The invention belongs to the technical field of application
program security detection, and provides a security APP
business logic vulnerability detection method and
system, a medium and a
server, and the method comprises the steps: constructing a standardized
time sequence model of a security transaction process, dynamically collecting
instruction sequence data during the actual operation of a security APP, comparing an
instruction sequence with the standardized
time sequence model, and obtaining a security APP
business logic vulnerability detection result. And carrying out risk grade division and sorting on the identified abnormal
instruction sequence, carrying out
simulation verification on an operation path corresponding to the high-risk abnormal sequence, confirming the validity of the
business logic vulnerability, and generating a detection report. According to the method, automatic vulnerability identification and
verification of the security
transaction service full link are realized, the detection coverage rate and efficiency are improved, the service logic
vulnerability detection coverage rate can be improved to about 90% or above, the detection efficiency is improved to about 10 times or above of manual work, the artificial scene construction cost is reduced, different broker APP personalized rules can be adapted, and the security
transaction service full link vulnerability identification and
verification method is suitable for popularization and application. And the method has high expansibility and adaptability.