Mobile application vulnerability iterative penetration test method based on dynamic environment adaptation

By generating abstract syntax trees and iterative penetration testing methods, the risk nodes and code differences of mobile applications are automatically identified, and the problem of inefficiency of traditional penetration testing methods in dynamic environments is solved, and fast and accurate vulnerability detection and positioning is achieved.

CN120354412AActive Publication Date: 2025-07-22SHENYANG XINXIN JINGZHI COMPUTER SECURITY DETECTION TECH CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510420143.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-03
Publication Date
2025-07-22
Estimated Expiration
2045-04-03

AI Technical Summary

Technical Problem

Traditional penetration testing methods are slow to respond to changes in the dynamic environment of mobile applications, making it difficult to quickly locate new vulnerabilities, and have high artificial dependence, resulting in inefficient testing.

Method used

By generating an abstract syntax tree, extracting risk node sets and performing penetration tests, building vulnerability node sets, combining external dependency library scanning, automatically identifying code differences and targeting the iterative penetration test, focusing on new risk points.

Benefits of technology

It improves the accuracy and response speed of vulnerability detection, reduces manpower investment, can detect new vulnerabilities in a timely manner, and improves the overall security of mobile applications.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure BDA0005344997280000031
    Figure BDA0005344997280000031
  • Figure BDA0005344997280000051
    Figure BDA0005344997280000051
  • Figure BDA0005344997280000061
    Figure BDA0005344997280000061
Patent Text Reader

Abstract

The invention relates to the field of mobile application security testing, in particular to a mobile application vulnerability iterative penetration testing method based on dynamic environment adaptation, which comprises the following steps: firstly, performing code analysis to generate an abstract syntax tree, traversing the abstract syntax tree to extract nodes related to risk component calling, and constructing a potential risk node set; performing penetration testing on all nodes in the potential risk node set, verifying whether vulnerabilities exist really, and constructing a first vulnerability node set; after the version of the mobile application is upgraded, code difference analysis is carried out, modification and newly-added parts of codes are automatically identified, penetration testing is triggered in a targeted mode, newly-added risk points are focused, newly-added vulnerabilities are found in time, and by carrying out iterative penetration testing on the upgraded version, the vulnerability detection accuracy can be improved, dynamic environment changes can be better adapted, and the vulnerability detection efficiency is improved. And accurate positioning of the vulnerabilities is carried out.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of mobile application security testing, and particularly to an iterative penetration testing method for mobile application vulnerabilities based on dynamic environment adaptation. Background Art

[0002] Vulnerabilities in mobile applications may lead to serious consequences such as data leakage and service interruption. Especially for some components in mobile applications, due to problems in design, implementation, or configuration, they are easily targeted by attackers. With the rapid upgrade of mobile application versions, while introducing new functional experiences, it also increases the risk of introducing vulnerabilities. The upgrade of mobile application versions is a key vulnerability introduction risk point that needs to be monitored in the dynamic environment change. At the same time, the call chain of each component in the mobile application may involve multiple dependent libraries, and the mutual dependency relationships between these libraries may increase the attack surface.

[0003] Testing mobile application vulnerabilities relies on penetration testing. As a security testing method, penetration testing can identify and verify potential security vulnerabilities in mobile applications by simulating the behavior of malicious attackers. Traditional penetration testing methods are manually executed by professional security experts, with a high degree of dependence on manual labor and a long testing cycle, making it difficult to respond in a timely manner to rapidly iterating mobile applications. Although automated tools can be combined with manual testing to conduct large-scale vulnerability testing on mobile applications, when faced with changes in the dynamic environment of mobile applications, such as the upgrade of mobile application versions, redundant testing needs to be repeated for each version, resulting in low testing efficiency and difficulty in quickly focusing on and locating newly added vulnerability risk points. Summary of the Invention

[0004] To solve the above problems proposed in the background art, the present invention provides an iterative penetration testing method for mobile application vulnerabilities based on dynamic environment adaptation.

[0005] The technical solution of the present invention is as follows:

[0006] An iterative penetration testing method for mobile application vulnerabilities based on dynamic environment adaptation, comprising the following steps:

[0007] S1. Obtain the APK file of the current version of the mobile application, perform decompilation to obtain the compiled code, parse the compiled code, generate an abstract syntax tree based on the logical call relationship of functions, traverse the abstract syntax tree to extract risk nodes related to the call of risk components, and construct a set of potential risk nodes based on all nodes;

[0008] S2. Conduct penetration testing on all nodes in the set of potential risk nodes, mark the nodes with vulnerabilities as a type of vulnerability nodes, and construct a first set of vulnerability nodes based on all type of vulnerability nodes;

[0009] S3. Perform vulnerability scanning on the external dependency libraries used by each node in the potential risk node set, mark the nodes corresponding to the external dependency libraries with detected vulnerabilities as secondary vulnerability nodes, and add the secondary vulnerability nodes to the first vulnerability node set;

[0010] Associate the node positions of the primary vulnerability nodes and the secondary vulnerability nodes in the abstract syntax tree to the first vulnerability node set respectively;

[0011] S4. Repeat S1 for the updated version of the mobile application to construct an iterative risk node set, perform node difference analysis on the iterative risk node set and the potential risk node set to obtain difference nodes: newly added nodes, deleted nodes, and modified nodes;

[0012] S5. Trigger penetration testing for the newly added nodes and the modified nodes to obtain primary difference vulnerability nodes; perform vulnerability scanning on the external dependency libraries used by the newly added nodes and the modified nodes to obtain secondary difference vulnerability nodes; update the primary difference vulnerability nodes and the secondary difference vulnerability nodes to the first vulnerability node set to obtain a second vulnerability node set, and associate the node positions of the primary difference vulnerability nodes and the secondary difference vulnerability nodes in the abstract syntax tree to the second vulnerability node set respectively to obtain the vulnerability test results of the updated version of the mobile application.

[0013] Specifically, in S5, the primary difference vulnerability nodes and the secondary difference vulnerability nodes are updated to the first vulnerability node set according to the set vulnerability node update rules, specifically as follows:

[0014] Perform penetration testing on the newly added nodes: if the obtained primary difference vulnerability nodes and secondary difference vulnerability nodes are newly added vulnerability nodes, add them to the second vulnerability node set;

[0015] Perform penetration testing on the modified nodes: if the obtained primary difference vulnerability nodes and secondary difference vulnerability nodes are newly added vulnerability nodes, add them to the second vulnerability node set; if the primary vulnerability nodes or secondary vulnerability nodes existing in the risk nodes before update are repaired and there are no newly added vulnerability nodes, delete this risk node from the first vulnerability node set.

[0016] In S2, perform penetration testing on all nodes in the potential risk node set to obtain vulnerability nodes with detected vulnerabilities. The process of penetration testing is as follows: use dynamic detection tools to perform dynamic verification on all nodes in the potential risk node set for weak key security, SQL injection attack, and authentication bypass respectively, and obtain vulnerability nodes with different types of vulnerabilities such as weak key security vulnerabilities, SQL injection attack vulnerabilities, and authentication bypass vulnerabilities respectively.

[0017] In S3, vulnerability scanning is performed on the external dependency libraries used by each node in the potential risk node set, and the nodes corresponding to the external dependency libraries with vulnerabilities detected are marked as type-two vulnerability nodes, obtaining the vulnerability information of each external dependency library. The vulnerability information includes: the number of vulnerabilities, the vulnerability number, and the CVSS score of the vulnerability.

[0018] Further, according to the number of vulnerabilities and the CVSS score of the external dependency library, calculate the risk score of the external dependency library, and list the external dependency libraries with a risk score greater than or equal to the risk score threshold in the blacklist of dependency libraries used for mobile application version updates. The calculation formula for the risk score is as follows:

[0019]

[0020] where R is the risk score, n is the number of vulnerabilities of the external dependency library, N is the number of code blocks in which the external dependency library is called, w i is the weighting coefficient corresponding to vulnerability i, and CVSS i is the CVSS score of vulnerability i.

[0021] Perform penetration testing on the deleted nodes obtained in S4: If there are type-one vulnerability nodes or type-two vulnerability nodes among the corresponding risk nodes to be deleted before the update, then delete this risk node in the first vulnerability node set.

[0022] In S1, traverse the abstract syntax tree to extract the nodes related to the risk component calls. The risk components include the Activity component, Service component, Content Provider component, and Broadcast Receiver component of the mobile application.

[0023] The present invention also provides a mobile application vulnerability iterative penetration testing system based on dynamic environment adaptation, including:

[0024] Code parsing module: used to obtain the APK file of the current version of the mobile application, obtain the compiled code through decompilation processing, perform code parsing on the compiled code, generate an abstract syntax tree based on the logical call relationship of functions, traverse the abstract syntax tree to extract the risk nodes related to the risk component calls, and construct a potential risk node set based on all nodes;

[0025] Type-one vulnerability confirmation module: used to perform penetration testing on all nodes in the potential risk node set, mark the nodes with vulnerabilities as type-one vulnerability nodes, and construct a first vulnerability node set based on all type-one vulnerability nodes;

[0026] Type II Vulnerability Confirmation Module: It is used to perform vulnerability scanning on the external dependency libraries used by each node in the set of potential risk nodes, mark the nodes corresponding to the external dependency libraries with detected vulnerabilities as Type II vulnerability nodes, and add the Type II vulnerability nodes to the first set of vulnerability nodes; associate the node positions of the Type I vulnerability nodes and the Type II vulnerability nodes in the abstract syntax tree with the first set of vulnerability nodes respectively;

[0027] Difference Analysis Module: It is used to repeatedly execute S1 on the updated version of the mobile application, construct an iterative set of risk nodes, perform node difference analysis on the iterative set of risk nodes and the set of potential risk nodes, and obtain difference nodes: newly added nodes, deleted nodes, and modified nodes;

[0028] Iterative Penetration Testing Module: It is used to trigger penetration testing on the newly added nodes and modified nodes to obtain Type I difference vulnerability nodes; perform vulnerability scanning on the external dependency libraries used by the newly added nodes and modified nodes to obtain Type II difference vulnerability nodes; update the Type I difference vulnerability nodes and the Type II difference vulnerability nodes to the first set of vulnerability nodes to obtain a second set of vulnerability nodes, and associate the node positions of the Type I difference vulnerability nodes and the Type II difference vulnerability nodes in the abstract syntax tree with the second set of vulnerability nodes respectively to obtain the vulnerability test results of the updated version of the mobile application.

[0029] In addition, the present invention provides a mobile application vulnerability iterative penetration testing device based on dynamic environment adaptation, including a processor and a memory. Among them, when the processor executes the computer program stored in the memory, it implements the above-mentioned mobile application vulnerability iterative penetration testing method based on dynamic environment adaptation.

[0030] The present invention also provides a computer-readable storage medium storing a computer program, and when the program is executed by a processor, it can implement the steps of the above-mentioned mobile application vulnerability iterative penetration testing method based on dynamic environment adaptation.

[0031] The beneficial effects of the present invention are as follows:

[0032] 1. For the mobile application vulnerability iterative penetration testing method based on dynamic environment adaptation provided by the present invention, first, code parsing is performed to generate an abstract syntax tree, the nodes related to the risk component calls are extracted by traversing the abstract syntax tree, a set of potential risk nodes is constructed, penetration testing is performed on all nodes in the set of potential risk nodes to verify whether there are real vulnerabilities, and a first set of vulnerability nodes is constructed; after the mobile application version is upgraded, code difference analysis is performed to automatically identify the modified and newly added parts of the code, and penetration testing is triggered accordingly, focusing on the newly added risk points, timely discovering newly added vulnerabilities, with low human input and fast response speed. By performing iterative penetration testing on the upgraded version, the accuracy of vulnerability detection can be improved, better adapting to dynamic environment changes and accurately positioning vulnerabilities.

[0033] 2. By comprehensively analyzing the vulnerability risks of each component of the mobile application itself and external libraries, the present invention reduces the possibility of attackers using these vulnerabilities for attacks, so that potential security hazards can be more effectively identified and repaired, thereby significantly improving the overall security of the mobile application. Detailed implementation manners

[0034] The exemplary implementation manners of the present disclosure will be described in more detail below.

[0035] Embodiment

[0036] This embodiment provides a method for iterative penetration testing of mobile application vulnerabilities based on dynamic environment adaptation, including the following steps:

[0037] S1. Obtain the APK file of the current version of the mobile application, perform decompilation processing to obtain the compiled code, perform code parsing on the compiled code, generate an abstract syntax tree based on the logical call relationship of functions, traverse the abstract syntax tree to extract risk nodes related to the call of risk components, and construct a set of potential risk nodes based on all nodes.

[0038] In step S1, the APK file contains all the bytecodes after the code compilation of the mobile application, but these bytecodes cannot be directly read and need to be converted into readable compiled code through decompilation processing. For example, the apktool decompilation tool can be used to decompile the obtained APK file to obtain the compiled code. The obtained compiled code can be parsed using a parsing library, such as the existing JavaParser, to generate an abstract syntax tree (AST) based on the logical call relationship of functions.

[0039] Traverse the abstract syntax tree to extract nodes related to the call of risk components. The risk components include the Activity component, Service component, Content Provider component, and Broadcast Receiver component of the mobile application. The Activity component is used to manage the user interface of the mobile application and is the component responsible for interacting with the user. If it is not set properly, it may lead to unauthorized access to the mobile application. The Service component runs in the background as a service component of the mobile application. If it is maliciously called, it may lead to the leakage of the mobile user's personal information and data, or cause the interruption of the service. The ContentProvider component is used to share data between mobile application programs and may lead to the leakage of information. The BroadcastReceiver component is used to receive and respond to broadcast messages. If it is maliciously exploited, it may lead to serious consequences such as the leakage of sensitive information.

[0040] S2. Perform penetration testing on all nodes in the potential risk node set, mark the nodes with vulnerabilities as type-I vulnerable nodes, construct a first vulnerable node set based on all type-I vulnerable nodes, and associate the node positions of type-I vulnerable nodes in the abstract syntax tree with the first vulnerable node set.

[0041] Perform penetration testing on all nodes in the potential risk node set to obtain vulnerable nodes with vulnerabilities. The process of penetration testing is as follows: Use dynamic detection tools to perform dynamic verification of weak key security, SQL injection attack, and authentication bypass on all nodes in the potential risk node set, and respectively obtain vulnerable nodes with different types of vulnerabilities such as weak key security vulnerability, SQL injection attack vulnerability, and authentication bypass vulnerability.

[0042] Table 1 Example script for verifying weak key security

[0043]

[0044]

[0045] When performing penetration testing, write a Hook script through the Frida dynamic verification tool. For example, Table 1 is a script for verifying AES weak keys. First, confirm whether the mobile application uses the ECB encryption mode (line 6), and test whether data can be decrypted by dynamically injecting weak keys (lines 10 - 12). This is a simple example. By defining a hardcoded key "123456789" and calling this.init() to force the replacement of the key, in actual penetration testing, the theft of the key is performed through Frida's Memory.scan() to search the memory and extract the real key, rather than using a hardcoded key for replacement. When returning to the original result and continuing to execute at line 13, the key has been replaced with a custom value. If the encrypted data of the mobile application can be decrypted due to the replacement of the weak key, the vulnerability is established and there is a vulnerability.

[0046] Table 2 Example script for verifying SQL injection attack

[0047]

[0048] First, use Java.use to obtain a reference to the native SQLiteDatabase class of the node code program in the mobile application (line 1), record the SQL statement, and output all executed SQL statements (lines 3 - 4). Check whether the SQL statement contains UNION SELECT, which is a common attack method for SQL injection. If the SQL statement contains UNION SELECT, output vulnerability confirmation information (lines 5 - 9).

[0049] Table 3 Example script for verifying authentication bypass

[0050]

[0051] Table 3 provides a Hook script for authentication bypass, which implements an authentication bypass vulnerability and returns true regardless of the input password. The second line dynamically obtains a reference to the target class com.example.auth.AuthHelper. By recording the incoming password and forcing the return of true (lines 3 - 7), the password verification is always successful, that is, the authentication is bypassed and the vulnerability is established.

[0052] S3. Perform vulnerability scanning on the external dependency libraries used by each node in the set of potential risk nodes, mark the nodes corresponding to the external dependency libraries with vulnerabilities detected as secondary vulnerability nodes, add the secondary vulnerability nodes to the first set of vulnerability nodes, and associate the node positions of the secondary vulnerability nodes in the abstract syntax tree with the first set of vulnerability nodes.

[0053] Perform vulnerability scanning on the external dependency libraries used by each node in the set of potential risk nodes. For example, OWASPDependency - Check can be used to scan the external dependency libraries used by each node to obtain the vulnerability information of each external dependency library. The vulnerability information includes: the number of vulnerabilities, vulnerability numbers, and vulnerability CVSS scores. Mark the nodes corresponding to the external dependency libraries with vulnerabilities detected as secondary vulnerability nodes.

[0054] Furthermore, according to the number of vulnerabilities and vulnerability CVSS scores of the external dependency libraries, calculate the risk scores of the external dependency libraries, list the external dependency libraries with risk scores greater than or equal to the risk score threshold in the blacklist of dependency libraries used for mobile application version updates. The calculation formula for the risk score is as follows:

[0055]

[0056] where R is the risk score, n is the number of vulnerabilities of the external dependency library, N is the number of code blocks where the external dependency library is called, w i is the weighting coefficient corresponding to vulnerability i, and CVSS i is the CVSS score of vulnerability i.

[0057] S4. Repeat S1 for the updated version of the mobile application to construct an iterative set of risk nodes, perform node difference analysis on the iterative set of risk nodes and the set of potential risk nodes, and obtain the difference nodes: newly added nodes, deleted nodes, and modified nodes.

[0058] In step S4, perform node difference analysis on the iterative set of risk nodes and the set of potential risk nodes using the node difference analysis algorithm, as shown in Table 4.

[0059] Table 4 Node Difference Analysis Algorithm

[0060]

[0061]

[0062] In the algorithm of Table 4, the function diff_analysis is defined to compare two sets: the set of potential risk nodes (old_set) and the set of iterative risk nodes (new_set). If a node exists in the iterative risk node set but not in the potential risk node set, it is a newly added node (line 2). If a node exists in the potential risk node set but not in the iterative risk node set, it is a deleted node (line 3). If a node is partially modified, it is a modified node (lines 4 - 7).

[0063] S5. Trigger penetration testing for newly added nodes and modified nodes to obtain a set of first - type differential vulnerability nodes; perform vulnerability scanning on the external dependency libraries used by newly added nodes and modified nodes to obtain a set of second - type differential vulnerability nodes; update the set of first - type differential vulnerability nodes and the set of second - type differential vulnerability nodes to the first vulnerability node set to obtain the second vulnerability node set, and associate the node positions of the first - type differential vulnerability nodes and the second - type differential vulnerability nodes in the abstract syntax tree to the second vulnerability node set respectively to obtain the vulnerability test results of the updated version of the mobile application.

[0064] In step S5, update the set of first - type differential vulnerability nodes and the set of second - type differential vulnerability nodes to the first vulnerability node set according to the set vulnerability node update rules, specifically:

[0065] Perform penetration testing on newly added nodes: If the obtained first - type differential vulnerability nodes and second - type differential vulnerability nodes are newly added vulnerability nodes, add them to the second vulnerability node set;

[0066] Perform penetration testing on modified nodes: If the obtained first - type differential vulnerability nodes and second - type differential vulnerability nodes are newly added vulnerability nodes, add them to the second vulnerability node set; if a first - type vulnerability node or a second - type vulnerability node that existed in the risk nodes before the update is fixed and there are no newly added vulnerability nodes, delete this risk node from the first vulnerability node set.

[0067] Perform penetration testing on the obtained deleted nodes: If there is a first - type vulnerability node or a second - type vulnerability node in the corresponding risk node that was deleted before the update, delete this risk node from the first vulnerability node set.

[0068] As shown in Table 5, define the set V1 as the first vulnerability node set, define V1_updated as the updated first vulnerability node set, and V2 as the second vulnerability node set. Add the newly added vulnerability nodes to the second vulnerability node set (lines 4 - 10). If there are no newly added vulnerabilities and the original vulnerabilities have been fixed, delete this risk node from the first vulnerability node set (lines 11 - 24), and also include deleting the vulnerabilities related to the deleted nodes from the first vulnerability node set (lines 25 - 27).

[0069] Table 5 Vulnerability Node Update Rule Algorithm

[0070]

[0071]

[0072] The present invention also provides a mobile application vulnerability iterative penetration testing system based on dynamic environment adaptation, including:

[0073] Code parsing module: used to obtain the APK file of the current version of the mobile application, obtain the compiled code through decompilation processing, perform code parsing on the compiled code, generate an abstract syntax tree based on the logical call relationship of functions, traverse the abstract syntax tree to extract risk nodes related to the call of risk components, and construct a potential risk node set based on all nodes;

[0074] Type - I vulnerability confirmation module: used to perform penetration testing on all nodes in the potential risk node set, mark the nodes with vulnerabilities as type - I vulnerability nodes, and construct a first vulnerability node set based on all type - I vulnerability nodes;

[0075] Type - II vulnerability confirmation module: used to perform vulnerability scanning on the external dependency libraries used by each node in the potential risk node set, mark the nodes corresponding to the externally dependent libraries with detected vulnerabilities as type - II vulnerability nodes, and add the type - II vulnerability nodes to the first vulnerability node set; associate the node positions of the type - I vulnerability nodes and type - II vulnerability nodes in the abstract syntax tree with the first vulnerability node set respectively;

[0076] Difference analysis module: used to repeatedly execute S1 on the updated version of the mobile application, construct an iterative risk node set, perform node difference analysis on the iterative risk node set and the potential risk node set, and obtain difference nodes: newly added nodes, deleted nodes, modified nodes;

[0077] Iterative Penetration Testing Module: It is used to conduct penetration testing on newly added nodes and modified nodes to obtain a set of nodes with type-I differential vulnerabilities; perform vulnerability scanning on the external dependency libraries used by newly added nodes and modified nodes to obtain a set of nodes with type-II differential vulnerabilities; update the set of type-I differential vulnerability nodes and type-II differential vulnerability nodes to the first vulnerability node set to obtain the second vulnerability node set, and associate the node positions of the type-I differential vulnerability nodes and type-II differential vulnerability nodes in the abstract syntax tree to the second vulnerability node set respectively to obtain the vulnerability test results of the updated version of the mobile application.

[0078] In addition, the present invention also provides a mobile application vulnerability iterative penetration testing device based on dynamic environment adaptation, including a processor and a memory. When the processor executes the computer program stored in the memory, the above-mentioned mobile application vulnerability iterative penetration testing method based on dynamic environment adaptation is implemented.

[0079] Finally, the present invention provides a computer-readable storage medium storing a computer program, and when the program is executed by a processor, the above-mentioned mobile application vulnerability iterative penetration testing method based on dynamic environment adaptation can be implemented.

[0080] The mobile application vulnerability iterative penetration testing method provided by the present invention first performs code parsing to generate an abstract syntax tree, traverses the abstract syntax tree to extract nodes related to risk component calls, constructs a set of potential risk nodes, conducts penetration testing on all nodes in the set of potential risk nodes to verify whether there are actual vulnerabilities, and constructs the first vulnerability node set; after the mobile application version is upgraded, code difference analysis is performed to automatically identify the modified and newly added parts of the code, and penetration testing is triggered specifically to focus on newly added risk points and timely discover newly added vulnerabilities. By performing iterative penetration testing on the upgraded version, the accuracy of vulnerability detection can be improved, better adapt to dynamic environment changes, and accurately locate vulnerabilities. By comprehensively analyzing the vulnerability risks of each component of the mobile application itself and external libraries, the possibility of attackers using these vulnerabilities for attacks is reduced, so that potential security hazards can be more effectively identified and repaired, thus significantly improving the overall security of the mobile application.

Claims

1. A mobile application vulnerability iterative penetration testing method based on dynamic environment adaptation, characterized in that It includes the following steps: S1. Obtain the APK file of the current version of the mobile application, decompile it to obtain the compiled code, parse the compiled code, generate an abstract syntax tree based on the logical call relationship of functions, traverse the abstract syntax tree to extract risk nodes related to the call of risk components, and build a set of potential risk nodes based on all nodes; S2. Conduct penetration testing on all nodes in the set of potential risk nodes, mark the nodes with vulnerabilities as type-I vulnerability nodes, and build a first set of vulnerability nodes based on all type-I vulnerability nodes; S3. Scan the external dependency libraries used by each node in the set of potential risk nodes for vulnerabilities, mark the nodes corresponding to the external dependency libraries with detected vulnerabilities as type-II vulnerability nodes, and add the type-II vulnerability nodes to the first set of vulnerability nodes; Associate the node positions of the type-I vulnerability nodes and type-II vulnerability nodes in the abstract syntax tree with the first set of vulnerability nodes respectively; S4. Repeat S1 for the updated version of the mobile application to build an iterative set of risk nodes, conduct node difference analysis on the iterative set of risk nodes and the set of potential risk nodes to obtain difference nodes: newly added nodes, deleted nodes, and modified nodes; S5. Trigger penetration testing on the newly added nodes and modified nodes to obtain type-I difference vulnerability nodes; Scan the external dependency libraries used by the newly added nodes and modified nodes for vulnerabilities to obtain type-II difference vulnerability nodes; Update the type-I difference vulnerability nodes and type-II difference vulnerability nodes to the first set of vulnerability nodes to obtain a second set of vulnerability nodes, and associate the node positions of the type-I difference vulnerability nodes and type-II difference vulnerability nodes in the abstract syntax tree with the second set of vulnerability nodes respectively to obtain the vulnerability test results of the updated version of the mobile application.

2. The iterative penetration testing method for mobile application vulnerabilities based on dynamic environment adaptation according to claim 1, characterized in that, In S5, the type-I difference vulnerability nodes and type-II difference vulnerability nodes are updated to the first set of vulnerability nodes according to the set vulnerability node update rules, specifically: Conduct penetration testing on the newly added nodes: If the obtained type-I difference vulnerability nodes and type-II difference vulnerability nodes are newly added vulnerability nodes, add them to the second set of vulnerability nodes; Conduct penetration testing on the modified nodes: If the obtained type-I difference vulnerability nodes and type-II difference vulnerability nodes are newly added vulnerability nodes, add them to the second set of vulnerability nodes; If the type-I vulnerability nodes or type-II vulnerability nodes existing in the risk nodes before update are repaired and there are no newly added vulnerability nodes, delete this risk node from the first set of vulnerability nodes.

3. The method for iteratively penetrating and testing vulnerabilities of a mobile application based on dynamic environment adaptation according to claim 1, wherein, In S2, conduct penetration testing on all nodes in the set of potential risk nodes to obtain vulnerability nodes with vulnerabilities. The process of penetration testing is: Use dynamic detection tools to conduct dynamic verification on all nodes in the set of potential risk nodes for weak key security, SQL injection attack, and authentication bypass respectively, and obtain vulnerability nodes with different types of vulnerabilities such as weak key security vulnerability, SQL injection attack vulnerability, and authentication bypass vulnerability respectively.

4. The iterative penetration testing method for mobile application vulnerabilities based on dynamic environment adaptation according to claim 1, wherein In S3, scan the external dependency libraries used by each node in the set of potential risk nodes for vulnerabilities, mark the nodes corresponding to the external dependency libraries with detected vulnerabilities as type-II vulnerability nodes, and obtain the vulnerability information of each external dependency library. The vulnerability information includes: the number of vulnerabilities, vulnerability numbers, and vulnerability CVSS scores.

5. The method for iterative penetration testing of mobile application vulnerabilities based on dynamic environment adaptation according to claim 4, wherein, Calculate the risk score of the external dependency library based on the number of vulnerabilities and the CVSS score of the vulnerabilities in the external dependency library. List the external dependency libraries with a risk score greater than or equal to the risk score threshold in the blacklist of dependency libraries used for mobile application version updates. The calculation formula for the risk score is as follows: Wherein, R is the risk score, n is the number of vulnerabilities in the external dependency library, N is the number of code blocks where the external dependency library is called, w i is the weighting coefficient corresponding to vulnerability i, and CVSS i is the CVSS score of vulnerability i.

6. The method for iteratively penetrating and testing vulnerabilities of a mobile application based on dynamic environment adaptation according to claim 1, wherein Perform penetration testing on the pruned nodes obtained in S4: If there is a type I vulnerability node or a type II vulnerability node among the corresponding risk nodes to be pruned before the update, delete this risk node from the first vulnerability node set.

7. The iterative penetration testing method for mobile application vulnerabilities based on dynamic environment adaptation according to claim 1, characterized in that In S1, traverse the abstract syntax tree to extract nodes related to the invocation of risk components. The risk components include the Activity component, Service component, Content Provider component, and Broadcast Receiver component of the mobile application.

8. A mobile application vulnerability iterative penetration testing system based on dynamic environment adaptation, characterized in that, Include: Code parsing module: used to obtain the APK file of the current version of the mobile application, obtain the compiled code through decompilation processing, perform code parsing on the compiled code, generate an abstract syntax tree based on the logical call relationship of functions, traverse the abstract syntax tree to extract risk nodes related to the invocation of risk components, and construct a potential risk node set based on all nodes; Type I vulnerability confirmation module: used to perform penetration testing on all nodes in the potential risk node set, mark the nodes with vulnerabilities as type I vulnerability nodes, and construct a first vulnerability node set based on all type I vulnerability nodes; Type II vulnerability confirmation module: used to perform vulnerability scanning on the external dependency libraries used by each node in the potential risk node set, mark the nodes corresponding to the external dependency libraries with detected vulnerabilities as type II vulnerability nodes, and add the type II vulnerability nodes to the first vulnerability node set; Associate the node positions of the type I vulnerability nodes and type II vulnerability nodes in the abstract syntax tree to the first vulnerability node set respectively; Difference analysis module: used to repeatedly execute S1 for the updated version of the mobile application, construct an iterative risk node set, perform node difference analysis on the iterative risk node set and the potential risk node set, and obtain difference nodes: newly added nodes, pruned nodes, and modified nodes; Iterative penetration testing module: used to trigger penetration testing on the newly added nodes and modified nodes to obtain type I difference vulnerability nodes; Perform vulnerability scanning on the external dependency libraries used by the newly added nodes and modified nodes to obtain type II difference vulnerability nodes; Update the type I difference vulnerability nodes and type II difference vulnerability nodes to the first vulnerability node set to obtain a second vulnerability node set. Associate the node positions of the type I difference vulnerability nodes and type II difference vulnerability nodes in the abstract syntax tree to the second vulnerability node set respectively to obtain the vulnerability test result of the updated version of the mobile application.

9. A mobile application vulnerability iterative penetration testing device based on dynamic environment adaptation, characterized in that, It includes a processor and a memory. Among them, when the processor executes the computer program stored in the memory, it implements the method for iterative penetration testing of mobile application vulnerabilities based on dynamic environment adaptation as described in any one of claims 1-7.

10. A computer-readable storage medium, characterized in that, Used to store a computer program. Among them, when the computer program is executed by the processor, it implements the method for iterative penetration testing of mobile application vulnerabilities based on dynamic environment adaptation as described in any one of claims 1-7.

Citation Information

Patent Citations

  • Method and apparatus for detecting system vulnerability, computer device and storage medium

    CN108965327A

  • Event-driven vulnerability penetration test system, method, device and equipment

    CN115987673A

  • Vulnerability verification method, system and device based on static security test and medium

    CN119538253A

  • Code vulnerability detection and validation

    US20250061207A1