Data transmission security test method and device, medium and program product
By capturing the transmitted data between the equipment and the service platform, generating simulated event data and simulating actual scenarios, the problems of comprehensiveness and low degree of automation in the existing technology are solved, and efficient data transmission security performance testing is achieved.
Patent Information
- Application Number
- CN202510903500.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-01
- Publication Date
- 2025-08-19
- Estimated Expiration
- 2045-07-01
AI Technical Summary
The prior art tests are not comprehensive and have low degree of automation in equipment data transmission security performance testing, and cannot effectively simulate actual threats, resulting in inefficient testing.
By capturing the transmitted data of the tested device and the service platform, generating simulated event data, and sending it to the measured device using the simulated base station to simulate specific events in the actual usage scenario, the response status of the test device, and combining preset test cases and playback attacks, the security test results are determined.
It improves the comprehensiveness and efficiency of equipment testing, can accurately simulate actual threat scenarios, and improves the accuracy and automation of data transmission security performance testing.
Smart Images

Figure CN120512697A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of security testing technology, and in particular to a data transmission security testing method, device, medium, and program product. Background Art
[0002] With the development of mobile communications and smart devices, OTA (Over-The-Air) upgrades have become a common method for remote firmware updates. Using this technology, device manufacturers or service providers can push firmware updates to user devices over wireless networks to fix vulnerabilities, improve performance, and add new features. OTA upgrades have become particularly important in smartphones, embedded systems, automotive electronics, and other fields.
[0003] In testing scenarios such as before device shipment, it's often necessary to test the device's data transmission security performance under different service functions, such as during an OTA upgrade. Currently, testing device transmission security performance is limited to passive packet capture and static analysis, lacking the ability to actively simulate specific events. This results in limited testing comprehensiveness. Furthermore, the testing process relies heavily on manual operations and has a low level of automation, resulting in low testing efficiency. Summary of the Invention
[0004] The purpose of the embodiments of the present application is to provide a data transmission security testing method, device, medium and program product to improve the comprehensiveness and testing efficiency of the data transmission security performance testing of the device.
[0005] In a first aspect, an embodiment of the present application provides a data transmission security testing method, comprising: Capture the transmission data between the device under test and the service platform; generating simulated event data based on the transmission data; Sending the simulated event data to the device under test; determining a response state of the device under test to the simulated event data; A security test result of the device under test is determined based on the response status.
[0006] In an embodiment of the present application, by capturing the transmission data between the device and the service platform and generating simulated event data, it is possible to automatically simulate specific events in actual usage scenarios and test the response status of the device, thereby effectively improving the comprehensiveness and efficiency of device testing.
[0007] In some possible embodiments, the device under test communicates with the service platform through a simulated base station; The capturing of the transmission data between the device under test and the service platform includes: The data application unit of the simulated base station is used to capture the transmission data of the communication between the device under test and the service platform.
[0008] In an embodiment of the present application, by utilizing a simulated base station as the communication medium between the device under test and the service platform, the communication transmission data between the device under test and the service platform can be automatically captured based on the data application unit of the simulated base station, thereby further improving the accuracy of the transmission security test.
[0009] In some possible embodiments, sending the simulated event data to the device under test includes: The simulated event data is imported into the simulated base station, so that the simulated base station sends the simulated event data to the device under test.
[0010] In an embodiment of the present application, by using a simulated base station to send simulated event data, it is possible to simulate specific events in a real transmission scenario and perform performance testing, further improving the accuracy of the transmission security test.
[0011] In some possible embodiments, generating simulation event data based on the transmission data includes: The transmission data is tampered with according to a preset data tampering test case to obtain corresponding simulated event data.
[0012] In the embodiment of the present application, data tampering events are simulated to test the response and security of the device, thereby further improving the comprehensiveness of the data transmission security performance test.
[0013] In some possible embodiments, generating simulation event data based on the transmission data includes: Based on the transmission data, corresponding simulation event data is generated according to a preset replay test case.
[0014] In the embodiment of the present application, the response and security of the device are tested by simulating replay attack events, thereby further improving the comprehensiveness of the data transmission security performance test.
[0015] In some possible embodiments, the transmission data is data required by the device under test when executing a preset OTA upgrade process.
[0016] In an embodiment of the present application, by performing simulation tests on the transmission data of the OTA upgrade scenario, the data transmission security during the OTA upgrade process can be accurately tested.
[0017] In some possible embodiments, determining a security test result of the device under test based on the response status includes: Initializing data for the device under test; Triggering the device under test to re-execute the preset OTA upgrade process; Determine a second response state of the device under test when re-executing the preset OTA upgrade process; A security test result of the device under test is determined based on the response status and the second response status.
[0018] In an embodiment of the present application, after the simulated data transmission test, the data of the device under test is initialized and the normal OTA upgrade process is re-executed. The security test results are comprehensively determined based on the response status of the simulated event test process and the normal test process, thereby further improving the accuracy of the transmission security test.
[0019] In a second aspect, an embodiment of the present application provides a data transmission security testing device, comprising: Data capture module, used to capture the transmission data between the device under test and the service platform; a simulation generation module, configured to generate simulation event data based on the transmission data; A data sending module, configured to send the simulated event data to the device under test; a response determination module, configured to determine a response status of the device under test to the simulated event data; A result determination module is used to determine a security test result of the device under test based on the response status.
[0020] In a third aspect, an embodiment of the present application provides an electronic device comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, wherein the processor can implement the method described in any embodiment of the first aspect when executing the program.
[0021] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the method described in any embodiment of the first aspect can be implemented.
[0022] In a fifth aspect, an embodiment of the present application provides a computer program product, which includes a computer program, wherein when the computer program is executed by a processor, it can implement the method described in any embodiment of the first aspect. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following is a brief introduction to the drawings required for use in the embodiments of the present application. It should be understood that the following drawings only show certain embodiments of the present application and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other relevant drawings can be obtained based on these drawings without creative work.
[0024] Figure 1 A flowchart of a data transmission security testing method provided in an embodiment of the present application; Figure 2 A test topology diagram of the data transmission security testing method provided in an embodiment of the present application; Figure 3 A schematic diagram of the structure of a data transmission security testing device provided in an embodiment of the present application; Figure 4 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0025] The technical solutions in the embodiments of the present application will be described below in conjunction with the drawings in the embodiments of the present application.
[0026] It should be noted that similar reference numerals and letters represent similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined or explained in subsequent drawings. At the same time, in the description of this application, the terms "first", "second", etc. are only used to distinguish the description and should not be understood as indicating or implying relative importance.
[0027] It should be noted that smart devices and automotive systems require multiple tests before leaving the factory. In addition to basic mechanical and electrical safety tests, they often also require functional and performance testing. For example, testing the device's data transmission security performance, including data transmission security performance testing during the OTA upgrade process.
[0028] Currently, traditional approaches to data transmission security testing primarily rely on pre-set, fixed transmission scenarios, capturing data packets during transmission to perform basic security analysis of communication link status, encryption protocols, and sensitive information. Because these approaches rely solely on passive packet capture and static analysis, they are unable to simulate real-world threats like man-in-the-middle attacks and data tampering, resulting in limited testing. Furthermore, the testing process is heavily reliant on manual operations and has a low level of automation, hindering efficiency and making it difficult to meet the rapid iteration requirements of connected vehicle testing.
[0029] In response to the problems existing in the above-mentioned prior art, an embodiment of the present application provides a data transmission security testing method, which can not only effectively increase the coverage of test scenarios and improve the comprehensiveness of the test; but also improve the degree of automation of the test process, thereby improving test efficiency.
[0030] like Figure 1 As shown, the embodiment of the present application provides a data transmission security testing method, which may include the following steps: S1. Capture the transmission data between the device under test and the service platform.
[0031] The method of the embodiment of the present application can be executed by an automated testing device, which can be a PC detection device in which one or more testing tools can be deployed.
[0032] For example, by connecting the automated test equipment, the device under test, and the service platform to the same communication network, the devices can communicate with each other.
[0033] Based on this, data communication of specific functions can be carried out between the service platform and the device under test, such as initiating / receiving instructions or requests between the service platform and the device under test, the device under test downloading data from the service platform, and the device under test uploading data to the service platform.
[0034] For example, the automated testing equipment may capture the transmission data between the device under test and the service platform in a preset manner during the implementation of a certain communication function, for example, by accessing the data transceiver API interface of the device under test or the service platform to capture data.
[0035] For example, the captured transmission data can be PCAP packets. PCAP (Packet Capture) is a standard file format for storing captured network data packets. It is widely used in network analysis, monitoring, and security, and is often generated by tools such as Wireshark (a network packet analysis software) and TCPDump (a network data collection and analysis tool). PCAP files record the raw data of network packets and their metadata (such as capture time and length), facilitating offline analysis.
[0036] It should be noted that automated test equipment can capture transmission data through serial access. That is, the automated test equipment can intercept data transmitted between the device under test and the service platform and then control (or modify) the transmission and reception of this data. Alternatively, automated test equipment can capture transmission data through parallel or bypass access. In this manner, the automated test equipment's data capture process does not affect the data being sent and received between the device under test and the service platform.
[0037] S2. Generate simulated event data based on the transmission data.
[0038] Based on the captured transmission data, the automated testing equipment can generate corresponding simulated event data according to preset conversion rules. For example, simulated event data can be data that performs relevant operations on the transmission data, such as generating an event instruction set for illegally intercepting or attempting to crack the transmission data; it can also be secondary transmission data generated after relevant modifications have been made to the transmission data.
[0039] S3. Send simulated event data to the device under test.
[0040] After generating the simulated event data, the automated test equipment may send the simulated event data to the device under test.
[0041] For example, the automated test equipment may replace the originally captured transmission data with the simulated event data to send to the device under test; or it may keep the transmission of the original transmission data intact and additionally send these simulated event data on this basis.
[0042] S4. Determine the response status of the device under test to the simulated event data.
[0043] For example, corresponding test items may be set for different simulated event data. After the simulated event data is sent to the device under test, the response status of the device under test to the simulated event data may be determined based on these test items.
[0044] For example, it is possible to test whether the device under test can identify the specific simulated event corresponding to the simulated event data; it is possible to test the various processing performances of the device under test for transmitted data under the influence of the simulated event data, such as transmission confidentiality, transmission efficiency, transmission time, data integrity, accuracy, etc.
[0045] S5. Determine a security test result of the device under test based on the response status.
[0046] For example, the security test result of the device under test may be determined based on the response status of the device under test under different test items, and a corresponding test report may be generated.
[0047] Exemplarily, corresponding scoring rules and scoring contribution weights can also be set according to the importance of different test items. Based on the response status of the device under test under different test items, the comprehensive score of the device under test is calculated in combination with the corresponding scoring rules and scoring contribution weights, and the security test results of the device under test are determined based on this.
[0048] It should be noted that the test processes in the embodiments of the present application can be automatically executed through preset test strategies, thereby effectively reducing manual intervention and improving test efficiency and accuracy.
[0049] In an embodiment of the present application, by capturing the transmission data between the device under test and the service platform during the implementation of the function, generating simulated event data based on this and sending it to the device under test, it is possible to automatically simulate specific events in actual usage scenarios and test the device's response status to this, thereby effectively improving the comprehensiveness and efficiency of device testing.
[0050] In some possible embodiments, the device under test communicates with the service platform through a simulated base station; Step S1, capturing the transmission data between the device under test and the service platform, may include: S101: Utilize a data application unit of a simulated base station to capture transmission data between a device under test and a service platform.
[0051] For example, the R&S-CMW500 (a wireless communication tester) can be used to simulate a base station. It is a test platform widely used in wireless device R&D, certification, and production testing. It can simulate various wireless communication network environments and supports multiple communication standards, such as 2G, 3G, 4G, 5G, Wi-Fi, and Bluetooth.
[0052] It should be noted that by installing a CMW500 white card on the device under test, it can communicate with the automated test equipment and the service platform. The device under test and the service platform can communicate through a simulated base station (such as CMW500). Based on this, the simulated base station can capture the transmission data between the device under test and the service platform through its Data Application Unit (DAU).
[0053] As you can understand, the DAU module is a key component of the CMW500, specifically designed for data application testing. It captures and analyzes data packets (transmitted data) during communications between wireless devices (e.g., between the device under test and the service platform), supporting functions such as packet capture, analysis, replay, and tampering. By utilizing the CMW500's DAU module to capture and analyze inter-device communication messages, the security of the transmission process can be more effectively verified.
[0054] For example, the DAU module can capture all data packets sent and received by the wireless device during the OTA upgrade process, including control information, firmware data, etc. For example, by analyzing the captured messages (transmission data), the integrity and security of the data transmission can be checked, such as checking the SSL / TLS protocol version, key exchange process, and encryption algorithm usage.
[0055] Based on this, by building a simulated base station to achieve communication between the device under test and the service platform, the data application unit based on the simulated base station can automatically capture the communication transmission data between the device under test and the service platform, further improving the accuracy of the transmission security test.
[0056] In some possible embodiments, step S3, sending simulated event data to the device under test, may include: S301: Importing simulated event data into a simulated base station, so that the simulated base station sends the simulated event data to a device under test.
[0057] It should be noted that the automated test equipment can import data into the simulated base station, thereby calling the relevant API interface through the simulated base station to send simulated event data to the device under test.
[0058] For example, after the automated testing equipment generates the simulated event data, the simulated event data can be transmitted and imported into the simulated base station via a communication method such as wired, wireless, Bluetooth, or WIFI.
[0059] Based on this, by using simulated base stations to transmit simulated event data, it is possible to more conveniently and efficiently simulate specific events in real transmission scenarios and conduct performance tests, further improving the accuracy of transmission security tests.
[0060] In some possible embodiments, step S2, generating simulated event data based on the transmission data, may include: S201: Tamper with the transmission data according to a preset data tampering test case to obtain corresponding simulated event data.
[0061] It should be noted that after capturing the data transmitted between the device under test and the service platform, the data can be tampered with based on a pre-set data tampering test. By sending the tampered message (simulated event data) to the device under test, the device's ability to detect and handle tampered data can be tested.
[0062] Illustratively, based on a preset data tampering test case, the transmitted data can be tampered with by adding a tampering method of the preset data content to obtain the modified data as the simulated event data.
[0063] Exemplarily, based on a preset data tampering test case, the transmitted data may be tampered with by deleting the content, and the modified data may be obtained as simulated event data.
[0064] Exemplarily, based on preset data tampering test cases, the parameters or content in the transmitted data can also be changed according to preset rules (the tampering method of changing the parameter content), such as modifying the content of the data packet, encryption algorithm parameters, etc., to obtain the modified data as simulated event data.
[0065] It should be noted that for the simulated event data generated by different data tampering test cases, the corresponding response status of the device under test can be tested and obtained respectively, and corresponding security test results can be generated according to different response statuses.
[0066] For example, different data tampering test cases refer to test cases with different tampering types (addition, deletion, or modification), or they may refer to test cases with the same tampering type but different degrees of tampering. For example, for a tampering method involving the addition (deletion) of preset data content, different amounts of data addition (deletion) can be set for different data tampering test cases; for a tampering method involving the modification of parameter content, different modification rules can be set for different data tampering test cases.
[0067] Based on this, corresponding simulated event data is generated through preset test cases, thereby simulating data tampering events in actual scenarios to test the response and security of the device, thereby further improving the comprehensiveness of data transmission security performance testing.
[0068] In some possible embodiments, step S2, generating simulated event data based on the transmission data, may include: S211. Based on the transmission data, generate corresponding simulation event data according to the preset replay test case.
[0069] It's important to note that replay attacks, also known as replay attacks or playback attacks, occur when an attacker sends a packet that has already been received by a target device in order to deceive the system. These attacks are primarily used during the authentication process to compromise the authenticity of the authentication process. Replay attacks can be carried out by the attacker or by an adversary that intercepts and retransmits the data.
[0070] Based on automated test equipment or simulated base stations themselves, it is possible to simulate replay attack events in actual scenarios.
[0071] For example, based on the captured transmission data, you can choose to replay the unmodified transmission data directly or the modified data. By resending the captured message (transmission data) to the device under test, you can test the device's ability to handle duplicate data packets and its security against replay attacks.
[0072] For example, replaying network packets in PCAP format can be used to reproduce faults or test device performance, supporting IPv4 / IPv6 protocol stacks and filtered replay. For example, the replay process can also be implemented using testing tools such as Wireshark.
[0073] It should be noted that before replaying the data, you can replay the entire PCAP file or selectively filter specific messages for replay. For example, if you want to test the sending function of the client or simulate the client to launch an attack, it is more appropriate to selectively filter and replay the messages sent by the client; if you want to test the entire interaction process, including the response of the service platform, it is more appropriate to use a complete replay. In addition, you can also make a selection based on the size of the PCAP file: if it is determined that the PCAP file is larger than a preset threshold, you can use a filtered replay method to improve efficiency. In addition, if the network environment is complex and there is interference, you can use a complete replay method to better simulate the real environment.
[0074] It should be noted that by utilizing the automated testing process of the embodiments of the present application, more test scenarios can be covered, including tampering and replay testing of transmitted data, effectively improving the comprehensiveness of the test.
[0075] Based on this, the comprehensiveness of data transmission security performance testing is further improved by simulating replay attack events to test the response and security of the device.
[0076] In some possible embodiments, the transmitted data is data required by the device under test when executing a preset OTA upgrade process.
[0077] like Figure 2 As shown, it can be understood that the service platform is a platform for providing OTA upgrade functions to the device under test. The device under test communicates with the service platform (OTA upgrade platform) through the installed white card and can respond to preset trigger instructions to execute the preset OTA upgrade process.
[0078] By capturing data transmitted between the device under test and the service platform during the pre-set OTA upgrade process, the captured data can be analyzed using pre-set scripts, Wireshark tools, or the CMW500's built-in message replay software, such as performing a security analysis of the PCAP packets. For example, tests can include verifying the security of data transmission during the OTA upgrade process, such as analyzing SSL / TLS versions, checking key exchange and authentication methods, and evaluating symmetric encryption algorithms and integrity protection algorithms.
[0079] It should be noted that traditional device testing solutions are not optimized for OTA upgrade scenarios and lack specialized testing for key aspects such as firmware signature verification and integrity check. The embodiments of this application test OTA upgrade scenarios, adding dedicated test items such as signature verification and integrity check, to test upgrade package anti-tampering, anti-counterfeiting and other security items.
[0080] It can be understood that the automated testing method of the embodiment of the present application can ensure that the data transmission of the device under test during the OTA upgrade process is more secure and protect the user device from attacks.
[0081] Based on this, by conducting simulation tests on the transmission data of the OTA upgrade scenario, the data transmission security during the OTA upgrade process can be accurately tested.
[0082] In some possible embodiments, step S5, determining a security test result of the device under test based on the response status, may include: S501, initializing data of the device under test; S502: Trigger the device under test to re-execute the preset OTA upgrade process; S503: Determine the second response state of the device under test when re-executing the preset OTA upgrade process; S504: Determine a security test result of the device under test based on the response status and the second response status.
[0083] It should be noted that after completing the process of testing the device under test based on the simulated event data, the data of the device under test can be initialized, that is, the device under test is restored to the state before step S1 (before data transmission with the service platform); then, the device under test is triggered to re-execute the preset OTA upgrade process. During the re-execution of the preset OTA upgrade process, no simulated event data is generated, and no other impact is exerted on the device under test. The device under test is in the second response state of re-executing the preset OTA upgrade process (that is, testing the response state of the device under test when normally executing the preset OTA upgrade process); finally, the response state and the second response state are combined to comprehensively determine the security test result of the device under test.
[0084] For example, the response state represents the security performance of the device under test when it is affected by attack events such as data tampering and replay during the OTA upgrade process, and the second response state represents the security performance of the device under test when it is not affected by other influencing factors during the OTA upgrade process. Therefore, the difference in security performance between the two can be compared as a basis for determining the security test results of the device under test.
[0085] Based on this, after the simulated data transmission test, the data of the device under test is initialized and the normal OTA upgrade process is re-executed. The security test results are comprehensively determined according to the response status of the simulated event test process and the normal test process, thereby further improving the accuracy of the transmission security test.
[0086] Please refer to Figure 3 , Figure 3The data transmission security test device provided in some embodiments of the present application is shown in the block diagram. It should be understood that the data transmission security test device is similar to the above-mentioned Figure 1 Corresponding to the method embodiment, the various steps involved in the above method embodiment can be executed. The specific functions of the data transmission security testing device can be found in the description above. To avoid repetition, detailed description is appropriately omitted here.
[0087] Figure 3 The data transmission security testing device includes at least one software function module that can be stored in a memory in the form of software or firmware or fixed in the data transmission security testing device, and the data transmission security testing device includes: The data capture module 310 is used to capture the transmission data between the device under test and the service platform; A simulation generation module 320 for generating simulation event data based on the transmission data; The data sending module 330 is used to send simulated event data to the device under test; a response determination module 340 for determining a response status of the device under test to the simulated event data; The result determination module 350 is configured to determine a security test result of the device under test based on the response status.
[0088] It can be understood that the above-mentioned device embodiment corresponds to the method embodiment of the present invention. The data transmission security testing device provided by the embodiment of the present invention can implement the data transmission security testing method provided by any method embodiment of the present invention.
[0089] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working process of the device described above can refer to the corresponding process in the aforementioned method, and will not be described in detail here.
[0090] like Figure 4 As shown, some embodiments of the present application provide an electronic device 400, which includes: a memory 410, a processor 420, and a computer program stored in the memory 410 and executable on the processor 420, wherein the processor 420 reads the program from the memory 410 through the bus 430 and executes the program to implement a method of any embodiment included in the above-mentioned data transmission security testing method.
[0091] Processor 420 can process digital signals and can include various computing architectures, such as a complex instruction set computer architecture, a reduced instruction set computer architecture, or an architecture that implements a combination of multiple instruction sets. In some examples, processor 420 can be a microprocessor.
[0092] The memory 410 can be used to store instructions executed by the processor 420 or data related to the execution of instructions. These instructions and / or data may include code for implementing some or all functions of one or more modules described in the embodiments of this application. The processor 420 of the embodiment of the present disclosure can be used to execute the instructions in the memory 410 to implement the method shown above. The memory 410 includes dynamic random access memory, static random access memory, flash memory, optical memory, or other memory known to those skilled in the art.
[0093] Some embodiments of the present application further provide a computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a processor, the method described in the method embodiment is executed.
[0094] Some embodiments of the present application further provide a computer program product, which, when executed on a computer, enables the computer to execute the method described in the method embodiment.
[0095] It should be noted that the various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. Similarities between the various embodiments can be referred to in conjunction with each other. For device embodiments, since they are generally similar to method embodiments, their description is relatively simple, and for relevant details, reference can be made to the description of the method embodiments.
[0096] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can also be implemented in other ways. The device embodiments described above are merely illustrative. For example, the flowcharts and block diagrams in the accompanying drawings show the possible architectures, functions, and operations of the devices, methods, and computer program products according to the multiple embodiments of the present application. In this regard, each box in the flowchart or block diagram can represent a module, a program segment, or a portion of code, and the module, program segment, or a portion of code contains one or more executable instructions for implementing the specified logical functions. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in an order different from that marked in the accompanying drawings. For example, two consecutive boxes can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flowchart, and the combination of boxes in the block diagram and / or flowchart, can be implemented using a dedicated hardware-based system that performs the specified function or action, or can be implemented using a combination of dedicated hardware and computer instructions.
[0097] In addition, the functional modules in each embodiment of the present application can be integrated together to form an independent part, or each module can exist independently, or two or more modules can be integrated to form an independent part.
[0098] If the functions are implemented in the form of software function modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes a number of instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as USB flash drives, mobile hard drives, read-only memories (ROM), random access memories (RAM), magnetic disks or optical disks.
[0099] The foregoing is merely an embodiment of the present application and is not intended to limit the scope of protection of the present application. Various modifications and variations are possible for those skilled in the art. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present application shall be included within the scope of protection of the present application. It should be noted that similar reference numerals and letters represent similar items in the following figures. Therefore, once an item is defined in one figure, it does not need to be further defined or explained in subsequent figures.
[0100] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.
[0101] It should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply the existence of any such actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article, or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or device. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of other identical elements in the process, method, article, or device comprising the element.
Claims
1. A data transmission security testing method, characterized in that: include: Capture the transmission data between the device under test and the service platform; generating simulated event data based on the transmission data; Sending the simulated event data to the device under test; determining a response state of the device under test to the simulated event data; A security test result of the device under test is determined based on the response status.
2. The data transmission security testing method according to claim 1, characterized in that: The device under test communicates with the service platform through a simulated base station; The capturing of the transmission data between the device under test and the service platform includes: The data application unit of the simulated base station is used to capture the transmission data of the communication between the device under test and the service platform.
3. The data transmission security testing method according to claim 2, characterized in that: The sending the simulated event data to the device under test includes: The simulated event data is imported into the simulated base station, so that the simulated base station sends the simulated event data to the device under test.
4. The data transmission security testing method according to claim 1, wherein: The generating of simulation event data based on the transmission data comprises: The transmission data is tampered with according to a preset data tampering test case to obtain corresponding simulated event data.
5. The data transmission security testing method according to claim 1, wherein: The generating of simulation event data based on the transmission data comprises: Based on the transmission data, corresponding simulation event data is generated according to a preset replay test case.
6. The data transmission security testing method according to claim 1, characterized in that: The transmission data is the data required by the device under test when executing a preset OTA upgrade process.
7. The data transmission security testing method according to claim 6, characterized in that: Determining a security test result of the device under test based on the response status includes: Initializing data for the device under test; Triggering the device under test to re-execute the preset OTA upgrade process; Determine a second response state of the device under test when re-executing the preset OTA upgrade process; A security test result of the device under test is determined based on the response status and the second response status.
8. An electronic device, characterized in that: The invention comprises a memory, a processor and a computer program stored in the memory and executable on the processor, wherein the processor can implement the data transmission security testing method according to any one of claims 1 to 7 when executing the program.
9. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the data transmission security testing method according to any one of claims 1 to 7 is executed.
10. A computer program product, characterized in that The computer program product includes a computer program, and when the computer program is executed by a processor, the data transmission security testing method according to any one of claims 1 to 7 is implemented.
Citation Information
Patent Citations
Penetration testing method and device based on central computing platform
CN115563618A
Intelligent networked automobile data security test system and method
CN116545903A
Security test method and device for equipment
CN117527442A
Computer-implemented method and data processing system for testing device security
WO2018084808A1
Method for automatically testing network element, test center, test network element, and storage medium
WO2024187877A1