The invention discloses a
network application vulnerability automatic detection method and
system based on a large
language model, and solves the problems of low
vulnerability detection efficiency and low accuracy in the prior art. The method comprises the following steps of: S1, searching a path of an
application programming interface (API) (Application Program Interface); s2, a big
language model vulnerability analysis step; s3, a step of generating a script of a vulnerability PoC (
Proof Of Concept: Conceptual
Verification); s4, an IDOR (Insecure Direct Object Reference) vulnerability crawler identification step is carried out, and the step S4 is carried out according to the vulnerability crawler identification step and the step S4, the step S4 is carried out according to the vulnerability crawler identification step, and the step S4 is carried out according to the vulnerability crawler identification step. S5, a vulnerability
verification step; and S6, a
report generation step. According to the method and the
system, the whole process from path searching to vulnerability
hypothesis generation to automatic vulnerability
verification is realized through driving the synergistic effect of multiple modules, the targets of zero
false alarm and near-zero manual confirmation are achieved, the efficiency and the accuracy of
network application security testing are greatly improved, and powerful support is provided for
network security protection.