Vulnerability detection method and device, electronic equipment and storage medium
The visualized security testing aggregation platform automates vulnerability detection by executing multiple scripts across different branches, improving efficiency and reducing costs by eliminating manual operations.
Patent Information
- Application Number
- CN202510396422.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-31
- Publication Date
- 2025-07-15
AI Technical Summary
Existing vulnerability detection methods are inefficient, long cycles and high labor costs to run test items through command line, making it difficult to meet the needs of multiple security tests.
Using a visual security test aggregation platform, multiple security test item scripts are deployed, and different test item scripts are configured for different security branches. Through a graphical interface, the target security test item script is automatically called for security testing, obtain business data and vulnerability detection, determine the vulnerability type, level and location, and mark and display it.
It improves the efficiency of security testing, shortens the detection cycle, reduces labor costs, provides intuitive display of vulnerability detection results, and improves user experience and vulnerability repair efficiency.
Smart Images

Figure CN120316779A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of computer security technologies, and in particular, to a vulnerability detection method, apparatus, electronic device, and storage medium. Background Art
[0002] With the continuous development of computer technologies, computer security has also become a key concern. Vulnerability detection is an important part of the field of computer security. It aims to discover exploitable security vulnerabilities in computer systems and can detect and repair these vulnerabilities in a timely manner.
[0003] The existing method for vulnerability detection mainly runs test item scripts through the command line. That is, testers find the test item script files to be executed through the command line interface provided by the computer operating system, and then manually run a test item script file to perform a security test corresponding to the running test item script, and thus perform vulnerability detection.
[0004] However, when multiple security tests are required for vulnerability detection, the method of running test item scripts through the command line has problems such as low detection efficiency, long test cycle, and high labor cost. Summary of the Invention
[0005] To solve the above technical problems, the present disclosure provides a vulnerability detection method, apparatus, electronic device, and storage medium.
[0006] The first aspect of the embodiments of the present disclosure provides a vulnerability detection method, which is applied to a visual security test aggregation platform. Multiple security test item scripts are deployed in the visual security test aggregation platform, and different security test item scripts are configured for different security branches, including:
[0007] In response to a target operation of a user, determine a to-be-detected object corresponding to the target operation, obtain service data corresponding to the to-be-detected object, and determine at least one target security test item script for performing vulnerability detection on the to-be-detected object, where the target operation is an operation for performing vulnerability detection;
[0008] Invoke at least one target security test item script, so that the at least one target security test item script performs a security test on the to-be-detected object based on the service data to obtain a security test result;
[0009] Based on the security test result, determine whether there is a vulnerability in the to-be-detected object; when it is determined that there is a vulnerability in the to-be-detected object, determine the vulnerability type, vulnerability level, and vulnerability location corresponding to the vulnerability in the to-be-detected object, perform vulnerability annotation, and display the vulnerability annotation result.
[0010] In some embodiments of the present disclosure, obtaining service data corresponding to an object to be detected includes:
[0011] When the security branch corresponding to the object to be detected is the application security branch, the object to be detected is the application to be detected, and the application to be detected is monitored based on the proxy plugin deployed in the application to be detected, and the service data corresponding to the application to be detected is captured;
[0012] When the security branch corresponding to the object to be detected is the network security branch or the data security branch, the object to be detected is the network to be detected or the database to be detected, and a target scanner plugin corresponding to the network to be detected or the database to be detected is determined;
[0013] The network to be detected or the database to be detected is scanned based on the target scanner plugin to obtain service data corresponding to the network to be detected or the database to be detected.
[0014] In some embodiments of the present disclosure, before monitoring the application to be detected based on the proxy plugin deployed in the application to be detected and capturing the service data corresponding to the application to be detected, the vulnerability detection method further includes:
[0015] Determining whether to update the proxy plugin;
[0016] When it is determined that the proxy plugin needs to be updated, perform the update operation of the proxy plugin, monitor the application to be detected based on the updated proxy plugin, and obtain service data.
[0017] In some embodiments of the present disclosure, after obtaining the service data corresponding to the object to be detected, the vulnerability detection method further includes:
[0018] Perform target processing on the service data to determine whether there is abnormal field data in the service data;
[0019] Call at least one target security test item script so that at least one target security test item script performs a security test on the object to be detected based on the service data to obtain a security test result, including:
[0020] When it is determined that there is abnormal field data in the service data, call at least one target security test item script so that at least one target security test item script performs a security test on the object to be detected based on the abnormal field data to obtain a security test result.
[0021] In some embodiments of the present disclosure, determining whether there is a vulnerability in the object to be detected based on the security test result includes:
[0022] Match the security test result with the vulnerability information in the preset feature library and the preset vulnerability library to obtain a matching result;
[0023] Determine whether there is a vulnerability based on the matching result;
[0024] The preset feature library includes the feature information of known vulnerabilities, and the preset vulnerability library includes the vulnerability description information of known vulnerabilities; the security test results are matched with the vulnerability information in the preset feature library and the preset vulnerability library to obtain a matching result, including:
[0025] Extract the target feature information corresponding to the security test result;
[0026] Perform feature matching on the target feature information with the feature information of known vulnerabilities in the preset feature library and the vulnerability description information of known vulnerabilities in the preset vulnerability library respectively to obtain a matching result.
[0027] In some embodiments of the present disclosure, multiple security test item scripts are deployed to the visual security test aggregation platform after being defined based on the target format file. Each security test item script includes request information, matching conditions, target vulnerability description information, and request execution logic corresponding to the security test item script.
[0028] In some embodiments of the present disclosure, when it is determined that there is a vulnerability in the object to be detected, after determining the vulnerability type, vulnerability level, and vulnerability location corresponding to the vulnerability in the object to be detected and performing vulnerability annotation, the vulnerability detection method further includes:
[0029] Obtain the context information of the vulnerability corresponding to the object to be detected;
[0030] Perform validity detection on the vulnerability based on the context information.
[0031] A second aspect of the embodiments of the present disclosure provides a vulnerability detection device, which is applied to a visual security test aggregation platform. Multiple security test item scripts are deployed in the visual security test aggregation platform, and different security test item scripts are configured for different security branches, including:
[0032] An information determination module, configured to determine an object to be detected corresponding to a target operation in response to a target operation of a user, obtain service data corresponding to the object to be detected, and determine at least one target security test item script for performing vulnerability detection on the object to be detected. The target operation is an operation for performing vulnerability detection;
[0033] A security test module, configured to call at least one target security test item script, so that at least one target security test item script performs a security test on the object to be detected based on the service data to obtain a security test result;
[0034] A vulnerability detection annotation module is used to determine whether there is a vulnerability in the object to be detected based on the security test results; when it is determined that there is a vulnerability in the object to be detected, the vulnerability type, vulnerability level, and vulnerability location corresponding to the vulnerability in the object to be detected are determined, and vulnerability annotation is performed, and the vulnerability annotation result is displayed.
[0035] The third aspect of the embodiments of the present disclosure provides an electronic device, including:
[0036] A processor;
[0037] A memory for storing executable instructions;
[0038] Wherein, the processor is configured to read the executable instructions from the memory and execute the executable instructions to implement the vulnerability detection method provided in the first aspect above.
[0039] The fourth aspect of the embodiments of the present disclosure provides a computer-readable storage medium storing a computer program, which, when executed by a processor, causes the processor to implement the vulnerability detection method provided in the first aspect above.
[0040] The fifth aspect of the embodiments of the present disclosure provides a computer program product including a computer program or instruction, which, when executed by a processor, implements the vulnerability detection method as described in the first aspect above.
[0041] The sixth aspect of the embodiments of the present disclosure provides a vehicle, which includes the electronic device provided in the third aspect.
[0042] The technical solutions provided by the embodiments of the present disclosure have the following advantages compared with the prior art:
[0043] The vulnerability detection method, apparatus, electronic device, and storage medium provided by the embodiments of the present disclosure are applied to a visual security testing aggregation platform. Multiple security testing item scripts are deployed in the visual security testing aggregation platform, and different security testing item scripts are configured for different security branches. It can respond to the user's target operation and determine the object to be detected corresponding to the target operation. After determining the object to be detected, obtain the business data corresponding to the object to be detected, and determine at least one target security testing item script for performing vulnerability detection on the object to be detected, where the target operation is an operation for performing vulnerability detection. After determining at least one target security testing item script, call at least one target security testing item script, so that at least one target security testing item script performs security testing on the object to be detected based on the business data to obtain a security testing result. Furthermore, based on the security testing result, determine whether there is a vulnerability in the object to be detected. When it is determined that there is a vulnerability in the object to be detected, determine the vulnerability type, vulnerability level, and vulnerability location corresponding to the vulnerability in the object to be detected, and perform vulnerability annotation, and display the vulnerability annotation result. Thus, by deploying multiple security testing item scripts on the visual security testing aggregation platform according to different security branches, when it is determined that security testing needs to be performed on the object to be detected, at least one target security testing item script corresponding to the object to be detected can be called to perform security testing simultaneously, improving the efficiency of security testing, thereby improving the efficiency of vulnerability detection, shortening the detection cycle, and avoiding manually operating the security testing item script for security testing, reducing the labor cost. Description of the Drawings
[0044] The drawings here are incorporated into the specification and form a part of this specification, showing embodiments consistent with the present disclosure, and are used together with the specification to explain the principles of the present disclosure.
[0045] To more clearly illustrate the technical solutions in the embodiments of the present disclosure or in the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, for those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0046] Figure 1 is a flowchart of a vulnerability detection method provided by an embodiment of the present disclosure;
[0047] Figure 2 is a schematic structural diagram of a visual security testing aggregation platform provided by an embodiment of the present disclosure;
[0048] Figure 3 is a flowchart of another vulnerability detection method provided by an embodiment of the present disclosure;
[0049] Figure 4It is a schematic structural diagram of a vulnerability detection device provided by an embodiment of the present disclosure;
[0050] Figure 5 It is a schematic structural diagram of an electronic device provided by an embodiment of the present disclosure. Detailed implementation manners
[0051] In order to be able to more clearly understand the above-mentioned objects, features, and advantages of the present disclosure, the solutions of the present disclosure will be further described below. It should be noted that, without conflict, the embodiments of the present disclosure and the features in the embodiments may be combined with each other.
[0052] In the following description, many specific details are set forth in order to fully understand the present disclosure, but the present disclosure may also be implemented in other ways different from those described herein; obviously, the embodiments in the specification are only a part of the embodiments of the present disclosure, rather than all the embodiments.
[0053] It should be understood that the various steps recorded in the method embodiments of the present disclosure may be executed in different orders and / or executed in parallel. In addition, the method embodiments may include additional steps and / or omit the steps shown. The scope of the present disclosure is not limited in this regard.
[0054] It should be noted that, in this article, relational terms such as "first" and "second" are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variant thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or also includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "including a..." does not exclude the existence of another identical element in the process, method, article or device including the said element.
[0055] It should be noted that the modifications of "one" and "multiple" mentioned in the present disclosure are illustrative rather than restrictive. Those skilled in the art should understand that, unless otherwise clearly specified in the context, it should be understood as "one or more".
[0056] Under normal circumstances, the existing vulnerability detection mainly adopts the method of running test item scripts through the command line. That is, the tester finds the test item script file to be executed through the command line interface provided by the computer operating system, and then manually runs a test item script file to perform security tests corresponding to the running test item script, and then conducts vulnerability detection. However, when multiple security tests need to be performed for vulnerability detection, the method of running test item scripts through the command line has problems such as low detection efficiency, long test cycle, and high labor cost. To address this issue, the embodiments of the present disclosure provide a vulnerability detection method, which will be introduced below in combination with specific embodiments.
[0057] Figure 1 is a flowchart of a vulnerability detection method provided by an embodiment of the present disclosure. This method can be executed by a vulnerability detection device, which can be implemented in software and / or hardware, and can be configured in an electronic device, such as a server or a terminal. Specifically, the terminal includes an in-vehicle terminal, a mobile phone, a computer, a tablet computer, etc. In addition, this method can be applied to Figure 2 the visualized security test aggregation platform shown in the figure. It can be understood that the vulnerability detection method provided by the embodiments of the present disclosure can also be applied in other scenarios or aggregation platforms.
[0058] As Figure 2 shown in the figure, the visualized security test aggregation platform includes a display layer, an application layer, a core layer, and a data layer.
[0059] Among them, the display layer is mainly used to display information related to vulnerabilities for the convenience of users to view. Specifically, the display layer includes the display of security test information, the display of vulnerability statistics information, the display of security reports, and the display of task management related to vulnerabilities. This facilitates users to better view and analyze vulnerability information.
[0060] The security test item management is mainly used to manage multiple security test item scripts deployed in the visualized security test aggregation platform, specifically including the addition, deletion, change, etc. of security test item scripts.
[0061] The application layer is mainly used to provide rich data services and application services. Specifically, it includes application services such as sensitive information identification, hard coding detection, vulnerability detection, component vulnerability analysis, and vulnerability distribution display.
[0062] The core layer is mainly used to connect and integrate various key functional areas or modules to ensure the smooth operation and high efficiency of the entire system. Specifically, it can include the agent, i.e., the proxy plugin framework, Open JDK, i.e., the toolkit for building the platform at the bottom layer of the platform, Spring Boot, i.e., the platform technology framework, and Engineapi, i.e., the interface for docking with the data layer.
[0063] The data layer is mainly used for data storage and management. Specifically, it includes data storage, DB, i.e., the database, files, etc., for storing and managing files in different formats.
[0064] As Figure 1 shown, the vulnerability detection method provided in this embodiment is applied to the visualization security test aggregation platform. Multiple security test item scripts are deployed in the visualization security test aggregation platform, and different security test item scripts are configured for different security branches. This vulnerability detection method can be applied to in-vehicle systems to detect vulnerabilities in in-vehicle network systems, etc. Specifically, the vulnerability detection method includes the following steps.
[0065] S110. In response to the user's target operation, determine the object to be detected corresponding to the target operation, obtain the business data corresponding to the object to be detected, and determine at least one target security test item script for performing vulnerability detection on the object to be detected. The target operation is an operation for performing vulnerability detection.
[0066] In the embodiments of the present disclosure, the target operation may include the user's click operation on the vulnerability detection button; it may also include the user's input operation for vulnerability detection, such as inputting identification information, domain names, etc. of the object to be detected; it may also include the user's selection operation on the object to be detected, etc.
[0067] In the embodiments of the present disclosure, at least one security test item script can be graphically displayed to clearly present the overall architecture and logical relationship of the security test items, facilitating users such as testers to view the security test item scripts, ensuring the convenience when selecting security test item scripts, and thus ensuring comprehensive and non-missing testing.
[0068] In the embodiments of the present disclosure, the security branches of the object to be detected may include application security branches, network security branches, data security branches, etc. For different security branches, the corresponding business data is also different. Exemplarily, for the application security branch, the business data may include interface data packets (such as http headers, interface configuration parameters, cookies, JSON / XML data, etc.), data streams, key function call data, etc.; for the network security branch, the business data may include data related to network maintenance and network data transmission; for the data security branch, the business data may include the data stored in the database.
[0069] Specifically, after the visual security testing aggregation platform determines the object to be detected corresponding to the target operation, it determines the target security branch corresponding to the object to be detected, and obtains the business data corresponding to the object to be detected based on the business data acquisition method corresponding to the target security branch.
[0070] Further, after the visual security testing aggregation platform obtains the business data corresponding to the object to be detected, it determines at least one target security test item script for performing vulnerability detection on the object to be detected.
[0071] In some embodiments of the present disclosure, the user's target operation includes an operation of selecting a security test item script. The visual security testing aggregation platform can, after obtaining the business data corresponding to the object to be detected, parse the user's target operation, determine the security test item script selected by the user, and determine it as at least one target security test item script for performing vulnerability detection on the object to be detected.
[0072] In some other embodiments of the present disclosure, the user's target operation does not include an operation of selecting a security test item script. The visual security testing aggregation platform can, after obtaining the business data corresponding to the object to be detected, determine at least one security test item script that has a corresponding relationship with the security branch corresponding to the object to be detected based on a preset security policy, and determine it as at least one target security test item script for performing vulnerability detection on the object to be detected.
[0073] S120. Invoke at least one target security test item script so that at least one target security test item script performs a security test on the object to be detected based on the business data to obtain a security test result.
[0074] Specifically, after the visual security testing aggregation platform obtains the business data and determines at least one target security test item script for performing vulnerability detection on the object to be detected, it schedules at least one target security test item script based on a preset intelligent scheduling and resource allocation mechanism, and invokes at least one target security test item script so that at least one target security test item script performs a security test on the object to be detected based on the business data to obtain a security test result.
[0075] S130. Determine whether there are vulnerabilities in the object to be detected based on the security test result; when it is determined that there are vulnerabilities in the object to be detected, determine the vulnerability type, vulnerability level, and vulnerability location corresponding to the vulnerabilities in the object to be detected, perform vulnerability annotation, and display the vulnerability annotation result.
[0076] In the embodiments of the present disclosure, the vulnerability level is determined based on the potential impact and exploitation difficulty of the vulnerability, and is divided into high-risk vulnerabilities, medium-risk vulnerabilities, low-risk vulnerabilities, and prompt information.
[0077] The classification of vulnerability types is determined based on the universality, potential harm, and exploitation difficulty of vulnerabilities, combined with industry data and expert judgment, and stored in the database of the Visual Security Testing Aggregation Platform.
[0078] Among them, high-risk vulnerabilities usually refer to serious problems that can directly lead to the complete control of the system or data leakage, such as remote code execution or SQL injection. The corresponding vulnerability types can include injection types (such as EL expression, HQL, JNI, LDAP, NoSQL, SMTP, Xpath, reflection, command execution), server-side request forgery, insecure XML Decode, path traversal, insecure JSON deserialization, etc.
[0079] Medium-risk vulnerabilities usually refer to vulnerabilities that may affect system functions or data integrity, but have a higher exploitation difficulty or a limited impact range. The corresponding vulnerability types can include reflective XSS, XXE, etc.
[0080] Low-risk vulnerabilities usually refer to those involving information leakage or configuration issues with relatively minor impacts. The corresponding vulnerability types can include cookies not set to Secure, Header injection, weak random number algorithms, weak hash algorithms, weak encryption algorithms, insecure readline, insecure redirects, insecure forwards, clickjacking, etc.
[0081] Hint information usually refers to vulnerabilities with relatively minor impacts on the system. The corresponding vulnerability types can include the lack of content-security-policy response headers, the lack of X-content-Type-Options response headers, the lack of X-XSS-Protection response headers, incorrect strict-Transport-security configurations, etc.
[0082] Specifically, after obtaining the security test results, the Visual Security Testing Aggregation Platform determines whether there are vulnerabilities in the object to be detected by combining the vulnerability information in the preset feature library and the preset vulnerability library. When it is determined that there are vulnerabilities in the object to be detected, it determines the corresponding vulnerability type and location of the vulnerabilities in the object to be detected, scores the vulnerabilities based on a preset vulnerability scoring model, determines the vulnerability level based on the scoring results, and then performs vulnerability annotation based on the vulnerability type, location, and level, and at the same time displays the vulnerability annotation results. Among them, the vulnerability annotation results include the vulnerability location, the type of the vulnerability, the vulnerability level, the associated projects of the vulnerability, the vulnerability detection time, etc. Exemplarily, the vulnerability flag result is that there is insecure JSON deserialization in the POST of / demo / yaml_post_e, the vulnerability level is high risk, the detection time is XX:XX on XX / XX / XXXX, and the associated projects are also displayed.
[0083] In the embodiments of the present disclosure, it is possible to determine a to-be-detected object corresponding to a target operation in response to the target operation of the user. After determining the to-be-detected object, obtain the service data corresponding to the to-be-detected object, and determine at least one target security test item script for performing vulnerability detection on the to-be-detected object, where the target operation is an operation for performing vulnerability detection. After determining at least one target security test item script, call at least one target security test item script, so that at least one target security test item script performs a security test on the to-be-detected object based on the service data to obtain a security test result. Furthermore, determine whether there is a vulnerability in the to-be-detected object based on the security test result. When it is determined that there is a vulnerability in the to-be-detected object, determine the vulnerability type, vulnerability level, and vulnerability location corresponding to the vulnerability in the to-be-detected object, and perform vulnerability annotation, and display the vulnerability annotation result. Thus, by deploying multiple security test item scripts on the visual security test aggregation platform according to different security branches, when it is determined that a security test needs to be performed on the to-be-detected object, at least one target security test item script corresponding to the to-be-detected object is called to perform the security test simultaneously, which improves the efficiency of the security test, thereby improving the efficiency of vulnerability detection, shortening the detection cycle, and avoiding manually operating the security test item script for security testing, reducing the labor cost.
[0084] Based on the above embodiments of the present disclosure, by annotating the vulnerability and displaying the vulnerability annotation result, the user can more intuitively see the vulnerability detection result, which is convenient for the user to view and analyze the vulnerability detection result, further improving the user experience.
[0085] In the embodiments of the present disclosure, the visual security test aggregation platform can, after determining the to-be-detected object, adopt different data acquisition methods to obtain service data according to different security branches corresponding to the to-be-detected object. Specifically, obtaining the service data corresponding to the to-be-detected object may include: when the security branch corresponding to the to-be-detected object is the application security branch, the to-be-detected object is the to-be-detected application program, and monitor the to-be-detected application program based on the proxy plugin deployed in the to-be-detected application program to capture the service data corresponding to the to-be-detected application program; when the security branch corresponding to the to-be-detected object is the network security branch or the data security branch, the to-be-detected object is the to-be-detected network or the to-be-detected database, determine the target scanner plugin corresponding to the to-be-detected network or the to-be-detected database; scan the to-be-detected network or the to-be-detected database based on the target scanner plugin to obtain the service data corresponding to the to-be-detected network or the to-be-detected database.
[0086] In an embodiment of the present disclosure, the proxy plugin adopts a multi - protocol support architecture, which can collect the business data of an application in real - time, such as application programming interface data, communication data of network interfaces such as CAN bus and Ethernet, etc., and send the collected business data to the visualization security test aggregation platform. The proxy plugin is deployed into the application, and through the hook mechanism, monitoring points are inserted at the web container level for data monitoring and collection.
[0087] The proxy plugin can also be used to parse the business data after collecting the business data of the application, such as parsing the restful API call path, HTTP status code, session identifier, etc.
[0088] In some embodiments of the present disclosure, when the security branch corresponding to the object to be detected is the application security branch, the object to be detected is the application to be detected. The application to be detected is started, and the application to be detected is monitored based on the proxy plugin deployed in the application to be detected, and the business data corresponding to the application to be detected is captured. The proxy plugin sends the captured business data to the visualization security test aggregation platform, and then the visualization security test aggregation platform obtains the business data corresponding to the object to be detected.
[0089] In some other embodiments of the present disclosure, when the security branch corresponding to the object to be detected is the network security branch or the data security branch, different types of scanner plugins are deployed for different objects to be detected. It is determined whether to perform a security scan. If so, the target scanner plugin corresponding to the object to be detected is started, and the network to be detected or the database to be detected is scanned based on the target scanner plugin to obtain the business data corresponding to the network to be detected or the database to be detected, and the business data is stored in the corresponding asset library.
[0090] In the embodiments of the present disclosure, different business data acquisition methods can be adopted for objects to be detected with different security branches. The application is monitored by deploying a proxy plugin in the application to obtain the business data of the application to be detected; the network to be detected or the database to be detected is scanned by means of a scanner plugin to obtain the business data corresponding to the network to be detected or the database to be detected. Thus, the flexibility of business data acquisition is improved.
[0091] In the embodiments of the present disclosure, in order to ensure the normal operation of the proxy plugin deployed in the application, it is necessary to check the proxy plugin before using it to collect data and determine whether settings need to be made. Specifically, before monitoring the application to be detected based on the proxy plugin deployed in the application to be detected and capturing the business data corresponding to the application to be detected, the vulnerability detection method may further include: determining whether to update the settings of the proxy plugin; when it is determined that the settings of the proxy plugin need to be updated, performing an update operation on the proxy plugin, and monitoring the application to be detected based on the updated proxy plugin to obtain business data.
[0092] Specifically, before the visual security test aggregation platform monitors the application to be detected based on the proxy plugin deployed in the application to be detected, it checks the proxy plugin corresponding to the application to be detected based on a preset proxy plugin detection program to determine whether the proxy plugin can operate normally or whether there is a version update for the proxy plugin. If the proxy plugin cannot operate normally or there is a version update for the proxy plugin, the proxy plugin is reset or the version update settings are performed to ensure the normal and effective operation of the proxy plugin. Furthermore, the application to be detected is monitored based on the proxy plugin after the update settings to obtain the business data of the object to be detected.
[0093] In the embodiments of the present disclosure, it is possible to check the proxy plugin to determine whether an update is required, and when an update is required, update the settings of the proxy plugin to ensure the normal operation of the proxy plugin. Moreover, based on the updated proxy plugin, the application to be detected is monitored, ensuring the operation effectiveness of the proxy plugin and the accuracy of data monitoring.
[0094] In the embodiments of the present disclosure, after the visual security test aggregation platform obtains the business data corresponding to the object to be detected, it pre-processes the object to be detected, and then performs a security test based on the data after the target processing. Specifically, after obtaining the business data corresponding to the object to be detected, the vulnerability detection method may further include: performing target processing on the business data to determine whether there is abnormal field data in the business data.
[0095] In the embodiments of the present disclosure, the target processing can be understood as performing data cleaning, data normalization processing, data field detection, etc. on the business data. Specifically, it may include performing data packet parsing, protocol field extraction, abnormal data filtering, protocol compliance verification, field abnormality detection, etc. on the business data.
[0096] Specifically, after the visual security testing aggregation platform obtains the business data corresponding to the object to be detected, it performs target processing on the business data, including data cleaning and data normalization, and then conducts protocol compliance verification and field anomaly detection on the processed data to determine whether there is abnormal field data in the business data. Among them, the specific implementation methods of protocol compliance verification and field anomaly detection are similar to the existing ones and will not be elaborated here.
[0097] Further, when it is determined that there is abnormal field data, at least one target security testing item script is called, so that at least one target security testing item script conducts security testing on the object to be detected based on the business data, and a security testing result is obtained. Specifically, it may include: calling at least one target security testing item script, so that at least one target security testing item script conducts security testing on the object to be detected based on the abnormal field data, and a security testing result is obtained.
[0098] When it is determined that there is no abnormal field data, it is determined that there are no vulnerabilities, and the process ends. Alternatively, at least one target security testing item script is called, so that at least one target security testing item script conducts security testing on the object to be detected based on the business data after data cleaning and data normalization, and a security testing result is obtained.
[0099] In the embodiments of the present disclosure, it is possible to determine whether there is abnormal field data by performing target processing on the business data. When it is determined that there is abnormal field data, security testing is only performed based on the abnormal field data, which improves the efficiency of security testing. At the same time, by performing target processing on the business data, such as data cleaning, and conducting security testing based on the processed business data, the accuracy of security testing is further improved.
[0100] In the embodiments of the present disclosure, a preset feature library and a preset vulnerability library are set in the visual security testing aggregation platform. Specifically, determining whether there are vulnerabilities in the object to be detected based on the security testing result may include: matching the security testing result with the vulnerability information in the preset feature library and the preset vulnerability library to obtain a matching result; and determining whether there are vulnerabilities based on the matching result.
[0101] Among them, the preset feature library includes the feature information of known vulnerabilities; the preset vulnerability library includes the vulnerability description information of known vulnerabilities, that is, more detailed vulnerability information of known vulnerabilities, such as detailed description information of vulnerabilities, information on the scope of influence of vulnerabilities, etc.
[0102] Further, match the security test results with the vulnerability information in the preset feature library and the preset vulnerability library to obtain a matching result, which may specifically include: extracting the target feature information corresponding to the security test results; performing feature matching on the target feature information with the feature information of known vulnerabilities in the preset feature library and the vulnerability description information of known vulnerabilities in the preset vulnerability library respectively to obtain a matching result.
[0103] Specifically, after obtaining the security test results, the visual security test aggregation platform can extract the feature information of the security test results through a preset machine learning model, obtain the target feature information corresponding to the security test results, and perform feature matching on the target feature information with the feature information of known vulnerabilities in the preset feature library and the vulnerability description information of known vulnerabilities in the preset vulnerability library respectively to obtain a matching result. Among them, the specific implementation manner of performing feature matching is similar to the implementation manner of matching text features, which will not be elaborated here.
[0104] When the matching result is that the target feature information matches the feature information of known vulnerabilities in the preset feature library and the vulnerability description information of known vulnerabilities in the preset vulnerability library respectively, it is determined that there is a vulnerability; otherwise, vice versa.
[0105] In the embodiments of the present disclosure, it is possible to determine whether there is a vulnerability by matching with the vulnerability information in the preset feature library and the preset vulnerability library, which improves the accuracy and efficiency of vulnerability detection.
[0106] In the embodiments of the present disclosure, multiple security test item scripts are defined based on a target format file and then deployed to the visual security test aggregation platform. Each security test item script includes request information, matching conditions, target vulnerability description information, and request execution logic corresponding to the security test item script.
[0107] The security test item scripts may include scripts for security test items such as SQL injection, XSS cross-site scripting, remote command execution, and interface replay attack. Among them, SQL injection can be understood as a test item script in which an attacker constructs malicious SQL statements to manipulate the database to obtain sensitive data or damage data integrity; XSS cross-site scripting can be understood as a test item script that injects malicious scripts into a web page to steal user information or hijack a session and executes using unfiltered user input; remote command execution can be understood as a test item script that uses a vulnerability to execute malicious system instructions on a server, resulting in the server being controlled or data leakage; interface replay attack can be understood as a test item script that intercepts and repeats legitimate requests to bypass authentication for unauthorized operations.
[0108] In the embodiments of the present disclosure, the target format file can be any format file recognizable by the visual security test aggregation platform. Exemplarily, the target format file can be a YAML file.
[0109] In the embodiments of the present disclosure, the request execution logic defines the protocol type, request path, method, dynamic variable injection method, etc. for vulnerability detection.
[0110] Exemplarily, taking the vulnerability detection of the target system of the target domain name as an example, the security test item script can send a specific http request to the target domain name, match predefined rules according to the response content, such as status code, response header, response body, etc., and perform security tests according to the request execution logic.
[0111] In the embodiments of the present disclosure, the method of defining multiple security test item scripts through the target format file ensures the standardization of multiple security test item scripts, and the security test item scripts can be called through the visual interface. Moreover, it can support and execute any security test item script, improving the management efficiency and test efficiency of the security test item scripts. At the same time, combined with multi-protocol support and dynamic variable mechanism, the detection efficiency and accuracy are improved.
[0112] In the embodiments of the present disclosure, when the visual security test aggregation platform determines that there is a vulnerability, it can detect the validity of the vulnerability in combination with the vulnerability context information. Specifically, when it is determined that there is a vulnerability in the object to be detected, after determining the vulnerability type, vulnerability level and vulnerability location corresponding to the vulnerability in the object to be detected and performing vulnerability annotation, the vulnerability detection method may further include: obtaining the context information of the vulnerability corresponding to the object to be detected; detecting the validity of the vulnerability based on the context information.
[0113] Specifically, when the visual security test aggregation platform determines that there is a vulnerability, it obtains the context information of the vulnerability based on the vulnerability location, that is, the context code information of the vulnerability, and detects the validity of the vulnerability in combination with the code execution stack, determines whether there is a vulnerability in the context code information of the vulnerability, and when there is a vulnerability in the context code information of the vulnerability, whether the vulnerability type is the same as the vulnerability type of the vulnerability. If they are the same, it is considered that the validity detection of the vulnerability fails, and the vulnerability and the vulnerability corresponding to the context code information of the vulnerability are determined as one vulnerability; if they are different, it is determined that the validity detection of the vulnerability passes.
[0114] In the embodiments of the present disclosure, the validity of the vulnerability can be detected through the context information of the vulnerability, avoiding the repeated annotation of vulnerabilities of the same vulnerability type and improving the effectiveness of vulnerability annotation.
[0115] The following is an illustration with a specific example:
[0116] The user inputs the target domain name in the visualization interface of the visualization security test aggregation platform; controls the start of the target scanner plugin corresponding to the target domain name, scans the target system corresponding to the target domain name to obtain business data, and stores the business data in the asset library; the visualization security test aggregation platform performs feature matching on the obtained business data with the vulnerabilities in the preset feature library and the preset vulnerability library to obtain a matching result; determines whether there are security vulnerabilities based on the matching result; when it is determined that there are security vulnerabilities, generates a security report, marks the vulnerabilities, details the relevant information of the detected vulnerabilities, and provides modification suggestions to help the user solve the vulnerability problems; when it is determined that there are no security vulnerabilities, indicates that the system is secure and the process ends.
[0117] Figure 3 It is a flowchart of another vulnerability detection method provided by an embodiment of the present disclosure. As Figure 3 shown, the vulnerability detection method may include the following steps:
[0118] S310. In response to the user's target operation, determine the object to be detected corresponding to the target operation.
[0119] In the embodiment of the present disclosure, when the security branch corresponding to the object to be detected is the network security branch or the data security branch, steps S320 - S330 are executed; when the security branch corresponding to the object to be detected is the application security branch, steps S340 - S360 are executed.
[0120] S320. When the security branch corresponding to the object to be detected is the network security branch or the data security branch, and the object to be detected is the network to be detected or the database to be detected, determine the target scanner plugin corresponding to the network to be detected or the database to be detected.
[0121] S330. Based on the target scanner plugin, scan the network to be detected or the database to be detected to obtain the business data corresponding to the network to be detected or the database to be detected.
[0122] S340. When the security branch corresponding to the object to be detected is the application security branch, and the object to be detected is the application program to be detected, determine whether to update the proxy plugin deployed in the application program to be detected.
[0123] In the embodiment of the present disclosure, when it is necessary to update the proxy plugin, step S350 is executed; otherwise, step S360 is executed.
[0124] S350. When it is determined that it is necessary to update the proxy plugin, perform the update operation of the proxy plugin, and monitor the application program to be detected based on the updated proxy plugin to obtain the business data corresponding to the application program to be detected.
[0125] S360. When it is determined that no update settings are required for the proxy plugin, the application to be detected is detected based on the proxy plugin deployed in the application to be detected, and the business data corresponding to the application to be detected is captured.
[0126] S370. Perform target processing on the business data to determine whether there is abnormal field data in the business data. When it is determined that there is abnormal field data in the business data, at least one target security test item script for performing vulnerability detection on the object to be detected is called, so that at least one target security test item script performs a security test on the object to be detected based on the abnormal field data, and a security test result is obtained.
[0127] S380. Match the security test result with the vulnerability information in the preset feature library and the preset vulnerability library to obtain a matching result; determine whether there is a vulnerability based on the matching result.
[0128] In the embodiment of the present disclosure, when it is determined that there is no vulnerability in the object to be detected, step S390 is executed; when it is determined that there is a vulnerability in the object to be detected, step S3010 is executed.
[0129] S390. When it is determined that there is no vulnerability in the object to be detected, it is determined that the system is secure and the process terminates.
[0130] S3010. When it is determined that there is a vulnerability in the object to be detected, determine the vulnerability type, vulnerability level, and vulnerability location corresponding to the vulnerability in the object to be detected, perform vulnerability annotation, display the vulnerability annotation result, and provide repair suggestions at the same time.
[0131] It should be noted that the specific implementation manners of steps S310 - S3010 are similar to those of the related steps in the above - mentioned embodiments of the present disclosure, and will not be elaborated here.
[0132] In an embodiment of the present disclosure, in response to a user's target operation, the corresponding object to be detected for the target operation can be determined, and the security branch corresponding to the object to be detected can be determined. Different methods for obtaining service data are determined based on different security branches, improving the flexibility of service data acquisition. At the same time, after obtaining the service data, target processing is performed on the service data to determine whether there is abnormal field data in the service data. When it is determined that there is abnormal field data in the service data, at least one target security test item script for performing vulnerability detection on the object to be detected is called, so that at least one target security test item script performs a security test on the object to be detected based on the abnormal field data to obtain a security test result. Multiple target security test item scripts can be called simultaneously to perform the security test, eliminating the need for manual operation, reducing labor costs, and at the same time, improving the efficiency and simplicity of the security test, thereby improving the efficiency of vulnerability detection and shortening the vulnerability detection cycle. Then, the characteristic information of the security test result is extracted, and by matching it with the vulnerability information in the preset characteristic library and the preset vulnerability library, it is determined whether there is a vulnerability in the object to be detected. When it is determined that there is a vulnerability in the object to be detected, the vulnerability type, vulnerability level, and vulnerability location corresponding to the vulnerability in the object to be detected are determined, and vulnerability annotation is performed. The vulnerability annotation result is displayed, and at the same time, a repair suggestion is provided. The vulnerability annotation result can be visually displayed to the user, enabling the user to have a clear understanding of the vulnerability detection result and improving the user experience. At the same time, by providing a repair suggestion, it can help the user repair the vulnerability and improve the efficiency of vulnerability repair.
[0133] Figure 4 It is a schematic structural diagram of a vulnerability detection device provided by an embodiment of the present disclosure.
[0134] In an embodiment of the present disclosure, the vulnerability detection device can be disposed in an electronic device and is understood as some functional modules in the above-mentioned electronic device. Specifically, it can be applied to a visual security test aggregation platform, where multiple security test item scripts are deployed, and different security test item scripts are configured for different security branches. The electronic device can be a server or a terminal. Among them, the terminal specifically includes an in-vehicle terminal, a mobile phone, a computer, a tablet computer, etc., which are not limited here.
[0135] As Figure 4 shown, the vulnerability detection device 400 can include an information determination module 410, a security test module 420, and a vulnerability detection and annotation module 430.
[0136] The information determination module 410 can be used to determine the object to be detected corresponding to the target operation in response to the user's target operation, obtain the service data corresponding to the object to be detected, and determine at least one target security test item script for performing vulnerability detection on the object to be detected. The target operation is an operation for performing vulnerability detection.
[0137] The security test module 420 can be used to call at least one target security test item script, so that at least one target security test item script performs a security test on the object to be detected based on the service data, and obtains a security test result.
[0138] The vulnerability detection annotation module 430 can be used to determine whether there is a vulnerability in the object to be detected based on the security test result; when it is determined that there is a vulnerability in the object to be detected, determine the vulnerability type, vulnerability level, and vulnerability location corresponding to the vulnerability in the object to be detected, and perform vulnerability annotation, and display the vulnerability annotation result.
[0139] In the embodiments of the present disclosure, in response to a target operation of a user, the object to be detected corresponding to the target operation can be determined. After determining the object to be detected, the service data corresponding to the object to be detected is obtained, and at least one target security test item script for performing vulnerability detection on the object to be detected is determined, where the target operation is an operation for performing vulnerability detection. After determining at least one target security test item script, call at least one target security test item script, so that at least one target security test item script performs a security test on the object to be detected based on the service data, and obtains a security test result. Furthermore, based on the security test result, it is determined whether there is a vulnerability in the object to be detected. When it is determined that there is a vulnerability in the object to be detected, determine the vulnerability type, vulnerability level, and vulnerability location corresponding to the vulnerability in the object to be detected, and perform vulnerability annotation, and display the vulnerability annotation result. Thus, by deploying multiple security test item scripts on the visual security test aggregation platform according to different security branches, when it is determined that a security test needs to be performed on the object to be detected, at least one target security test item script corresponding to the object to be detected is simultaneously subjected to a security test by calling, which improves the efficiency of the security test, and further improves the efficiency of vulnerability detection, shortens the detection cycle, and avoids manually operating the security test item script for security testing, reducing the labor cost.
[0140] In some embodiments of the present disclosure, the information determination module 410 can specifically be used to, when the security branch corresponding to the object to be detected is the application security branch, the object to be detected is the application program to be detected, monitor the application program to be detected based on the proxy plugin deployed in the application program to be detected, and capture the service data corresponding to the application program to be detected;
[0141] When the security branch corresponding to the object to be detected is the network security branch or the data security branch, the object to be detected is the network to be detected or the database to be detected, and determine the target scanner plugin corresponding to the network to be detected or the database to be detected;
[0142] Scan the network to be detected or the database to be detected based on the target scanner plugin, and obtain the service data corresponding to the network to be detected or the database to be detected.
[0143] In some embodiments of the present disclosure, the vulnerability detection device 400 may further include a proxy plugin update module.
[0144] The proxy plugin update module may be configured to determine whether to update the proxy plugin before monitoring the application under test based on the proxy plugin deployed in the application under test and capturing the business data corresponding to the application under test;
[0145] When it is determined that the proxy plugin needs to be updated, perform the update operation of the proxy plugin, monitor the application under test based on the updated proxy plugin, and obtain the business data.
[0146] In some embodiments of the present disclosure, the vulnerability detection device 400 may further include a data processing module.
[0147] The data processing module may be configured to perform target processing on the business data after obtaining the business data corresponding to the object under test, and determine whether there is abnormal field data in the business data.
[0148] The security testing module 420 may be specifically configured to, when it is determined that there is abnormal field data in the business data, call at least one target security testing item script, so that at least one target security testing item script performs a security test on the object under test based on the abnormal field data to obtain a security test result.
[0149] In some embodiments of the present disclosure, the vulnerability detection annotation module 430 may be specifically configured to match the security test result with the vulnerability information in the preset feature library and the preset vulnerability library to obtain a matching result;
[0150] Determine whether there is a vulnerability based on the matching result.
[0151] The preset feature library includes the feature information of known vulnerabilities, and the preset vulnerability library includes the vulnerability description information of known vulnerabilities.
[0152] The vulnerability detection annotation module 430 may also be specifically configured to extract the target feature information corresponding to the security test result;
[0153] Perform feature matching on the target feature information with the feature information of known vulnerabilities in the preset feature library and the vulnerability description information of known vulnerabilities in the preset vulnerability library respectively to obtain a matching result.
[0154] In some embodiments of the present disclosure, multiple security testing item scripts are defined based on a target format file and then deployed to the visual security testing aggregation platform. Each security testing item script includes request information, matching conditions, target vulnerability description information, and request execution logic corresponding to the security testing item script.
[0155] In some embodiments of the present disclosure, the vulnerability detection device 400 may further include a validity detection module.
[0156] The validity detection module may be configured to, when it is determined that there is a vulnerability in the object to be detected, determine the vulnerability type, vulnerability level, and vulnerability location corresponding to the vulnerability in the object to be detected, and after performing vulnerability annotation, obtain the context information of the vulnerability corresponding to the object to be detected;
[0157] Perform validity detection on the vulnerability based on the context information.
[0158] It should be noted that, Figure 4 the vulnerability detection device 400 shown can execute each step in the above method embodiments, and implement each process and effect in the above method embodiments, which will not be elaborated here.
[0159] Figure 5 is a schematic structural diagram of an electronic device provided by an embodiment of the present disclosure.
[0160] In an embodiment of the present disclosure, Figure 5 the electronic device shown may be a server or a terminal. Among them, the terminal specifically includes a vehicle-mounted terminal, a mobile phone, a computer, a tablet computer, etc., which are not limited herein.
[0161] As Figure 5 shown, the electronic device may include a processor 510 and a memory 520 storing computer program instructions.
[0162] Specifically, the above-mentioned processor 510 may include a central processing unit (CPU), or an application specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of the present disclosure.
[0163] The memory 520 may include a mass memory for information or instructions. By way of example and not limitation, the memory 520 may include a hard disk drive (HDD), a floppy disk drive, a flash memory, an optical disk, a magneto-optical disk, a magnetic tape, or a universal serial bus (USB) drive, or a combination of two or more of these. Where appropriate, the memory 520 may include removable or non-removable (or fixed) media. Where appropriate, the memory 520 may be inside or outside the integrated gateway device. In a particular embodiment, the memory 520 is a non-volatile solid-state memory. In a particular embodiment, the memory 520 includes a read-only memory (ROM). Where appropriate, the ROM may be a mask-programmed ROM, a programmable ROM (PROM), an erasable PROM (EPROM), an electrically erasable PROM (EEPROM), an electrically alterable ROM (EAROM), or a flash memory, or a combination of two or more of these.
[0164] The processor 510 reads and executes the computer program instructions stored in the memory 520 to perform the steps of the vulnerability detection method provided by the embodiments of the present disclosure.
[0165] In one example, the electronic device may further include a transceiver 530 and a bus 540. Among them, as Figure 5 shown, the processor 510, the memory 520, and the transceiver 530 are connected through the bus 540 and complete communication with each other.
[0166] The bus 540 includes hardware, software, or both. By way of example and not limitation, the bus may include an Accelerated Graphics Port (AGP) or other graphics bus, an Extended Industry Standard Architecture (EISA) bus, a Front Side BUS (FSB), a Hyper Transport (HT) interconnect, an Industrial Standard Architecture (ISA) bus, an InfiniBand interconnect, a Low Pin Count (LPC) bus, a memory bus, a MicroChannel Architecture (MCA) bus, a Peripheral Component Interconnect (PCI) bus, a PCI-Express (PCI-X) bus, a Serial Advanced Technology Attachment (SATA) bus, a Video Electronics Standards Association Local Bus (VLB) bus, or other suitable buses, or a combination of two or more of these. Where appropriate, the bus 540 may include one or more buses.
[0167] Embodiments of the present disclosure also provide a computer-readable storage medium that may store a computer program. When the computer program is executed by a processor, the processor is caused to implement the vulnerability detection method provided by the embodiments of the present disclosure.
[0168] The above storage medium may, for example, include a memory 520 for computer program instructions, and the above instructions may be executed by a processor 510 of an electronic device to complete the vulnerability detection method provided by the embodiments of the present disclosure. Optionally, the storage medium may be a non-transitory computer-readable storage medium. For example, the non-transitory computer-readable storage medium may be a ROM, a Random Access Memory (RAM), a Compact Disc ROM (CD-ROM), a magnetic tape, a floppy disk, and an optical data storage device, etc.
[0169] Embodiments of the present disclosure also provide a vehicle that includes an electronic device and can achieve the various processes and effects in the above embodiments of the present disclosure, which will not be elaborated herein.
[0170] Embodiments of the present disclosure also provide a computer program product, which includes a computer program or instruction. When the computer program or instruction is executed by a processor, it implements the vulnerability detection method provided by the embodiments of the present disclosure, and can achieve each process and effect in the above embodiments of the present disclosure, which will not be elaborated herein.
[0171] The foregoing are only specific embodiments of the present disclosure, enabling those skilled in the art to understand or implement the present disclosure. Various modifications to these embodiments will be obvious to those skilled in the art, and the general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present disclosure. Therefore, the present disclosure will not be limited to these embodiments described herein, but rather will be accorded the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A vulnerability detection method, characterized in that, Applied to a visualization security testing aggregation platform, where multiple security testing item scripts are deployed in the visualization security testing aggregation platform, and different security testing item scripts are configured for different security branches, including: In response to a target operation of a user, determining a to-be-detected object corresponding to the target operation, obtaining service data corresponding to the to-be-detected object, and determining at least one target security testing item script for performing vulnerability detection on the to-be-detected object, where the target operation is an operation for performing vulnerability detection; Invoking the at least one target security testing item script, so that the at least one target security testing item script performs a security test on the to-be-detected object based on the service data to obtain a security test result; Determining whether there are vulnerabilities in the to-be-detected object based on the security test result; when it is determined that there are vulnerabilities in the to-be-detected object, determining the vulnerability type, vulnerability level, and vulnerability location corresponding to the vulnerabilities in the to-be-detected object, and performing vulnerability annotation, and displaying the vulnerability annotation result.
2. The method according to claim 1, wherein The obtaining service data corresponding to the to-be-detected object includes: When the security branch corresponding to the to-be-detected object is an application security branch, the to-be-detected object is a to-be-detected application program, monitoring the to-be-detected application program based on a proxy plugin deployed in the to-be-detected application program, and capturing service data corresponding to the to-be-detected application program; When the security branch corresponding to the to-be-detected object is a network security branch or a data security branch, the to-be-detected object is a to-be-detected network or a to-be-detected database, determining a target scanner plugin corresponding to the to-be-detected network or the to-be-detected database; Scanning the to-be-detected network or the to-be-detected database based on the target scanner plugin to obtain service data corresponding to the to-be-detected network or the to-be-detected database.
3. The method according to claim 2, wherein Before the monitoring the to-be-detected application program based on a proxy plugin deployed in the to-be-detected application program and capturing service data corresponding to the to-be-detected application program, the method further includes: Determining whether to perform an update setting on the proxy plugin; When it is determined that an update setting needs to be performed on the proxy plugin, performing an update operation on the proxy plugin, monitoring the to-be-detected application program based on the updated proxy plugin, and obtaining the service data.
4. The method according to claim 1 or 2, characterized in that, After the obtaining service data corresponding to the to-be-detected object, the method further includes: Performing target processing on the service data to determine whether there is abnormal field data in the service data; The invoking the at least one target security testing item script, so that the at least one target security testing item script performs a security test on the to-be-detected object based on the service data to obtain a security test result, includes: When it is determined that there is abnormal field data in the service data, invoking the at least one target security testing item script, so that the at least one target security testing item script performs a security test on the to-be-detected object based on the abnormal field data to obtain the security test result.
5. The method according to claim 1, characterized in that The determining whether there are vulnerabilities in the to-be-detected object based on the security test result includes: Match the security test results with the vulnerability information in the preset feature library and the preset vulnerability library to obtain a matching result; Determine whether there is a vulnerability based on the matching result; The preset feature library includes the feature information of known vulnerabilities, and the preset vulnerability library includes the vulnerability description information of known vulnerabilities; the matching the security test results with the vulnerability information in the preset feature library and the preset vulnerability library to obtain a matching result includes: Extract the target feature information corresponding to the security test results; Perform feature matching on the target feature information with the feature information of known vulnerabilities in the preset feature library and the vulnerability description information of known vulnerabilities in the preset vulnerability library respectively to obtain the matching result.
6. The method according to claim 1, wherein The multiple security test item scripts are deployed to the visual security test aggregation platform after being defined based on a target format file. Each security test item script includes request information, matching conditions, target vulnerability description information, and request execution logic corresponding to the security test item script.
7. The method according to claim 1, wherein After determining that there is a vulnerability in the object to be detected, determining the vulnerability type, vulnerability level, and vulnerability location corresponding to the vulnerability in the object to be detected, and performing vulnerability annotation, the method further includes: Obtain the context information of the vulnerability corresponding to the object to be detected; Perform validity detection on the vulnerability based on the context information.
8. A vulnerability detection device, characterized in that, Applied to a visual security test aggregation platform, in which multiple security test item scripts are deployed, and different security test item scripts are configured for different security branches, including: An information determination module, configured to respond to a target operation of a user, determine the object to be detected corresponding to the target operation, obtain the service data corresponding to the object to be detected, and determine at least one target security test item script for performing vulnerability detection on the object to be detected, where the target operation is an operation for performing vulnerability detection; A security test module, configured to call the at least one target security test item script, so that the at least one target security test item script performs a security test on the object to be detected based on the service data to obtain a security test result; A vulnerability detection and annotation module, configured to determine whether there is a vulnerability in the object to be detected based on the security test result; when it is determined that there is a vulnerability in the object to be detected, determine the vulnerability type, vulnerability level, and vulnerability location corresponding to the vulnerability in the object to be detected, and perform vulnerability annotation, and display the vulnerability annotation result.
9. An electronic device, characterized in that, Including: A processor; A memory for storing executable instructions; Wherein, the processor is configured to read the executable instructions from the memory and execute the executable instructions to implement the vulnerability detection method described in any one of claims 1-7 above.
10. A computer-readable storage medium, characterized in that, The storage medium stores a computer program, and when the computer program is executed by the processor, the processor is caused to implement the vulnerability detection method described in any one of claims 1-7 above.