooth.
[0072] S302, the testing device loads the security testing policy library corresponding to the Bluetooth type.
[0073] In the embodiments of the present disclosure, the security testing policy library includes at least one piece of security testing item information, and the security testing item information includes a test script and a judgment criterion.
[0074] In the embodiments of the present disclosure, the security testing policy library is carefully designed to adapt to the characteristics of different Bluetooth types. Each policy library contains at least one piece of security testing item information. Each security testing policy library is customized according to the protocol implementation and security mechanism characteristics of the corresponding Bluetooth type, and designs security testing item information including test scripts and judgment criteria. For each security testing item, the test script provides specific test steps and operation processes to guide the testing device on how to interact with the Bluetooth module to be tested. To ensure the accuracy and consistency of the test results, each test item has a clear judgment criterion. The judgment criterion defines what test results are considered qualified or unqualified and refines the evaluation criteria according to different test purposes.
[0075] S303, the testing device executes the corresponding test process based on each piece of security testing item information, and evaluates the security status of the Bluetooth module according to the test results.
[0076] The Bluetooth security testing method provided by the embodiments of the present disclosure pre-configures security testing policy libraries corresponding to different Bluetooth types. Each policy library is customized according to the protocol implementation and security mechanism characteristics of the corresponding Bluetooth type, and designs security testing item information including test scripts and judgment criteria. During the testing process, the type of the Bluetooth module to be tested is first determined, and the matching security testing policy library is automatically loaded, so as to accurately select the appropriate test content and automatically execute the test process. This method realizes the intelligence and automation of the testing process, improves the compatibility of the test scheme with multiple Bluetooth types, can be applied to the security testing requirements of different Bluetooth types, effectively avoids the limitations of traditional schemes that only support a single Bluetooth type, and provides a more comprehensive, efficient and reliable Bluetooth security evaluation means.
[0077] In the embodiments of the present disclosure, the security test project information is any one of the following: authentication project information, transmitted data project information, protocol stack attack project information, and vulnerability scanning project information. Optionally, the security test policy library corresponding to the Bluetooth type may include authentication project information, transmitted data project information, protocol stack attack project information, and vulnerability scanning project information at the same time. By integrating various security test project information in the security test policy library, a comprehensive security check of the Bluetooth module is realized, ensuring that potential security threats can be accurately identified even in complex application environments, thereby more comprehensively and reliably evaluating the security status of the Bluetooth device.
[0078] In some embodiments, corresponding test processes are executed based on each security test project information, and the security status of the Bluetooth module is evaluated according to the test results, including: controlling an unauthorized device to pair and interact with the Bluetooth module based on the authentication project information, and evaluating the authentication ability of the Bluetooth module based on the interaction results.
[0079] The embodiments of the present disclosure simulate an unauthorized device attempting to pair and interact with the Bluetooth module, which can truly reflect the response behavior of the Bluetooth module when facing illegal access, thereby determining whether its authentication mechanism is sound. Through actual interaction testing, the processing logic of the Bluetooth module for illegal requests is dynamically detected, ensuring that the evaluation results are closer to the actual scenario and improving the credibility of the test.
[0080] Combined with Figure 4 As shown, the embodiments of the present disclosure provide another Bluetooth security test method. The Bluetooth security test method includes:
[0081] S401, the test device determines the Bluetooth type of the Bluetooth module to be tested.
[0082] S402, the test device loads the security test policy library corresponding to the Bluetooth type.
[0083] S403, the test device controls an unauthorized device to pair and interact with the Bluetooth module based on the authentication project information, and evaluates the authentication ability of the Bluetooth module based on the interaction results.
[0084] In some embodiments, the authentication project information includes an authentication test script and a judgment criterion for whether the authentication ability is qualified. Controlling an unauthorized device to pair and interact with the Bluetooth module based on the authentication project information, and evaluating the authentication ability of the Bluetooth module based on the interaction results, includes: controlling the Bluetooth module to broadcast based on the authentication project information, and controlling the unauthorized device to send a pairing request to the Bluetooth module; in the case of unsuccessful pairing, controlling the unauthorized device to send a control instruction to the Bluetooth module; when the Bluetooth module refuses to execute the control instruction, determining that the authentication ability of the Bluetooth module is qualified; when the Bluetooth module accepts and executes the control instruction, determining that the authentication ability of the Bluetooth module is unqualified.
[0085] Based on the authentication project information, the test device controls the Bluetooth module under test to enter the discoverable state and broadcast based on the test script, so as to simulate the state exposed by the Bluetooth device in the normal usage scenario; at the same time, the test device controls the unauthorized device to actively search and attempt to establish a connection with the Bluetooth module based on the test script, and send a pairing request to it, simulating the behavior of potential attackers. During this process, detect whether the Bluetooth module requires entering a verification code or adopts other authentication mechanisms for pairing verification.
[0086] If the Bluetooth module does not complete the pairing process (for example, does not enter the correct verification code or does not perform user confirmation), the test device further attempts to send control commands (such as audio playback, unlocking the car door, etc.) to the Bluetooth module to detect whether it allows unauthorized devices to perform sensitive operations without authentication.
[0087] If the Bluetooth module refuses to execute the control command, it means that its authentication mechanism is effective and can prevent unauthorized access, and it is determined that its authentication ability is qualified; on the contrary, if the Bluetooth module accepts and executes the control command sent by the unauthorized device, it indicates that its authentication mechanism has defects and cannot effectively prevent illegal access, and it is determined that its authentication ability is unqualified.
[0088] In the embodiments of the present disclosure, a framework of a test script can be built using a Bluetooth protocol stack library such as PyBluez, etc., to implement automated tests for Bluetooth broadcasting, pairing requests, verification code verification, and control operations, ensuring that the test results have practical reference value and are applicable to the security assessment requirements of various Bluetooth types such as classic Bluetooth and low-power Bluetooth.
[0089] In some embodiments, corresponding test processes are executed based on the information of each security test item, and the security status of the Bluetooth module is evaluated according to the test results, including: obtaining the data packet sent to the Bluetooth module based on the information of the transmitted data item; performing at least one security verification process on the data packet to obtain the verification result of each security verification; based on the verification result of each security verification, evaluating the transmission data protection ability of the Bluetooth module. Here, by capturing and performing security verification processes on the data packets sent to the Bluetooth module, the risk of data being tampered with, forged, or leaked during the transmission process can be effectively identified, thereby determining whether the Bluetooth module has sufficient data protection mechanisms.
[0090] Combined Figure 5 As shown, the embodiments of the present disclosure provide another Bluetooth security test method, and the Bluetooth security test method includes:
[0091] S501, the test device determines the Bluetooth type of the Bluetooth module to be tested.
[0092] S502, the test device loads the security test policy library corresponding to the Bluetooth type.
[0093] S503, The test device obtains the data packet sent to the Bluetooth module based on the transmitted data item information.
[0094] S504, The test device performs at least one security verification process on the data packet to obtain the verification result of each security verification.
[0095] S505, The test device evaluates the transmission data protection ability of the Bluetooth module based on the verification result of each security verification.
[0096] In some embodiments, the transmitted data item information includes a transmission data security test script and a judgment criterion for whether the transmission data protection ability is qualified. Here, the transmission data security test script can be in the form of a Python script or other executable scripts, which can be flexibly adapted to different Bluetooth types.
[0097] In some embodiments, the security verification is any one of the following: encryption security verification, identity security verification, protocol security verification, and data integrity verification. As shown in Table 1, each security verification can include multiple test contents. The transmitted data item information includes the test method and passing standard for each verification content, and these passing standards together constitute the judgment criterion for whether the transmission data protection ability is qualified.
[0098] Table 1
[0099]
[0100] In the embodiments of the present disclosure, the test device controls the Bluetooth module to establish a connection with the target device (such as a user terminal or a Bluetooth key) and perform normal communication based on the transmission data security test script. During this process, a Bluetooth packet capture tool (such as Bluefruit LE Sniffer or other compatible Bluetooth sniffing devices) is used to capture the data packets on the Bluetooth communication link in real time. The captured data packets include, but are not limited to, pairing negotiation information, identity authentication interaction, data transmission instructions, and data payloads, etc., to ensure that the entire communication process is covered. Then, at least one security verification process is performed on the captured data packets, such as encryption security verification, identity security verification, protocol security verification, and data integrity verification, so as to effectively identify the security defects in the transmission process. When the verification result of each security verification is successful, it is determined that the transmission data protection ability of the Bluetooth module is qualified; when the verification result of any one security verification is failed, it is determined that the transmission data protection ability of the Bluetooth module is unqualified.
[0101] In some embodiments, corresponding test processes are executed based on each item of security test information, and the security status of the Bluetooth module is evaluated according to the test results, including: generating an attack payload based on the protocol stack attack item information; sending the attack payload to the Bluetooth module and monitoring the running state of the Bluetooth module; and evaluating the anti-attack ability of the Bluetooth module based on the running state of the Bluetooth module. Here, the protocol stack attack can be a protocol stack POC (Proof of Concept) attack. By simulating the behavior of a real attacker and using predefined or constructed attack payloads to actively attack the Bluetooth module, security vulnerabilities existing in the Bluetooth protocol stack implementation can be effectively discovered.
[0102] Combined with Figure 6 As shown, the embodiments of the present disclosure provide another Bluetooth security test method. The Bluetooth security test method includes:
[0103] S601, the test device determines the Bluetooth type of the Bluetooth module to be tested.
[0104] S602, the test device loads the security test policy library corresponding to the Bluetooth type.
[0105] S603, the test device generates an attack payload based on the protocol stack attack item information.
[0106] S604, the test device sends the attack payload to the Bluetooth module and monitors the running state of the Bluetooth module.
[0107] S605, the test device evaluates the anti-attack ability of the Bluetooth module based on the running state of the Bluetooth module.
[0108] In the embodiments of the present disclosure, the authentication item information includes a protocol stack attack test script and a judgment criterion for whether the anti-attack ability is qualified. The protocol stack attack test script can be in the form of a Python script or other executable scripts, and can be flexibly adapted to different Bluetooth types.
[0109] The test device automatically constructs and generates various types of attack payloads according to the protocol stack attack test script. These attack payloads are scripted and encapsulated based on the publicly disclosed POC vulnerability exploitation methods, such as replay attacks, malformed packet injection, illegal protocol interactions, etc., to simulate the means that a real attacker may use. By scripting the POC, the automated execution and result controllability of the attack test are realized, and at the same time, a good extension interface is provided for newly added attack types in the future. The attack payload is sent to the Bluetooth module under test by the test device simulating the behavior of the attack end, and the running state of the Bluetooth module is continuously monitored during the test process, including but not limited to whether crashes, restarts, connection interruptions, resource exhaustion, etc. occur. When the running state of the Bluetooth module is normal, it is determined that the anti-attack ability of the Bluetooth module is qualified; when the running state of the Bluetooth module is abnormal, it is determined that the anti-attack ability of the Bluetooth module is unqualified.
[0110] In some embodiments, corresponding test processes are executed based on the information of each security test item, and the security status of the Bluetooth module is evaluated according to the test results, including: based on the vulnerability scanning item information, attempting to trigger potential vulnerabilities of the Bluetooth module; monitoring the operating status of the Bluetooth module and whether the device to which the Bluetooth module belongs is in an alarm state; and determining the vulnerability protection ability of the Bluetooth module based on the occurrence of the operating status of the Bluetooth module and the alarm state of the device to which the Bluetooth module belongs.
[0111] By constructing test cases using known vulnerability characteristics or common attack patterns and attempting to trigger potential vulnerabilities in the Bluetooth module, security risks existing in its protocol implementation, communication logic, or system integration can be actively discovered, avoiding omissions caused by relying solely on static analysis or manual experience judgment. During the vulnerability triggering process, the system monitors the operating status of the Bluetooth module in real time and whether its affiliated device (such as a vehicle terminal) generates security alarms. This dynamic monitoring method can truly reflect the response ability of the Bluetooth module when facing attacks and the overall security of the system.
[0112] Combined Figure 7 As shown, an embodiment of the present disclosure provides another Bluetooth security test method. The Bluetooth security test method includes:
[0113] S701, the test device determines the Bluetooth type of the Bluetooth module to be tested.
[0114] S702, the test device loads the security test policy library corresponding to the Bluetooth type.
[0115] S703, the test device attempts to trigger potential vulnerabilities of the Bluetooth module based on the vulnerability scanning item information.
[0116] S704, the test device monitors the operating status of the Bluetooth module and whether the device to which the Bluetooth module belongs is in an alarm state.
[0117] S705, the test device determines the vulnerability protection ability of the Bluetooth module based on the occurrence of the operating status of the Bluetooth module and the alarm state of the device to which the Bluetooth module belongs.
[0118] In some embodiments, the authentication item information includes a vulnerability scanning test script and a judgment criterion for whether the vulnerability protection ability is qualified. Here, the vulnerability scanning test script can be in the form of a Python script or other executable scripts, which can be flexibly adapted to different Bluetooth types.
[0119] Each Bluetooth type has its corresponding potential vulnerabilities. The vulnerability scope of classic Bluetooth includes: CVE-2017-1000250, CVE-2017-1000251, CVE-2020-12352, CVE-2020-12351, etc.
[0120] The vulnerability scope of Bluetooth Low Energy includes: CVE-2017-1000250, CVE-2017-1000251, CVE-2020-12352, CVE-2020-12351, CVE-2019-17519, CVE-2019-16336, CVE-2019-17517, CVE-2019-17518, CVE-2019-17520, CVE-2019-19195, CVE-2019-19196, CVE-2020-10061, CVE-2020-10069, CVE-2020-13594, CVE-2019-17061, CVE-2019-17060, CVE-2019-19192, CVE-2019-19193, CVE-2020-13595, CVE-2019-19194, CVE-2020-13593, etc.
[0121] The test device calls the vulnerability scanning test script corresponding to the current Bluetooth type, loads the vulnerability payloads related to known vulnerabilities, and simulates real attack behaviors to initiate tests on the Bluetooth module. For example, when testing the CVE-2020-12351 vulnerability, the test device constructs and sends data packets in a specific format to try to trigger the CVE-2020-12351 vulnerability of the Bluetooth module. After the vulnerability payload is sent, the test device continuously monitors the running status of the Bluetooth module, including but not limited to: whether it disconnects, whether it refuses service, whether it cannot respond to new connection requests, etc. At the same time, for the device to which the Bluetooth module belongs (such as a vehicle terminal), the test device also detects whether it shows an alarm state through methods such as image recognition, serial port logs, and indicator light status, such as abnormal phenomena such as crashing, restarting, and interface freezing, so as to assist in judging whether there are security issues.
[0122] When the operating state of the Bluetooth module is normal and the device to which the Bluetooth module belongs does not have an alarm state, it is determined that the vulnerability protection ability of the Bluetooth module is qualified; when the operating state of the Bluetooth module is abnormal or the device to which the Bluetooth module belongs has an alarm state, it is determined that the vulnerability protection ability of the Bluetooth module is unqualified. Specifically, if the Bluetooth module can still operate stably after receiving the attack payload, without abnormal behaviors, and the device to which it belongs has no security warnings, it is determined that the Bluetooth module has good protection ability against this vulnerability; if the Bluetooth module has abnormal behaviors such as crashing, restarting, or connection interruption, or the device to which it belongs has fault signals such as a black screen or flashing indicator lights, it indicates that there is a corresponding vulnerability in the module, and it is determined that the Bluetooth module's protection ability against this vulnerability is unqualified.
[0123] In the embodiments of the present disclosure, determining the Bluetooth type of the Bluetooth module to be tested includes: the test device sends customized detection data packets and captures the response characteristics of the Bluetooth module in real time (such as protocol version identifier, MTU negotiation parameters, encryption negotiation process). By comparing with the pre-set Bluetooth protocol fingerprint database (covering classic Bluetooth 4.2 to 5.3, low-power Bluetooth 5.0 to 5.4, dual-mode protocol stack, etc.), information such as the protocol version and functional attributes of the Bluetooth module is identified, and based on this information, the Bluetooth type of the Bluetooth module is determined. Further, the test device can determine the service function of the Bluetooth module according to the Bluetooth type of the Bluetooth module and the device type of the device to which the Bluetooth module belongs. Taking the device type of the device to which the Bluetooth module belongs as a vehicle terminal as an example, the service functions of the classic Bluetooth module are voice communication and audio playback, and the service functions of the low-power Bluetooth module are unlocking the vehicle door and starting the engine.
[0124] In the embodiments of the present disclosure, a basic security test policy library and a common security test policy library can be configured for each Bluetooth type. For example, a basic security test policy library and a common security test policy library are configured for the classic Bluetooth type, and a basic security test policy library and a common security test policy library are configured for the low-power Bluetooth type. The basic security test policy library of a Bluetooth type can configure the security test item information required for each device type to which the Bluetooth module of the Bluetooth type belongs; the basic security test policy library of a Bluetooth type can configure the security test item information specifically required for each device type to which the Bluetooth module of the Bluetooth type belongs. Among them, the security test item information specifically required for the device type to which the Bluetooth module of the Bluetooth type belongs is determined by the service function of the Bluetooth module and the device type.
[0125] In some embodiments, loading the security test policy library corresponding to the Bluetooth type includes: loading the basic security test policy library corresponding to the Bluetooth type; screening out the specifically required security test item information from the public security test policy library corresponding to the Bluetooth type based on the device type of the device to which the Bluetooth module belongs and the business function of the Bluetooth module; and adding the specifically required security test item information to the basic security test policy library to obtain the final required security test policy library for the Bluetooth type.
[0126] In some embodiments, loading the security test policy library corresponding to the Bluetooth type includes: determining the historical security risk trigger success rate, asset importance, and threat intelligence of the Bluetooth module; determining the comprehensive risk coefficient of the Bluetooth module based on the historical security risk trigger success rate, asset importance, and threat intelligence of the Bluetooth module; and adjusting the execution parameters of each security test item information in the security test policy library based on the comprehensive risk coefficient.
[0127] In the embodiments of the present disclosure, the historical security risk trigger success rate is the frequency of vulnerabilities exposed by the Bluetooth module in past security tests. The asset importance characterizes the criticality of the Bluetooth module and the device to which it belongs in the business or system. The threat intelligence refers to real-time attack trends, vulnerability exploitation methods, and hacker activity information related to the security of the Bluetooth module. The test device automatically retrieves the historical test records of each Bluetooth module, counts the failure rates under different attack scenarios, and obtains the historical security risk trigger success rate. The asset importance is dynamically assigned according to the combination of the device type and business function of the device to which the Bluetooth module belongs. For example, the asset importance of the Bluetooth module in a vehicle-mounted device is 1.2 times that of the Bluetooth module in a household appliance device. The threat intelligence system is connected to the authoritative databases in related fields in real time. When a new Bluetooth man-in-the-middle attack mode is detected as active, it automatically raises the priority of relevant test items. Based on the data in the above three dimensions, the analytic hierarchy process is used to calculate the comprehensive risk coefficient, and the Bluetooth modules are divided into three risk levels: low, medium, and high. According to the risk level of the Bluetooth module, the execution parameters of each security test item information in the security test policy library of the Bluetooth module are adjusted. The execution parameters may include the strictness of the judgment criteria, the number of executions of the test process, the number of test cases (such as attack payloads) used, etc.
[0128] Combined with Figure 8 As shown, the embodiments of the present disclosure provide a Bluetooth security test device 800. The Bluetooth security test device 800 can be used as the test device in the above embodiments. The Bluetooth security test device 800 includes a Bluetooth identification module 801, a policy loading module 802, and a security test module 803.
[0129] The Bluetooth identification module 801 is configured to: determine the Bluetooth type of the Bluetooth module to be tested, where the Bluetooth type includes classic Bluetooth and low-power Bluetooth.
[0130] The policy loading module 802 is configured to load a security test policy library corresponding to the Bluetooth type, where the security test policy library includes at least one piece of security test item information, and the security test item information includes a test script and a determination criterion.
[0131] The security test module 803 is configured to execute a corresponding test process based on each piece of security test item information and evaluate the security status of the Bluetooth module according to the test results.
[0132] The Bluetooth security test device 800 provided by the embodiments of the present disclosure pre-configures a security test policy library corresponding to different Bluetooth types. Each policy library is customized to design security test item information including test scripts and determination criteria according to the protocol implementation and security mechanism characteristics of the corresponding Bluetooth type. During the test, first, the type of the Bluetooth module to be tested is determined, and the matching security test policy library is automatically loaded, so as to accurately select the appropriate test content and automatically execute the test process. This method realizes the intelligence and automation of the test process, improves the compatibility of the test scheme with multiple Bluetooth types, can be applied to the security test requirements of different Bluetooth types, effectively avoids the limitation of the traditional scheme that only supports a single Bluetooth type, and provides a more comprehensive, efficient and reliable means for Bluetooth security evaluation.
[0133] In some embodiments, the security test item information is any one of the following: authentication item information, transmitted data item information, protocol stack attack item information, and vulnerability scanning item information.
[0134] In some embodiments, the security test module 803 is configured to control an unauthorized device to pair and interact with the Bluetooth module based on the authentication item information, and evaluate the authentication ability of the Bluetooth module based on the interaction result.
[0135] In some embodiments, the security test module 803 is configured to control the Bluetooth module to broadcast based on the authentication item information, and control an unauthorized device to send a pairing request to the Bluetooth module; in the case of unsuccessful pairing, control the unauthorized device to send a control instruction to the Bluetooth module; when the Bluetooth module refuses to execute the control instruction, determine that the authentication ability of the Bluetooth module is qualified; when the Bluetooth module accepts and executes the control instruction, determine that the authentication ability of the Bluetooth module is unqualified.
[0136] In some embodiments, the security test module 803 is configured to obtain data packets sent to the Bluetooth module based on the transmitted data item information; perform at least one security verification process on the data packets to obtain the verification results of each security verification; and evaluate the transmitted data protection ability of the Bluetooth module based on the verification results of each security verification.
[0137] In some embodiments, the security verification is any one of the following: encryption security verification, identity security verification, protocol security verification, and data integrity verification.
[0138] In some embodiments, the security test module 803 is configured to: determine that the transmission data protection capability of the Bluetooth module is qualified when the verification result of each security verification is successful; and determine that the transmission data protection capability of the Bluetooth module is unqualified when the verification result of any security verification is failed.
[0139] In some embodiments, the security test module 803 is configured to: generate an attack payload based on the protocol stack attack project information; send the attack payload to the Bluetooth module and monitor the running state of the Bluetooth module; and evaluate the anti-attack capability of the Bluetooth module based on the running state of the Bluetooth module.
[0140] In some embodiments, the security test module 803 is configured to: determine that the anti-attack capability of the Bluetooth module is qualified when the running state of the Bluetooth module is normal; and determine that the anti-attack capability of the Bluetooth module is unqualified when the running state of the Bluetooth module is abnormal.
[0141] In some embodiments, the security test module 803 is configured to: attempt to trigger potential vulnerabilities of the Bluetooth module based on the vulnerability scanning project information; monitor the running state of the Bluetooth module and whether the device to which the Bluetooth module belongs appears in an alarm state; and determine the vulnerability protection capability of the Bluetooth module based on the running state of the Bluetooth module and the occurrence of the alarm state of the device to which the Bluetooth module belongs.
[0142] In some embodiments, the security test module 803 is configured to: determine that the vulnerability protection capability of the Bluetooth module is qualified when the running state of the Bluetooth module is normal and the device to which the Bluetooth module belongs does not appear in an alarm state; and determine that the vulnerability protection capability of the Bluetooth module is unqualified when the running state of the Bluetooth module is abnormal or the device to which the Bluetooth module belongs appears in an alarm state.
[0143] Combined Figure 9 As shown in the figure, an electronic device 900 is provided in an embodiment of the present disclosure. The sub-device 900 may be used as the test device in the above embodiments. The electronic device 900 includes a processor 901 and a memory 902. Optionally, the air outlet temperature prediction device 900 may further include a communication interface 903 and a bus 904. Among them, the processor 901, the communication interface 903, and the memory 902 may complete communication with each other through the bus 904. The communication interface 903 may be used for information transmission. The processor 901 may call the logical instructions in the memory 902 to execute the Bluetooth security test method of the above embodiments.
[0144] In addition, when the logical instructions in the above-mentioned memory 902 are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium.
[0145] As a computer-readable storage medium, the memory 902 can be used to store software programs and computer-executable programs, such as the program instructions / modules corresponding to the methods in the embodiments of the present disclosure. The processor 901 executes functional applications and data processing by running the program instructions / modules stored in the memory 902, that is, implements the Bluetooth security testing method in the above embodiments.
[0146] The memory 902 may include a program storage area and a data storage area. Among them, the program storage area can store an operating system and application programs required for at least one function; the data storage area can store data created according to the use of the terminal device, etc. In addition, the memory 902 may include high-speed random access memory and may also include non-volatile memory.
[0147] The embodiments of the present disclosure provide a computer-readable storage medium storing computer-executable instructions, and the computer-executable instructions are set to execute the above-mentioned Bluetooth security testing method.
[0148] The technical solution of the embodiments of the present disclosure can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes one or more instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in the embodiments of the present disclosure. The foregoing storage medium may be a non-transitory storage medium, for example: a USB flash drive, a mobile hard disk, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), a magnetic disk, or an optical disc, etc., which are various media that can store program codes.
[0149] The above description and the accompanying drawings fully illustrate the embodiments of the present disclosure, enabling those skilled in the art to practice them. Other embodiments may include structural, logical, electrical, process, and other changes. The embodiments merely represent possible variations. Unless explicitly required, individual components and functions are optional, and the order of operations may vary. Parts and features of some embodiments may be included in or replace parts and features of other embodiments. Moreover, the terms used in this application are only for describing the embodiments and do not limit the claims. As used in the description of the embodiments and the claims, unless the context clearly indicates otherwise, the singular forms "a", "an", and "the" are intended to also include the plural forms. Similarly, as used in this application, the term "and / or" refers to any and all possible combinations including one or more of the associated listed items. Additionally, when used in this application, the term "comprise" and its variants "comprises" and / or "comprising" etc. mean the presence of the stated features, wholes, steps, operations, elements, and / or components, but do not exclude the presence or addition of one or more other features, wholes, steps, operations, elements, components, and / or groupings of these. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, or apparatus including the element. In this article, each embodiment may focus on the differences from other embodiments, and the same or similar parts among the embodiments may be referred to each other. For the methods, products, etc. disclosed in the embodiments, if they correspond to the method part disclosed in the embodiments, the relevant parts may refer to the description of the method part.
[0150] Those skilled in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner may depend on the specific application and design constraints of the technical solution. The technician may use different methods for each specific application to implement the described functions, but such implementation should not be considered to have reached the scope of the embodiments of the present disclosure. The technician can clearly understand that for the convenience and brevity of description, the specific working processes of the systems, devices, and units described above can refer to the corresponding processes in the foregoing method embodiments, and will not be elaborated herein.
[0151] In the embodiments disclosed in this article, the disclosed methods, products (including but not limited to devices, equipment, etc.) can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units can be merely a logical function division. In actual implementation, there can be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Additionally, the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces. The indirect coupling or communication connection of devices or units can be in electrical, mechanical, or other forms. The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to implement this embodiment. Additionally, in the embodiments of the present disclosure, the various functional units can be integrated in a processing unit, or each unit can exist physically separately, or two or more units can be integrated in one unit.
[0152] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to embodiments of the present disclosure. In this regard, each block in the flowchart or block diagram can represent a module, a program segment, or a part of code that contains one or more executable instructions for implementing the specified logical function. In some alternative implementations, the functions marked in the blocks can occur in a different order than marked in the accompanying drawings. For example, two consecutive blocks can actually be executed substantially in parallel, and they can sometimes be executed in the reverse order, depending on the functions involved. In the descriptions corresponding to the flowcharts and block diagrams in the accompanying drawings, the operations or steps corresponding to different blocks can also occur in a different order than disclosed in the description. Sometimes, there is no specific order between different operations or steps. For example, two consecutive operations or steps can actually be executed substantially in parallel, and they can sometimes be executed in the reverse order, depending on the functions involved. Each block in the block diagram and / or flowchart, as well as combinations of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or actions, or can be implemented by a combination of dedicated hardware and computer instructions.
Claims
1. A Bluetooth security testing method, characterized in that, Including: Determine the Bluetooth type of the Bluetooth module to be tested, where the Bluetooth type includes classic Bluetooth and low-power Bluetooth; Load the security test policy library corresponding to the Bluetooth type, where the security test policy library includes at least one item of security test project information, and the security test project information includes a test script and a judgment criterion; Execute the corresponding test process based on each item of security test project information, and evaluate the security status of the Bluetooth module according to the test results.
2. The Bluetooth security testing method according to claim 1, wherein The security test project information is any one of the following: authentication project information, transmitted data project information, protocol stack attack project information, and vulnerability scanning project information.
3. The Bluetooth security testing method according to claim 2, wherein Execute the corresponding test process based on each item of security test project information, and evaluate the security status of the Bluetooth module according to the test results, including: controlling an unauthorized device to pair and interact with the Bluetooth module based on the authentication project information, and evaluating the authentication ability of the Bluetooth module based on the interaction result.
4. The Bluetooth security testing method according to claim 3, wherein Controlling an unauthorized device to pair and interact with the Bluetooth module based on the authentication project information, and evaluating the authentication ability of the Bluetooth module based on the interaction result, including: Controlling the Bluetooth module to broadcast based on the authentication project information, and controlling an unauthorized device to send a pairing request to the Bluetooth module; When the pairing is not successful, controlling the unauthorized device to send a control instruction to the Bluetooth module; When the Bluetooth module refuses to execute the control instruction, determine that the authentication ability of the Bluetooth module is qualified; When the Bluetooth module accepts and executes the control instruction, determine that the authentication ability of the Bluetooth module is unqualified.
5. The Bluetooth security testing method according to claim 2, wherein Execute the corresponding test process based on each item of security test project information, and evaluate the security status of the Bluetooth module according to the test results, including: Obtain the data packet sent to the Bluetooth module based on the transmitted data project information; Perform at least one security verification process on the data packet to obtain the verification result of each security verification; Evaluate the transmitted data protection ability of the Bluetooth module based on the verification result of each security verification.
6. The Bluetooth security testing method according to claim 5, characterized in that, The security verification is any one of the following: encryption security verification, identity security verification, protocol security verification, and data integrity verification.
7. The Bluetooth security testing method according to claim 5, characterized in that, Evaluate the transmitted data protection ability of the Bluetooth module based on the verification result of each security verification, including: When the verification result of each security verification is successful, determine that the transmitted data protection ability of the Bluetooth module is qualified; and when the verification result of any one security verification is failed, determine that the transmitted data protection ability of the Bluetooth module is unqualified.
8. The Bluetooth security testing method according to claim 2, wherein Execute the corresponding test process based on each item of security test project information, and evaluate the security status of the Bluetooth module according to the test results, including: Generate an attack payload based on the protocol stack attack project information; Send the attack payload to the Bluetooth module and monitor the running status of the Bluetooth module; Evaluate the anti-attack ability of the Bluetooth module based on the running status of the Bluetooth module.
9. The Bluetooth security testing method according to claim 8, wherein Evaluate the anti-attack ability of the Bluetooth module based on the running status of the Bluetooth module, including: When the running status of the Bluetooth module is normal, determine that the anti-attack ability of the Bluetooth module is qualified; When the running status of the Bluetooth module is abnormal, determine that the anti-attack ability of the Bluetooth module is unqualified.
10. The Bluetooth security testing method according to claim 2, wherein Execute the corresponding test process based on each item of security test project information, and evaluate the security status of the Bluetooth module according to the test results, including: Based on the vulnerability scanning project information, attempt to trigger potential vulnerabilities in the Bluetooth module; Monitor the running status of the Bluetooth module and whether the device to which the Bluetooth module belongs appears in an alarm state; Determine the vulnerability protection ability of the Bluetooth module based on the running status of the Bluetooth module and the occurrence of the alarm state of the device to which the Bluetooth module belongs.
11. The Bluetooth security testing method according to claim 10, wherein Determine the vulnerability protection ability of the Bluetooth module based on the running status of the Bluetooth module and the occurrence of the alarm state of the device to which the Bluetooth module belongs, including: When the running status of the Bluetooth module is normal and the device to which the Bluetooth module belongs does not appear in an alarm state, determine that the vulnerability protection ability of the Bluetooth module is qualified; When the running status of the Bluetooth module is abnormal or the device to which the Bluetooth module belongs appears in an alarm state, determine that the vulnerability protection ability of the Bluetooth module is unqualified.
12. A Bluetooth security testing device, characterized in that, Including: A Bluetooth identification module, configured to: determine the Bluetooth type of the Bluetooth module to be tested, where the Bluetooth type includes classic Bluetooth and low-power Bluetooth; A policy loading module, configured to: load the security test policy library corresponding to the Bluetooth type, where the security test policy library includes at least one item of security test project information, and the security test project information includes test scripts and judgment criteria; A security test module, configured to: execute the corresponding test process based on each item of security test project information and evaluate the security status of the Bluetooth module according to the test results.
13. An electronic device, comprising a processor and a memory storing program instructions, characterized in that, The processor is configured to execute the Bluetooth security test method according to any one of claims 1 to 11 when running program instructions.
14. A storage medium, characterized in that, Computer program instructions are stored in the storage medium, and when the computer program instructions are run by the processor, the Bluetooth security test method according to any one of claims 1 to 11 is executed.