Interface testing method, device, equipment, medium and program product

Through the gray-box interface testing method, the object information in the memory of the application under test is scanned, the interface code segments are obtained and decompiled, and test cases are constructed. This solves the problems of incomplete testing and low efficiency in the existing technology and achieves more efficient and comprehensive security testing.

CN120670281APending Publication Date: 2025-09-19INDUSTRIAL AND COMMERCIAL BANK OF CHINA
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411911166.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-24
Publication Date
2025-09-19

AI Technical Summary

Technical Problem

Existing technologies make it difficult to ensure the comprehensiveness and efficiency of application security testing. Traditional black-box testing is prone to missing test points, while white-box testing consumes a lot of manpower and has a high false alarm rate.

Method used

The gray-box interface testing method establishes a connection with the debug interface of the application under test, scans the object information in the application memory, obtains the interface definition specifications and code segments, decompiles to obtain the interface content, constructs test cases and performs testing.

Benefits of technology

It improves the coverage and efficiency of interface testing, reduces the risk of test omissions, and improves the quality of security testing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120670281A_ABST
    Figure CN120670281A_ABST
Patent Text Reader

Abstract

The invention provides an interface testing method, relates to the field of information security, and can be applied to the technical field of financial science and technology. The method comprises the following steps: establishing debugging connection with a debugging interface of a tested application; scanning information of each object in m kinds of objects in an application memory of the tested application through the debugging connection to obtain an object information set; based on the information of each object in the object information set, information of an interface used by each object is obtained from the application memory, and an interface information set of the tested application is obtained; and testing the interfaces in the interface information set. The invention further provides an interface testing device and equipment, a storage medium and a program product.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of information security and can be used in the field of financial technology or other fields. More specifically, it relates to an interface testing method, device, equipment, medium and program product. Background Art

[0002] With the increasing complexity of current application architectures and the increasing number of interfaces exposed by applications, security testing of large-scale products often faces many challenges. For example, when using traditional black-box testing, testers do not need to understand the internal code or implementation details of the program and only focus on the input and output of the software. However, due to a lack of understanding of business functions, test points may be missed, making it difficult to ensure the comprehensiveness of the test. White-box testing methods require testers to have an in-depth understanding of the internal structure of the application, which is labor-intensive and inefficient, and has a high false alarm rate, requiring manual analysis to confirm vulnerabilities. Summary of the Invention

[0003] In view of the above problems, the present disclosure provides an interface testing method, apparatus, device, medium and program product using a gray box approach.

[0004] In a first aspect of the embodiments of the present disclosure, an interface testing method is provided. The method comprises: establishing a debugging connection with a debugging interface of an application under test; scanning information about each of m types of objects in the application memory of the application under test through the debugging connection to obtain an object information set, where m is an integer greater than or equal to 2; based on the information about each object in the object information set, obtaining information about the interface used by each object from the application memory to obtain an interface information set of the application under test; and testing the interfaces in the interface information set.

[0005] According to an embodiment of the present disclosure, obtaining information about the interface used by each object from the application memory based on the information of each object in the object information set includes: obtaining the interface definition specification of the object based on the information of each object; determining the code segment in the object for defining the interface used based on the interface definition specification of the interface; and extracting the interface information from the code segment.

[0006] According to an embodiment of the present disclosure, the testing of the interfaces in the interface information set includes: based on the interface name of each interface in the interface information set, obtaining the code snippet where each interface is located from the application memory of the application under test; decompiling the obtained code snippet to obtain an interface code segment; extracting the interface content of each interface from the interface code segment; constructing a test case for each interface based on the interface content; and using the test case of each interface to test the corresponding interface.

[0007] According to an embodiment of the present disclosure, the application under test is a Java application, and based on the interface name of each interface in the interface information set, the code of the class where each interface is located is obtained from the application memory of the application under test to obtain the interface code segment, which includes: searching the bytecode of the application under test based on the interface name of each interface to locate the bytecode of the class where each interface is located; and decompiling the bytecode of the class where each interface is located to obtain the interface code segment.

[0008] According to an embodiment of the present disclosure, the construction of a test case for each interface based on the interface content includes: constructing a legitimate request message for each interface based on the interface content; inputting the legitimate request message and the interface code segment of each interface into a mature large language model, and using a preset first prompt instruction to prompt the large language model to output interface business logic information; matching a test case to be used corresponding to the interface business logic information from pre-stored basic security test cases; and using the information of the test case to be used to change the information in the legitimate request message to obtain at least one test case.

[0009] According to an embodiment of the present disclosure, constructing a test case for each interface based on the interface content also includes: constructing a legitimate request message for each interface based on the interface content; inputting the legitimate request message and the interface code segment of each interface into a mature large language model, and using a preset second prompt instruction to prompt the large language model to output at least one test case.

[0010] According to an embodiment of the present disclosure, the m types of objects include at least middleware and an architecture framework.

[0011] According to an embodiment of the present disclosure, scanning the information of each of the m types of objects in the application memory of the application under test through the debugging connection to obtain an object information set includes: obtaining pre-configured dictionary data, the dictionary data including a correspondence between specified class names and object information; and when the scan finds that the class loaded in the application memory of the application under test matches the specified class name in the dictionary data, obtaining corresponding object information based on the correspondence in the dictionary data.

[0012] According to a second aspect of an embodiment of the present disclosure, an interface testing device is provided. The device includes: a connection module, a first acquisition module, a second acquisition module, and an interface testing module. The connection module is used to establish a debugging connection with the debugging interface of the application under test. The first acquisition module is used to scan the information of each of the m types of objects in the application memory of the application under test through the debugging connection to obtain an object information set, where m is an integer greater than or equal to 2. The second acquisition module is used to obtain information about the interface used by each object from the application memory based on the information of each object in the object information set to obtain an interface information set of the application under test. The interface testing module is used to test the interfaces in the interface information set.

[0013] According to an embodiment of the present disclosure, the interface test module also includes an interface parameter information acquisition unit, a test message generation unit, a request sending unit and a result analysis unit. The interface parameter information acquisition unit is used to: first, based on the interface name of each interface in the interface information set, obtain the code snippet where each interface is located from the application memory of the application under test, then decompile the obtained code snippet to obtain the interface code segment, and then extract the interface content of each interface from the interface code segment. The test message generation unit constructs a test case for each interface based on the interface content. The request sending unit is used to send the test message corresponding to the test case to the application under test. The result analysis unit is used to obtain the response result of the application under test to each test message, analyze the response result, and determine whether there is a vulnerability in the interface.

[0014] A third aspect of an embodiment of the present disclosure provides an electronic device, comprising: one or more processors; and a memory for storing one or more computer programs, wherein the one or more processors execute the one or more computer programs to implement the steps of the above method.

[0015] A fourth aspect of the embodiments of the present disclosure further provides a computer-readable storage medium on which a computer program or instruction is stored, and the steps of the above method are implemented when the above computer program or instruction is executed by a processor.

[0016] The fifth aspect of the embodiments of the present disclosure further provides a computer program product, including a computer program or instructions, which implement the steps of the above method when the above computer program or instructions are executed by a processor. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] The above contents and other objects, features and advantages of the present disclosure will become more apparent through the following description of the embodiments of the present disclosure with reference to the accompanying drawings, in which:

[0018] Figure 1 Schematically illustrates an application scenario diagram of the interface testing method, apparatus, device, medium, and program product according to an embodiment of the present disclosure;

[0019] Figure 2 The following schematically shows a flow chart of an interface testing method according to an embodiment of the present disclosure;

[0020] Figure 3 The following schematically illustrates the operation flow of testing an interface in an interface testing method according to an embodiment of the present disclosure;

[0021] Figure 4 The system architecture of the interface testing method according to an embodiment of the present disclosure is schematically shown;

[0022] Figure 5 Schematically shows Figure 4 The structure diagram of the route acquisition module in the system architecture shown;

[0023] Figure 6 Schematically shows Figure 4 The structural diagram of the test module in the system architecture shown;

[0024] Figure 7 Schematically shows a flow chart of an interface testing method according to another embodiment of the present disclosure;

[0025] Figure 8 A schematic diagram illustrating a structure of an interface testing device according to an embodiment of the present disclosure is shown; and

[0026] Figure 9 The structure of an electronic device according to an embodiment of the present disclosure is schematically shown. DETAILED DESCRIPTION

[0027] Hereinafter, embodiments of the present disclosure will be described with reference to the accompanying drawings. However, it should be understood that these descriptions are merely exemplary and are not intended to limit the scope of the present disclosure. In the detailed description below, for ease of explanation, many specific details are set forth to provide a comprehensive understanding of the embodiments of the present disclosure. However, it is apparent that one or more embodiments may also be implemented without these specific details. In addition, in the following description, descriptions of well-known structures and technologies are omitted to avoid unnecessary confusion of the concepts of the present disclosure.

[0028] The terms used herein are only for describing specific embodiments and are not intended to limit the present disclosure. The terms "comprise," "include," etc. used herein indicate the presence of the features, steps, operations, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, or components.

[0029] All terms used herein (including technical and scientific terms) have the meanings commonly understood by those skilled in the art unless otherwise defined. It should be noted that the terms used herein should be interpreted as having a meaning consistent with the context of this specification and should not be interpreted in an idealized or overly rigid manner.

[0030] When expressions such as "at least one of A, B, and C, etc." are used, they should generally be interpreted in accordance with the meaning commonly understood by those skilled in the art (for example, "a system having at least one of A, B, and C" should include but is not limited to a system having A alone, B alone, C alone, A and B, A and C, B and C, and / or A, B, C, etc.).

[0031] The disclosed embodiments provide an interface testing method, apparatus, device, medium, and program product that can automatically scan the application memory of the application under test in a graybox manner to obtain the full interface information used by the application under test during operation. Based on the scan results, a legitimate request message corresponding to the interface is generated. A test message can then be constructed based on the legitimate request message. By sending the test message to the application server of the application under test and obtaining the response from the application server, the tester can determine whether the application under test has vulnerabilities. This method can improve the interface coverage of the test, increase test efficiency, reduce the risk of test omissions, and enhance the quality of application security testing.

[0032] Figure 1 The application scenario diagram of the interface testing method, apparatus, device, medium and program product according to the embodiments of the present disclosure is schematically shown.

[0033] like Figure 1 As shown, the application scenario according to this embodiment may include a first terminal device 11, a second terminal device 12, a third terminal device 13, a network 14, and a server (cluster) 15. The network 14 is used as a medium for providing a communication link between the first terminal device 11, the second terminal device 12, the third terminal device 13, and the server (cluster) 15. The network 14 may include various connection types, such as wired or wireless communication links or fiber optic cables.

[0034] A user may use a first terminal device 11, a second terminal device 12, or a third terminal device 13 to interact with a server (cluster) 15 via a network 14 to receive or send messages, etc. Various communication client applications may be installed on the first terminal device 11, the second terminal device 12, or the third terminal device 13, such as shopping applications, web browser applications, search applications, instant messaging tools, email clients, social platform software, etc. (for example only).

[0035] The first terminal device 11 , the second terminal device 12 , and the third terminal device 13 may be various electronic devices having display screens and supporting web browsing, including but not limited to smart phones, tablet computers, laptop computers, desktop computers, and the like.

[0036] Server (cluster) 15 can be a backend management server that provides various services. It can analyze and process received user requests and other data, and provide feedback to the terminal devices regarding the results (e.g., web pages, information, or data obtained or generated based on user requests). For example, a user can use first terminal device 11, second terminal device 12, or third terminal device 13 to send an interface test instruction for a specific application to server (cluster) 15. Server (cluster) 15 will test the interface of the tested application according to the interface test instruction and return the test results to first terminal device 11, second terminal device 12, or third terminal device 13 for the user to view.

[0037] It should be noted that the interface testing method provided in the embodiment of the present disclosure can generally be executed by the server (cluster) 15. Accordingly, the interface testing device provided in the embodiment of the present disclosure can generally be set in the server (cluster) 15. The interface testing method provided in the embodiment of the present disclosure can also be executed by a server or server cluster that is different from the server (cluster) 15 and can communicate with the first terminal device 11, the second terminal device 12, the third terminal device 13 and / or the server (cluster) 15. Accordingly, the interface testing device provided in the embodiment of the present disclosure can also be set in a server or server cluster that is different from the server (cluster) 15 and can communicate with the first terminal device 11, the second terminal device 12, the third terminal device 13 and / or the server (cluster) 15.

[0038] It should be understood that Figure 1 The number of terminal devices, networks and servers in the embodiment is merely illustrative. Any number of terminal devices, networks and servers may be provided as required.

[0039] Description: It should be noted that the interface testing method and device provided in the embodiments of the present disclosure can be used in the field of financial technology, and can also be used in any field other than the field of financial technology. The present disclosure does not limit the application field.

[0040] The following will be based on Figure 1 The scenario described is described in detail about the interface testing method and device of the embodiment of the present disclosure.

[0041] Figure 2 The flowchart of the interface testing method according to an embodiment of the present disclosure is schematically shown. Figure 2As shown, the interface testing method may include operations S210 to S240.

[0042] In operation S210, a debugging connection is established with the debugging interface of the application under test, for example, by creating a Socket connection.

[0043] In operation S220 , information of each of m types of objects in the application memory of the application under test is scanned through the debugging connection to obtain an object information set, where m is an integer greater than or equal to 2.

[0044] In operation S230 , based on the information of each object in the object information set, information of the interface used by each object is obtained from the application memory to obtain an interface information set of the application under test.

[0045] The m types of objects can be all kinds of objects that will use interfaces or define interfaces in application development, which can greatly improve the coverage of the interfaces obtained in S230 and obtain the full amount of interfaces of the application under test as much as possible. For example, middleware and architecture frameworks are usually used in the development of many applications, and interfaces are defined in the middleware and architecture framework to interact with external objects. In this case, the m objects can include at least two types of objects: middleware and architecture framework. In other embodiments, when there are other objects that can define interfaces or use interfaces (such as user-defined objects), the m types of objects can also include user-defined objects.

[0046] Each type of object in the object information set may contain one or more objects. For example, multiple different middlewares may be used in application development. Accordingly, operation S220 will obtain information about each middleware, including its type and name. For another example, application development typically uses only one architecture framework. Accordingly, operation S220 will obtain information about the architecture framework, such as the Spring framework or the Struts framework.

[0047] In one embodiment, in operation S230, based on information about each object (e.g., object type, object name, etc.), an interface definition specification of the object (e.g., information about which classes are allowed to add or define interfaces) is obtained. Based on the interface definition specification of the interface, a code segment in the object that defines the interface to be used is determined, and then interface information (e.g., interface routing information, interface name, and / or interface path, etc.) is extracted from the code segment.

[0048] Next, in operation S240, the interfaces in the interface information set are tested.

[0049] It can be seen that the embodiment of the present disclosure uses a gray box method to scan the information of various objects that use interfaces in the application memory of the application under test, and then conducts targeted scanning from these objects in the application memory to extract the information of the interfaces used therein, which can improve the coverage of the scanned interfaces. Compared with the black box testing method, it can improve the coverage of interface testing and reduce the risk of test omissions. At the same time, compared with the white box testing method, it does not need to go deep into the specific details of the content of the application under test, and the testing efficiency is high.

[0050] Figure 3 The operational flow of testing an interface in an interface testing method according to an embodiment of the present disclosure is schematically illustrated.

[0051] like Figure 3 As shown, according to an embodiment of the present disclosure, the above-mentioned operation S240 may specifically include operations S241 to S245.

[0052] First, in operation S241, based on the interface name of each interface in the interface information set, the code snippet of each interface is obtained from the application memory of the application under test. For example, the code of the class where each interface is located is obtained from the application memory of the application under test.

[0053] Next, in operation S242, the obtained code snippet is decompiled to obtain an interface code segment. Considering that the code obtained from the application memory is already compiled low-level code (such as bytecode or machine code), the original code obtained from the application memory of the tested application can be decompiled to obtain an interface code segment expressed in a high-level language, which is convenient for subsequent processing.

[0054] Next, in operation S243, the interface content of each interface, such as interface function, parameters, parameter type, request method, etc., is extracted from the interface code segment.

[0055] Next, in operation S244 , a test case for each interface is constructed based on the interface content.

[0056] Finally, in operation S245 , the corresponding interface is tested using the test case of each interface.

[0057] According to the embodiment of the present disclosure, when constructing a test case, the interface content of each interface is obtained by obtaining the code fragment where each interface is located from the application memory and decompiling it. In this way, the obtained interface content has high authenticity and accuracy, which can make the constructed test case more effective and avoid affecting the test analysis of the interface due to the unreasonableness of the test case itself.

[0058] Figure 4 The system architecture of the interface testing method according to an embodiment of the present disclosure is schematically shown.

[0059] like Figure 4 As shown, combined Figure 1 Server (cluster) 15 may include an application server under test 101 and a test server 102. A route acquisition module 103 is deployed on application server under test 101, and a test module 104 is deployed on test server 102. Route acquisition module 103 and test module 104 together constitute the interface testing apparatus of the embodiment of the present disclosure, which can be used to execute the interface testing method of the embodiment of the present disclosure.

[0060] Among them, the routing acquisition module 103 is responsible for obtaining the interface information of the application under test. Figure 5 shown.

[0061] The test module 104 can construct a test message based on the obtained interface information, send the test message to the application under test, obtain the response information corresponding to the application under test, and determine whether the application under test has a security vulnerability. For specific structure reference Figure 6 shown.

[0062] Figure 5 The structure diagram of the route acquisition module 103 is schematically shown. When using the interface testing device of the embodiment of the present disclosure, the application under test needs to enable the debugging function. The route acquisition module 103 can establish a debugging connection with the debugging interface of the application under test by creating a Socket connection, and then obtain information about m types of objects in the application memory of the application under test through the debugging connection. Then, based on the information about the objects in the application memory obtained, the interface information of the application under test is obtained. In one embodiment, the m types of objects are specifically middleware and architecture framework. After obtaining information about all middleware used in the application under test and information about the architecture framework, the full interface information of the application under test can be further obtained.

[0063] like Figure 5 As shown, the routing acquisition module 10 may include a middleware information acquisition unit 201 , an architecture framework information acquisition unit 202 , an interface information acquisition unit 203 and an interface parameter information acquisition unit 204 .

[0064] The middleware information acquisition unit 201 can be used to identify and determine the information of all middleware used by the application under test during operation (such as the type, version, name, etc. of the middleware). In one embodiment, the middleware information acquisition unit 201 can obtain the middleware information by analyzing the information of the classes loaded in the virtual machine. Specifically, dictionary data specifying class names and middleware information can be pre-configured. The middleware information acquisition unit 201 scans the application memory, and when it finds that the class loaded therein matches the specified class name in the dictionary data, it can determine the middleware information used by the application under test during operation. The output of the middleware information acquisition unit 201 provides key context information for subsequent interface information acquisition and test strategy formulation.

[0065] The architecture framework information acquisition unit 202 is used to analyze the architecture framework type used by the application under test. For example, by querying a specified method of a specified object in the application memory, it obtains the core class information of the framework and determines the framework (e.g., Spring or Struts) used by the application under test based on the pre-configured correspondence between class information and frameworks.

[0066] The interface information acquisition unit 203 is used to determine which code segment (class or instance) to extract from the application memory to obtain the full routing information of the application based on the application middleware information obtained by the middleware information acquisition unit 201 and the architecture framework information obtained by the architecture framework information acquisition unit 202. Specifically, each type of middleware or architecture framework usually has its own interface definition specification, which defines which class and field defines the relevant information of the interface. For example, the Spring framework can search for the RequestMappingHandlerMapping class instance and read the mappingRegistry field to obtain routing information such as the mapping relationship between the interface path and the corresponding processing function, and then extract interface information such as the interface name and interface path. In this way, the interface information used can be searched for in a specific class or code based on the interface definition specification of each object, which can improve the efficiency of searching for interface information and avoid the inefficiency of scanning the code of each object to search for the interface.

[0067] The interface parameter information acquisition unit 204 is used to further acquire the interface content of the interface based on the analysis results of the interface information acquisition unit 203. For example, first, based on the interface name analyzed by the interface information acquisition unit 203, a quick search can be performed on the bytecode of the application under test from the application memory to locate the bytecode of the class where the interface is located. The bytecode of the class is then decompiled to obtain the interface code segment of each interface. Next, the interface content, such as the interface function name, interface parameter name and parameter type, interface request method, and other data, can be extracted from the interface code segment. In this way, a legitimate request message corresponding to the interface can be assembled based on the interface content, which serves as the basis for constructing a test message.

[0068] Figure 6 The structure of the test module 104 is schematically shown. Figure 6 As shown, the module 104 may include a test message generating unit 301 , a request sending unit 302 and a result analyzing unit 303 .

[0069] The test message generation unit 301 can be used to: first extract the legitimate request message spliced ​​by the routing acquisition module 101, where the legitimate request message contains the correct interface access path and corresponding request parameters; then simultaneously send the legitimate request message of each interface and the interface code segment obtained by decompilation into a mature large language model, and use the semantic understanding ability of the large language model to assist in the generation of test cases.

[0070] In one embodiment, a preset first prompt instruction can be used to prompt the large language model to analyze the interface business logic and output corresponding interface business logic information. A test case corresponding to the interface business logic information is then matched from pre-stored basic security test cases. The information in the test case is used to modify the information in the legitimate request message to obtain at least one test case. The interface business logic information can, for example, be information obtained by the large language model classifying interface functions and / or prompts for key test points for interface testing. For example, the large language model may analyze the "upload" interface as a file upload interface and prompt a focus on file upload testing. Alternatively, the large language model may analyze the "getAccout" interface as an account name retrieval interface and prompt a focus on unauthorized access testing. In this way, based on the semantic understanding results of the large language model, basic security test cases can be specifically retrieved from the database to generate test messages. These test messages can simulate attacks such as unauthorized access, SQL injection, and cross-site scripting (XSS) attacks to verify the application's ability to handle abnormal input and its security. This method significantly improves the targeted nature of the test messages generated by the test message generation unit 301.

[0071] In another embodiment, a preset second prompt instruction can be used to prompt the large language model to construct a certain number of test messages based on the input legitimate request message and interface code segment. At the same time, the information in the basic security test case pre-stored in the database is used to modify the legitimate request message to construct a portion of the test message. The test messages obtained through both methods are then used to test the interface. In this way, the semantic understanding ability of the large language model can be utilized to expand the source of test messages, ensuring that the test messages can cover a wide range of security test cases and help discover and prevent potential security vulnerabilities.

[0072] Request sending unit 302 is used to send the test message generated by test message generation unit 301 to the application under test. This unit is responsible for establishing a URL based on the test message type (e.g., HTTP, GET, POST, etc.) and the target interface, and sending the request. Request sending unit 302 is also responsible for processing the application under test's response, including receiving data, handling timeouts, and redirects, and receiving the corresponding response for further analysis.

[0073] The result analysis unit 303 is used to analyze the response received by the request sending unit 302. The result analysis unit 303 first checks the status code of the response to determine whether the request is successful. For a successful response, the result analysis unit 303 further analyzes the response content, such as checking the returned data structure, verifying the integrity and consistency of the data, and identifying any potential security issues. If the response indicates an abnormality or suspected security vulnerability, the result analysis unit 303 will record the relevant information in detail and provide an alarm for the tester to further confirm. Specifically, there are several vulnerability detection methods:

[0074] ① When sending a specified attack message, determine whether the response message contains special characters to confirm whether there is a related vulnerability;

[0075] ② Determine whether the server responds differently when the interface is accessed with or without authentication information to determine whether there is an unauthorized access vulnerability;

[0076] ③ Determine whether the application under test triggers access to third-party services when sending specific attack messages to confirm whether there are related vulnerabilities.

[0077] ④ Regular expression matching is used to determine whether the response message contains specific data to determine whether there is any problem such as sensitive information leakage.

[0078] Figure 7 A flowchart of an interface testing method according to another embodiment of the present disclosure is schematically shown. The flow chart can be applied to Figure 4 Specifically, the process may include steps S1 to S8.

[0079] Step S1: Deploy the application under test and enable the application debugging function.

[0080] Step S2: Connect to the application under test and establish a debugging connection.

[0081] Step S3: After the connection is successful, determine the information of all middleware and architecture framework used by the application under test.

[0082] Step S4: Based on the result of step S3, scan the application memory routing of the application under test, retrieve and identify the full routing information of the application under test, and extract interface information such as the interface path and interface name of the interface from each routing information.

[0083] Step S5: According to the interface name of each interface, the class where the interface is located is retrieved from the application memory, and the class code is decompiled to obtain the interface code segment of each interface. Then, the interface function name, interface parameter name and parameter type, interface request method and other data of the interface are extracted from the interface code segment of each interface, and the legal request message of the interface is spliced ​​out based on these data.

[0084] Step S6: Send the legal request message and the corresponding interface code segment into the large language model, and give the large language model corresponding prompt instructions (for example, assuming you are a security expert, the following is the legal request message "xxxx" of the interface, and the interface code "xxxx", please analyze the business logic information of the interface and give the test points, or please give several test cases for testing the interface and explain the test purpose of each test case). Use the large model to help understand the purpose of the interface and generate test messages in a targeted manner.

[0085] Step S7: Using the basic test values ​​in the basic security test cases pre-stored in the database, the parameter values ​​in the normal message are replaced with the test values ​​to construct a test message.

[0086] Step S8: The test messages generated by the large language model and the constructed test messages are aggregated and sent to the application under test one by one. The response of the application server under test is judged. If it is confirmed to be a vulnerability, an alarm is displayed.

[0087] In this way, the interface testing method and apparatus according to the disclosed embodiments can implement automated gray-box interface testing based on interface scanning, automatically identifying all exposed interfaces of an application, forming legitimate request messages, and constructing test messages accordingly. The method and apparatus then determine whether vulnerabilities exist by observing the server's response to the test messages. The disclosed embodiments can effectively improve the efficiency and coverage of security testing, enhancing test quality.

[0088] Figure 8 The figure schematically shows a structural diagram of an interface testing device according to an embodiment of the present disclosure.

[0089] like Figure 8 As shown, the interface testing device 800 according to this embodiment may include a connection module 810 , a first acquisition module 820 , a second acquisition module 830 and an interface testing module 840 .

[0090] The connection module 810 is used to establish a debugging connection with the debugging interface of the application under test. In one embodiment, the connection module 810 can perform the operation S210 described above.

[0091] The first acquisition module 820 is configured to scan, through a debugging connection, information about each of the m types of objects in the application memory of the application under test to obtain an object information set, where m is an integer greater than or equal to 2. In one embodiment, the first acquisition module 820 may perform operation S220 described above. In one embodiment, the first acquisition module 820 may include the aforementioned middleware information acquisition unit 201 and architecture framework information acquisition unit 202.

[0092] The second acquisition module 830 is configured to obtain information about the interfaces used by each object from the application memory based on the information about each object in the object information set, thereby obtaining an interface information set for the application under test. In one embodiment, the second acquisition module 830 may perform operation S230 described above. In one embodiment, the second acquisition module 830 may include the interface information acquisition unit 203 described above.

[0093] The interface testing module 840 is used to test the interfaces in the interface information set. In one embodiment, the interface testing module 840 can perform the operation S240 described above. In one embodiment, the interface testing module 840 also includes the aforementioned interface parameter information acquisition unit 204, the test message generation unit 301, the request sending unit 302, and the result analysis unit 303.

[0094] The apparatus 800 may perform a reference Figures 2 to 7 The interface testing method introduced here can be found in the previous article and will not be repeated here.

[0095] According to embodiments of the present disclosure, any multiple modules among the connection module 810, the first acquisition module 820, the second acquisition module 830, the interface test module 840, the route acquisition module 103, and the test module 104 may be combined into a single module, or any one of these modules may be split into multiple modules. Alternatively, at least part of the functionality of one or more of these modules may be combined with at least part of the functionality of other modules and implemented in a single module. According to embodiments of the present disclosure, at least one of the connection module 810, the first acquisition module 820, the second acquisition module 830, the interface test module 840, the route acquisition module 103, and the test module 104 may be at least partially implemented as a hardware circuit, such as a field programmable gate array (FPGA), a programmable logic array (PLA), a system on a chip, a system on a substrate, a system on a package, an application-specific integrated circuit (ASIC), or may be implemented in hardware or firmware through any other reasonable means of circuit integration or packaging, or may be implemented in any one of the three implementation methods of software, hardware, and firmware, or any appropriate combination of any of these. Alternatively, at least one of the connection module 810, the first acquisition module 820, the second acquisition module 830, the interface test module 840, the routing acquisition module 103 and the test module 104 can be at least partially implemented as a computer program module, which can perform corresponding functions when executed.

[0096] Figure 9 The structure of an electronic device according to an embodiment of the present disclosure is schematically shown.

[0097] like Figure 9 As shown, the electronic device 900 according to an embodiment of the present disclosure includes a processor 901, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 902 or a program loaded from a storage unit 908 into a random access memory (RAM) 903. The processor 901 may include, for example, a general-purpose microprocessor (e.g., a CPU), an instruction set processor and / or a related chipset and / or a special-purpose microprocessor (e.g., an application-specific integrated circuit (ASIC)), etc. The processor 901 may also include onboard memory for caching purposes. The processor 901 may include a single processing unit or multiple processing units for performing different actions of the method flow according to the embodiment of the present disclosure.

[0098] Various programs and data required for the operation of the electronic device 900 are stored in the RAM 903. The processor 901, the ROM 902, and the RAM 903 are connected to each other via a bus 904. The processor 901 executes the various operations of the method flow according to the embodiment of the present disclosure by executing the programs in the ROM 902 and / or the RAM 903. It should be noted that the programs may also be stored in one or more memories other than the ROM 902 and the RAM 903. The processor 901 may also execute the various operations of the method flow according to the embodiment of the present disclosure by executing the programs stored in the one or more memories.

[0099] According to an embodiment of the present disclosure, electronic device 900 may further include an input / output (I / O) interface 905, which is also connected to bus 904. Electronic device 900 may also include one or more of the following components connected to I / O interface 905: an input section 906 including a keyboard, mouse, etc.; an output section 907 including devices such as a cathode ray tube (CRT), liquid crystal display (LCD), and speakers; a storage section 908 including a hard disk; and a communication section 909 including a network interface card such as a LAN card or modem. Communication section 909 performs communication processing via a network such as the Internet. A drive 910 is also connected to I / O interface 905 as needed. Removable media 911, such as a magnetic disk, optical disk, magneto-optical disk, semiconductor memory, etc., is installed in drive 910 as needed, so that computer programs read from the removable media can be installed into storage section 908 as needed.

[0100] The present disclosure also provides a computer-readable storage medium, which may be included in the device / apparatus / system described in the above embodiments, or may exist independently and not be incorporated into the device / apparatus / system. The computer-readable storage medium carries one or more programs, and when executed, implements the method according to the embodiments of the present disclosure.

[0101] According to an embodiment of the present disclosure, a computer-readable storage medium may be a non-volatile computer-readable storage medium, and may include, for example, but is not limited to: a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof. In the present disclosure, a computer-readable storage medium may be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. For example, according to an embodiment of the present disclosure, a computer-readable storage medium may include the ROM 902 and / or RAM 903 described above, and / or one or more memories other than ROM 902 and RAM 903.

[0102] The embodiments of the present disclosure also include a computer program product, which includes a computer program containing program code for executing the method shown in the flowchart. When the computer program product is run in a computer system, the program code is used to enable the computer system to implement the method provided by the embodiments of the present disclosure.

[0103] The computer program executes the above functions defined in the system / device of the embodiment of the present disclosure when the processor 901 executes the computer program. According to the embodiment of the present disclosure, the system, device, module, unit, etc. described above can be implemented by a computer program module.

[0104] In one embodiment, the computer program may be stored on a tangible storage medium such as an optical storage device or a magnetic storage device. In another embodiment, the computer program may be transmitted and distributed in the form of a signal on a network medium, downloaded and installed via the communication portion 909, and / or installed from a removable medium 911. The program code contained in the computer program may be transmitted using any appropriate network medium, including but not limited to wireless, wired, or any suitable combination thereof.

[0105] In such an embodiment, the computer program can be downloaded and installed from a network via the communication section 909, and / or installed from a removable medium 911. When the computer program is executed by the processor 901, the above-described functions defined in the system of the embodiment of the present disclosure are performed. According to the embodiment of the present disclosure, the systems, devices, means, modules, units, etc. described above can be implemented by computer program modules.

[0106] According to an embodiment of the present disclosure, the program code for executing the computer program provided by the embodiment of the present disclosure can be written in any combination of one or more programming languages. Specifically, these computer programs can be implemented using high-level procedural and / or object-oriented programming languages, and / or assembly / machine languages. Programming languages ​​include, but are not limited to, languages ​​such as Java, C++, Python, "C" or similar programming languages. The program code can be executed entirely on the user computing device, partially on the user device, partially on a remote computing device, or entirely on a remote computing device or server. In cases involving a remote computing device, the remote computing device can be connected to the user computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computing device (for example, using an Internet service provider to connect via the Internet).

[0107] The flowcharts and block diagrams in the accompanying drawings illustrate the possible implementation architecture, functions and operations of the systems, methods and computer program products according to various embodiments of the present disclosure. In this regard, each box in the flowchart or block diagram can represent a module, program segment, or a part of code, and the above-mentioned module, program segment, or a part of code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in an order different from that marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram or flowchart, and the combination of boxes in the block diagram or flowchart, can be implemented with a dedicated hardware-based system that performs the specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.

[0108] The above describes the embodiments of the present disclosure. However, these embodiments are for illustrative purposes only and are not intended to limit the scope of the present disclosure. Although each embodiment has been described separately above, this does not mean that the measures in each embodiment cannot be advantageously used in combination. Without departing from the scope of the present disclosure, those skilled in the art may make various substitutions and modifications, which should all fall within the scope of the present disclosure.

Claims

1. An interface testing method, wherein: The method comprises: Establish a debug connection with the debug interface of the application under test; Scanning information of each of m types of objects in the application memory of the application under test through the debugging connection to obtain an object information set, where m is an integer greater than or equal to 2; Based on the information of each object in the object information set, obtaining information of the interface used by each object from the application memory to obtain the interface information set of the tested application; and The interfaces in the interface information set are tested.

2. The method according to claim 1, wherein The acquiring, from the application memory, information about the interface used by each object based on the information about each object in the object information set includes: Acquire an interface definition specification of each object based on the information of the object; Determining, based on the interface definition specification of the object, a code segment in the object for defining an interface used therein; and Extract interface information from the code segment.

3. The method according to claim 1, wherein The testing of the interface in the interface information set includes: Based on the interface name of each interface in the interface information set, obtaining a code snippet where each interface is located from the application memory of the application under test; Decompile the obtained code snippet to obtain the interface code segment; Extracting interface content of each interface from the interface code segment; Constructing a test case for each interface based on the interface content; and Use the test cases for each interface to test the corresponding interface.

4. The method according to claim 3, wherein: The constructing of a test case for each interface based on the interface content includes: Constructing a legal request message for each interface based on the interface content; Inputting the legal request message and the interface code segment of each interface into a mature large language model, and using a preset first prompt instruction to prompt the large language model to output interface business logic information; Matching a test case to be used corresponding to the interface business logic information from pre-stored basic security test cases; The information of the test case to be used is used to change the information in the legal request message to obtain at least one test case.

5. The method according to claim 4, wherein The constructing of a test case for each interface based on the interface content further includes: The legal request message and the interface code segment of each interface are input into a mature large language model, and a preset second prompt instruction is used to prompt the large language model to output at least one test case.

6. The method according to claim 1, wherein The m objects include at least middleware and architecture framework.

7. The method according to claim 1 or 6, wherein: Scanning information of each of the m types of objects in the application memory of the application under test through the debugging connection to obtain an object information set includes: Obtaining pre-configured dictionary data, the dictionary data including a correspondence between a specified class name and object information; and When the scanning finds that the class loaded in the application memory of the tested application matches the specified class name in the dictionary data, the corresponding object information is obtained based on the corresponding relationship in the dictionary data.

8. An interface testing device, wherein: The device comprises: A connection module, used to establish a debugging connection with the debugging interface of the application under test; A first acquisition module is configured to scan information of each of m types of objects in the application memory of the application under test through the debugging connection to obtain an object information set, where m is an integer greater than or equal to 2; A second acquisition module is configured to acquire information of interfaces used by each object from the application memory based on information of each object in the object information set, so as to obtain an interface information set of the application under test; and The interface testing module is used to test the interfaces in the interface information set.

9. An electronic device comprising: one or more processors; a memory for storing one or more computer programs, The one or more processors execute the one or more computer programs to implement the steps of the method according to any one of claims 1 to 7.

10. A computer-readable storage medium having a computer program or instruction stored thereon, wherein: When the computer program or instruction is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.

11. A computer program product comprising a computer program or instructions, wherein: When the computer program or instruction is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.