Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

219 results about "Security testing" patented technology

Security testing is a process intended to reveal flaws in the security mechanisms of an information system that protect data and maintain functionality as intended. Due to the logical limitations of security testing, passing security testing is not an indication that no flaws exist or that the system adequately satisfies the security requirements.

Power generation side industrial control system network security target building method based on virtual-real combination

The invention discloses a virtual-real combination-based power generation side industrial control system network security target construction method. The method comprises the following steps of: constructing a virtual-real combination target environment consisting of a physical equipment layer and a virtual model layer; the heterogeneous industrial control protocol between the physical equipment layer and the virtual model layer is analyzed, protocol semantic information is extracted, and a bidirectional dynamic mapping rule of a physical equipment state and a virtual model state is generated based on the protocol semantic information; based on a state change event of the physical equipment layer, according to a bidirectional dynamic mapping rule, synchronizing changed equipment state data to the virtual model layer in real time, and simulating protocol behavior logic corresponding to the equipment state data in the virtual model layer according to a security test requirement; and based on the attack instruction or the abnormal state signal generated by the virtual model layer, according to the protocol specification format of the target physical equipment, converting the instruction or the signal into an executable control command, and driving the physical equipment layer to execute an operation corresponding to the control command.
Owner:HUANENG POWER INT INC +1

Automated security testing systems using multi-tiered language models

PendingUS20250335601A1Platform integrity maintainanceLocal languageSecurity testing
Cost-effective cyber security risk countermeasure systems and methods enable LLM-based automated security testing for managed cybersecurity services, without leaking sensitive information about target systems. In embodiments, this is accomplished by utilizing flexible local language models that identify and filter target system specific information when communicating with a public large language model to obtain highly accurate security testing patterns.
Owner:HITACHI LTD

Unauthorized vulnerability detection method, device and equipment and readable storage medium

The invention discloses an unauthorized vulnerability detection method, device and equipment and a readable storage medium, and is applied to the field of security detection, and the method comprises the steps: carrying out the semantic recognition of real business flow data through a large language model, and determining a to-be-detected interface; performing semantic analysis on the parameters of the to-be-detected interface by using a large language model to determine target parameters; extracting a parameter value with an unauthorized vulnerability risk in the target parameter from the historical real service flow data; generating a test effective load of the to-be-detected interface based on the target parameter and the parameter value by utilizing a large language model and a preset rule base; and performing unauthorized vulnerability detection on the to-be-detected interface by using the test payload, and determining a detection result. According to the method, the natural language understanding capability of a large language model is utilized, the limitation of traditional regularization preprocessing and effective load generation is broken through, and the method is adaptive to diversified scenes of a complex system.
Owner:HANGZHOU DBAPPSECURITY CO LTD

Test case sample cutting method, device and system and storage medium

The embodiment of the invention provides a test case sample cutting method, device and system and a storage medium, and relates to the technical field of network security testing. The method comprises the following steps: constructing an industrial control system attack tactical library; wherein the tactical library comprises classified and arranged attack techniques and corresponding security attributes; performing information analysis and semantic analysis on the test case sample to generate structured data of the test case sample and / or function points in the test case sample; and cutting the test case sample according to the security attribute and / or the structured data and / or the function point to obtain a test fragment corresponding to the security attribute and / or the function point. According to the method, classification-based attack techniques and security attributes are cut by constructing a tactical library, key information can be accurately extracted and test intentions can be understood through information analysis and semantic analysis, redundant tests are avoided, cut test fragments can concentrate on specific security attributes or function points, the test coverage range is more accurate, and the test efficiency is improved. And the distributed security test effect is improved.
Owner:STATE GRID SHANDONG ELECTRIC POWER CO +2

Implicit gradient optimization-based large language model jailbreak attack resisting method

The invention discloses an implicit gradient optimization-based large language model prison break attack resisting method, which is characterized in that continuous gradient optimization on resistance tokens is realized through a Gumbel-Softmax technology, calculation cost is reduced in combination with a two-stage proxy model screening mechanism, and semantic concealment is kept by adopting a dynamic regularization strategy. The system comprises a gradient optimization module, an agent screening module and a migration enhancement module, and can effectively improve the attack success rate and the cross-model migration capability of resistance prompts. The technical problems that a traditional attack resisting method is low in efficiency and poor in concealment are solved, the attack cost is reduced while the large model attack success rate is increased, the API calling frequency is effectively reduced, and the method is suitable for the field of large language model security testing.
Owner:ZHEJIANG UNIV +1

Method and system for automatically detecting network application vulnerabilities based on large language model

The invention discloses a network application vulnerability automatic detection method and system based on a large language model, and solves the problems of low vulnerability detection efficiency and low accuracy in the prior art. The method comprises the following steps of: S1, searching a path of an application programming interface (API) (Application Program Interface); s2, a big language model vulnerability analysis step; s3, a step of generating a script of a vulnerability PoC (Proof Of Concept: Conceptual Verification); s4, an IDOR (Insecure Direct Object Reference) vulnerability crawler identification step is carried out, and the step S4 is carried out according to the vulnerability crawler identification step and the step S4, the step S4 is carried out according to the vulnerability crawler identification step, and the step S4 is carried out according to the vulnerability crawler identification step. S5, a vulnerability verification step; and S6, a report generation step. According to the method and the system, the whole process from path searching to vulnerability hypothesis generation to automatic vulnerability verification is realized through driving the synergistic effect of multiple modules, the targets of zero false alarm and near-zero manual confirmation are achieved, the efficiency and the accuracy of network application security testing are greatly improved, and powerful support is provided for network security protection.
Owner:ENTROPY (BEIJING) NETWORK TECHNOLOGY CO LTD

Dynamic fuzz testing and vulnerability detection method oriented to API (Application Program Interface)

The invention discloses an API-oriented dynamic fuzz testing and vulnerability detection method, and belongs to the technical field of software security testing. The method comprises the following steps: extracting a dependency relationship, an input parameter, an output response and context state data of API calling, generating an initial API dependency graph, dynamically updating by capturing API state change in real time, forming an API state graph, and executing boundary-oriented variation based on parameter constraint characteristics, so as to obtain an API state graph; generating a variation test parameter, calling an API (Application Program Interface) of the variation test parameter to monitor a process memory behavior and response metadata, and generating a multi-dimensional abnormal signal; and performing mode matching on the abnormal signal and the vulnerability feature knowledge base, outputting a vulnerability type label and generating a path tracing report. According to the method, a context state sensing dynamic graph modeling technology is adopted, and a boundary-oriented intelligent variation strategy and multi-source abnormal behavior collaborative analysis are combined, so that precise vulnerability triggering, intelligent vulnerability judgment and complex scene coverage can be realized.
Owner:GUANGZHOU DAPU INFORMATION TECHNOLOGY CO LTD

Large language model security test method based on evolutionary dynamic adversarial attack

The invention discloses a large language model security testing method based on evolutionary dynamic adversarial attacks, and relates to the technical field of security testing. Comprising the following steps: 1, creating a dynamic attack generation engine, constructing an adversarial evolution architecture by utilizing the dynamic attack generation engine, and generating a test sample based on the adversarial evolution architecture for a large language model security test; the method comprises the following steps: 1, establishing a large-scale language model, 2, calculating investigation parameters of harmlessness, honesty and helpfulness based on a Constancy AI principle, calculating a security alignment gap index SAGI by using the investigation parameters, and intelligently judging a value drift condition of the large-scale language model according to the security alignment gap index SAGI, 3, establishing a multi-modal joint defense engine, and carrying out intelligent judgment on the value drift condition of the large-scale language model according to the value drift condition of the large-scale language model. Steganalysis, syntax tree analysis and audio anomaly detection functions are integrated, and all-around threat detection coverage of texts, codes, images and voices is carried out on a detected large language model.
Owner:INSPUR QILU SOFTWARE IND

Construction method and device for dynamic attack and defense test environment of industrial control system

The invention relates to the technical field of industrial control system security testing, and provides a construction method and device for a dynamic attack and defense testing environment of an industrial control system. The method comprises the following steps: realizing virtualization operation and behavior modeling of industrial control firmware through a hardware system simulation technology based on logic self-learning; constructing a meta-aggregation data resource pool to realize intelligent scheduling and automatic deployment of industrial control component resources; when it is detected that the behavior of the industrial equipment is abnormal, deviation behavior data are complemented based on a causal relationship reasoning mechanism, and a simulation model is driven to be adjusted; constructing a digital-analog fusion model supporting space-time driving and data synchronization, and realizing data consistency and linkage between a virtual environment and a real environment; an AI agent mechanism is introduced, an attack path is automatically deduced, a defense strategy is optimized, and intelligent evaluation of a drilling process is completed; attack protection scene configuration and control are carried out through an interactive user interface, and simulation and verification operations in a complex dynamic attack and defense environment are realized.
Owner:SHANDONG COMP SCI CENTNAT SUPERCOMP CENT IN JINAN +1

Information security testing and evidence obtaining platform

The invention relates to the technical field of information security, and discloses an information security testing and evidence obtaining platform, which comprises a graphical user interface module for acquiring project information, project types, equipment information and task information, and storing the project information in a relational database; and encrypting and storing the equipment information. And the protocol simulation module integrates SSH, HTTP and MySQL protocol client libraries, realizes remote equipment login, dynamically loads plug-in configuration and executes a multi-dimensional evaluation algorithm, such as regular matching, keyword scanning and configuration priority analysis. A standard rule base is arranged in the compliance rule judgment module, a quantitative evaluation result is generated through Boolean operation, and an SM2 signature engine is integrated for data signature and integrity verification. The abstract is recalculated through the public key data packet and the signature value is compared, so that the data integrity is ensured. According to the invention, the accuracy and pertinence of equipment safety assessment are ensured.
Owner:CHENGDU CHUANGXIN HUATONG INFORMATION TECH CO LTD

5G RedCap application layer security test method, system and device for power business and medium

The invention relates to the technical field of 5G communication security, and discloses a 5G RedCap application layer security test method, system, device and medium for power business, comprising: constructing a power business test scene library, setting a test case for each scene, performing power business communication environment simulation, and in the application layer communication process of a terminal and a master station, establishing a test case for each scene; multiple types of security attacks are dynamically injected to obtain a detection result of the security event; and constructing a multi-dimensional safety evaluation index system, carrying out quantitative scoring and grade evaluation on the application layer safety performance of the 5G RedCap terminal in the power business scene, and generating a test report. According to the method, the test efficiency and consistency are greatly improved, a quantitative security assessment result is provided, the expandability is good, the power business protocol, the business logic and the security risk characteristics are deeply fused, and a business semantic driven security test system is constructed.
Owner:GUIZHOU POWER GRID CO LTD

Test case level-to-level management system

According to the test case level-to-level management system provided by the invention, a dynamic perception-intelligent decision-accurate execution closed-loop system is constructed through cooperative operation of the intelligent arrangement center module, the multi-modal test fusion module and the heterogeneous execution environment adaptation module. Real-time dynamic allocation of test resources is realized based on a bidirectional sensing mechanism, and the resource utilization rate is improved; a data feedback channel of five-dimensional linkage of interface testing, function testing, UI testing, performance testing and safety testing is established through a multi-modal testing fusion module, and cross-modal conversion and multiplexing are carried out on key testing elements such as boundary value cases and safety injection points, so that the coverage rate of a testing scene is increased, and the defect escape rate is reduced; the heterogeneous execution environment adaptation module realizes automatic identification and accurate matching of a virtual machine, a container and a physical machine environment based on a feature fingerprint database, manual configuration errors are eliminated, environment adaptation time consumption is reduced, the test period is greatly shortened, and the defect positioning efficiency is greatly improved.
Owner:HUANENG INFORMATION TECH CO LTD +1

Deep learning framework fuzzy testing method based on large model cue word optimization

The invention relates to the cross technical field of artificial intelligence and software security testing, in particular to a deep learning framework fuzz testing method based on large model cue word optimization, which is used for improving vulnerability mining efficiency and testing intelligence level of fuzz testing on a deep learning framework. According to the method, the advantages of a large language model in the aspects of code understanding and generation are fully utilized, and efficient vulnerability detection of a deep learning framework is realized by introducing a cue word adaptive optimization and variation mechanism. The method mainly comprises the following steps: (1) providing a deep learning framework API classification method and a cue word routing mechanism; (2) proposing a large model cue word adaptive optimization mechanism; and (3) proposing a deep learning framework fuzzy test variation strategy and a dynamic selection mechanism. According to the method, the automation and vulnerability discovery capability of fuzzy testing can be remarkably improved while the generation quality is ensured, and the method has relatively high universality and application value.
Owner:HUNAN UNIV

Method for Secure Access to Digital Data

The invention relates to a method for secure access to digital data, said digital data being encrypted with a given user's public encryption key and stored on a server. The method comprises the following steps:A. receiving at said server a request from said user to access said digital data;B. transmitting, via said server, via a secure communication interface, a request to a secure user device to release a password stored on said user device;C. obtaining said password via said secure communication interface, from said user device in response to a validated security test issued by said user device to a user; andD. retrieving, via said server, the user's encrypted private key, said user's private key being encrypted with said password, and decrypting said user's encrypted private key with said password to obtain that user's private key, and decrypting said encrypted digital data with said user's private key, and presenting said digital data to said user.Another method is provided for new users who do not yet have encryption keys, where the sender temporarily encrypts the digital data and, upon user enrollment, the server re-encrypts the data to the user's public encryption key before proceeding with the server-assisted decryption process.
Owner:MAILSPEC LLC

Software development-oriented security processing method and device, equipment and medium

The invention relates to the technical field of data security, can be applied to business scenes of financial science and technology, medical health and the like, and discloses a security processing method, device and equipment oriented to software development and a medium. Obtaining an architecture design document to identify potential safety hazards and generate design improvement suggestions; generating a code based on the business logic description and the design improvement suggestion, and completing security detection and repair to obtain a processed code and a code repair record; performing security test on the processed code and recording a test result; collecting data of exception identification, hidden danger identification, code detection and repair and security test to update the security knowledge base; and generating a security analysis report based on the demand exception list, the design improvement suggestion, the code repair record and the test result. According to the invention, through a security identification and restoration process from demand to test, early discovery of security problems, linkage processing and knowledge self-updating are realized.
Owner:PING AN TECH (SHENZHEN) CO LTD

Multi-agent driven safety alarm log simulation generation method

The invention discloses a multi-agent-driven security alarm log simulation generation method, and relates to the technical field of network security, and the method comprises the following steps: S1, obtaining a sample log; s2, on the basis of the sample log, obtaining and defining an overall feature as Ft, a session feature as Fs, a field feature as Fc, an overall rule as Rt, a session rule as Rs and a field rule as Rc; s3, Ft, Fs, Fc, Rt, Rs and Rc are input into the large language model, logs are generated, and the generated logs are classified into overall logs, session logs and field logs; s4-S6, performing outer-layer circulation, middle-layer circulation and inner-layer circulation on the basis of the generated overall log, session log and field log, so as to obtain a final simulation security alarm log set; and S7, performing quality evaluation on the generated simulation security alarm log. According to the method, the security simulation logs meeting the requirements are generated through various agents, and the method is very valuable in scenes such as security testing, security simulation and application security testing.
Owner:BANK OF SHANGHAI

Large language model (LLM) supply chain security

Disclosed are various approaches for large language model (LLM) supply chain security. In one example, an LLM-extended software bill of materials can be extended to provide LLM specific supply chain information for an LLM application that communicates with an LLM service. The LLM-extended software bill of materials can be attached to the LLM application. An LLM specific security test can be performed on the LLM application. A signed LLM security test attestation can be attached to the LLM-extended software bill of materials based on completion of the automated LLM security test. The LLM application or the LLM-extended software bill of materials can be published or transmitted to a predetermined network endpoint.
Owner:AMERICAN EXPRESS TRAVEL RELATED SERVICES CO INC

Security test system

To grasp appropriate operation procedures of a Web site including operation with sequentiality and to efficiently / effectively perform automatic patrol.SOLUTION: A security test system 1 examining whether or not there is security vulnerability in a Web application acquires and analyzes a Web page to be patrolled in an object Web site 3, sets to prompt information related to a content of the acquired Web page, and inputs it to a LLM 4, creates operation procedure information on the Web page, simulates operation regarding the Web page according to the operation procedure information, acquires an URL related to a link in the Web page, and registers it to a page list 14 to be patrolled.SELECTED DRAWING: Figure 1
Owner:UB SECURE CO LTD

Security test system and method for electric power information system

The invention discloses an electric power information system safety test system and method, and the system comprises a test management scheduling platform, a multi-level test execution engine, a real-time lossless collection and monitoring module, an intelligent analysis and decision engine, a digital twin simulation test platform, and a system self-protection and toughness evaluation module. According to the security test system and method for the electric power information system, all-around and deep security coverage of the electric power information system is realized, the breadth and depth of vulnerability discovery are remarkably improved, meanwhile, a real-time security test with lossless business is realized, high continuity and high availability of electric power production business are guaranteed, and secondly, the security of the electric power information system is improved. The intelligent and automatic testing process is realized, and the testing efficiency and the accurate decision-making capability of safety management are greatly improved.
Owner:STATE GRID HENAN ELECTRIC POWER CO WENXIAN POWER SUPPLY CO

Auditing and remediating identified security vulnerability in source code using llm

Information is received that pertains to a security vulnerability of a program identified by security testing. The information includes the security vulnerability and the source code responsible for the security vulnerability. Based on the information pertaining to the security vulnerability, a prompt is generated to input to a large language model (LLM). The prompt is generated to solicit a response from the LLM including whether the security vulnerability is an actual security vulnerability; a justification as to why the LLM has indicated that the security vulnerability is an actual security vulnerability or not; and in a case in which the security vulnerability is an actual security vulnerability, a recommended fix to resolve the security vulnerability.
Owner:MICRO FOCUS LLC

Privacy protection fine tuning and security testing method for large model

The invention discloses a privacy protection fine tuning and security testing method for a large model, and belongs to the technical field of artificial intelligence, and the method comprises the steps: 1, enabling a data provider to cooperate with an edge coordinator to generate a feature extraction edge auxiliary model based on edge-end federal pre-training, and carrying out the feature matching of distillation privacy data based on multiple spatial data; 2, the data provider generates distillation data with an invisible backdoor; and step 3, the task initiator finely adjusts the cloud target large model and performs a security test. The method aims at protecting the privacy of private data of the data provider, reducing the scale of fine adjustment data and realizing the security test of the fine adjustment process of the large model.
Owner:NANJING UNIV OF POSTS & TELECOMM

A multi-level quantitative evaluation method for an electronic product information clearing, verifying and tracing credible closed loop system

PendingCN122346411ATechnology developmentAttack
The application discloses a kind of multi-level quantitative evaluation methods for electronic product information clearing, verification and traceable credible closed-loop system, comprising S100, evaluation framework establishment and test environment preparation step: S110, define evaluation model, the evaluation model includes clearing effect layer (L1), verification credible layer (L2), trace and authentication layer (L3), system behavior and security layer (L4) and performance and efficiency layer (L5).The application has the advantages that: from qualitative to quantitative: a large number of quantitative indicators such as KL divergence, bit recovery rate, throughput are introduced, and the evaluation results are objective, accurate and comparable.The method carries out deep security testing: not only test function, but also take the system itself as attack target, carry out penetration testing and process behavior monitoring, can find deeply hidden design defects and security vulnerabilities, which cannot be achieved by traditional function testing.At the same time, the method can guide technology development, and provide decision basis for procurement and supervision;And high automation and repeatability.
Owner:GUIZHOU UNIV

A network protocol fuzzing method, device, storage medium and equipment

PendingCN122293562APathPingLinguistic model
This application provides a method, apparatus, storage medium, and device for network protocol fuzzing. The method introduces retrieval-enhanced generation technology into protocol fuzzing. By retrieving external knowledge, it provides context for a large language model, ensuring the accuracy of protocol specifications and thus improving the accuracy of generated test cases in protocol testing. Simultaneously, it utilizes the large language model to analyze the out-degree value of the state of the seed to be mutated, and then intelligently allocates test resources based on the out-degree value, thereby enhancing the efficiency of state space exploration. Thus, by combining the large language model with external knowledge retrieval capabilities, test cases that conform to protocol specifications and cover more protocol paths are generated, effectively improving the effectiveness and coverage of network protocol security testing.
Owner:BEIJING UNIV OF POSTS & TELECOMM

Application security test method and device and electronic equipment

The invention discloses an application security test method and device and electronic equipment, and relates to the field of artificial intelligence or other related technical fields, and the method comprises the steps: carrying out the feature extraction of application data of a target application, and obtaining L application features of the target application; determining a demand tag of the target application based on the L application features; determining N test cases corresponding to the target application based on the demand tag of the target application; and performing security testing on the target application based on the N test cases. According to the method and the device, the technical problem of low test efficiency caused by the fact that a tester needs to gradually perform security test case design for different iteration versions of the application in the prior art is solved.
Owner:INDUSTRIAL AND COMMERCIAL BANK OF CHINA

Systems and methods for automated website security testing

Systems and methods are provided for automated website security testing. The systems and methods reduce or eliminate the need for a user to manually click through a web application to perform application security testing by embedding one or more API calls to the application security testing service within an already-existing automated user interface test. When a web page is reached during the user interface that that is desired to be tested using the application security test, a cookie associated with the web page is obtained and provided to the API associated with the application security test. The application security test then returns a result and the user interface test continues. Any number of additional API calls for to the application security test service may be performed for any other number of web pages as the user interface test progresses through the web pages as well.
Owner:AMAZON TECH INC

Large model application security management and control platform

The application discloses a large model application security management and control platform, and relates to the field of large model security application management and control.The platform comprises an MCP protection module, an RAG protection module, an API interface protection module, a secure link module, a gateway application protection module, a data set protection module, a security test evaluation module, a security audit module and a security monitoring and early warning module.The MCP protection module is used for providing security protection when MCP external tools are dispatched.The RAG protection module is used for providing security protection when RAG external data is retrieved.The API interface protection module is used for providing security protection when API interfaces are called.The secure link module is used for providing security protection when data is transmitted.The gateway application protection module is used for providing security protection when a dialogue question and answer is performed.The data set protection module is used for providing data security detection when fine tuning is performed.The security test evaluation module is used for evaluating the large model.The security audit module is used for performing whole-process log auditing on each module.The security monitoring and early warning module is used for performing real-time monitoring on each module, and an early warning is sent when an anomaly is found.The application can provide security protection functions in the large model application process.
Owner:NAT IND INFORMATION SECURITY DEV RES CENT

Python-based putty trusted software testing method and system

PendingCN122152699AError detection/correctionTest documentAutomatic control
The application belongs to the field of trusted software security testing, and discloses a putty trusted software testing method and system based on Python. The application replaces traditional manual operation with an automatic control mode taking Python as the core, so that the full test process of the SIS (Supervisory Information System) safety and trusted infrastructure can be quickly carried out after the version is released. The application automatically processes test case analysis, command execution, output collection, matching judgment, screenshot recording and report generation, thereby avoiding the cumbersome process of manually executing test instructions, manually comparing outputs, manually taking screenshots and manually arranging test documents.
Owner:HUANENG POWER INT CO LTD RIZHAO POWER PLANT +2

A large model threat sample library construction method

PendingCN122433830AEvaluation resultData mining
The application belongs to the technical field of large model security, and specifically discloses a large model threat sample library construction method, which comprises the following steps: step S1, embedding malicious instructions or malicious data into prompt words to construct threat samples; step S2, inputting the threat samples into a target large model as prompt words; step S3, using an evaluation large model to evaluate the output results of the target large model; and step S4, if the evaluation result is harmful content, adding the threat sample into a threat sample library, otherwise, discarding the threat sample. The application solves the problem of the lack of a threat sample library for security testing of an existing large model, and automatically tests and evaluates the threat samples during the construction of the sample library, so that the threat samples can be stored in the library only after the evaluation, thereby effectively improving the construction efficiency of the threat sample library. Meanwhile, the constructed threat sample library can support the security testing of the target large model, and can be used to improve the security of the target large model.
Owner:CHINESE PEOPLES LIBERATION ARMY UNIT 32802

Methods, systems, and storage media for generating parameters for network security test cases.

This invention discloses a method for completing generation parameters of network security test cases, including acquiring data information of a target power system network; extracting query elements; constructing a non-connected graph of generation parameters; embedding the non-connected graph of generation parameters into a knowledge graph to obtain knowledge graph query results; and generating the data information required for test case generation based on the knowledge graph query results, thus completing the parameter completion for network security test case generation. This invention also discloses a system for implementing the method for completing generation parameters of the network security test cases, and a storage medium including the method for completing generation parameters of the network security test cases. This invention, by associating the acquired data information and automatically generating the missing parameters required for constructing test cases, not only achieves parameter completion for network security test cases but also has higher reliability, accuracy, and efficiency.
Owner:STATE GRID HUNAN ELECTRIC POWER COMPANY LIMITED +3

A security test method, device, equipment, medium and product are applied

The application provides an application security testing method and device, equipment, medium and product, which can be applied to the fields of artificial intelligence technology and financial technology. The method comprises the following steps: determining test information of a to-be-detected application in an operation test process; the test information comprises to-be-detected information called by the to-be-detected application in the operation test process of the to-be-detected application; determining a corresponding compliance baseline of the to-be-detected application based on a pre-trained baseline generation model; the compliance baseline comprises a compliance information call baseline; the compliance information call baseline is used for representing information allowed to be called by the to-be-detected application; determining a baseline deviation between the test information and the determined compliance baseline, and determining a security detection result of the to-be-detected application according to the baseline deviation; the baseline deviation comprises an information deviation between the to-be-detected information and the compliance information call baseline.
Owner:INDUSTRIAL AND COMMERCIAL BANK OF CHINA