Framework characteristic-based php automatic vulnerability scanning method, apparatus and device, and medium

By building a PHP framework feature library and syntax analysis technology, the problems of framework identification and time consumption in PHP vulnerability scanning are solved, and efficient and accurate vulnerability detection is achieved.

CN120597285APending Publication Date: 2025-09-05HANGZHOU ANHENG INFORMATION SECURITY TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510747912.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-05
Publication Date
2025-09-05

AI Technical Summary

Technical Problem

Existing PHP automated vulnerability mining technology has difficulty identifying framework-based user parameter input and dangerous functions, and scanning takes too long in a complex PHP framework environment, affecting the efficiency and accuracy of vulnerability detection.

Method used

By building an input function feature library, a dangerous function feature library and a user development path library, and combining syntax analysis and taint analysis technology, vulnerability scanning is performed on the PHP framework characteristics, vulnerability scanning parameters are determined and vulnerability scanning results are generated.

Benefits of technology

It shortens vulnerability scanning time, improves the accuracy and practicality of vulnerability detection, and can quickly identify potential security risks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120597285A_ABST
    Figure CN120597285A_ABST
Patent Text Reader

Abstract

The invention discloses a php automatic vulnerability scanning method and device based on framework characteristics, equipment and a medium, and relates to the technical field of computers. Comprising the following steps: analyzing a target php code obtained from a target code library to obtain framework information of the target php code; determining vulnerability scanning parameters corresponding to the target php code based on the framework information and a preset vulnerability parameter configuration library; the vulnerability parameter configuration library is a database generated based on a plurality of php frameworks; the vulnerability scanning parameters comprise an input function, a danger function, vulnerability scanning times, vulnerability scanning depth and a scanning directory; and performing vulnerability scanning operation on the target php code based on the vulnerability scanning parameter to obtain a corresponding vulnerability scanning result. Therefore, automatic vulnerability mining can be carried out for the php, the vulnerability scanning time is shortened, and the vulnerability detection accuracy and practicability are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer technology, and in particular to a PHP automated vulnerability scanning method, device, equipment and medium based on framework characteristics. Background Art

[0002] PHP (Hypertext Preprocessor) is a general-purpose open-source scripting language that is cross-platform, easy to read, and simple to develop. It can be used to create simple personal web pages, meeting basic needs such as displaying personal information, as well as supporting the development of complex enterprise applications, such as large e-commerce platforms and enterprise management systems, with complex business logic. Its flexibility and ease of use make PHP an ideal choice for rapid prototyping and iteration, and it is particularly widely used in small and medium-sized projects and startups. However, due to the widespread use of PHP in numerous web applications, manual vulnerability discovery is inefficient and prone to omissions. Therefore, to ensure the security of these PHP-based web applications, research and practice in automated PHP vulnerability discovery is particularly important. This approach can improve vulnerability discovery efficiency while maximizing the comprehensiveness of potential security risks, ensuring the stable and secure operation of web applications.

[0003] Existing technical solutions primarily utilize a combination of dynamic and static analysis techniques, leveraging the comprehensiveness of static analysis and the accuracy of dynamic analysis. By using dynamic analysis to verify static analysis results, more accurate results can be obtained while reducing false positive rates. However, existing automated vulnerability mining technologies have the following limitations. Firstly, due to the variability of the PHP language and the complexity of modern PHP frameworks, existing automated analysis programs struggle to identify framework-specific user parameter input, resulting in input parameter recognition failures. In actual automated vulnerability mining, many PHP applications are built using various frameworks, each with its own unique architecture and parameter passing methods. When processing user requests, input parameters are encapsulated, routed, and forwarded. Automated analysis programs are often designed based on common PHP syntax rules and common input patterns, making it difficult to accurately understand how these frameworks obtain, process, and pass user input parameters. Secondly, existing automated analysis programs struggle to identify dangerous functions within the framework, or, after discovering a dangerous function, are unable to iterate and re-scan. PHP has a rich function library, which contains numerous functions that may pose security risks. In complex PHP framework environments, calls to these functions may be hidden by the framework's design patterns or encapsulated through multiple layers of encapsulation. On the other hand, due to the sheer size of the framework and its add-ons, existing automated tools consume a significant amount of time during scanning. Modern PHP applications often integrate numerous framework components and third-party plug-ins to achieve rich functionality. A complete PHP project may contain a large number of code files, ranging from the framework's core code, various extension module codes, to business logic code. Each component has a large number of code files. When automated vulnerability mining tools scan these, they need to traverse numerous file directories and analyze various code logic and function call relationships. This makes the scanning process time-consuming, especially when dealing with large, complex PHP applications. This time cost can be unacceptably high, seriously affecting vulnerability mining efficiency and making it impossible to promptly discover and fix security risks in the application.

[0004] From the above, it can be seen that how to automate vulnerability mining for PHP, shorten vulnerability scanning time and improve the accuracy and practicality of vulnerability detection is an urgent problem to be solved. Summary of the Invention

[0005] In view of this, the purpose of the present invention is to provide a framework-based automated vulnerability scanning method, device, equipment, and medium for PHP, which can automatically detect vulnerabilities in PHP, shorten vulnerability scanning time, and improve the accuracy and practicality of vulnerability detection. The specific scheme is as follows:

[0006] In the first aspect, the present application provides a PHP automated vulnerability scanning method based on framework characteristics, including:

[0007] Obtaining target PHP code from a target code library and analyzing the target PHP code to obtain framework information of the target PHP code; the target code library includes a local code library and a remote code library;

[0008] Determining vulnerability scanning parameters corresponding to the target PHP code based on the framework information and a preset vulnerability parameter configuration library; the vulnerability parameter configuration library is a database generated based on several PHP frameworks, including an input function feature library, a dangerous function feature library, and a user development path library; the vulnerability scanning parameters include input functions, dangerous functions, vulnerability scan times, vulnerability scan depth, and scan directories;

[0009] A vulnerability scanning operation is performed on the target PHP code based on the vulnerability scanning parameters to obtain corresponding vulnerability scanning results.

[0010] Optionally, before obtaining the target PHP code from the target code library, the method further includes:

[0011] Combing through several PHP frameworks to obtain several input functions and corresponding function calling methods corresponding to the several PHP frameworks, and building an input function feature library based on the several input functions and the corresponding function calling methods;

[0012] Determine the dangerous functions corresponding to the plurality of PHP frameworks based on historical PHP vulnerability cases, and build a dangerous function feature library based on the dangerous functions;

[0013] The directory structure, file naming conventions and module organization of the several PHP frameworks are analyzed, and a user development path library is constructed based on the analysis results.

[0014] Optionally, analyzing the target PHP code to obtain framework information of the target PHP code includes:

[0015] Determine the PHP framework corresponding to the target PHP code according to the code directory structure, naming rules and characteristic functions of the target PHP code to obtain the framework information of the target PHP code.

[0016] Optionally, determining vulnerability scanning parameters corresponding to the target PHP code based on the framework information and a preset vulnerability parameter configuration library includes:

[0017] Determine an input function corresponding to the target PHP code based on the framework information and the input function feature library;

[0018] Determine the dangerous function corresponding to the target PHP code based on the framework information and the dangerous function feature library;

[0019] A scan directory corresponding to the target PHP code is determined based on the framework information and the user development path library.

[0020] Optionally, performing a vulnerability scanning operation on the target PHP code based on the vulnerability scanning parameters to obtain corresponding vulnerability scanning results includes:

[0021] Performing a syntax analysis operation on the target PHP code using a preset syntax analysis technology to obtain an abstract syntax tree corresponding to the target PHP code, and determining, based on the abstract syntax tree, call conditions of various functions and parameter information of logical structures contained in the target PHP code;

[0022] Determining tainted data using a preset taint analysis technology based on an input function corresponding to the target PHP code; the tainted data is user input data that poses a security risk;

[0023] Perform data flow analysis on the parameter information to generate a data flow propagation chain related to the tainted data, and generate corresponding vulnerability scanning results based on the data flow propagation chain and the dangerous function corresponding to the target PHP code.

[0024] Optionally, performing data flow analysis on the parameter information to generate a data flow propagation chain related to the tainted data includes:

[0025] A program data flow graph is generated based on the parameter information, and the tainted data is tracked based on the program data flow graph to generate a data flow propagation chain related to the tainted data.

[0026] Optionally, after performing a vulnerability scanning operation on the target PHP code based on the vulnerability scanning parameters to obtain corresponding vulnerability scanning results, the method further includes:

[0027] A vulnerability scanning report in a preset data format is output according to the vulnerability scanning result; the preset format includes a text format and a structured data format.

[0028] In a second aspect, the present application provides a PHP automated vulnerability scanning device based on framework characteristics, including:

[0029] A framework information acquisition module is used to obtain target PHP code from a target code library and analyze the target PHP code to obtain framework information of the target PHP code; the target code library includes a local code library and a remote code library;

[0030] A vulnerability scanning parameter configuration module is configured to determine vulnerability scanning parameters corresponding to the target PHP code based on the framework information and a preset vulnerability parameter configuration library; the vulnerability parameter configuration library is a database generated based on several PHP frameworks, including an input function feature library, a dangerous function feature library, and a user development path library; the vulnerability scanning parameters include input functions, dangerous functions, vulnerability scan times, vulnerability scan depth, and scan directories;

[0031] The vulnerability scanning result generating module is used to perform a vulnerability scanning operation on the target PHP code based on the vulnerability scanning parameters to obtain corresponding vulnerability scanning results.

[0032] In a third aspect, the present application provides an electronic device, comprising:

[0033] Memory, used to store computer programs;

[0034] A processor is used to execute the computer program to implement the aforementioned PHP automated vulnerability scanning method based on framework characteristics.

[0035] In a fourth aspect, the present application provides a computer-readable storage medium for storing a computer program, wherein the computer program, when executed by a processor, implements the aforementioned framework-based PHP automated vulnerability scanning method.

[0036] The present application provides a PHP automated vulnerability scanning method based on framework characteristics. First, the target PHP code is obtained from a target code library, and the target PHP code is analyzed to obtain the framework information of the target PHP code; the target code library includes a local code library and a remote code library; then, vulnerability scanning parameters corresponding to the target PHP code are determined based on the framework information and a preset vulnerability parameter configuration library; the vulnerability parameter configuration library is a database generated based on several PHP frameworks, including an input function feature library, a dangerous function feature library, and a user development path library; the vulnerability scanning parameters include input functions, dangerous functions, vulnerability scanning times, vulnerability scanning depth, and scanning directories; finally, a vulnerability scanning operation is performed on the target PHP code based on the vulnerability scanning parameters to obtain corresponding vulnerability scanning results.

[0037] As can be seen from the above, this application analyzes the framework information of the target PHP code and determines vulnerability scanning parameters corresponding to the target PHP code using the preset vulnerability parameter configuration library. In other words, the vulnerability scanning parameters used for vulnerability scanning are quickly matched from the preset vulnerability parameter configuration library based on the characteristics of different PHP frameworks, so as to perform vulnerability scanning on the target PHP code. This enables automated vulnerability mining for PHP, shortens vulnerability scanning time, and improves the accuracy and practicality of vulnerability detection. BRIEF DESCRIPTION OF THE DRAWINGS

[0038] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are merely embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without paying any creative work.

[0039] Figure 1 This is a flow chart of a PHP automated vulnerability scanning method based on framework characteristics disclosed in this application;

[0040] Figure 2 This is a schematic diagram of a PHP automated vulnerability scanning device based on framework characteristics disclosed in this application;

[0041] Figure 3 This is a structural diagram of an electronic device disclosed in this application. DETAILED DESCRIPTION

[0042] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0043] Traditional PHP vulnerability detection relies heavily on manual review, which has numerous limitations. First, manual review is an extremely time-consuming and labor-intensive process. Auditors must review code line by line, analyzing the code logic and the calls to various functions. Faced with a massive PHP codebase, this process can be time-consuming and inefficient. For example, in a large web application with numerous functional modules and tens or even hundreds of thousands of lines of code, manually troubleshooting common vulnerabilities like SQL injection and file manipulation can take weeks or even months, making it difficult to quickly assess the application's security. Second, manual review is prone to omissions. Due to limited human attention, prolonged code review can lead to fatigue, potentially overlooking potential vulnerabilities. Furthermore, the professional skills and experience levels of different auditors vary, making it difficult for inexperienced auditors to accurately identify more subtle or emerging vulnerability types. For example, complex code may be overlooked because auditors fail to thoroughly track changes in user input data during different execution stages. Furthermore, manual review coverage is relatively limited. Auditors can often only conduct investigations based on known vulnerability patterns and the attack methods they have mastered. It is difficult to detect unknown, undiscovered new vulnerabilities manually. With the continuous development of network technology, attackers' methods are becoming increasingly diverse and complex, and new types of vulnerabilities are constantly emerging. Manual audits alone are difficult to keep up with this changing trend and cannot comprehensively cover all possible security risks. In addition, manual audits lack standardized processes and repeatability. When reviewing the same code, different auditors may obtain different audit results due to their different ideas and methods, and it is difficult to ensure that the previous audit situation can be fully reproduced during the subsequent review process, which poses a challenge to the accuracy and stability of vulnerability mining. To this end, this application provides a PHP automated vulnerability scanning solution based on framework features, which can perform automated vulnerability mining for PHP, shorten vulnerability scanning time, and improve the accuracy and practicality of vulnerability detection.

[0044] See also Figure 1 As shown, the embodiment of the present application discloses a PHP automated vulnerability scanning method based on framework characteristics, including:

[0045] Step S11: Obtain target PHP code from a target code library, and analyze the target PHP code to obtain framework information of the target PHP code.

[0046] In this embodiment, the framework information used by the target PHP code is analyzed based on multiple dimensions such as code directory structure, naming rules, and characteristic functions. Specifically, analyzing the target PHP code to obtain the framework information of the target PHP code may include: determining the PHP framework corresponding to the target PHP code based on the code directory structure, naming rules, and characteristic functions of the target PHP code to obtain the framework information of the target PHP code. It is understood that the specific types of the target code library include, but are not limited to, local code libraries and remote code libraries.

[0047] In this embodiment, by analyzing and summarizing experience from numerous past PHP projects and mainstream frameworks, input functions are determined based on the characteristics of each framework, providing a key basis for subsequent vulnerability discovery. Common mainstream PHP frameworks such as Laravel, Symfony, and ThinkPHP all have relatively fixed functions and methods for processing user input. Taking the Laravel framework as an example, it provides a Request class to retrieve parameters passed by the user through different request methods. For example, the $request->input('name'); function is called to retrieve an input parameter with a specified name. Specifically, before obtaining the target PHP code from the target code library, the method may also include: sorting through several PHP frameworks to obtain several input functions and corresponding function call methods corresponding to the frameworks, and constructing an input function feature library based on these input functions and corresponding function call methods. Specifically, by collecting commonly used input functions and corresponding call methods from these different frameworks, categorizing them by framework, and clearly annotating information such as the request type each function targets and the characteristics of the parameters it obtains, an input feature library is constructed. In this way, when conducting automated vulnerability mining, facing PHP applications developed based on different frameworks, we can use this feature library to accurately locate and identify which functions are used to obtain user input, and then analyze whether these input data are used unreasonably during the subsequent code execution process, such as whether they enter dangerous functions without sufficient verification and filtering, thereby discovering possible vulnerabilities.

[0048] Furthermore, the PHP language contains numerous dangerous functions. These functions are called and hidden differently in different mainstream frameworks, making it particularly important to build a database of dangerous functions specific to mainstream frameworks. Taking the Laravel framework as an example, while the framework itself incorporates security considerations into the design of many functions, improper use by developers can still trigger vulnerabilities related to dangerous functions. For example, when functions like whereRaw and \DB::raw are called, they use native SQL statements for queries. The same situation occurs with the where function in thinkphp. When parameters are enclosed in double quotes, the thinkphp framework does not filter user input, leading to security issues. Specifically, before obtaining the target PHP code from the target code repository, the process can also include: determining dangerous functions corresponding to the various PHP frameworks based on historical PHP vulnerability cases, and building a dangerous function signature library based on these dangerous functions. Specifically, by referring to the code audit experience and security vulnerability cases of numerous past PHP projects and combining existing knowledge of dangerous PHP functions, the specific manifestations of these functions in mainstream frameworks can be analyzed.

[0049] Furthermore, for mainstream PHP frameworks, their directory structures, file naming conventions, and module organization methods are studied in depth. For example, the Laravel framework usually has clear directory divisions such as routes, controllers, models, and views. Specifically, before obtaining the target PHP code from the target code library, it can also include: analyzing the directory structure, file naming conventions, and module organization methods of the several PHP frameworks, and building a user development path library based on the obtained analysis results. That is, by analyzing the interaction mechanism and boundaries between the core code and the user-defined code in the framework, the vulnerability scanning process can be simplified. Only a hash check is performed on the core code to determine that its file has not been modified. If the core code is found to be modified, a deep scan is performed on the corresponding file, thereby greatly shortening the vulnerability scanning time.

[0050] Step S12: determining vulnerability scanning parameters corresponding to the target PHP code based on the framework information and a preset vulnerability parameter configuration library.

[0051] In this embodiment, the vulnerability scanning parameter configuration corresponding to the framework information is derived, such as the input function feature library, dangerous function feature library, user development directory that needs to be scanned, user-defined input function, dangerous function, number of loop iteration scans and depth, and other configuration information of the corresponding framework. Specifically, the vulnerability scanning parameters corresponding to the target PHP code based on the framework information and the preset vulnerability parameter configuration library may include: determining the input function corresponding to the target PHP code based on the framework information and the input function feature library; determining the dangerous function corresponding to the target PHP code based on the framework information and the dangerous function feature library; and determining the scanning directory corresponding to the target PHP code based on the framework information and the user development path library.

[0052] Step S13: Perform a vulnerability scanning operation on the target PHP code based on the vulnerability scanning parameters to obtain corresponding vulnerability scanning results.

[0053] In this embodiment, PHP code is first parsed lexically and syntactically using a syntax analysis technique to construct an abstract syntax tree (AST). By traversing and analyzing the nodes of the AST, the call status of various functions in the code, the logical structure of statements, and the like can be accurately located. Specifically, performing a vulnerability scan on the target PHP code based on the vulnerability scanning parameters to obtain corresponding vulnerability scan results may include: performing a syntax parsing operation on the target PHP code using a preset syntax analysis technique to obtain an abstract syntax tree corresponding to the target PHP code, and determining parameter information containing the call status and logical structure of various functions in the target PHP code based on the abstract syntax tree; determining tainted data based on an input function corresponding to the target PHP code using a preset taint analysis technique; the tainted data being user input data that presents a security risk; performing data flow analysis on the parameter information to generate a data flow propagation chain associated with the tainted data, and generating corresponding vulnerability scan results based on the data flow propagation chain and the dangerous functions corresponding to the target PHP code. That is, using taint analysis technology, mark external input (native input and framework-specific input functions, global variables, etc.) as the source of taint, and use data flow analysis technology combined with the corresponding data flow propagation chain to analyze whether it flows into the dangerous function feature library.

[0054] It's important to note that data flow analysis plays a key role in automated PHP vulnerability discovery. By generating a program data flow graph, the propagation path of input taint (i.e., user input data that may pose a security risk) within the program can be clearly traced, thereby identifying potential vulnerabilities. Specifically, performing data flow analysis on the parameter information to generate a data flow propagation chain associated with the tainted data may include generating a program data flow graph based on the parameter information and tracing the tainted data based on the program data flow graph to generate a data flow propagation chain associated with the tainted data. Specifically, when parsing PHP code, all input sources are marked. These input sources are the user data obtained through various input functions mentioned above, and serve as the starting point of the data flow, i.e., the source of the taint. For example, when a PHP page obtains a user-passed parameter via the $_GET method, the variable corresponding to this parameter is an input taint. By thoroughly analyzing the PHP source code and syntax tree, we analyze how this tainted data flows through various function calls, variable assignments, conditional statements, and other statements, thus developing a data flow analysis and propagation strategy. For example, tainted data might be processed in a custom function, undergo some calculations or concatenation within that function, and then passed as a parameter to another function. This custom function is then marked as a new input source. Once the tainted data passes through a filter function that cannot be bypassed, the propagation flow of the tainted data ends and cannot be passed further. Based on specific types of dangerous functions and frameworks, a specific data flow propagation chain is constructed.

[0055] Furthermore, the embodiment of the present application generates a vulnerability scanning report that is easy to analyze based on the obtained vulnerability scanning results. Specifically, after performing a vulnerability scanning operation on the target PHP code based on the vulnerability scanning parameters to obtain the corresponding vulnerability scanning results, it can also include: outputting a vulnerability scanning report in a preset data format according to the vulnerability scanning results; the preset format includes a text format and a structured data format. That is, the vulnerability scanning results are displayed in a clear, intuitive and easy-to-understand manner. The output content will list the discovered vulnerabilities in detail, including but not limited to the file path where the vulnerability is located, the specific number of code lines, the vulnerability type (such as file inclusion vulnerability, SQL injection vulnerability, command execution vulnerability, etc.), the taint propagation path, and a brief description of the vulnerability and risk level assessment information. The output format can be diversified, and a detailed text report can be generated for easy manual viewing and archiving; it can also be output in a structured data format (such as JSON format) to facilitate integration with other security management tools or platforms to achieve an automated vulnerability management process.

[0056] As can be seen from the above, the embodiments of the present application analyze and summarize past experience with numerous PHP projects and mainstream frameworks, and based on the characteristics of each framework, construct input function signature libraries and risky function signature libraries for mainstream frameworks. When conducting automated vulnerability mining for PHP applications developed based on different frameworks, this signature library can be used to accurately locate and identify which functions are used to obtain user input. This signature library can then be used to analyze whether this input data is improperly exploited during subsequent code execution, such as whether it enters risky functions without sufficient validation and filtering, thereby uncovering potential vulnerabilities. By thoroughly studying the directory structure, file naming conventions, and module organization of different frameworks, the interaction mechanisms and boundaries between core code and user-defined code within the framework are analyzed. A hash check is performed on the core code to ensure that the file has not been modified. If modifications are found to be present, a deep scan of the corresponding file is performed, significantly reducing vulnerability scanning time. By performing data flow analysis on the input data, the propagation path of input taints (i.e., user input data that may pose a security risk) within the program can be clearly traced, thereby uncovering potential vulnerabilities. This enables automated vulnerability mining for PHP, shortening vulnerability scanning time and improving the accuracy and practicality of vulnerability detection.

[0057] See also Figure 2 As shown, the embodiment of the present application discloses a PHP automated vulnerability scanning device based on framework characteristics, including:

[0058] The framework information acquisition module 11 is used to obtain the target PHP code from the target code library and analyze the target PHP code to obtain the framework information of the target PHP code; the target code library includes a local code library and a remote code library;

[0059] A vulnerability scanning parameter configuration module 12 is configured to determine vulnerability scanning parameters corresponding to the target PHP code based on the framework information and a preset vulnerability parameter configuration library; the vulnerability parameter configuration library is a database generated based on several PHP frameworks, including an input function feature library, a dangerous function feature library, and a user development path library; the vulnerability scanning parameters include input functions, dangerous functions, vulnerability scan times, vulnerability scan depth, and scan directories;

[0060] The vulnerability scanning result generating module 13 is used to perform a vulnerability scanning operation on the target PHP code based on the vulnerability scanning parameters to obtain a corresponding vulnerability scanning result.

[0061] As can be seen from the above, the present embodiment analyzes the framework information of the target PHP code and determines vulnerability scanning parameters corresponding to the target PHP code using the preset vulnerability parameter configuration library. That is, vulnerability scanning parameters for vulnerability scanning are quickly matched from the preset vulnerability parameter configuration library based on the characteristics of different PHP frameworks, so as to perform vulnerability scanning on the target PHP code. This enables automated vulnerability mining for PHP, shortens vulnerability scanning time, and improves the accuracy and practicality of vulnerability detection.

[0062] In some specific implementations, the framework information acquisition module 11 may specifically include:

[0063] The framework information acquisition unit is used to determine the PHP framework corresponding to the target PHP code according to the code directory structure, naming rules and characteristic functions of the target PHP code to obtain the framework information of the target PHP code.

[0064] In some specific implementations, the vulnerability scanning parameter configuration module 12 may specifically include:

[0065] An input function determining unit, configured to determine an input function corresponding to the target PHP code based on the framework information and the input function feature library;

[0066] A dangerous function determining unit, configured to determine a dangerous function corresponding to the target PHP code based on the framework information and the dangerous function feature library;

[0067] A scanning directory determining unit is used to determine a scanning directory corresponding to the target PHP code based on the framework information and the user development path library.

[0068] In some specific implementations, the vulnerability scanning result generating module 13 may specifically include:

[0069] a parameter information determining unit, configured to perform a syntax parsing operation on the target PHP code using a preset syntax analysis technology to obtain an abstract syntax tree corresponding to the target PHP code, and determine, based on the abstract syntax tree, parameter information of call conditions and logical structures of various functions in the target PHP code;

[0070] A tainted data determining unit, configured to determine tainted data using a preset taint analysis technology based on an input function corresponding to the target PHP code; the tainted data being user input data that presents a security risk;

[0071] The vulnerability scanning result generation submodule is used to perform data flow analysis on the parameter information to generate a data flow propagation chain related to the tainted data, and generate corresponding vulnerability scanning results based on the data flow propagation chain and the dangerous function corresponding to the target PHP code.

[0072] Furthermore, in some specific implementations, the vulnerability scanning result generation submodule may specifically include:

[0073] A data flow propagation chain generating unit is configured to generate a program data flow graph based on the parameter information, and to track the tainted data based on the program data flow graph to generate a data flow propagation chain related to the tainted data.

[0074] In some specific implementations, the framework-based PHP automated vulnerability scanning device may further include:

[0075] An input function feature library construction unit is used to sort out several PHP frameworks to obtain several input functions and corresponding function calling methods corresponding to the several PHP frameworks, and to construct an input function feature library based on the several input functions and corresponding function calling methods;

[0076] A dangerous function feature library construction unit is used to determine dangerous functions corresponding to the plurality of PHP frameworks based on historical PHP vulnerability cases, and to construct a dangerous function feature library based on the dangerous functions;

[0077] A user development path library construction unit is used to analyze the directory structure, file naming conventions and module organization of the plurality of PHP frameworks, and to construct a user development path library based on the obtained analysis results;

[0078] The vulnerability scanning report output unit is used to output a vulnerability scanning report in a preset data format according to the vulnerability scanning result; the preset format includes a text format and a structured data format.

[0079] Furthermore, the embodiment of the present application also discloses an electronic device, Figure 3 This is a structural diagram of an electronic device 20 according to an exemplary embodiment. The content in the diagram should not be considered as any limitation on the scope of use of this application. The electronic device 20 may specifically include: at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input / output interface 25, and a communication bus 26. The memory 22 is used to store a computer program, which is loaded and executed by the processor 21 to implement the relevant steps of the framework-based PHP automated vulnerability scanning method disclosed in any of the aforementioned embodiments. In addition, the electronic device 20 in this embodiment may specifically be an electronic computer.

[0080] In this embodiment, the power supply 23 is used to provide operating voltage for each hardware device on the electronic device 20; the communication interface 24 can create a data transmission channel between the electronic device 20 and the external device. The communication protocol it follows is any communication protocol that can be applied to the technical solution of this application and is not specifically limited here; the input and output interface 25 is used to obtain external input data or output data to the outside world. Its specific interface type can be selected according to specific application needs and is not specifically limited here.

[0081] In addition, the memory 22, as a carrier for resource storage, can be a read-only memory, random access memory, disk or CD, etc. The resources stored thereon can include an operating system 221, a computer program 222, etc., and the storage method can be temporary storage or permanent storage.

[0082] The operating system 221 is used to manage and control the hardware devices on the electronic device 20 and the computer program 222, which can be Windows Server, Netware, Unix, Linux, etc. In addition to including a computer program capable of implementing the framework-based PHP automated vulnerability scanning method performed by the electronic device 20 as disclosed in any of the aforementioned embodiments, the computer program 222 can further include computer programs capable of completing other specific tasks.

[0083] Furthermore, this application discloses a computer-readable storage medium for storing a computer program. When executed by a processor, the computer program implements the aforementioned framework-based automated vulnerability scanning method for PHP. The specific steps of this method can be found in the corresponding content disclosed in the aforementioned embodiments and will not be further described here.

[0084] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on its differences from the other embodiments. Reference can be made to the descriptions of the identical or similar parts between the various embodiments. For the devices disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the descriptions are relatively simple, and the relevant parts can be referred to the descriptions of the methods.

[0085] Professionals may further appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the above description has generally described the components and steps of each example according to their functions. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professionals and technicians may use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0086] The steps of the methods or algorithms described in conjunction with the embodiments disclosed herein may be implemented directly using hardware, a software module executed by a processor, or a combination of the two. The software module may be placed in random access memory (RAM), internal memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, a hard disk, a removable disk, a CD-ROM, or any other form of storage medium known in the art.

[0087] Finally, it should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or device. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of additional identical elements in the process, method, article, or device comprising the element.

[0088] The above is a detailed introduction to the technical solution provided by the present application. Specific examples are used herein to illustrate the principles and implementation methods of the present application. The description of the above embodiments is only used to help understand the method of the present application and its core idea. At the same time, for those skilled in the art, according to the ideas of the present application, there may be changes in the specific implementation methods and application scope. In summary, the content of this specification should not be understood as a limitation on the present application.

Claims

1. A PHP automated vulnerability scanning method based on framework characteristics, characterized in that: include: Obtain target PHP code from a target code library, and analyze the target PHP code to obtain framework information of the target PHP code; The target code library includes a local code library and a remote code library; Determining vulnerability scanning parameters corresponding to the target PHP code based on the framework information and a preset vulnerability parameter configuration library; the vulnerability parameter configuration library is a database generated based on several PHP frameworks, including an input function feature library, a dangerous function feature library, and a user development path library; the vulnerability scanning parameters include input functions, dangerous functions, vulnerability scan times, vulnerability scan depth, and scan directories; A vulnerability scanning operation is performed on the target PHP code based on the vulnerability scanning parameters to obtain corresponding vulnerability scanning results.

2. The PHP automated vulnerability scanning method based on framework characteristics according to claim 1 is characterized in that: Before obtaining the target PHP code from the target code library, the method further includes: Combing through several PHP frameworks to obtain several input functions and corresponding function calling methods corresponding to the several PHP frameworks, and building an input function feature library based on the several input functions and the corresponding function calling methods; Determine the dangerous functions corresponding to the plurality of PHP frameworks based on historical PHP vulnerability cases, and build a dangerous function feature library based on the dangerous functions; The directory structure, file naming conventions and module organization of the several PHP frameworks are analyzed, and a user development path library is constructed based on the analysis results.

3. The PHP automated vulnerability scanning method based on framework characteristics according to claim 1 is characterized in that: The target PHP code is analyzed to obtain framework information of the target PHP code, including: Determine the PHP framework corresponding to the target PHP code according to the code directory structure, naming rules and characteristic functions of the target PHP code to obtain the framework information of the target PHP code.

4. The PHP automated vulnerability scanning method based on framework characteristics according to claim 1 is characterized in that: The determining of vulnerability scanning parameters corresponding to the target PHP code based on the framework information and a preset vulnerability parameter configuration library includes: Determine an input function corresponding to the target PHP code based on the framework information and the input function feature library; Determine the dangerous function corresponding to the target PHP code based on the framework information and the dangerous function feature library; A scan directory corresponding to the target PHP code is determined based on the framework information and the user development path library.

5. The PHP automated vulnerability scanning method based on framework characteristics according to claim 4 is characterized in that: The performing a vulnerability scanning operation on the target PHP code based on the vulnerability scanning parameters to obtain corresponding vulnerability scanning results includes: Performing a syntax analysis operation on the target PHP code using a preset syntax analysis technology to obtain an abstract syntax tree corresponding to the target PHP code, and determining, based on the abstract syntax tree, call conditions of various functions and parameter information of logical structures contained in the target PHP code; Determining tainted data using a preset taint analysis technology based on an input function corresponding to the target PHP code; the tainted data is user input data that poses a security risk; Perform data flow analysis on the parameter information to generate a data flow propagation chain related to the tainted data, and generate corresponding vulnerability scanning results based on the data flow propagation chain and the dangerous function corresponding to the target PHP code.

6. The PHP automated vulnerability scanning method based on framework characteristics according to claim 5 is characterized in that: The performing data flow analysis on the parameter information to generate a data flow propagation chain related to the tainted data includes: A program data flow graph is generated based on the parameter information, and the tainted data is tracked based on the program data flow graph to generate a data flow propagation chain related to the tainted data.

7. The PHP automated vulnerability scanning method based on framework characteristics according to any one of claims 1 to 6, characterized in that: After performing a vulnerability scanning operation on the target PHP code based on the vulnerability scanning parameters to obtain corresponding vulnerability scanning results, the method further includes: A vulnerability scanning report in a preset data format is output according to the vulnerability scanning result; the preset format includes a text format and a structured data format.

8. A PHP automated vulnerability scanning device based on framework characteristics, characterized in that: include: A framework information acquisition module is used to obtain target PHP code from a target code library and analyze the target PHP code to obtain framework information of the target PHP code; The target code library includes a local code library and a remote code library; A vulnerability scanning parameter configuration module is configured to determine vulnerability scanning parameters corresponding to the target PHP code based on the framework information and a preset vulnerability parameter configuration library; the vulnerability parameter configuration library is a database generated based on several PHP frameworks, including an input function feature library, a dangerous function feature library, and a user development path library; the vulnerability scanning parameters include input functions, dangerous functions, vulnerability scan times, vulnerability scan depth, and scan directories; The vulnerability scanning result generating module is used to perform a vulnerability scanning operation on the target PHP code based on the vulnerability scanning parameters to obtain corresponding vulnerability scanning results.

9. An electronic device, characterized in that: include: Memory, used to store computer programs; A processor is used to execute the computer program to implement the PHP automated vulnerability scanning method based on framework characteristics as described in any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that Used to store a computer program, wherein when the computer program is executed by a processor, it implements the PHP automated vulnerability scanning method based on framework characteristics as described in any one of claims 1 to 7.