Test device and test method
The test apparatus addresses the limitation of existing systems by automatically collecting attack codes from a database and executing penetration tests on detected vulnerabilities, ensuring thorough and efficient testing.
Patent Information
- Application Number
- JP2023202304
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-11-30
- Publication Date
- 2025-06-11
AI Technical Summary
Existing penetration test apparatuses are limited in their ability to automatically collect attack codes corresponding to newly detected vulnerabilities, leading to potential gaps in testing capabilities.
A test apparatus equipped with a vulnerability detection unit, an access information storage unit, an attack code collection unit, and a test execution unit, which automatically collects attack codes from a database using access information and executes penetration tests on detected vulnerabilities.
Enables efficient and automatic collection of necessary attack codes for detected vulnerabilities, ensuring comprehensive penetration testing can be performed without manual intervention.
Smart Images

Figure 2025087958000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to an apparatus and method for performing a penetration test.
Background Art
[0002] In recent years, with the increase in cyberattacks, the importance of penetration testing has been increasing. Penetration testing verifies the vulnerability of a system or its resistance to cyberattacks by actually attempting to attack or intrude into a computer system or the like. Note that a control device for controlling a penetration test so as to increase the success rate of the attack has been proposed (for example, Patent Document 1).
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] In the prior art, a test apparatus for performing a penetration test holds test attack codes in advance for assumed vulnerabilities. Then, the test apparatus verifies the vulnerability of the test target system by attacking it using the held attack codes. However, in this configuration, for example, if an unexpected vulnerability is found, there is a risk that the necessary test cannot be performed because the corresponding attack code is not held.
[0005] An object according to one aspect of the present invention is to provide a test apparatus that can automatically collect attack codes corresponding to vulnerabilities detected in a test target and perform a penetration test.
Means for Solving the Problems
[0006] A test apparatus according to one aspect of the present invention includes a vulnerability detection unit that detects vulnerabilities in a system under test, an access information storage unit that stores access information for accessing a database that provides attack codes for penetration testing, an attack code collection unit that collects attack codes corresponding to the vulnerabilities detected by the vulnerability detection unit by accessing the database using the access information, and a test execution unit that executes a penetration test on the system under test using the attack codes collected by the attack code collection unit.
Advantages of the Invention
[0007] According to the above aspect, it is possible to automatically collect the necessary attack codes for the detected vulnerabilities in the system under test and perform a penetration test.
Brief Description of the Drawings
[0008]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
Figure 10
Best Mode for Carrying Out the Invention
[0009] FIG. 1 shows an example of the functional configuration of a test apparatus according to an embodiment of the present invention. A test apparatus 1 according to an embodiment of the present invention executes a penetration test on a test target system 2. The test target system 2 is not particularly limited, but for example, is a computer system or facility including one or more computers. Alternatively, the test target system 2 may be a communication system including one or more communication devices.
[0010] The test apparatus 1 includes a vulnerability detection unit 11, an attack code storage unit 12, an attack code setting unit 13, an attack code collection unit 14, an access information storage unit 15, a test execution unit 16, and a user interface unit 17. Note that the test apparatus 1 may further include other functions or devices not shown in FIG. 1.
[0011] The vulnerability detection unit 11 detects vulnerabilities in the test target system 2 by executing a vulnerability scan on the test target system 2. In this embodiment, the vulnerability detection unit 11 detects vulnerabilities identified by CVE (Common Vulnerabilities and Exposures) identification numbers. Note that CVE identification numbers are numbered by MITRE, a non-profit organization supported by the US government.
[0012] The attack code storage unit 12 stores attack codes for a penetration test on the test target system 2. In this embodiment, the attack code is a program or script that describes the procedure for attacking the test target system 2. The attack code is created, for example, by a user of the test apparatus 1 (that is, a person who tests the test target system 2) and stored in the attack code storage unit 12. Also, the attack codes collected by the attack code collection unit 14 from the attack code database 3, which will be described later, are also stored in the attack code storage unit 12.
[0013] The attack code setting unit 13 sets an attack code corresponding to the vulnerability detected by the vulnerability detection unit 11. When the attack code corresponding to the detected vulnerability is stored in the attack code storage unit 12, the attack code setting unit 13 acquires the attack code from the attack code storage unit 12 and sets it in the test execution unit 16. When the attack code corresponding to the detected vulnerability is not stored in the attack code storage unit 12, the attack code setting unit 13 requests the attack code collection unit 14 to collect the attack code.
[0014] The attack code collection unit 14 refers to the access information stored in the access information storage unit 15 and collects the attack code requested by the attack code setting unit 13. The access information stored in the access information storage unit 15 indicates a database that stores attack codes for a penetration test of the test target system 2. In the example shown in Fig. 1, the access information represents information for accessing each attack code database 3 (3a to 3n).
[0015] The attack code database 3 is connected to a network such as the Internet, and manages attack codes for penetration testing for each vulnerability. In this embodiment, the attack code database 3 manages attack codes for penetration testing for each CVE identification number. The attack code database 3 provides the requested attack code for a fee or free of charge. Alternatively, the attack code database 3 provides the requested attack code to a user who has been registered in advance.
[0016] The attack code collection unit 14 passes the attack code collected from the attack code database 3 to the attack code setting unit 13. Then, the attack code setting unit 13 sets the attack code received from the attack code collection unit 14 in the test execution unit 16. In addition, the attack code setting unit 13 may store the attack code received from the attack code collection unit 14 in the attack code storage unit 12.
[0017] The test execution unit 16 executes a penetration test on the system under test 2 using the attack code set by the attack code setting unit 13. The user interface unit 17 provides an interface with the user of the test device 1.
[0018] In this way, when the test device 1 does not hold the attack code corresponding to the vulnerability of the system under test 2 in the device itself, it automatically collects the attack code from the attack code database 3 connected to the network. Therefore, a penetration test related to the vulnerability of the system under test 2 can be efficiently executed. In the prior art, when the necessary attack code is not held in the device itself, the attack code is manually acquired from the attack code database 3.
[0019] FIG. 2 is a flowchart showing an example of the operation of the test device 1 according to an embodiment of the present invention. The processing of this flowchart is executed in response to an instruction input by the user of the test device 1 to start a penetration test on the system under test 2.
[0020] In S1, the vulnerability detection unit 11 detects the vulnerability of the system under test 2 by executing a vulnerability scan on the system under test 2. Each vulnerability is represented by a CVE identification number. That is, the vulnerability detection unit 11 identifies the CVE identification number representing each vulnerability found in the system under test 2.
[0021] In S2, the attack code setting unit 13 determines whether the attack code corresponding to the CVE identification number specified in S1 is stored in the attack code storage unit 12. When one or more attack codes are not stored in the attack code storage unit 12, the processing of the test device 1 proceeds to S3. In S3, the attack code setting unit 13 identifies the CVE identification number for which the corresponding attack code should be collected. When the attack codes corresponding to all the CVE identification numbers specified in S1 are stored in the attack code storage unit 12, the processing of the test device 1 proceeds to S7.
[0022] Figure 3 shows an example of a procedure for identifying CVE identification numbers for which corresponding attack codes should be collected. This procedure corresponds to S1 to S3 shown in Figure 2.
[0023] In S1, when a CVE identification number representing a vulnerability detected from the test target system 2 is identified, the identified CVE identification number is recorded in the detected CVE list shown in Figure 3. In this example, "CVE-2009-XX313" to "CVE-2023-XX105" are recorded in the detected CVE list. Also, the test device 1 holds an attackable CVE list that manages CVE identification numbers representing vulnerabilities that the test device 1 can attack. In this example, the test device 1 has attack codes for "CVE-2009-XX313" to "CVE-2022-XX345" respectively, and attacks can be performed on these vulnerabilities in the penetration test.
[0024] In S2 to S3, the attack code setting unit 13 identifies CVE identification numbers among those recorded in the detected CVE list that are not registered in the attackable CVE list. In this example, three CVE identification numbers (CVE-2022-XX346, CVE-2023-XX104, CVE-2023-XX105) are identified. Then, the identified CVE identification numbers are recorded in the attack code collection CVE list. Note that the identified CVE identification numbers (i.e., the CVE identification numbers recorded in the attack code collection CVE list) represent vulnerabilities for which the test device 1 does not hold corresponding attack codes.
[0025] In this way, in S1 to S3, the attack code collection CVE list shown in Figure 3 is created. Then, the test device 1 executes the processing after S4. However, when no CVE identification numbers are recorded in the attack code collection CVE list, S4 to S6 are skipped. That is, when all the attack codes corresponding to the vulnerabilities detected from the test target system 2 are stored in the attack code storage unit 12, S4 to S6 are skipped.
[0026] When one or more CVE identification numbers are recorded in the attack code collection CVE list, in S4 of the flowchart shown in FIG. 2, the attack code setting unit 13 notifies the CVE identification numbers recorded in the attack code collection CVE list to the attack code collection unit 14. Then, the attack code collection unit 14 accesses the database that provides the attack code by referring to the access information stored in the access information storage unit 15.
[0027] FIG. 4 shows an example of access information. The access information represents information for accessing the database that provides the attack code. The access information identifies, for example, each attack code database 3 (3a to 3n) shown in FIG. 1. Note that the access information is created in advance by the user of the test device 1, for example.
[0028] The attack code collection unit 14 searches for the CVE identification numbers recorded in the attack code collection CVE list by referring to the access information. That is, the attack code collection unit 14 checks whether the attack code corresponding to the CVE identification number recorded in the attack code collection CVE list is stored in the database represented by the access information. At this time, the attack code collection unit 14 executes web scraping on the database represented by the access information using, for example, the CVE identification number recorded in the attack code collection CVE list as a search keyword. In the embodiments shown in FIGS. 1 and 3, web scraping is executed for "CVE-2022-XX346", "CVE-2023-XX104", and "CVE-2023-XX105" on the attack code databases 3a to 3n, respectively. Then, the attack code collection unit 14 identifies the database in which the search target CVE identification number hits.
[0029] FIG. 5 shows an example of the search results by the attack code collection unit 14. In this example, the search results by the attack code collection unit 14 indicate whether there is an attack code corresponding to the CVE identification number recorded in the attack code collection CVE list shown in FIG. 3 in each database registered as the access information shown in FIG. 4. In this example, the attack code database DB-001 (3a) can provide the attack code corresponding to "CVE-2022-XX346" and the attack code corresponding to "CVE-2023-XX105". Also, the attack code database DB-002 (3b) can provide the attack code corresponding to "CVE-2023-XX104" and the attack code corresponding to "CVE-2023-XX105". Furthermore, the attack code database DB-XYZ (3n) can provide the attack code corresponding to "CVE-2023-XX105". At this time, the attack code collection unit 14 detects the URL representing the position where each attack code is stored in each attack code database. And the search results by the attack code collection unit 14 include the detected URL.
[0030] Next, in S5 of the flowchart shown in FIG. 2, the attack code collection unit 14 determines the attack code to be collected from the attack code database 3. At this time, the attack code collection unit 14 may activate the user interface unit 17 to allow the user of the test device 1 to select the attack code to be collected. In this case, the user interface unit 17 provides an attack code selection screen shown in FIG. 6 in response to an instruction from the attack code collection unit 14. The attack code selection screen displays the search results by the attack code collection unit 14. Further, the attack code selection screen includes buttons or the like for allowing the user to select each record of the search results. Then, the user selects, on the attack code selection screen, the database from which the attack code is to be collected for each vulnerability (i.e., each CVE identification number). In this example, as shown in FIG. 7, the attack code database DB-001 (3a) is selected for "CVE-2022-XX346", the attack code database DB-002 (3b) is selected for "CVE-2023-XX104", and the attack code database DB-XYZ (3n) is selected for "CVE-2023-XX105". Note that the user may select a plurality of attack codes or a plurality of databases for one vulnerability (i.e., CVE identification number).
[0031] Further, the attack code collection unit 14 may determine the attack code to be collected from the attack code database without selection by the user of the test device 1. In this case, for example, it is preferable that priorities are set in advance for the attack code databases 3a to 3n. The priorities of the attack code databases 3a to 3n are set by, for example, the user of the test device 1. Then, the attack code collection unit 14 determines the attack code to be collected from the attack code database 3 according to this priority. For example, it is assumed that a high priority is set for the attack code database DB-001 (3a).
[0032] The attack code corresponding to 「CVE-2022-XX346」 is only available in the attack code database DB-001(3a). Therefore, the attack code collection unit 14 automatically determines the attack code database DB-001(3a) for 「CVE-2022-XX346」. Similarly, the attack code corresponding to 「CVE-2023-XX104」 is only available in the attack code database DB-002(3b). Thus, the attack code collection unit 14 automatically determines the attack code database DB-002(3b) for 「CVE-2023-XX104」. In contrast, the attack code corresponding to 「CVE-2023-XX105」 is available in the attack code database DB-001(3a) and the attack code database DB-XYZ(3n). In this case, the attack code collection unit 14 determines the attack code database DB-001(3a) for 「CVE-2023-XX105」 according to the priority order.
[0033] Subsequently, in S6 of the flowchart shown in FIG. 2, the attack code collection unit 14 collects the attack code from the URL of the attack code database determined in S5. Then, as shown in FIG. 8, the attack code collection unit 14 adds the collected attack code to the attack code storage unit 12. At this time, the attack code is stored in, for example, the BLOB (Binary Large Object) format.
[0034] In S7, the attack code setting unit 13 sets the attack code corresponding to the vulnerability so that the test execution unit 16 can perform a penetration test on the test target system 2. At this time, the attack code setting unit 13 may, for example, start the user interface unit 17 and let the user of the test device 1 set the necessary information. In this case, the user interface unit 17 provides the test information setting screen shown in FIG. 9 according to the instruction from the attack code setting unit 13.
[0035] The test information setting screen sequentially displays a setting form one by one for each vulnerability detected from the test target system 2. The setting form includes fields related to the setting of the IP address and fields related to the setting of the port, in addition to the attack code ID, the attack code, and the vulnerability to be targeted (CVE identification number). The field related to the setting of the IP address allows the user of the test device 1 to input whether it is necessary to set the IP address of the attack target. If it is necessary to set it, the user is further asked to input the IP address of the attack target. Similarly, the field related to the setting of the port allows the user of the test device 1 to input whether it is necessary to set the port of the attack target. If it is necessary to set it, the user is further asked to input the port of the attack target. Also, depending on the attack code, it is specified in advance whether it is necessary to set the IP address / port of the attack target. In this case, the user inputs the information required by the attack code (i.e., IP address, port, etc.).
[0036] When the input operation is completed, the user clicks the "Next" button. Then, the test information setting screen displays the setting form corresponding to the next vulnerability. Hereinafter, the user sets the necessary information for each vulnerability (or each attack code) in the same procedure. And when the setting for all vulnerabilities is completed, the attack code setting unit 13 instructs the test execution unit 16 to execute the penetration test.
[0037] In S8, the test execution unit 16 executes a penetration test for each vulnerability detected from the test target system 2 using the set attack code. And the test execution unit 16 outputs the result of the penetration test.
[0038] As described above, when the test apparatus 1 according to the embodiment of the present invention executes a penetration test using attack codes corresponding to the vulnerabilities of the system 2 to be tested, if it does not hold the necessary attack codes in its own apparatus, it automatically collects the attack codes from the attack code database 3 connected to the network. Therefore, the penetration test related to the vulnerabilities of the system 2 to be tested can be efficiently executed.
[0039] <Hardware Configuration> FIG. 10 shows an example of the hardware configuration of the test apparatus 1. The test apparatus 1 is realized by a computer 200 including a processor 201, a memory 202, a storage device 203, an input / output device 204, a recording medium reader 205, and a communication interface 206.
[0040] The processor 201 controls the operation of the test apparatus 1 by executing the penetration test support program stored in the storage device 203. The penetration test support program includes program codes describing the procedures of the flowchart shown in FIG. 2. Therefore, by the processor 201 executing this program, the functions of the vulnerability detection unit 11, the attack code setting unit 13, the attack code collection unit 14, the test execution unit 16, and the user interface unit 17 shown in FIG. 1 are provided. The memory 202 is used as a working area for the processor 201. The storage device 203 stores the penetration test support program and other programs. Note that the attack code storage unit 12 and the access information storage unit 15 are realized using the storage device 203.
[0041] The input / output device 204 includes input devices such as a keyboard, a mouse, a touch panel, and a microphone. Also, the input / output device 204 includes output devices such as a display device and a speaker. The recording medium reader 205 can acquire the data and information recorded on the recording medium 210. The recording medium 210 is a removable recording medium detachable from the computer 200. Also, the recording medium 210 is realized by, for example, a semiconductor memory, a medium that records signals by optical action, or a medium that records signals by magnetic action. Note that the penetration test support program may be provided from the recording medium 210 to the computer 200. The communication interface 206 provides a function of connecting to a network. Note that when the penetration test support program is stored in the program server 220, the computer 200 may acquire the penetration test support program from the program server 220.
Explanation of Signs
[0042] 1 Test apparatus 2 System under test 3(3a~3n) Attack code database 11 Vulnerability detection unit 12 Attack code storage unit 13 Attack code setting unit 14 Attack code collection unit 15 Access information storage unit 16 Test execution unit 17 User interface unit 200 Computer 201 Processor
Claims
1. A vulnerability detection unit that detects vulnerabilities in the system under test, An access information storage unit that stores access information for accessing a database that provides attack codes for penetration testing, An attack code collection unit that collects attack codes corresponding to the vulnerabilities detected by the vulnerability detection unit by accessing the database using the access information, A test execution unit that executes a penetration test on the system under test using the attack codes collected by the attack code collection unit, A test device comprising the above.
2. Further comprising an attack code storage unit that stores attack codes for penetration testing of the system under test, When the attack code corresponding to the vulnerability detected by the vulnerability detection unit is stored in the attack code storage unit, the test execution unit executes a penetration test on the system under test using the attack code stored in the attack code storage unit, When the attack code corresponding to the vulnerability detected by the vulnerability detection unit is not stored in the attack code storage unit, The attack code collection unit collects attack codes corresponding to the vulnerabilities detected by the vulnerability detection unit from the database, The test execution unit executes a penetration test on the system under test using the attack codes collected by the attack code collection unit, The attack codes collected by the attack code collection unit are stored in the attack code storage unit The test device according to claim 1, characterized in that.
3. The attack code storage unit stores attack codes in association with CVE (Common Vulnerabilities and Exposures) identification numbers, The vulnerability detection unit outputs a CVE identification number representing the vulnerability detected in the system under test, The attack code collection unit identifies a database capable of providing attack codes to be used in the penetration test of the system under test by performing web scraping on the CVE identification numbers output from the vulnerability detection unit for which the corresponding attack codes are not stored in the attack code storage unit The test device according to claim 2, characterized in that.
4. Detect vulnerabilities in the system under test, By accessing the database using access information for accessing a database that provides attack codes for penetration testing, attack codes corresponding to vulnerabilities detected in the system under test are collected, and a penetration test is executed on the system under test using the collected attack codes. A test method characterized by the above.
Citation Information
Patent Citations
Automatic test suite controller and program
JP2022041790A