System, method, and program for testing vulnerabilities in web applications
The system addresses the challenge of uniform vulnerability inspection across different web application environments by using large-scale language models to process source code and generate endpoint and vulnerability information, enabling efficient testing across diverse frameworks.
Patent Information
- Application Number
- JP2024013745
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2024-01-31
- Publication Date
- 2025-05-08
- Estimated Expiration
- 2044-01-31
AI Technical Summary
Existing methods for detecting vulnerabilities in web applications through static analysis face challenges in uniform application across different environments and frameworks, making it difficult to inspect vulnerabilities in various applications.
A system utilizing one or more computer processors to generate and process instruction information for large-scale language models, which outputs endpoint and vulnerability information based on web application source code, enabling uniform vulnerability inspection across diverse environments.
This approach allows for efficient and uniform vulnerability testing in various web applications, regardless of the underlying environment or framework, by leveraging large-scale language models to extract and analyze endpoint and specification information.
Smart Images

Figure 0007672747000001_ABST
Abstract
Description
[Technical field]
[0001] The present invention relates to a system, a method, and a program for testing vulnerabilities in a web application. [Background technology]
[0002] Conventionally, application vulnerabilities have been detected by static analysis of source code (see, for example, Patent Document 1 below). In such static analysis, typically, the data flow of the entire source code is inspected, and the flow from malicious input to the occurrence of the vulnerability is reproduced. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] JP 2019-003309 A Summary of the Invention [Problem to be solved by the invention]
[0004] However, since the static analysis described above requires different implementations for each environment, such as language and framework, it has been difficult to apply it uniformly to testing vulnerabilities in various applications built in diverse environments.
[0005] One of the objects of the embodiments of the present invention is to enable testing of vulnerabilities in various applications. Other objects of the embodiments of the present invention will become apparent by referring to the entire specification. [Means for solving the problem]
[0006] A system according to one embodiment of the present invention is a system for testing vulnerabilities in a web application, comprising one or more computer processors, wherein the one or more computer processors execute the following steps: generating first instruction information instructing to output endpoint information related to each of a plurality of endpoints in the web application, the endpoint information including processing information related to processing executed at the endpoints, based on a source code of the web application; inputting the first instruction information into a first large-scale language model and acquiring the endpoint information output from the first large-scale language model; acquiring specification information in which the specifications of the endpoint are described in a natural language; generating second instruction information instructing to output vulnerability information related to vulnerabilities of the endpoint based on the endpoint information and the specification information; and inputting the second instruction information into a second large-scale language model and acquiring the vulnerability information output from the second large-scale language model.
[0007] A method according to one embodiment of the present invention is executed by one or more computers and is a method for testing vulnerabilities of a web application, comprising the steps of generating first instruction information instructing output of endpoint information related to each of a plurality of endpoints in the web application, the endpoint information including processing information related to processing executed at the endpoint, based on a source code of the web application; inputting the first instruction information into a first large-scale language model and obtaining the endpoint information output from the first large-scale language model; obtaining specification information in which specifications of the endpoint are described in natural language; generating second instruction information instructing output of vulnerability information related to vulnerabilities of the endpoint based on the endpoint information and the specification information; and inputting the second instruction information into a second large-scale language model and obtaining the vulnerability information output from the second large-scale language model.
[0008] A program according to one embodiment of the present invention is a program for testing vulnerabilities in a web application, and causes one or more computers to execute the following steps: generating first instruction information instructing one or more computers to output endpoint information regarding each of a plurality of endpoints in the web application, the endpoint information including processing information regarding processing executed at the endpoints, based on the source code of the web application; inputting the first instruction information into a first large-scale language model and acquiring the endpoint information output from the first large-scale language model; acquiring specification information in which the specifications of the endpoint are described in natural language; generating second instruction information instructing one or more computers to output vulnerability information regarding vulnerabilities of the endpoint based on the endpoint information and the specification information; and inputting the second instruction information into a second large-scale language model and acquiring the vulnerability information output from the second large-scale language model. Effect of the Invention
[0009] Various embodiments of the present invention allow for testing of various applications for vulnerabilities. [Brief description of the drawings]
[0010] [Figure 1] 1 is a diagram showing a schematic configuration of a network including a vulnerability testing server 10 according to an embodiment of the present invention. [Diagram 2] FIG. 4 is a diagram illustrating an example of information managed by an inspection rule information table 152. [Diagram 3] 4 is a diagram illustrating an example of information managed by an examination management table 154. [Figure 4] FIG. 13 is a diagram illustrating an example of information managed by the inspection details management 156. [Diagram 5] FIG. 4 is a diagram illustrating an example of an examination screen 50. [Figure 6] FIG. 6 is a diagram illustrating an example of an inspection rule specification screen 60. [Figure 7] 4 is a flowchart illustrating a process executed by the server 10 when performing a vulnerability test. [Figure 8] FIG. 13 is a diagram illustrating a prompt for obtaining endpoint information. [Figure 9] FIG. 13 illustrates an example response from a large-scale language model to a prompt for obtaining endpoint information. [Figure 10] FIG. 13 is a diagram illustrating a prompt for obtaining specification information. [Figure 11] FIG. 13 is a diagram illustrating an example of a response from a large-scale language model to which a prompt for obtaining specification information is input. [Figure 12] FIG. 13 is a diagram illustrating a prompt for acquiring vulnerability information. [Figure 13] FIG. 13 is a diagram illustrating an example of a response from a large-scale language model to which a prompt for obtaining vulnerability information is input. [Figure 14] FIG. 13 is a diagram illustrating a prompt for extracting specification information. [Figure 15] FIG. 13 is a diagram illustrating an example of a response from a large-scale language model to which a prompt for extracting specification information is input. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0011] Hereinafter, embodiments of the present invention will be described with reference to the drawings. In each drawing, the same reference numerals may be used to denote the same or similar components.
[0012] FIG. 1 is a diagram showing a schematic configuration of a network including a vulnerability testing server 10 according to an embodiment of the present invention. As shown in the figure, the server 10 is communicatively connected to a user terminal 30 via a communication network 20 such as the Internet. Although only one user terminal 30 is shown in FIG. 1, the server 10 is communicatively connected to a plurality of user terminals 30. The vulnerability testing server 10 provides a vulnerability testing service that statically analyzes vulnerabilities of web applications to a user who operates the user terminal 30. The vulnerability testing server 10 is an example of a device that implements all or a part of the system of the present invention.
[0013] First, a description will be given of the hardware configuration of the vulnerability checking server 10. The vulnerability checking server 10 is configured as a general computer, and as shown in Fig. 1, includes a computer processor 11, a main memory 12, an input / output I / F 13, a communication I / F 14, and a storage (storage device) 15, and these components are electrically connected via a bus or the like (not shown).
[0014] The computer processor 11 is configured as a CPU, a GPU, or the like, and loads various programs stored in a storage 15 or the like into a main memory 12, and executes various instructions included in the programs. The main memory 12 is configured, for example, by a DRAM or the like.
[0015] The input / output I / F 13 includes various input / output devices for exchanging information with an operator, etc. The input / output I / F 13 includes, for example, an information input device such as a keyboard, a pointing device (e.g., a mouse, a touch panel, etc.), an audio input device such as a microphone, and an image input device such as a camera. The input / output I / F 13 also includes an image output device such as a display, and an audio output device such as a speaker.
[0016] The communication I / F 14 is implemented as hardware such as a network adapter, various communication software, or a combination of these, and is configured to realize wired or wireless communication via a communication network 20 or the like.
[0017] The storage 15 is configured, for example, with a magnetic disk or a flash memory. The storage 15 stores various programs including an operating system, various data, and the like. For example, as shown in Fig. 1, the storage 15 has a test rule information table 152 that manages information on test rules applicable to vulnerability testing, a test management table 154 that manages information on individual tests, and a test details management table 156 that manages information on the details of individual tests. Some of these tables may be integrated into one table, or may be divided into multiple tables.
[0018] Furthermore, for example, the storage 15 stores a server-side program 40 according to an embodiment of the present invention. The program 40 is a program for causing the server 10 to function as all or part of a system for providing a vulnerability testing service. At least a part of the server-side program 40 can be configured to be executed on the user terminal 30 side via a terminal-side program 42, which will be described later.
[0019] In this embodiment, the vulnerability testing server 10 may be configured using a plurality of computers each having the above-mentioned hardware configuration. For example, the server 10 is configured by a plurality of server devices.
[0020] The vulnerability testing server 10 thus configured can be configured to have the functions of a web server and an application server, and executes various processes in response to requests from the user terminal 30, and transmits screen data (e.g., HTML data) and control data according to the results of the processes to the user terminal 30. The user terminal 30 outputs a web page or other screen based on the received data.
[0021] Next, a description will be given of the hardware configuration of the user terminal 30. The user terminal 30 is configured as a general computer, and as shown in Fig. 1, includes a computer processor 31, a main memory 32, an input / output I / F 33, a communication I / F 34, and a storage (storage device) 35, and these components are electrically connected via a bus or the like (not shown).
[0022] The computer processor 31 is configured as a CPU, a GPU, or the like, and loads various programs stored in a storage 35 or the like into a main memory 32 and executes various instructions included in the programs. The main memory 32 is configured, for example, by a DRAM or the like.
[0023] The input / output I / F 33 includes various input / output devices for exchanging information with an operator, etc. The input / output I / F 33 includes, for example, an information input device such as a keyboard or a pointing device (e.g., a mouse, a touch panel, etc.), an audio input device such as a microphone, and an image input device such as a camera. The input / output I / F 33 also includes an image output device such as a display, and an audio output device such as a speaker.
[0024] The communication I / F 34 is implemented as hardware such as a network adapter, various communication software, or a combination of these, and is configured to realize wired or wireless communication via the communication network 20 or the like.
[0025] The storage 35 is configured, for example, by a magnetic disk or a flash memory. The storage 35 stores various programs including an operating system, various data, and the like. The programs stored in the storage 35 can be downloaded from an application market or the like and installed. The storage 35 also stores the above-mentioned terminal-side program 42. The program 42 is configured as a web browser or other application (for example, a terminal-side application for the vulnerability testing service of this embodiment, etc.) and can be configured to execute at least a part of the server-side program 40 as described above.
[0026] In this embodiment, the user terminal 30 may be configured as a smartphone, a tablet terminal, a personal computer, or the like.
[0027] A user operating a user terminal 30 configured in this manner can use the vulnerability testing service provided by the server 10 by communicating with the server 10 via a terminal-side program 42 installed in storage 35 or the like.
[0028] Next, a description will be given of the functions of the vulnerability testing server 10 configured as above. The computer processor 11 of the server 10 is configured to function as a management function control unit 112 and a testing control unit 114 by executing instructions included in a program (e.g., at least a part of the server-side program 40) loaded into the main memory 12, as shown in FIG.
[0029] The management function control unit 112 is configured to execute various processes related to the control of the management function of the vulnerability testing service. For example, the management function control unit 112 transmits screen data and control data of various screens related to the management function to the user terminal 30, executes various processes in response to an operation input by a user via the screen output on the user terminal 30, and transmits screen data and control data according to the results of the processes to the user terminal 30. The management functions controlled by the management function control unit 112 include, for example, login processing (user authentication), billing control, and management of user accounts.
[0030] The inspection control unit 114 is configured to execute various processes related to the control of the vulnerability inspection. For example, the inspection control unit 114 transmits screen data and control data of various screens for controlling the inspection to the user terminal 30, executes various processes in response to operation input by the user via the screens outputted on the user terminal 30, and transmits screen data and control data according to the results of the processes to the user terminal 30.
[0031] In this embodiment, the test control unit 114 is configured to generate first instruction information (prompt) for acquiring endpoint information, which instructs outputting endpoint information related to each of a plurality of endpoints in a web application based on the source code of the web application. In this embodiment, the endpoint information includes processing information (e.g., HTTP method and / or code) related to processing executed at the corresponding endpoint.
[0032] An endpoint, sometimes called an API endpoint, is an entrance for a client to access a specific function or data, and can also be said to be a point or unit of entry for an external attack. A client can obtain a response from an endpoint by sending an HTTP request. Endpoint information may include a path corresponding to the endpoint.
[0033] The inspection control unit 114 is configured to input the generated first instruction information to a first large-scale language model (LLM) and acquire endpoint information output from the first large-scale language model. The large-scale language model is a machine learning model in natural language processing trained using a large amount of data, and may be, for example, GPT provided by OpenAI, Inc., or BERT or PaLM provided by Google, Inc., Inc. For example, the instruction information is input via an API corresponding to such a large-scale language model.
[0034] Moreover, the test control unit 114 is configured to acquire specification information in which the specifications of the corresponding endpoint are described in a natural language.
[0035] In addition, the inspection control unit 114 is configured to generate second instruction information (prompt) for acquiring vulnerability information that instructs outputting vulnerability information related to vulnerabilities of an endpoint based on corresponding endpoint information and specification information, input the generated second instruction information to a second large-scale language model, and acquire the vulnerability information output from the second large-scale language model.
[0036] In this way, the vulnerability testing server 10 in this embodiment uses a large-scale language model to acquire endpoint information including processing information executed at each of multiple endpoints in a web application based on the source code, and acquires vulnerability information for the endpoints based on the corresponding endpoint information and specification information, and this mechanism can be uniformly applied to vulnerability testing of various applications built in various environments. In other words, the server 10 enables vulnerability testing of various applications.
[0037] Furthermore, since the vulnerability check server 10 acquires vulnerability information based on specification information written in natural language, it may be possible to detect vulnerabilities based on business logic (for example, vulnerabilities in authority management problems, etc.).
[0038] In this embodiment, the first large-scale language model used to obtain endpoint information and the second large-scale language model used to obtain vulnerability information may be the same large-scale language model or different large-scale language models.
[0039] In this embodiment, the specification information can be acquired in various ways. For example, the test control unit 114 acquires the specification information (for example, provided in advance by an administrator of a web application) stored in advance in the storage 15 or the like.
[0040] Also, the specification information may be acquired using a large-scale language model. That is, the inspection control unit 114 may be configured to generate third instruction information for acquiring specification information that instructs to output the specification information based on the endpoint information, input the third instruction information to a third large-scale language model, and acquire the specification information output from the third large-scale language model. The third large-scale language model may be the same large-scale language model as the first large-scale language model and / or the second large-scale language model, or may be a different large-scale language model. Such a configuration enables acquisition of the specification information of the endpoint based on the source code of the web application.
[0041] In this embodiment, the second instruction information for acquiring vulnerability information may be configured to instruct outputting the vulnerability information according to a predetermined vulnerability inspection rule. For example, the inspection control unit 114 is configured to acquire an inspection rule (e.g., registered in advance by a provider of a vulnerability inspection service) managed in the inspection rule information table 152, and generate second instruction information for instructing outputting the vulnerability information according to the inspection rule. Such a configuration may enable improvement of the accuracy of determining vulnerabilities of a large-scale language model, application of an inspection rule based on information not yet learned by the large-scale language model (e.g., new technology or a vulnerability with low recognition, etc.), and realization of customization such as determining that a vulnerability exists when a specific condition is satisfied.
[0042] Next, a specific example of one aspect of the vulnerability testing server 10 of this embodiment having such functions will be described. First, information managed by each table in this example will be described. FIG. 2 illustrates information managed by the testing rule information table 152 in this example. The testing rule information table 152 in this example manages information related to testing rules applicable to vulnerability testing, and as shown in the figure, manages information such as "rule name" and "test rule content" in which the testing rule is described in natural language in association with an "test rule ID" that identifies an individual testing rule. In this example, such testing rules are registered in advance by a provider of a vulnerability testing service. The testing rules include, for example, the following rules: Rule 1: If "userId" is specified as an argument to "badFunction" in the code, detect it as an "improper permission management" Rule 2: If the code uses "secureFunction" to output text, do not detect it as "Cross-Site Scripting." Rule 3: The escapex function is a function for SQL injection countermeasures, so even if the characters are correctly escaped and the string is concatenated, it is determined that there is no SQL injection vulnerability.
[0043] 3 illustrates information managed by the inspection management table 154 in this example. The inspection management table 154 in this example manages information related to vulnerability inspections, and as shown in the figure, manages information such as information about the user performing the inspection, "basic information" including the inspection date and time, "source code file storage path" which is the path where the source code file in which the source code of the web application to be inspected is written is stored, "source code file name" which is the file name of the source code file, and "applied inspection rule information" which is information about the inspection rule to be applied, in association with an "inspection ID" which identifies each inspection rule to be applied. The applied inspection rule information includes an inspection rule ID which identifies each inspection rule to be applied.
[0044] 4 illustrates information managed by the inspection details management table 156 in this example. The inspection details management table 156 in this example manages information on an endpoint basis in an inspection, and as illustrated, manages information such as an "HTTP method" corresponding to the process executed at the endpoint, a "path" identifying the endpoint, a "code" corresponding to the process executed at the endpoint, "specification information" which is information describing the specifications at the endpoint in natural language, and a "vulnerability inspection result" which is the result of a vulnerability inspection at the endpoint, in association with a combination of an "inspection ID" which identifies an individual inspection and an "endpoint ID" which identifies an individual endpoint of a web application to be inspected in the inspection.
[0045] The information managed by each table in this example has been described above. Next, the process executed by the vulnerability check server 10 and the screens output on the user terminal 30 in this example will be described.
[0046] 5 illustrates an inspection screen 50 output on the user terminal 30. The screen 50 is a screen for a user of the vulnerability inspection service to inspect for vulnerabilities by static analysis of source code, and as illustrated, has a first button 52 to which the text "Specify source code file" is added, a second button 54 to which the text "Specify inspection rule" is added, and a third button 56 to which the text "Start inspection" is added.
[0047] First button 52 is an object for specifying a file in which source code of a web application to be inspected for vulnerability is written. When button 52 is selected, a screen (not shown) for specifying a specific file is output, and the user can specify the file in which source code is written via the screen. When the file is specified, the source code file storage path and the source code file name are registered in inspection management table 154. Note that multiple files may be specified as the file in which source code is written.
[0048] The second button 54 is an object for specifying an inspection rule to be applied to the vulnerability inspection. When the button 54 is selected, an inspection rule specification screen 60, an example of which is shown in Fig. 6, is output. As shown in the figure, the screen 60 has an inspection rule specification area 62 for specifying an inspection rule, a setting button 64, and a back button 66.
[0049] The inspection rule designation area 62 displays a list of each rule name of a plurality of inspection rules (managed in the inspection rule information table 152) that can be applied to the vulnerability inspection, and a check box 621 is arranged to the left of each rule name. The user selects the check box 621 corresponding to the inspection rule to be applied to the vulnerability inspection, and then selects the setting button 64. When the button 64 is selected, the applied inspection rule information is registered in the inspection management table 154.
[0050] The third button 56 is an object for starting a vulnerability test. Fig. 7 is a flowchart illustrating a process executed by the server 10 in response to the selection of the button 56 (i.e., when a vulnerability test is performed). As shown in the figure, the server 10 first generates a prompt (first instruction information) for acquiring endpoint information (step S100). Specifically, a prompt instructing acquisition of endpoint information is generated based on the source code of the web application.
[0051] 8 shows an example of a prompt for obtaining endpoint information. As shown in the figure, the prompt instructs to extract the path of the endpoint and the function to be executed / call destination from the source code of the web application, and more specifically, to extract the HTTP method, path, and code as information for each endpoint. The contents of the source code are obtained from the source code file storage path and the source code file name managed in the inspection management table 154.
[0052] 7, the server 10 then acquires and registers the endpoint information (step S110). Specifically, a prompt for acquiring the endpoint information is input to the large-scale language model, and the endpoint information (HTTP method, path, and code) of each of the multiple endpoints output from the large-scale language model is registered in the inspection details management table 156.
[0053] Fig. 9 illustrates an example of a response from a large-scale language model to which the prompt for obtaining endpoint information illustrated in Fig. 8 has been input. As illustrated, based on the source code of a web application, an HTTP method, a path, and a code are extracted as endpoint information for each of multiple endpoints in the web application.
[0054] Returning to the flowchart of Fig. 7, the server 10 then generates a prompt (third instruction information) for acquiring specification information for the target endpoint (step S120). Specifically, an unprocessed endpoint is sequentially identified as the target endpoint from among the multiple endpoints, and a prompt for acquiring specification information for the target endpoint is generated. The prompt is a prompt that instructs acquisition of specification information based on the endpoint information.
[0055] 10 shows an example of a prompt for acquiring specification information. As shown in the figure, the prompt instructs the specification of an endpoint to be described from the endpoint information, specifically, the HTTP method executed at the endpoint, the path that identifies the endpoint, and a description of the endpoint specification. The endpoint information (HTTP method, path, and code) is acquired from the inspection details management table 156.
[0056] Returning to the flowchart of FIG. 7, the server 10 then acquires and registers the specification information (step S130). Specifically, a prompt for acquiring the specification information is input to the large-scale language model, and the specification information output from the large-scale language model is registered in the inspection details management table 156. In this example, the specification information is acquired using the same large-scale language model as the above-mentioned large-scale language model used to acquire the endpoint information. Note that in another example of this embodiment, the specification information may be acquired using a large-scale language model different from the large-scale language model used to acquire the endpoint information.
[0057] Fig. 11 illustrates an example of a response from a large-scale language model to which the prompt for obtaining endpoint information illustrated in Fig. 10 has been input. As illustrated, the endpoint specifications are described in natural language (Japanese in this example) based on the endpoint information.
[0058] 7, the server 10 then generates a prompt (second instruction information) for acquiring vulnerability information for the target endpoint (step S140). Specifically, a prompt is generated that instructs acquiring vulnerability information for the endpoint based on the specification information and the vulnerability testing rule.
[0059] 12 illustrates an example of a prompt for acquiring vulnerability information. As illustrated, the prompt instructs to point out vulnerabilities in an endpoint from the endpoint specification information and code in accordance with a vulnerability testing rule specified by the user (obtaining the vulnerability name, vulnerability description, and relevant code). The endpoint specification information and code are obtained from the testing details management table 156. Furthermore, the vulnerability testing rule specified by the user is obtained from the testing management table 154.
[0060] Returning to the flowchart of Fig. 7, the server 10 then acquires and registers vulnerability information (step S150). Specifically, a prompt for acquiring vulnerability information is input to the large-scale language model, and the vulnerability test result including the vulnerability information output from the large-scale language model is registered in the test details management table 156. In this example, the vulnerability information is acquired using the same large-scale language model as the above-mentioned large-scale language model used to acquire the endpoint information and the specification information. Note that in another example of this embodiment, the vulnerability information may be acquired using a large-scale language model different from the large-scale language model used to acquire the endpoint information and / or the specification information.
[0061] Fig. 13 illustrates an example of a response from a large-scale language model to which the prompt for acquiring vulnerability information illustrated in Fig. 12 is input. As illustrated, the endpoint specification information and code indicate vulnerabilities in the endpoint (vulnerabilities in session management and plaintext password storage). Note that if the prompt illustrated in Fig. 12 does not include a description of an SQL injection exclusion rule as a vulnerability testing rule (the rule is not applied), an SQL injection vulnerability may be detected.
[0062] 7, if there is an unprocessed endpoint (YES in step S160), the server 10 returns to step S120 and generates a prompt for acquiring specification information, acquires and registers specification information, generates a prompt for acquiring vulnerability information, and acquires and registers vulnerability information for the next endpoint (steps S120 to S150). This series of processes is repeated until there is no unprocessed endpoint (NO in step S160).
[0063] In the above example, the specification information of the endpoint is obtained using a large-scale language model, but the specification information may be provided individually by the user. In this case, the specification information of the endpoint is obtained from a file in which the specification information of the web application is described and provided by the user (for example, a button for specifying the file is placed on the inspection screen 50). Furthermore, in this case, the specification information for each endpoint may be extracted from the specification information described in the file using a large-scale language model (prompts and responses in this case are shown in Figs. 14 and 15, respectively).
[0064] The vulnerability testing server 10 according to the present embodiment described above uses a large-scale language model to acquire endpoint information including processing information executed at each of multiple endpoints in a web application based on the source code, and acquires vulnerability information for the endpoints based on the corresponding endpoint information and specification information, and this mechanism can be uniformly applied to vulnerability testing of various applications built in various environments. In other words, the server 10 enables vulnerability testing of various applications.
[0065] In other embodiments of the present invention, some or all of the functions of the vulnerability testing server 10 in the above-described embodiments can be realized by cooperation between the vulnerability testing server 10 and the user terminal 30, or can be realized by the user terminal 30. In other words, the system of the present invention can be configured by the vulnerability testing server 10, the vulnerability testing server 10 and the user terminal 30, or can be configured by the user terminal 30, in addition to being configured by the vulnerability testing server 10.
[0066] The processes and procedures described herein may be realized by software, hardware, or any combination thereof, other than those explicitly described. For example, the processes and procedures described herein may be realized by implementing logic corresponding to the processes and procedures in a medium such as an integrated circuit, a volatile memory, a non-volatile memory, or a magnetic disk. In addition, the processes and procedures described herein may be implemented as a computer program corresponding to the processes and procedures, and executed by various computers.
[0067] Although processes and procedures described herein are described as being performed by a single device, software, component, or module, such processes or procedures may be performed by multiple devices, software, components, and / or modules. Also, the software and hardware elements described herein may be realized by combining them into fewer components or breaking them down into more components.
[0068] In this specification, even if a component of the invention is described as either singular or plural, or described without limitation to either singular or plural, the component may be either singular or plural unless the context requires otherwise. [Explanation of symbols]
[0069] 10 Vulnerability testing server 11. Computer Processors 112 Management function control section 114 Inspection control section 15. Storage 152 Inspection rule information table 154 Inspection Management Table 156 Inspection Details Management Table 30 User terminals 40 Server-side programs 42 Terminal side program 50 Inspection screen 60 Inspection rule specification screen
Claims
1. 1. A system for testing vulnerabilities in web applications, comprising: one or more computer processors, the one or more computer processors comprising: generating first instruction information instructing output of endpoint information related to each of a plurality of endpoints in the web application, the endpoint information including processing information related to processing executed at the endpoint, based on a source code of the web application; inputting the first indication information into a first large-scale language model and obtaining the endpoint information output from the first large-scale language model; acquiring specification information in which a specification of the endpoint is described in a natural language; generating second instruction information instructing to output vulnerability information related to vulnerabilities of the endpoint based on the endpoint information and the specification information; inputting the second instruction information into a second large-scale language model, and acquiring the vulnerability information output from the second large-scale language model; system.
2. the second large-scale language model is the same large-scale language model as the first large-scale language model; The system of claim 1.
3. The processing information includes an HTTP method and / or code to be executed at the endpoint. The system of claim 1.
4. The one or more computer processors further perform a step of generating third instruction information instructing that the specification information is to be output based on the endpoint information; The step of acquiring the specification information includes inputting the third instruction information to a third large-scale language model, and acquiring the specification information output from the third large-scale language model. The system of claim 1.
5. the third large-scale language model is the same large-scale language model as the first large-scale language model and / or the second large-scale language model; The system of claim 4.
6. the second instruction information instructs outputting the vulnerability information in accordance with a predetermined vulnerability inspection rule; The system of claim 1.
7. 1. A method, executed by one or more computers, for testing vulnerabilities in a web application, comprising: generating first instruction information instructing output of endpoint information related to each of a plurality of endpoints in the web application, the endpoint information including processing information related to processing executed at the endpoint, based on a source code of the web application; inputting the first indication information into a first large-scale language model and obtaining the endpoint information output from the first large-scale language model; acquiring specification information in which a specification of the endpoint is described in a natural language; generating second instruction information instructing to output vulnerability information related to vulnerabilities of the endpoint based on the endpoint information and the specification information; inputting the second indication information into a second large-scale language model, and acquiring the vulnerability information output from the second large-scale language model; method.
8. A program for testing vulnerabilities in web applications, comprising: generating first instruction information instructing output of endpoint information related to each of a plurality of endpoints in the web application, the endpoint information including processing information related to processing executed at the endpoint, based on a source code of the web application; inputting the first indication information into a first large-scale language model and obtaining the endpoint information output from the first large-scale language model; acquiring specification information in which a specification of the endpoint is described in a natural language; generating second instruction information instructing to output vulnerability information related to vulnerabilities of the endpoint based on the endpoint information and the specification information; inputting the second instruction information to a second large-scale language model, and acquiring the vulnerability information output from the second large-scale language model; program.
Citation Information
Patent Citations
Code defect analysis method and device
CN117171741A
Code security review method and system based on large language model
CN117454388A
Inspection apparatus
JP2019003309A
Methods and systems for automatically generating and executing computer code using a natural language description of a data manipulation to be performed on a data set
US20240028312A1