Vulnerability detection method and device, electronic equipment and program product

By automatically determining keywords and generating test files, the problem of low security detection efficiency in existing technologies is solved, enabling more accurate identification of potential vulnerabilities, reducing the workload of security testers, and improving detection efficiency.

CN120880707APending Publication Date: 2025-10-31DAWNING INT INFORMATION IND CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510941990.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-08
Publication Date
2025-10-31

AI Technical Summary

Technical Problem

Existing technical tools can only identify common vulnerabilities, resulting in low security detection efficiency and requiring security testers to frequently repeat the search operation.

Method used

By responding to user-inputted detection parameters, the system automatically determines keywords and uses a target search tool to perform searches, generating multiple data entries to be detected. Based on each data entry, a test file is generated, and multiple vulnerability detection processes are performed to produce a vulnerability detection report.

Benefits of technology

It reduces the workload of security testers, accurately identifies potential security vulnerabilities, and improves security testing efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120880707A_ABST
    Figure CN120880707A_ABST
Patent Text Reader

Abstract

The invention provides a vulnerability detection method and device, electronic equipment and a program product. The method comprises the steps of determining a keyword corresponding to a detection parameter in response to the detection parameter input by a user, performing search processing on the keyword through a target search tool to obtain a search result, determining multiple pieces of to-be-detected data according to the search result, generating a test file according to the to-be-detected data for any one piece of to-be-detected data, and determining the to-be-detected data according to the test file. According to the method, the to-be-detected data is subjected to multiple vulnerability detection processing to obtain the detection results, and the vulnerability detection report is generated according to the detection results corresponding to the to-be-detected data, so that the security detection efficiency is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of cybersecurity, and more particularly to a method, apparatus, electronic device, and program product for detecting vulnerabilities. Background Technology

[0002] With the increasing sophistication and diversification of cyberattack methods, such as malware attacks and distributed denial-of-service attacks, website security faces unprecedented challenges. Cyberattacks can not only lead to customer data breaches, legal disputes, and economic losses, but also damage a company's brand image and reduce customer loyalty.

[0003] Currently, security testers need to use separate search methods for each type of security issue to obtain target websites and then use existing technical tools to conduct security checks on these websites. Existing technical tools can only scan target websites and identify common network vulnerabilities. The working principle of these tools is mainly to simulate hacker attack behavior, sending a series of carefully crafted requests to the target website, and then analyzing the website's responses to determine if security vulnerabilities exist.

[0004] During the vulnerability detection process, security testers need to perform frequent and repetitive search operations, and the technical tools can only identify common vulnerabilities, resulting in low security detection efficiency. Summary of the Invention

[0005] This application provides a vulnerability detection method, apparatus, electronic device, and program product to solve the technical problem of low security detection efficiency in the prior art.

[0006] Firstly, this application provides a vulnerability detection method, the method comprising:

[0007] In response to the detection parameters input by the user, the keyword corresponding to the detection parameters is determined;

[0008] The keywords are searched using a target search tool to obtain search results;

[0009] Based on the search results, multiple data points to be detected were identified;

[0010] For any piece of data to be tested, a test file is generated based on the data, and multiple vulnerability detection processes are performed on the data based on the test file to obtain the detection results;

[0011] A vulnerability detection report is generated based on the detection results corresponding to the multiple data to be detected.

[0012] In this way, by responding to the detection parameters input by the user, keywords are automatically determined and searched using target search tools to generate multiple data entries to be tested. This eliminates the tedious step of manually searching target websites one by one, greatly reducing the workload of security testers. Furthermore, based on each data entry to be tested, corresponding test files are generated for multiple vulnerability detection processes, which more accurately identify potential security vulnerabilities and generate vulnerability detection reports, thereby improving the efficiency of security testing.

[0013] Optionally, the method described above, based on the data to be detected, generates a test file, including:

[0014] The data to be detected is parsed to determine the parsing result, which includes any one or more of the following: protocol, domain name, path, query parameters, and preset fields.

[0015] Based on the analysis results, at least one target test scenario is determined;

[0016] Based on the at least one target test scenario and the analysis results, multiple mutation parameters are determined by updating the library using an algorithm.

[0017] A test file is generated based on the at least one target test scenario and the multiple mutation parameters.

[0018] In this way, a corresponding test file is generated based on each piece of data to be tested, which can more accurately identify potential security vulnerabilities and improve security testing efficiency.

[0019] Optionally, in the method described above, for any target test scenario, based on the target test scenario and the parsing result, multiple mutation parameters are determined by updating the library through an algorithm, including:

[0020] Based on the target test scenario and the analysis results, determine the mutation location of the data to be detected;

[0021] Based on the target test scenario, multiple mutation algorithms are determined in the algorithm update library;

[0022] Based on the multiple mutation algorithms, the original parameter values ​​at the positions to be mutated are mutated respectively to determine multiple mutation parameters.

[0023] In this way, by dynamically matching the target test scenario with the algorithm-updated library, the shortcomings of traditional tools in detecting new vulnerabilities are addressed, potential security vulnerabilities are identified more accurately, and security detection efficiency is improved.

[0024] Optionally, the method described above, based on the parsing results, determines at least one target test scenario, including:

[0025] If the parsing result includes the query parameters, determine whether the query parameters are preset query parameters. If so, determine that at least one target test scenario includes a database command injection scenario and a client script injection scenario.

[0026] If the parsing result includes the path, determine whether the path includes file features or directory features. If so, determine that at least one target test scenario includes a path traversal scenario.

[0027] If the parsing result includes the preset field, the preset field is identified to obtain the field type of the preset field. Based on the field type, a test command scenario corresponding to the test command is generated, and at least one target test scenario is determined to include the test command scenario.

[0028] In this way, by dynamically matching the target test scenario with the updated library through the algorithm, potential security vulnerabilities can be identified more accurately, thus improving the efficiency of security detection.

[0029] Optionally, in the method described above, the test file includes multiple mutation parameters, and based on the test file, the data to be detected undergoes multiple vulnerability detection processes to obtain detection results, including:

[0030] For any given mutation parameter, generate request information based on the mutation parameter and send the request information to the server;

[0031] Receive response information corresponding to the request information sent by the server;

[0032] Based on the response information, determine the response result corresponding to the variation parameter;

[0033] Among the response results corresponding to the multiple variation parameters, determine whether the number of abnormal response results is greater than a first threshold. If yes, the detection result is determined to be abnormal; otherwise, the detection result is determined to be normal.

[0034] In this way, by performing multiple vulnerability detection processes based on multiple variation parameters, potential security vulnerabilities can be identified more accurately, thus improving security detection efficiency.

[0035] Optionally, in the method described above, the response information includes a response code, response text, and response duration. Determining the response result corresponding to the variation parameter based on the response information includes:

[0036] Determine whether the response code is a preset response code;

[0037] If so, if the response information meets the preset conditions, the response result is determined to be a normal response; if the response information meets the preset conditions, the response result is determined to be an abnormal response, and the reason for the abnormal response result is also determined.

[0038] If not, then the response result is determined to be a normal response;

[0039] The preset conditions include:

[0040] The similarity between the response text and the preset text corresponding to the response code is greater than the second threshold;

[0041] The response text does not contain any preset error keywords;

[0042] The time difference between the response duration and the preset duration is less than the third threshold.

[0043] In this way, analyzing the response results can more accurately identify potential security vulnerabilities and improve security detection efficiency.

[0044] Optionally, the method described above generates a vulnerability detection report based on the detection results corresponding to the multiple sets of data to be detected, including:

[0045] Among multiple test results, it is determined whether there are any abnormal results, wherein the abnormal results are the test results that detect anomalies;

[0046] If so, at least one abnormal cause corresponding to at least one abnormal result is analyzed and processed to generate a first vulnerability detection report, which includes vulnerability analysis results and a first confidence level.

[0047] If not, a second vulnerability detection report is generated, which includes a second detection result and a second confidence level. The second detection result indicates that no vulnerability was detected.

[0048] This generates vulnerability detection reports, making it easier for users to view and locate vulnerability information, thus improving security detection efficiency.

[0049] Secondly, this application provides a vulnerability detection device, the device comprising:

[0050] The first determining module is used to determine the keyword corresponding to the detection parameter in response to the detection parameter input by the user;

[0051] The search module is used to process the keywords using a target search tool to obtain search results;

[0052] The second determining module is used to determine multiple pieces of data to be detected based on the search results;

[0053] The detection module is used to generate a test file based on any piece of data to be detected, and to perform multiple vulnerability detection processes on the data to be detected based on the test file to obtain the detection results.

[0054] The generation module is used to generate a vulnerability detection report based on the detection results corresponding to the multiple data to be detected.

[0055] Optionally, in the apparatus described above, the detection module is specifically used for:

[0056] The data to be detected is parsed to determine the parsing result, which includes any one or more of the following: protocol, domain name, path, query parameters, and preset fields.

[0057] Based on the analysis results, at least one target test scenario is determined;

[0058] Based on the at least one target test scenario and the analysis results, multiple mutation parameters are determined by updating the library using an algorithm.

[0059] A test file is generated based on the at least one target test scenario and the multiple mutation parameters.

[0060] Optionally, in the apparatus described above, for any target test scenario, the detection module is specifically used for:

[0061] Based on the target test scenario and the analysis results, determine the mutation location of the data to be detected;

[0062] Based on the target test scenario, multiple mutation algorithms are determined in the algorithm update library;

[0063] Based on the multiple mutation algorithms, the original parameter values ​​at the positions to be mutated are mutated respectively to determine multiple mutation parameters.

[0064] Optionally, in the apparatus described above, the detection module is specifically used for:

[0065] If the parsing result includes the query parameters, determine whether the query parameters are preset query parameters. If so, determine that at least one target test scenario includes a database command injection scenario and a client script injection scenario.

[0066] If the parsing result includes the path, determine whether the path includes file features or directory features. If so, determine that at least one target test scenario includes a path traversal scenario.

[0067] If the parsing result includes the preset field, the preset field is identified to obtain the field type of the preset field. Based on the field type, a test command scenario corresponding to the test command is generated, and at least one target test scenario is determined to include the test command scenario.

[0068] Optionally, in the apparatus described above, the test file includes multiple variation parameters, and the detection module is specifically used for:

[0069] For any given mutation parameter, generate request information based on the mutation parameter and send the request information to the server;

[0070] Receive response information corresponding to the request information sent by the server;

[0071] Based on the response information, determine the response result corresponding to the variation parameter;

[0072] Among the response results corresponding to the multiple variation parameters, determine whether the number of abnormal response results is greater than a first threshold. If yes, the detection result is determined to be abnormal; otherwise, the detection result is determined to be normal.

[0073] Optionally, in the apparatus described above, the response information includes a response code, response text, and response duration, and the detection module is specifically used for:

[0074] Determine whether the response code is a preset response code;

[0075] If so, if the response information meets the preset conditions, the response result is determined to be a normal response; if the response information meets the preset conditions, the response result is determined to be an abnormal response, and the reason for the abnormal response result is also determined.

[0076] If not, then the response result is determined to be a normal response;

[0077] The preset conditions include:

[0078] The similarity between the response text and the preset text corresponding to the response code is greater than the second threshold;

[0079] The response text does not contain any preset error keywords;

[0080] The time difference between the response duration and the preset duration is less than the third threshold.

[0081] Optionally, in the apparatus described above, the generation module is specifically used for:

[0082] Among multiple test results, it is determined whether there are any abnormal results, wherein the abnormal results are the test results that detect anomalies;

[0083] If so, at least one abnormal cause corresponding to at least one abnormal result is analyzed and processed to generate a first vulnerability detection report, which includes vulnerability analysis results and a first confidence level.

[0084] If not, a second vulnerability detection report is generated, which includes a second detection result and a second confidence level. The second detection result indicates that no vulnerability was detected.

[0085] Thirdly, this application provides an electronic device, including: a processor, and a memory communicatively connected to the processor;

[0086] The memory stores computer-executed instructions;

[0087] The processor executes computer execution instructions stored in the memory to implement the method described in any of the first aspects.

[0088] Fourthly, this application provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, are used to implement the method as described in any of the first aspects.

[0089] Fifthly, this application provides a computer program product, including a computer program that, when executed by a computer, implements the method as described in any one of the first aspects.

[0090] The vulnerability detection method, apparatus, electronic device, and program product provided in this application, in response to user-inputted detection parameters, determines the keywords corresponding to the detection parameters, searches for the keywords using a target search tool to obtain search results, identifies multiple pieces of data to be detected based on the search results, generates a test file for any one piece of data to be detected, and performs multiple vulnerability detection processes on the data to be detected based on the test file to obtain detection results. A vulnerability detection report is generated based on the detection results corresponding to each piece of data to be detected. In this way, by responding to user-inputted detection parameters, automatically determining keywords and using a target search tool to generate multiple pieces of data to be detected, the tedious step of manually searching each target website is eliminated, greatly reducing the workload of security testers. Furthermore, by generating a corresponding test file for each piece of data to be detected and performing multiple vulnerability detection processes, potential security vulnerabilities are more accurately identified, and a vulnerability detection report is generated, thus improving security detection efficiency. Attached Figure Description

[0091] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.

[0092] Figure 1 This is a schematic diagram of the structure of a vulnerability detection system provided in an embodiment of this application;

[0093] Figure 2 A flowchart illustrating a vulnerability detection method provided in an embodiment of this application;

[0094] Figure 3 A flowchart illustrating another vulnerability detection method provided in an embodiment of this application;

[0095] Figure 4 A schematic diagram of the structure of a vulnerability detection device provided in an embodiment of this application;

[0096] Figure 5 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application.

[0097] The accompanying drawings illustrate specific embodiments of this application, which will be described in more detail below. These drawings and descriptions are not intended to limit the scope of the concept in any way, but rather to illustrate the concept of this application to those skilled in the art through reference to particular embodiments. Detailed Implementation

[0098] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.

[0099] It should be noted that although the terms "first," "second," etc., are used to describe various types of information in the embodiments of this application, this information should not be limited to these terms. These terms are only used to distinguish information of the same type from each other. Optionally, without departing from the scope of this application, first information may also be referred to as second information, and similarly, second information may also be referred to as first information.

[0100] It should be understood that the terms "comprising" or "including" indicate the presence of the previously mentioned features, steps, or operations, but do not preclude the presence, occurrence, or addition of one or more other features, steps, or operations. The terms "and / or," etc., used in this application can be interpreted as inclusive, or mean any one or any combination thereof. Optionally, "A and / or B" means "any one of the following: A; B; A and B." Additionally, the character " / " generally indicates that the preceding and following objects are in an "or" relationship.

[0101] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in one or more embodiments of this specification are all information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, use and processing of related data must comply with relevant laws, regulations and standards, and corresponding operation entry points are provided for users to choose to authorize or refuse.

[0102] With the increasing sophistication and diversification of cyberattack methods, such as malware attacks and distributed denial-of-service attacks, website security faces unprecedented challenges. Cyberattacks can not only lead to customer data breaches, legal disputes, and economic losses, but also damage a company's brand image and reduce customer loyalty.

[0103] Currently, security testers need to use separate search methods for each type of security issue to obtain target websites and then use existing technical tools to conduct security checks on these websites. Existing technical tools can only scan target websites and identify common network vulnerabilities. The working principle of these tools is mainly to simulate hacker attack behavior, sending a series of carefully crafted requests to the target website, and then analyzing the website's responses to determine if security vulnerabilities exist.

[0104] During the vulnerability detection process, security testers need to perform frequent and repetitive search operations, and the technical tools can only identify common vulnerabilities, resulting in low security detection efficiency.

[0105] To address the aforementioned technical problems, this application provides a vulnerability detection method. Responding to user-inputted detection parameters, the method determines keywords corresponding to the parameters, searches for these keywords using a target search tool, obtains search results, identifies multiple pieces of data to be detected based on the search results, generates a test file for any one piece of data, performs multiple vulnerability detections on the data using the test file, obtains detection results, and generates a vulnerability detection report based on the detection results corresponding to each piece of data. This method automatically determines keywords and generates multiple pieces of data to be detected by responding to user-inputted detection parameters, eliminating the tedious step of manually searching target websites one by one, significantly reducing the workload of security testers. Furthermore, by generating a corresponding test file for each piece of data and performing multiple vulnerability detections, it more accurately identifies potential security vulnerabilities and generates a vulnerability detection report, thus improving security detection efficiency.

[0106] Below, in conjunction with Figure 1 The architecture of a vulnerability detection system will be illustrated with an example.

[0107] Figure 1 This is a schematic diagram of the structure of a vulnerability detection system provided in an embodiment of this application. Please refer to [link / reference]. Figure 1 , Figure 1 A vulnerability detection system can be implemented. A vulnerability detection system includes at least a user interface, a data processor, and memory.

[0108] User interfaces can be used to provide user feedback and interaction capabilities.

[0109] For example, the user interface can be used to receive detection parameters input by the user, display vulnerability detection reports to the user, and so on.

[0110] The user interface may also include configuration controls, which allow users to set the priority of detection tasks, select detection modes, and so on.

[0111] The front-end pages of the user interface can be built using development languages ​​such as Hypertext Markup Language (HTML), Cascading Style Sheets (CSS), and JavaScript to provide interactive elements such as forms, buttons, and charts.

[0112] The user interface's backend interface can communicate with the data processor via an Application Programming Interface (API).

[0113] For example, user-inputted detection parameters can be sent to the data processor via API, and vulnerability detection reports can also be received via API.

[0114] Data processors can include data parsing tools, test file generation tools, vulnerability detection engines, report generators, and so on.

[0115] Data parsing tools can be used to parse user-inputted detection parameters, parse search results output by search tools, and so on.

[0116] Test file generation tools can be used to generate test files for vulnerability detection.

[0117] A vulnerability detection engine can be used to execute vulnerability detection logic.

[0118] The report generator can be used to generate vulnerability detection reports based on the detection results.

[0119] The memory can be used to store data, detection parameters, algorithm update libraries, and so on.

[0120] The technical solution of this application and how the technical solution of this application solves the above-mentioned technical problems are described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments. The embodiments of this application will now be described with reference to the accompanying drawings.

[0121] The technical solutions shown in this application will now be described in detail through specific embodiments. It should be noted that the following embodiments may exist independently or in combination with each other; for the same or similar content, the description will not be repeated in different embodiments.

[0122] Figure 2 This is a flowchart illustrating a vulnerability detection method provided in an embodiment of this application. The execution entity in this embodiment can be a processor. The processor can be implemented in software or through a combination of software and hardware. Please refer to... Figure 2 The method includes:

[0123] S201. In response to the detection parameters input by the user, determine the keyword corresponding to the detection parameters.

[0124] Detection parameters can be used to represent the detection range.

[0125] For example, detection parameters can be target region, target type, target features, etc.

[0126] Keywords can be the system identifier corresponding to the detection parameters.

[0127] Users can input detection parameters through the interface provided by the system. In response to the user-input detection parameters, the system performs keyword extraction processing to determine the keywords.

[0128] The rules for keyword extraction can be implemented based on preset logic or algorithms.

[0129] For example, keywords can be extracted from the detection parameters input by the user using natural language processing algorithms.

[0130] It should be noted that the target parameters input by the user can be obtained according to any feasible implementation method, and the embodiments of this application do not limit this.

[0131] S202. Use a target search tool to search for keywords and obtain search results.

[0132] The target search tool can be a preset search engine.

[0133] Targeted search tools can be used to process keywords and obtain search results that match those keywords.

[0134] Search results can include multiple result items, each of which includes the address, access date, server type, and so on.

[0135] The target search tool can be a pre-set search tool in the vulnerability detection system, or it can be a standalone search tool that communicates and connects with the vulnerability detection system.

[0136] The data processor can send a request message, including keywords, to the target search tool. The target search tool then processes the keywords, generates a response message corresponding to the request message, and sends the response message, which includes the search results, back to the data processor.

[0137] It should be noted that search results can be obtained according to any feasible implementation method, and the embodiments of this application do not limit this.

[0138] S203. Based on the search results, identify multiple data points to be tested.

[0139] Multiple data points to be detected can be data extracted from search results.

[0140] It can perform feature extraction on multiple result items in the search results to identify multiple data to be detected.

[0141] It should be noted that multiple data points to be detected can be determined according to any feasible implementation method, and the embodiments of this application do not limit this.

[0142] S204. For any piece of data to be tested, generate a test file based on the data, and perform multiple vulnerability detection processes on the data to be tested based on the test file to obtain the detection results.

[0143] Test files can be files generated based on the data to be tested for vulnerability detection.

[0144] The test file may include at least one target test scenario and multiple variation parameters.

[0145] The target test scenario can be used to represent the test algorithm, test cases, test scripts, detection rules and other scenario information applicable to the test data to be tested.

[0146] Mutation parameters can be used to represent the parameters of the data to be detected after mutation in the target test scenario.

[0147] Optionally, a test file can be generated based on the data to be tested in the following manner: the data to be tested is parsed and processed to determine the parsing result; at least one target test scenario is determined based on the parsing result; multiple mutation parameters are determined by updating the library through an algorithm based on at least one target test scenario and the parsing result; and a test file is generated based on at least one target test scenario and multiple mutation parameters.

[0148] The parsing results include one or more of the following: protocol, domain name, path, query parameters, and preset fields.

[0149] Optionally, a test file can be generated based on the data to be tested in the following way: input the data to be tested into the test file generation model to obtain the model output result, which includes the test file.

[0150] It should be noted that test files can be generated according to any feasible implementation method, and this application embodiment does not limit this.

[0151] Optionally, the detection results can be obtained by performing multiple vulnerability detections on the data to be detected based on the test file in the following way: multiple request messages can be generated based on multiple mutation parameters in the test file, and the request messages can be sent to the server. The response messages corresponding to the multiple request messages can be received respectively, and the detection results can be determined based on the multiple response messages.

[0152] Optionally, the detection results can be obtained by performing multiple vulnerability detection processes on the data to be detected based on the test file in the following way: input multiple mutation parameters into a preset component, and perform multiple vulnerability detection processes based on the multiple mutation parameters through the preset component to obtain the detection results.

[0153] It should be noted that the vulnerability detection data can be processed multiple times according to any feasible implementation method to obtain the detection result, and the embodiments of this application do not limit this.

[0154] S205. Generate a vulnerability detection report based on the detection results corresponding to multiple data to be detected.

[0155] A vulnerability detection report may include a first vulnerability detection report and a second vulnerability detection report.

[0156] The first vulnerability detection report can be used to indicate the existence of vulnerabilities.

[0157] The second vulnerability detection report can be used to indicate that no vulnerabilities were detected.

[0158] Optionally, a vulnerability detection report can be generated by parsing and processing the detection results corresponding to multiple data to be detected using a preset model.

[0159] Optionally, a vulnerability detection report can be generated based on the detection results corresponding to multiple data to be detected in the following manner: among the multiple detection results, determine whether there are any abnormal results; if so, analyze and process at least one abnormal cause corresponding to at least one abnormal result to generate a first vulnerability detection report; if not, generate a second vulnerability detection report.

[0160] Among them, the abnormal results are the detection results of abnormalities. The first vulnerability detection report includes the vulnerability analysis results and the first confidence level, and the second vulnerability detection report includes the second detection results and the second confidence level. The second detection result indicates that no vulnerability was detected.

[0161] The first confidence level can be used to represent the confidence level of the vulnerability analysis results.

[0162] The second confidence level can be used to represent the confidence level corresponding to a vulnerability that has not been detected.

[0163] It should be noted that vulnerability detection reports can be generated according to any feasible implementation method, and this application embodiment does not limit this.

[0164] The vulnerability detection method provided in this embodiment determines the keywords corresponding to the user-input detection parameters, searches for the keywords using a target search tool, obtains search results, identifies multiple pieces of data to be detected based on the search results, generates a test file for any one piece of data to be detected, and performs multiple vulnerability detection processes on the data to be detected based on the test file to obtain detection results. A vulnerability detection report is generated based on the detection results corresponding to each piece of data to be detected. In this way, by responding to the user-input detection parameters, automatically determining keywords and using a target search tool to generate multiple pieces of data to be detected, the tedious step of manually searching each target website is eliminated, greatly reducing the workload of security testers. Furthermore, by generating a corresponding test file for each piece of data to be detected and performing multiple vulnerability detection processes, potential security vulnerabilities are more accurately identified, and a vulnerability detection report is generated, improving security detection efficiency.

[0165] Below, in conjunction with Figure 3 The process (S204) of generating a test file based on the data to be tested, and performing multiple vulnerability detections on the data to be tested based on the test file to obtain the detection results is explained.

[0166] Figure 3 This is a flowchart illustrating another vulnerability detection method provided in an embodiment of this application. Based on the above embodiments, see [link to relevant documentation]. Figure 3 The method includes:

[0167] S301. Analyze the data to be tested and determine the analysis results.

[0168] The parsing results include one or more of the following: protocol, domain name, path, query parameters, and preset fields.

[0169] The data to be detected can be analyzed and processed using a preset algorithm to determine the analysis result.

[0170] For example, the address in the data to be detected is parsed to obtain the protocol, domain name, path and query parameters, and the protocol, domain name, path and query parameters are determined as the parsing result.

[0171] S302. Based on the analysis results, determine at least one target test scenario.

[0172] The target test scenario can be a test scenario analyzed based on the parsing results.

[0173] Optionally, at least one target test scenario can be determined based on the analysis results and the preset model.

[0174] Optionally, at least one target test scenario can be determined based on the parsing results in the following manner: If the parsing results include query parameters, determine whether the query parameters are preset query parameters; if so, determine that at least one target test scenario includes a database command injection scenario and a client script injection scenario; if the parsing results include paths, determine whether the paths include file features or directory features; if so, determine that at least one target test scenario includes a path traversal scenario; if the parsing results include preset fields, identify and process the preset fields to obtain the field types of the preset fields, generate test command scenarios corresponding to the test commands based on the field types, and determine that at least one target test scenario includes test command scenarios.

[0175] For example, if the query parameter is: ? query=test, the system can analyze that the most likely vulnerability type is an input validation vulnerability, because the value of the query parameter is usually processed by the program. Therefore, the target test scenario is determined to be a database command injection scenario and a client-side script injection scenario.

[0176] Below, we will take any one of the target test scenarios from at least one target test scenario as an example:

[0177] S303. Based on the target test scenario and the analysis results, determine the mutation location of the data to be detected.

[0178] The location to be mutated can represent the location in the data to be detected where mutation is required.

[0179] The location to be mutated can be a protocol, query parameters, path, etc.

[0180] Based on the analysis results and the target test scenario, the position to be mutated can be determined through a parametric semantic weight model.

[0181] S304. Based on the target test scenario, determine multiple mutation algorithms in the algorithm update library.

[0182] An algorithm update library can be an algorithm library that is updated in real time.

[0183] The algorithm update library can contain the latest mutation algorithms.

[0184] Mutation algorithms can be used to mutate parameters at the locations to be mutated.

[0185] For example, for a target test scenario of database command injection, multiple mutation algorithms are identified as the injection algorithm corresponding to injecting a condition of 1=1, the addition algorithm corresponding to adding a single quote, and so on.

[0186] S305. Based on multiple mutation algorithms, mutate the original parameter values ​​at the positions to be mutated to determine multiple mutation parameters.

[0187] Mutation parameters can be used to perform vulnerability detection processing.

[0188] For any given mutation algorithm, the original parameter values ​​at the position to be mutated are mutated multiple times according to the mutation algorithm to determine multiple mutation parameters.

[0189] Multiple mutation parameters can include multiple mutation parameters corresponding to multiple mutation algorithms.

[0190] S306. Generate a test file based on at least one target test scenario and multiple variation parameters.

[0191] The test file includes multiple mutation parameters.

[0192] The test file can be in a preset format.

[0193] Test files can be used for vulnerability detection and handling.

[0194] For example, suppose the target test scenario for client-side script injection corresponds to 3 mutation parameters.

[0195] The test file may include at least one target test scenario and three mutation parameters corresponding to each target test scenario.

[0196] Below, we will take any one of the multiple mutation parameters as an example:

[0197] S307. Generate request information based on the mutation parameters and send the request information to the server.

[0198] The original request can be modified by replacing the parameters based on the mutated parameters, and the request information can be sent to the server.

[0199] S308. Receive the response information corresponding to the request information sent by the server.

[0200] The response information includes the response code, response text, and response duration.

[0201] S309. Based on the response information, determine the response result corresponding to the variation parameter.

[0202] The response information can be parsed and processed to determine the response result corresponding to the variation parameters.

[0203] Optionally, the response result corresponding to the variation parameter can be determined based on the response information in the following way: determine whether the response code is a preset response code; if yes, if the response information meets the preset conditions, determine the response result as a normal response, and if the response information meets the preset conditions, determine the response result as an abnormal response and the reason for the abnormal response result; if no, determine the response result as a normal response.

[0204] The preset conditions include:

[0205] The similarity between the response text and the preset text corresponding to the response code is greater than the second threshold;

[0206] The response text does not contain any preset error keywords;

[0207] The time difference between the response time and the preset time is less than the third threshold.

[0208] Preset response codes can be used to represent abnormal response codes.

[0209] The second threshold can be a pre-set value.

[0210] The preset error keywords can be pre-defined keywords.

[0211] The third threshold can be a pre-set value.

[0212] S310. Among the response results corresponding to multiple variable parameters, determine whether the number of response results with abnormal response is greater than the first threshold.

[0213] If so, then execute S311;

[0214] If not, then execute S312.

[0215] The first threshold can be a pre-set value.

[0216] The number of abnormal response results can be determined from the response results corresponding to multiple variation parameters, and it can be determined whether the number of abnormal response results is greater than the first threshold.

[0217] S311. The test result is determined to be abnormal.

[0218] S312. The test result is confirmed to be normal.

[0219] The implementation details of each step in this application embodiment can be found in the description of the corresponding steps or operations in the above method embodiments; repeated content will not be repeated.

[0220] The vulnerability detection method provided in this embodiment parses the data to be detected, determines the parsing result, identifies at least one target test scenario based on the parsing result, determines the mutation position of the data to be detected based on the target test scenario and the parsing result, determines multiple mutation algorithms in the algorithm update library based on the target test scenario, mutates the original parameter values ​​of the mutation position based on the multiple mutation algorithms, determines multiple mutation parameters, generates a test file including the multiple mutation parameters based on the at least one target test scenario and the multiple mutation parameters, generates request information based on the mutation parameter, sends the request information to the server, receives the response information corresponding to the request information sent by the server, determines the response result corresponding to the mutation parameter based on the response information, and determines whether the number of abnormal response results in the response results corresponding to the multiple mutation parameters is greater than a first threshold. If it is, the detection result is determined to be abnormal; otherwise, the detection result is determined to be normal. In this way, by dynamically matching the target test scenario through algorithm-updated libraries, the shortcomings of traditional tools in detecting new vulnerabilities are addressed. Based on the mutation algorithm, corresponding test files are generated and multiple vulnerability detection processes are performed, which more accurately identifies potential security vulnerabilities and improves security detection efficiency.

[0221] Figure 4 This is a schematic diagram of a vulnerability detection device provided in an embodiment of this application. Please refer to... Figure 4 The vulnerability detection device 400 includes a first determination module 401, a search module 402, a second determination module 403, a detection module 404, and a generation module 405, wherein...

[0222] The first determining module 401 is used to determine the keyword corresponding to the detection parameter in response to the detection parameter input by the user;

[0223] Search module 402 is used to perform search processing on the keywords using a target search tool to obtain search results;

[0224] The second determining module 403 is used to determine multiple pieces of data to be detected based on the search results;

[0225] The detection module 404 is used to generate a test file based on any piece of data to be detected, and to perform multiple vulnerability detection processes on the data to be detected based on the test file to obtain the detection result;

[0226] The generation module 405 is used to generate a vulnerability detection report based on the detection results corresponding to the multiple data to be detected.

[0227] Optionally, in the apparatus described above, the detection module 404 is specifically used for:

[0228] The data to be detected is parsed to determine the parsing result, which includes any one or more of the following: protocol, domain name, path, query parameters, and preset fields.

[0229] Based on the analysis results, at least one target test scenario is determined;

[0230] Based on the at least one target test scenario and the analysis results, multiple mutation parameters are determined by updating the library using an algorithm.

[0231] A test file is generated based on the at least one target test scenario and the multiple mutation parameters.

[0232] Optionally, in the apparatus described above, for any target test scenario, the detection module 404 is specifically used for:

[0233] Based on the target test scenario and the analysis results, determine the mutation location of the data to be detected;

[0234] Based on the target test scenario, multiple mutation algorithms are determined in the algorithm update library;

[0235] Based on the multiple mutation algorithms, the original parameter values ​​at the positions to be mutated are mutated respectively to determine multiple mutation parameters.

[0236] Optionally, in the apparatus described above, the detection module 404 is specifically used for:

[0237] If the parsing result includes the query parameters, determine whether the query parameters are preset query parameters. If so, determine that at least one target test scenario includes a database command injection scenario and a client script injection scenario.

[0238] If the parsing result includes the path, determine whether the path includes file features or directory features. If so, determine that at least one target test scenario includes a path traversal scenario.

[0239] If the parsing result includes the preset field, the preset field is identified to obtain the field type of the preset field. Based on the field type, a test command scenario corresponding to the test command is generated, and at least one target test scenario is determined to include the test command scenario.

[0240] Optionally, in the apparatus described above, the test file includes multiple variation parameters, and the detection module 404 is specifically used for:

[0241] For any given mutation parameter, generate request information based on the mutation parameter and send the request information to the server;

[0242] Receive response information corresponding to the request information sent by the server;

[0243] Based on the response information, determine the response result corresponding to the variation parameter;

[0244] Among the response results corresponding to the multiple variation parameters, determine whether the number of abnormal response results is greater than a first threshold. If yes, the detection result is determined to be abnormal; otherwise, the detection result is determined to be normal.

[0245] Optionally, in the apparatus described above, the response information includes a response code, response text, and response duration, and the detection module 404 is specifically used for:

[0246] Determine whether the response code is a preset response code;

[0247] If so, if the response information meets the preset conditions, the response result is determined to be a normal response; if the response information meets the preset conditions, the response result is determined to be an abnormal response, and the reason for the abnormal response result is also determined.

[0248] If not, then the response result is determined to be a normal response;

[0249] The preset conditions include:

[0250] The similarity between the response text and the preset text corresponding to the response code is greater than the second threshold;

[0251] The response text does not contain any preset error keywords;

[0252] The time difference between the response duration and the preset duration is less than the third threshold.

[0253] Optionally, in the apparatus described above, the generation module 405 is specifically used for:

[0254] Among multiple test results, it is determined whether there are any abnormal results, wherein the abnormal results are the test results that detect anomalies;

[0255] If so, at least one abnormal cause corresponding to at least one abnormal result is analyzed and processed to generate a first vulnerability detection report, which includes vulnerability analysis results and a first confidence level.

[0256] If not, a second vulnerability detection report is generated, which includes a second detection result and a second confidence level. The second detection result indicates that no vulnerability was detected.

[0257] Figure 5 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Please refer to... Figure 5 Electronic device 500 may include: memory 501, processor 502, and transceiver 503.

[0258] Memory 501 is used to store program instructions;

[0259] The processor 502 is used to execute the program instructions stored in the memory so that the electronic device 500 performs the above-described method.

[0260] Transceiver 503 may include a transmitter and / or a receiver. The transmitter may also be referred to as a transmitter, transmitter port, or transmitter interface, and the receiver may also be referred to as a receiver port, receiver interface, or similar descriptions. Exemplarily, memory 501, processor 502, and transceiver 503 are interconnected via bus 504.

[0261] This application also provides a computer program product that can be executed by a processor, and when the computer program product is executed, the above-described method can be implemented.

[0262] The vulnerability detection apparatus, electronic device, computer-readable storage medium, and computer program product of this application embodiment can execute the technical solutions shown in the above vulnerability detection method embodiments. Their implementation principles and beneficial effects are similar and will not be repeated here.

[0263] It should be noted that, for the sake of simplicity, the foregoing method embodiments are all described as a series of actions. However, those skilled in the art should understand that this application is not limited to the described order of actions, as some steps may be performed in other orders or simultaneously according to this application. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are all optional embodiments, and the actions and modules involved are not necessarily essential to this application.

[0264] It should be further noted that although the steps in the flowchart are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowchart may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these sub-steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the sub-steps or stages of other steps.

[0265] It should be understood that the above-described device embodiments are merely illustrative, and the device of this application can also be implemented in other ways. For example, the division of units / modules in the above embodiments is only a logical functional division, and there may be other division methods in actual implementation. For example, multiple units, modules, or components may be combined, or integrated into another system, or some features may be ignored or not executed.

[0266] Furthermore, unless otherwise specified, the functional units / modules in the various embodiments of this application can be integrated into one unit / module, or each unit / module can exist physically separately, or two or more units / modules can be integrated together. The integrated units / modules described above can be implemented in hardware or as software program modules.

[0267] When integrated units / modules are implemented in hardware, the hardware can be digital circuits, analog circuits, etc. The physical implementation of the hardware structure includes, but is not limited to, transistors, memristors, etc. Unless otherwise specified, the processor can be any suitable hardware processor, such as a CPU, GPU, FPGA, DSP, and ASIC, etc. Unless otherwise specified, the storage unit can be any suitable magnetic or magneto-optical storage medium, such as Resistive Random Access Memory (RRAM), Dynamic Random Access Memory (DRAM), Static Random Access Memory (SRAM), Enhanced Dynamic Random Access Memory (EDRAM), High-Bandwidth Memory (HBM), Hybrid Memory Cube (HMC), etc.

[0268] If the integrated unit / module is implemented as a software program module and sold or used as an independent product, it can be stored in a computer-readable storage device (CMD). Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a memory and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this application. The aforementioned memory includes various media capable of storing program code, such as a USB flash drive, read-only memory (ROM), random access memory (RAM), portable hard drive, magnetic disk, or optical disk.

[0269] In the above embodiments, the descriptions of each embodiment have their own emphasis. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments. The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as these combinations of technical features do not contradict each other, they should be considered within the scope of this specification.

[0270] Other embodiments of this application will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of this application that follow the general principles of this application and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of this application are indicated by the following claims.

[0271] It should be understood that this application is not limited to the precise structure described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of this application is limited only by the appended claims.

Claims

1. A vulnerability detection method, characterized in that, The method includes: In response to the detection parameters input by the user, the keyword corresponding to the detection parameters is determined; The keywords are searched using a target search tool to obtain search results; Based on the search results, multiple data points to be detected were identified; For any piece of data to be tested, a test file is generated based on the data, and multiple vulnerability detection processes are performed on the data based on the test file to obtain the detection results; A vulnerability detection report is generated based on the detection results corresponding to the multiple data to be detected.

2. The method according to claim 1, characterized in that, Based on the data to be tested, a test file is generated, including: The data to be detected is parsed to determine the parsing result, which includes any one or more of the following: protocol, domain name, path, query parameters, and preset fields. Based on the analysis results, at least one target test scenario is determined; Based on the at least one target test scenario and the analysis results, multiple mutation parameters are determined by updating the library using an algorithm. A test file is generated based on the at least one target test scenario and the multiple mutation parameters.

3. The method according to claim 2, characterized in that, For any given target test scenario, based on the target test scenario and the analysis results, multiple mutation parameters are determined by updating the library using an algorithm, including: Based on the target test scenario and the analysis results, determine the mutation location of the data to be detected; Based on the target test scenario, multiple mutation algorithms are determined in the algorithm update library; Based on the multiple mutation algorithms, the original parameter values ​​at the positions to be mutated are mutated respectively to determine multiple mutation parameters.

4. The method according to claim 2, characterized in that, Based on the analysis results, at least one target test scenario is determined, including: If the parsing result includes the query parameters, determine whether the query parameters are preset query parameters. If so, determine that at least one target test scenario includes a database command injection scenario and a client script injection scenario. If the parsing result includes the path, determine whether the path includes file features or directory features. If so, determine that at least one target test scenario includes a path traversal scenario. If the parsing result includes the preset field, the preset field is identified to obtain the field type of the preset field. Based on the field type, a test command scenario corresponding to the test command is generated, and at least one target test scenario is determined to include the test command scenario.

5. The method according to any one of claims 1-4, characterized in that, The test file includes multiple mutation parameters. Based on the test file, the data to be detected undergoes multiple vulnerability detection processes to obtain detection results, including: For any given mutation parameter, generate request information based on the mutation parameter and send the request information to the server; Receive response information corresponding to the request information sent by the server; Based on the response information, determine the response result corresponding to the variation parameter; Among the response results corresponding to the multiple variation parameters, determine whether the number of abnormal response results is greater than a first threshold. If yes, the detection result is determined to be abnormal; otherwise, the detection result is determined to be normal.

6. The method according to claim 5, characterized in that, The response information includes a response code, response text, and response duration. Based on the response information, the response result corresponding to the mutation parameter is determined, including: Determine whether the response code is a preset response code; If so, if the response information meets the preset conditions, the response result is determined to be a normal response; if the response information meets the preset conditions, the response result is determined to be an abnormal response, and the reason for the abnormal response result is also determined. If not, then the response result is determined to be a normal response; The preset conditions include: The similarity between the response text and the preset text corresponding to the response code is greater than the second threshold; The response text does not contain any preset error keywords; The time difference between the response duration and the preset duration is less than the third threshold.

7. The method according to claims 1-6, characterized in that, Based on the detection results corresponding to the multiple sets of data to be detected, a vulnerability detection report is generated, including: Among multiple test results, it is determined whether there are any abnormal results, wherein the abnormal results are the test results that detect anomalies; If so, at least one abnormal cause corresponding to at least one abnormal result is analyzed and processed to generate a first vulnerability detection report, which includes vulnerability analysis results and a first confidence level. If not, a second vulnerability detection report is generated, which includes a second detection result and a second confidence level. The second detection result indicates that no vulnerability was detected.

8. A vulnerability detection device, characterized in that, The device includes: The first determining module is used to determine the keyword corresponding to the detection parameter in response to the detection parameter input by the user; The search module is used to process the keywords using a target search tool to obtain search results; The second determining module is used to determine multiple pieces of data to be detected based on the search results; The detection module is used to generate a test file based on any piece of data to be detected, and to perform multiple vulnerability detection processes on the data to be detected based on the test file to obtain the detection results. The generation module is used to generate a vulnerability detection report based on the detection results corresponding to the multiple data to be detected.

9. An electronic device, characterized in that, include: A processor, and a memory communicatively connected to the processor; The memory stores computer-executed instructions; The processor executes computer execution instructions stored in the memory to implement the method as described in any one of claims 1 to 7.

10. A computer program product, characterized in that, Includes a computer program that, when executed by a processor, implements the method described in any one of claims 1-7.