Intelligent detection method for business logic vulnerabilities
By supervising and digitizing business logs, dynamically marking abnormal records, and conducting logical rule tracing analysis and optimization, the problem of poor tracing and detection of multi-dimensional impacts of vulnerabilities in existing technologies has been solved, and more efficient vulnerability detection and assessment has been achieved.
Patent Information
- Application Number
- CN202510864536.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-26
- Publication Date
- 2025-10-03
- Estimated Expiration
- 2045-06-26
AI Technical Summary
Existing intelligent identification technology based on business logs cannot effectively conduct multi-dimensional impact tracing analysis of existing vulnerabilities and autonomously evaluate and optimize detection effects, resulting in poor detection results.
By supervising and digitizing new business records, obtaining business logic specification identification, dynamically marking normal or abnormal records, conducting abnormal logic rule traceability analysis, combining business log data for multi-dimensional vulnerability impact analysis, and dynamically optimizing business logic rules based on the analysis results.
It has achieved the improvement of the multi-dimensional impact tracing analysis effect of existing vulnerabilities and the independent evaluation optimization of detection effects, thereby improving the coverage and accuracy of vulnerability detection.
Smart Images

Figure CN120744930A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of vulnerability detection, and in particular to an intelligent detection method for business logic vulnerabilities. Background Art
[0002] Business logic vulnerabilities refer to design or implementation flaws in an application's business processes or rules, which can be exploited by attackers to perform unauthorized operations, obtain sensitive information, or damage the system. Unlike traditional security vulnerabilities, such as SQL injection and cross-site scripting, business logic vulnerabilities usually do not involve direct technical attack methods, but instead achieve malicious purposes by abusing or bypassing the application's intended workflow.
[0003] When implementing existing business logic vulnerability detection technology based on intelligent identification of business logs, it is generally necessary to mark and train the business logs with several annotated identification results in advance, and to match and analyze the information to be identified corresponding to the business logs to determine whether it has been attacked. However, it can only detect and analyze vulnerabilities that have already been attacked, and cannot perform vulnerability impact analysis of different aspects of the vulnerabilities that have already occurred, nor can it independently evaluate and optimize the detection effect. There are problems with the multi-dimensional impact tracing analysis of the vulnerabilities that have already occurred, and the independent evaluation and optimization of the detection effect are poor. Summary of the Invention
[0004] The purpose of the present invention is to provide an intelligent detection method for business logic vulnerabilities, which is used to solve the technical problems of poor multi-dimensional impact tracing and analysis of existing vulnerabilities and poor autonomous evaluation and optimization of detection effects in existing solutions.
[0005] The purpose of the present invention can be achieved through the following technical solutions:
[0006] An intelligent detection method for business logic vulnerabilities, comprising:
[0007] Based on the business log, new business records are supervised and digitized to obtain the business logic specification identifier corresponding to the new business record. The business records are dynamically marked according to the business logic specification identifier to obtain normal business records or abnormal business records;
[0008] Conduct retrospective analysis of abnormal logic rules based on the abnormal business records obtained through analysis to determine the impact of logical vulnerabilities corresponding to the abnormal logic rules to which the abnormal business records belong, as well as their digital representation;
[0009] Based on business logs, conduct business logic vulnerability coverage analysis of different aspects of the logic vulnerability impact data obtained from the corresponding processing of all new business records, and dynamically optimize the business logic rules for the subsequent implementation of the existing business logic vulnerability detection solution based on the analysis results; dynamic optimization management of business logic rules includes maintaining the implementation of the existing business logic vulnerability detection solution, upgrading and optimizing some business logic rules for general vulnerability types or special vulnerability types of the existing business logic vulnerability detection solution, or upgrading and optimizing the overall business logic rules for general vulnerability types and special vulnerability types of the existing business logic vulnerability detection solution.
[0010] Preferably, newly added business records in the business log are obtained in real time, and business objects that actively perform business interactions in the business records are marked as target business objects, and business objects that passively perform business interactions with the target business objects in the business records are marked as target business interaction objects;
[0011] Obtain the interaction content and interaction results of the business actions corresponding to the target business object and the target business interaction object, sort and combine the target business interaction object, interaction content and interaction results, obtain the business sequence to be detected corresponding to the business record, and analyze the business logic standard data associated with the business sequence to be detected and the target business object through the business logic recognition model, and output the business logic specification identifier GF corresponding to the business record;
[0012] The business logic specification identifier includes a value of 0 or 1.
[0013] Preferably, the expression of the business logic identification model is Where [YJk] is the service sequence to be detected corresponding to the service record, k = 1, 2, 3; YJk is YJ1, YJ2, YJ3, which are the target service interaction object, interaction content, and interaction result respectively; UB is the service logic standard data associated with the target service object;
[0014] According to the business logic specification identifier with a value of 0, the business record is marked as a normal business record;
[0015] According to the business logic specification identifier with a value of 1, the corresponding business record is marked as an abnormal business record.
[0016] Preferably, the vulnerability type corresponding to the abnormal business record is obtained, and according to the vulnerability type, the total number of occurrences of the corresponding conventional vulnerability type is increased by one, or the total number of occurrences of the corresponding special vulnerability type is increased by one;
[0017] and, obtaining an abnormal logic rule between a target business object and a target business interaction object based on the abnormal business record, obtaining all other business objects with the same abnormal logic rule and marking them as verification business objects;
[0018] Perform business logic vulnerability verification on all verified business objects, count the total number of all verified business objects with business logic vulnerabilities in abnormal logic rules, and use the formula Calculate and analyze the logic vulnerability status value LY corresponding to the abnormal logic rule. In the formula, NY and NH are the total number of all verified business objects with business logic vulnerabilities and the total number of all verified business objects with the same abnormal logic rule, respectively.
[0019] Preferably, if the logic vulnerability impact value is 1, the logic vulnerability impact value corresponding to the abnormal logic rule is set to α, and the total number of overall vulnerabilities of the local business logic is increased by 1; α is the interaction impact coefficient corresponding to the abnormal logic rule;
[0020] If the logic vulnerability impact value is not 1, the logic vulnerability impact value corresponding to the abnormal logic rule is set to α×LY, and the total number of vulnerabilities in the local business logic is increased by one.
[0021] Preferably, obtain the total number of all newly added business records in the business log and their corresponding marked normal business records and abnormal business records, and use the formula Calculate the first vulnerability existence status value LC1 corresponding to all newly added business records; where YY1 is the total number of vulnerabilities in the local business logic; YY2 is the total number of vulnerabilities in the entire business logic; YZ is the total number of all newly added business records; η is the vulnerability type impact correction coefficient, which ranges from (1 to 3); β is the standard value of the first vulnerability existence status; and C is a real number greater than 0.
[0022] Preferably, the logical vulnerability impact values αi corresponding to all abnormal logical rules are obtained, where i is a different abnormal logical rule, i=1, 2, 3, ..., n; n is a positive integer representing the total number of abnormal logical rules, and the formula Calculate and obtain the second vulnerability existence state value LC2 corresponding to all abnormal logic rules; where μ is the second vulnerability existence state standard value.
[0023] Preferably, the first vulnerability existence status value and the second vulnerability existence status value are combined with the total number of occurrences of conventional vulnerability types and the total number of occurrences of special vulnerability types by using the formula LFj=ω×NLj to calculate the vulnerability type coverage value LFj corresponding to different vulnerability types of all business logics; wherein, j=1, 2; NLj is NL1 and NL2, which are the total number of occurrences of conventional vulnerability types and the total number of occurrences of special vulnerability types, respectively; LFj is LF1 and LF2, which are the vulnerability type coverage values corresponding to conventional vulnerability types and special vulnerability types, respectively; ω is the overall vulnerability existence influence coefficient, ω=max(LC 1, LC 2); max() represents obtaining the maximum value among different real numbers;
[0024] The vulnerability type coverage values obtained by calculating different vulnerability types are sorted and combined to obtain a vulnerability type coverage supervision sequence.
[0025] Preferably, data analysis is performed on the vulnerability type coverage supervision sequence to determine the vulnerability existence detection status corresponding to the business logic and implement targeted business logic vulnerability detection management.
[0026] Preferably, if the number of elements in the vulnerability type coverage supervision sequence is no greater than 1, the implementation of the existing business logic vulnerability detection solution is maintained;
[0027] If the number of elements in the vulnerability type coverage supervision sequence is greater than 1, the existing business logic vulnerability detection solution will be upgraded and optimized for some business logic rules of general vulnerability types or special vulnerability types;
[0028] If the number of elements in the vulnerability type coverage supervision sequence is greater than 1, the overall business logic rules for general vulnerability types and special vulnerability types will be upgraded and optimized for the existing business logic vulnerability detection solution.
[0029] Compared with the existing solutions, the present invention achieves the following beneficial effects:
[0030] The present invention supervises and digitally processes new business records based on business logs, obtains business logic specification identifiers corresponding to new business records, realizes digital representation of business logic specifications corresponding to new business records, and dynamically marks the corresponding business records according to the business logic specification identifiers to obtain normal business records or abnormal business records. It can not only obtain the specification type corresponding to the business record, but also provide reliable single-time supervision data support for subsequent data analysis of different aspects of business logic vulnerabilities.
[0031] The present invention performs a retrospective analysis of abnormal logic rules based on the abnormal business records obtained through analysis, determines the logical vulnerability impact and digital representation corresponding to the abnormal logic rules to which the abnormal business records belong, and realizes the extended analysis and digital processing representation of abnormal logic rules for abnormal business records marked by previous analysis, which can provide reliable mining and analysis data support for the multi-dimensional analysis of business logic vulnerability coverage of logic vulnerability impact data.
[0032] The present invention performs business logic vulnerability coverage analysis on different aspects of the logic vulnerability impact data obtained by corresponding processing of all new business records, and dynamically optimizes the business logic rules for the subsequent implementation of the existing business logic vulnerability detection solution based on the analysis results, thereby realizing an overall dimensional expansion analysis of the early local vulnerability supervision and analysis data, improving the multi-dimensional impact tracing analysis effect of the vulnerabilities that have occurred and the autonomous evaluation and optimization effect of the detection effect. BRIEF DESCRIPTION OF THE DRAWINGS
[0033] The present invention will be further described below with reference to the accompanying drawings.
[0034] Figure 1 This is a flowchart of an intelligent detection method for business logic vulnerabilities of the present invention.
[0035] Figure 2 This is a flowchart of the data analysis and digital processing of the logical vulnerability impact value in the present invention. DETAILED DESCRIPTION
[0036] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.
[0037] like Figure 1 As shown, the present invention is an intelligent detection method for business logic vulnerabilities, comprising:
[0038] Based on the business log, new business records are supervised and digitized to obtain the business logic specification identifier corresponding to the new business record. The business records are dynamically marked according to the business logic specification identifier to obtain normal business records or abnormal business records; including:
[0039] Obtaining newly added business records in the business log in real time, and marking the business objects that actively interact with the target business objects in the business records as target business objects, and marking the business objects that passively interact with the target business objects in the business records as target business interaction objects;
[0040] Specific business operations can be determined based on the actual application requirements of the actual application scenario, such as the XX management system. Business records added in real time to the business log refer to information automatically generated and recorded by the system whenever a specific business activity or event occurs during system operation. These records typically contain key details about the business operation, such as the time of the operation, the executing user, the operation type, and the data involved. For example, if business A requests an action to be performed on business B, business A is the target business object, and business B is the target business interaction object.
[0041] Obtain the interaction content and interaction results of the business actions corresponding to the target business object and the target business interaction object, sort and combine the target business interaction object, interaction content, and interaction results. Specifically, the interaction content can be business A requesting to add, delete, or modify data C of business B, and the interaction result can be request processing success or request processing failure. Obtain the business sequence to be detected corresponding to the business record, and perform data analysis on the business logic standard data associated with the business sequence to be detected and the target business object through the business logic recognition model, and output the business logic specification identifier GF corresponding to the corresponding business record;
[0042] Among them, the expression of the business logic identification model is Where [YJk] is the service sequence to be detected corresponding to the service record, k = 1, 2, 3; YJk is YJ1, YJ2, and YJ3, which are the target service interaction object, interaction content, and interaction result, respectively; UB is the business logic standard data associated with the target service object, which is determined based on the business logic design data of the target service object;
[0043] The business logic specification identifier is used to calculate the business interaction data between the target business object and the target business interaction object to digitally represent the corresponding single business logic specification state;
[0044] The business logic specification identifier contains a value of 0 or 1;
[0045] A business logic specification identifier with a value of 0 indicates the business logic specification of the corresponding business record;
[0046] A business logic standard flag with a value of 1 indicates that the business logic of the corresponding business record is not standardized;
[0047] According to the business logic specification identifier with a value of 0, the business record is marked as a normal business record;
[0048] According to the business logic specification identifier with a value of 1, the business record is marked as an abnormal business record;
[0049] In an embodiment of the present invention, new business records are supervised and digitized based on business logs to obtain business logic specification identifiers corresponding to the new business records, thereby realizing digital representation of the business logic specifications corresponding to the new business records. In addition, the business records are dynamically marked according to the business logic specification identifiers to obtain normal business records or abnormal business records. This can not only obtain the specification type corresponding to the business record, but also provide reliable single-time supervision data support for subsequent data analysis of different aspects of business logic vulnerabilities.
[0050] Based on the abnormal business records obtained through analysis, the abnormal logic rules are retroactively analyzed to determine the logical vulnerability impact and digital representation corresponding to the abnormal logic rules to which the abnormal business records belong; including:
[0051] Obtain the vulnerability type corresponding to the abnormal business record, and add one to the total number of regular vulnerability types or one to the total number of special vulnerability types according to the vulnerability type;
[0052] Vulnerability types include general vulnerability types and special vulnerability types. General vulnerability types refer to common vulnerabilities that were not considered during business logic design. Special vulnerability types refer to novel vulnerabilities that were not considered during business logic design. The vulnerability types corresponding to abnormal business records are reviewed and determined by business logic designers.
[0053] Furthermore, based on the abnormal business record, the abnormal logic rules between the target business object and the target business interaction object are obtained, and all other business objects with the same abnormal logic rules are obtained and marked as verification business objects. It can be understood that the logic rules are used by multiple business objects. When the logic rules are abnormal, it is necessary to further actively expand and mine other potential logic loopholes of the same abnormal logic rules.
[0054] Perform business logic vulnerability verification on all verified business objects, count the total number of all verified business objects with business logic vulnerabilities in abnormal logic rules, and use the formula Calculate and analyze the logic vulnerability status value LY corresponding to the abnormal logic rule. In the formula, NY and NH are the total number of all verified business objects with business logic vulnerabilities and the total number of all verified business objects with the same abnormal logic rule, respectively.
[0055] like Figure 2 As shown, if the logical vulnerability impact value is 1, the logical vulnerability impact value corresponding to the abnormal logical rule is set to α, and the total number of vulnerabilities in the local business logic is increased by 1; α is the interaction impact coefficient corresponding to the abnormal logical rule. The interaction impact coefficient is determined by professional and technical personnel in this field based on design requirements data and historical business data. The interaction impact coefficient is used to digitally represent the interaction impact corresponding to the abnormal logical rule;
[0056] If the logical vulnerability impact value is not 1, the logical vulnerability impact value corresponding to the abnormal logic rule is set to α×LY, and the total number of vulnerabilities in the local business logic is increased by one;
[0057] In an embodiment of the present invention, a retrospective analysis of abnormal logic rules is performed based on the abnormal business records obtained through analysis, and the logical vulnerability impact and digital representation corresponding to the abnormal logic rules to which the abnormal business records belong are determined. This realizes the extended analysis and digital processing representation of abnormal logic rules for abnormal business records marked by previous analysis, and can provide reliable mining and analysis data support for the multi-dimensional analysis of business logic vulnerability coverage of logic vulnerability impact data.
[0058] Based on business logs, we conduct business logic vulnerability coverage analysis on different aspects of the logic vulnerability impact data obtained from the corresponding processing of all new business records. Based on the analysis results, we dynamically optimize the business logic rules for the subsequent implementation of the existing business logic vulnerability detection solution; including:
[0059] Get all newly added business records in the business log and the total number of normal business records and abnormal business records with corresponding marks, and use the formula Calculate and obtain the first vulnerability existence status value LC1 corresponding to all newly added business records; where YY1 is the total number of vulnerabilities in the local business logic; YY2 is the total number of vulnerabilities in the entire business logic; YZ is the total number of all newly added business records; η is the vulnerability type impact correction coefficient, which ranges from (1 to 3) and can be specifically set to 1.514; β is the standard value of the first vulnerability existence status, which is determined based on the previous business logic vulnerability design requirements data or the previous security test data; C is a real number greater than 0, specifically 0.95;
[0060] And, obtain the logical vulnerability impact value αi corresponding to all abnormal logical rules that appear, i is a different abnormal logical rule, i = 1, 2, 3, ..., n; n is a positive integer, representing the total number of abnormal logical rules, and through the formula Calculate and obtain the second vulnerability existence status value LC2 corresponding to all abnormal logic rules; where μ is the standard value of the second vulnerability existence status, which is determined based on the previous business logic vulnerability design requirement data or the previous security test data, and μ>β;
[0061] It should be noted that the first vulnerability existence status value and the second vulnerability existence status value are used to calculate the logical vulnerability data corresponding to all abnormal logical rules from different aspects, so as to digitally represent the overall logical vulnerability impact;
[0062] The first vulnerability existence status value and the second vulnerability existence status value are combined with the total number of occurrences of common vulnerability types and the total number of occurrences of special vulnerability types through the formula LFj = ω × NLj to obtain the vulnerability type coverage value LFj corresponding to different vulnerability types of all business logics; in the formula, j = 1, 2; NLj is NL1 and NL2, which are the total number of occurrences of common vulnerability types and the total number of occurrences of special vulnerability types, respectively; LFj is LF1 and LF2, which are the vulnerability type coverage values corresponding to common vulnerability types and special vulnerability types, respectively; ω is the overall vulnerability existence influence coefficient, ω = max(LC 1, LC 2); max() indicates obtaining the maximum value among different real numbers;
[0063] It should be noted that the vulnerability type coverage value is used to calculate different vulnerability types in combination with the overall logical vulnerability impact data to digitally represent the type logical vulnerability impact caused by different vulnerability types;
[0064] Sort and combine the vulnerability type coverage values obtained by calculating different vulnerability types to obtain a vulnerability type coverage supervision sequence;
[0065] Conduct data analysis on vulnerability type coverage supervision sequences, determine the vulnerability detection status corresponding to the business logic, and implement targeted business logic vulnerability detection management;
[0066] If the number of elements in the vulnerability type coverage supervision sequence is not greater than 1, the vulnerability existence detection coverage normal state is generated, and the implementation of the existing business logic vulnerability detection plan is maintained;
[0067] If there are more than 1 elements in the vulnerability type coverage supervision sequence, a vulnerability existence detection coverage mild abnormal state is generated, and the existing business logic vulnerability detection solution is upgraded and optimized for some business logic rules of general vulnerability types or special vulnerability types; the upgrade and optimization of some business logic rules of general vulnerability types or special vulnerability types are implemented, and the vulnerability type to which the elements with more than 1 in the vulnerability type coverage supervision sequence belong is determined;
[0068] If the elements in the vulnerability type coverage supervision sequence are all greater than 1, a vulnerability detection coverage severe abnormality state is generated, and the overall business logic rules for general vulnerability types and special vulnerability types are upgraded and optimized for the existing business logic vulnerability detection solution;
[0069] In addition, by upgrading and optimizing some business logic rules, targeted logic rule supplements and additions can be implemented for abnormal vulnerability types; by upgrading and optimizing the overall business logic rules, comprehensive logic rule supplements and additions can be implemented for all vulnerability types.
[0070] In an embodiment of the present invention, by performing business logic vulnerability coverage analysis on different aspects of the logic vulnerability impact data obtained by corresponding processing of all newly added business records, dynamic optimization management of business logic rules is performed on the subsequent implementation of the existing business logic vulnerability detection solution based on the analysis results, and an overall dimensional expansion analysis of the early local vulnerability supervision and analysis data is achieved, thereby improving the multi-dimensional impact tracing analysis effect of the vulnerabilities that have occurred and the autonomous evaluation and optimization effect of the detection effect.
[0071] In addition, the formulas involved in the above are all calculated by removing dimensions and taking their numerical values. They are a formula that is closest to the actual situation obtained by collecting a large amount of data and simulating it through simulation software.
[0072] In the several embodiments provided by the present invention, it should be understood that the disclosed methods can be implemented in other ways. For example, the above-described embodiments of the invention are merely illustrative. For example, the division of modules is only a logical function division, and other division methods may be used in actual implementation.
[0073] Modules described as separate components may or may not be physically separate, and components shown as modules may or may not be physical modules, and may be located in one place or distributed across multiple network modules. Some or all of these modules may be selected to achieve the objectives of this embodiment based on actual needs.
[0074] In addition, the functional modules in various embodiments of the present invention may be integrated into a single processing module, each module may exist physically separately, or two or more modules may be integrated into a single module. The aforementioned integrated modules may be implemented in the form of hardware or hardware plus software functional modules.
[0075] It is obvious to a person skilled in the art that the present invention is not limited to the details of the exemplary embodiments described above, but that the present invention can be implemented in other specific forms without departing from the essential characteristics of the present invention.
[0076] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not limiting. Although the present invention has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solutions of the present invention may be modified or replaced by equivalents without departing from the spirit and scope of the technical solutions of the present invention.
Claims
1. An intelligent detection method for business logic vulnerabilities, characterized in that: include: Based on the business log, new business records are supervised and digitized to obtain the business logic specification identifier corresponding to the new business record. The business records are dynamically marked according to the business logic specification identifier to obtain normal business records or abnormal business records; Conduct retrospective analysis of abnormal logic rules based on the abnormal business records obtained through analysis to determine the impact of logical vulnerabilities corresponding to the abnormal logic rules to which the abnormal business records belong, as well as their digital representation; Based on business logs, conduct business logic vulnerability coverage analysis of different aspects of the logic vulnerability impact data obtained from the corresponding processing of all new business records, and dynamically optimize the business logic rules for the subsequent implementation of the existing business logic vulnerability detection solution based on the analysis results; dynamic optimization management of business logic rules includes maintaining the implementation of the existing business logic vulnerability detection solution, upgrading and optimizing some business logic rules for general vulnerability types or special vulnerability types of the existing business logic vulnerability detection solution, or upgrading and optimizing the overall business logic rules for general vulnerability types and special vulnerability types of the existing business logic vulnerability detection solution.
2. The intelligent detection method for business logic vulnerabilities according to claim 1, characterized in that: Obtaining newly added business records in the business log in real time, and marking the business objects that actively interact with the target business objects in the business records as target business objects, and marking the business objects that passively interact with the target business objects in the business records as target business interaction objects; Obtain the interaction content and interaction results of the business actions corresponding to the target business object and the target business interaction object, sort and combine the target business interaction object, interaction content and interaction results, obtain the business sequence to be detected corresponding to the business record, and analyze the business logic standard data associated with the business sequence to be detected and the target business object through the business logic recognition model, and output the business logic specification identifier GF corresponding to the business record; The business logic specification identifier includes a value of 0 or 1.
3. The intelligent detection method for business logic vulnerabilities according to claim 2, characterized in that: The expression of the business logic identification model is Where [YJk] is the service sequence to be detected corresponding to the service record, k = 1, 2, 3; YJk is YJ1, YJ2, YJ3, which are the target service interaction object, interaction content, and interaction result respectively; UB is the service logic standard data associated with the target service object; According to the business logic specification identifier with a value of 0, the business record is marked as a normal business record; According to the business logic specification identifier with a value of 1, the corresponding business record is marked as an abnormal business record.
4. The intelligent detection method for business logic vulnerabilities according to claim 3 is characterized in that: Obtain the vulnerability type corresponding to the abnormal business record, and add one to the total number of regular vulnerability types or one to the total number of special vulnerability types according to the vulnerability type; and, obtaining an abnormal logic rule between a target business object and a target business interaction object based on the abnormal business record, obtaining all other business objects with the same abnormal logic rule and marking them as verification business objects; Perform business logic vulnerability verification on all verified business objects, count the total number of all verified business objects with business logic vulnerabilities in abnormal logic rules, and use the formula Calculate and analyze the logic vulnerability status value LY corresponding to the abnormal logic rule. In the formula, NY and NH are the total number of all verified business objects with business logic vulnerabilities and the total number of all verified business objects with the same abnormal logic rule, respectively.
5. The intelligent detection method for business logic vulnerabilities according to claim 4, characterized in that: If the logical vulnerability impact value is 1, the logical vulnerability impact value corresponding to the abnormal logical rule is set to α, and the total number of vulnerabilities in the local business logic is increased by 1; α is the interaction impact coefficient corresponding to the abnormal logical rule; If the logic vulnerability impact value is not 1, the logic vulnerability impact value corresponding to the abnormal logic rule is set to α×LY, and the total number of vulnerabilities in the local business logic is increased by one.
6. The intelligent detection method for business logic vulnerabilities according to claim 5, characterized in that: Get all newly added business records in the business log and the total number of normal business records and abnormal business records with corresponding marks, and use the formula Calculate the first vulnerability existence status value LC1 corresponding to all newly added business records; where YY1 is the total number of vulnerabilities in the local business logic; YY2 is the total number of vulnerabilities in the entire business logic; YZ is the total number of all newly added business records; η is the vulnerability type impact correction coefficient, which ranges from (1 to 3); β is the standard value of the first vulnerability existence status; and C is a real number greater than 0.
7. The intelligent detection method for business logic vulnerabilities according to claim 6, characterized in that: Get the logical vulnerability impact value αi corresponding to all abnormal logic rules that appear, where i is a different abnormal logic rule, i = 1, 2, 3, ..., n; n is a positive integer representing the total number of abnormal logic rules, and use the formula Calculate and obtain the second vulnerability existence state value LC2 corresponding to all abnormal logic rules; where μ is the second vulnerability existence state standard value.
8. The intelligent detection method for business logic vulnerabilities according to claim 7, characterized in that: The first vulnerability existence status value and the second vulnerability existence status value are combined with the total number of regular vulnerability types and the total number of special vulnerability types using the formula LFj = ω × NLj to obtain the vulnerability type coverage value LFj corresponding to different vulnerability types in all business logics; where j = 1, 2; NLj is NL1 and NL2, which are the total number of common vulnerability types and the total number of special vulnerability types respectively; LFj is LF1 and LF2, which are the vulnerability type coverage values corresponding to common vulnerability types and special vulnerability types respectively; ω is the overall vulnerability impact coefficient, ω = max(LC 1, LC 2); max() means obtaining the maximum value among different real numbers; The vulnerability type coverage values obtained by calculating different vulnerability types are sorted and combined to obtain a vulnerability type coverage supervision sequence.
9. The intelligent detection method for business logic vulnerabilities according to claim 8, characterized in that: Conduct data analysis on the vulnerability type coverage supervision sequence to determine the vulnerability detection status corresponding to the business logic and implement targeted business logic vulnerability detection management.
10. The intelligent detection method for business logic vulnerabilities according to claim 9, characterized in that: If the number of elements in the vulnerability type coverage supervision sequence is no more than 1, the existing business logic vulnerability detection solution will be maintained; If the number of elements in the vulnerability type coverage supervision sequence is greater than 1, the existing business logic vulnerability detection solution will be upgraded and optimized for some business logic rules of general vulnerability types or special vulnerability types; If the number of elements in the vulnerability type coverage supervision sequence is greater than 1, the overall business logic rules for general vulnerability types and special vulnerability types will be upgraded and optimized for the existing business logic vulnerability detection solution.
Citation Information
Patent Citations
Detection method and system for service logic vulnerability attacks
CN110135166A
Service logic security test method and system and storage medium
CN116820983A
Automatic business logic vulnerability mining method
CN117349159A
Business logic coding framework generation method and system based on large language model
CN117724683A
Application logic vulnerability detection method
CN119397548A