CN111488287B - 注入漏洞测试用例的生成方法、装置、介质及电子设备 - Google Patents
注入漏洞测试用例的生成方法、装置、介质及电子设备 Download PDFInfo
- Publication number
- CN111488287B CN111488287B CN202010301315.5A CN202010301315A CN111488287B CN 111488287 B CN111488287 B CN 111488287B CN 202010301315 A CN202010301315 A CN 202010301315A CN 111488287 B CN111488287 B CN 111488287B
- Authority
- CN
- China
- Prior art keywords
- features
- test case
- feature
- constraint
- constraint relation
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Active
Links
- 238000012360 testing method Methods 0.000 title claims abstract description 224
- 238000002347 injection Methods 0.000 title claims abstract description 136
- 239000007924 injection Substances 0.000 title claims abstract description 136
- 238000000034 method Methods 0.000 title claims abstract description 42
- 238000004590 computer program Methods 0.000 claims description 9
- 230000002452 interceptive effect Effects 0.000 claims description 5
- 238000012545 processing Methods 0.000 description 16
- 230000004044 response Effects 0.000 description 14
- 238000010586 diagram Methods 0.000 description 8
- 230000008901 benefit Effects 0.000 description 4
- 230000000694 effects Effects 0.000 description 4
- 238000001514 detection method Methods 0.000 description 3
- 230000006870 function Effects 0.000 description 3
- 238000004891 communication Methods 0.000 description 2
- 238000012986 modification Methods 0.000 description 2
- 230000004048 modification Effects 0.000 description 2
- 230000003287 optical effect Effects 0.000 description 2
- 238000007792 addition Methods 0.000 description 1
- 230000004075 alteration Effects 0.000 description 1
- 238000013475 authorization Methods 0.000 description 1
- 230000008859 change Effects 0.000 description 1
- 238000000354 decomposition reaction Methods 0.000 description 1
- 238000011161 development Methods 0.000 description 1
- 238000005516 engineering process Methods 0.000 description 1
- 239000000284 extract Substances 0.000 description 1
- 238000003780 insertion Methods 0.000 description 1
- 230000037431 insertion Effects 0.000 description 1
- 230000010354 integration Effects 0.000 description 1
- 230000007246 mechanism Effects 0.000 description 1
- 239000013307 optical fiber Substances 0.000 description 1
- 230000035515 penetration Effects 0.000 description 1
- 238000005215 recombination Methods 0.000 description 1
- 230000006798 recombination Effects 0.000 description 1
- 239000004065 semiconductor Substances 0.000 description 1
- 238000012546 transfer Methods 0.000 description 1
Images
Classifications
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F11/00—Error detection; Error correction; Monitoring
- G06F11/36—Preventing errors by testing or debugging software
- G06F11/3668—Software testing
- G06F11/3672—Test management
- G06F11/3684—Test management for test design, e.g. generating new test cases
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/57—Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities
- G06F21/577—Assessing vulnerabilities and evaluating computer system security
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F2221/00—Indexing scheme relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F2221/03—Indexing scheme relating to G06F21/50, monitoring users, programs or devices to maintain the integrity of platforms
- G06F2221/033—Test or assess software
Landscapes
- Engineering & Computer Science (AREA)
- Theoretical Computer Science (AREA)
- Computer Hardware Design (AREA)
- General Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Software Systems (AREA)
- Quality & Reliability (AREA)
- Computing Systems (AREA)
- Testing Electric Properties And Detecting Electric Faults (AREA)
- Test And Diagnosis Of Digital Computers (AREA)
- Debugging And Monitoring (AREA)
Abstract
Description
Claims (8)
Priority Applications (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN202010301315.5A CN111488287B (zh) | 2020-04-16 | 2020-04-16 | 注入漏洞测试用例的生成方法、装置、介质及电子设备 |
Applications Claiming Priority (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN202010301315.5A CN111488287B (zh) | 2020-04-16 | 2020-04-16 | 注入漏洞测试用例的生成方法、装置、介质及电子设备 |
Publications (2)
Publication Number | Publication Date |
---|---|
CN111488287A CN111488287A (zh) | 2020-08-04 |
CN111488287B true CN111488287B (zh) | 2023-05-16 |
Family
ID=71798788
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
CN202010301315.5A Active CN111488287B (zh) | 2020-04-16 | 2020-04-16 | 注入漏洞测试用例的生成方法、装置、介质及电子设备 |
Country Status (1)
Country | Link |
---|---|
CN (1) | CN111488287B (zh) |
Families Citing this family (1)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN113515748A (zh) * | 2021-05-20 | 2021-10-19 | 云账户技术(天津)有限公司 | 一种检测sql注入的方法及装置 |
Citations (3)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN101894237A (zh) * | 2010-08-03 | 2010-11-24 | 南开大学 | 应用遗传算法自动生成xss跨站点脚本漏洞检测参数的方法 |
CN102592084A (zh) * | 2011-12-27 | 2012-07-18 | 奇智软件(北京)有限公司 | 一种漏洞修复客户端逻辑的测试方法及系统 |
CN108256334A (zh) * | 2018-01-26 | 2018-07-06 | 平安科技(深圳)有限公司 | 漏洞测试方法、装置、计算机设备和存储介质 |
Family Cites Families (7)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN102136051B (zh) * | 2011-05-06 | 2013-02-20 | 南开大学 | 一种应用SGM-SQL注入模型驱动web应用渗透测试的方法 |
CN103780614B (zh) * | 2014-01-21 | 2016-12-07 | 金华比奇网络技术有限公司 | 一种基于模拟攻击扩展的sql注入漏洞挖掘方法 |
CN104391793B (zh) * | 2014-11-27 | 2017-07-14 | 中国联合网络通信集团有限公司 | 测试步骤及测试脚本生成方法及装置 |
CN106354638A (zh) * | 2016-08-29 | 2017-01-25 | 广州唯品会信息科技有限公司 | 基于词法分析的自动测试方法及装置 |
US10394694B2 (en) * | 2018-01-15 | 2019-08-27 | Fujitsu Limited | Unexplored branch search in hybrid fuzz testing of software binaries |
CN109902002B (zh) * | 2019-02-14 | 2020-06-02 | 浙江口碑网络技术有限公司 | 组合测试用例的生成方法及装置、存储介质、计算机设备 |
CN110543421B (zh) * | 2019-08-31 | 2022-03-29 | 华南理工大学 | 基于测试用例自动生成算法的单元测试自动执行方法 |
-
2020
- 2020-04-16 CN CN202010301315.5A patent/CN111488287B/zh active Active
Patent Citations (3)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN101894237A (zh) * | 2010-08-03 | 2010-11-24 | 南开大学 | 应用遗传算法自动生成xss跨站点脚本漏洞检测参数的方法 |
CN102592084A (zh) * | 2011-12-27 | 2012-07-18 | 奇智软件(北京)有限公司 | 一种漏洞修复客户端逻辑的测试方法及系统 |
CN108256334A (zh) * | 2018-01-26 | 2018-07-06 | 平安科技(深圳)有限公司 | 漏洞测试方法、装置、计算机设备和存储介质 |
Non-Patent Citations (1)
Title |
---|
练坤梅 ; 许静 ; 田伟 ; 张莹 ; .SQL注入漏洞多等级检测方法研究.计算机科学与探索.2011,(第05期),全文. * |
Also Published As
Publication number | Publication date |
---|---|
CN111488287A (zh) | 2020-08-04 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
Trinh et al. | S3: A symbolic string solver for vulnerability detection in web applications | |
US10177996B2 (en) | System and method for validating documentation of representational state transfer (REST) services | |
US10915702B2 (en) | Methods and systems for validating multiple methods of input using a unified rule set | |
Wassermann et al. | Sound and precise analysis of web applications for injection vulnerabilities | |
Bisht et al. | Waptec: whitebox analysis of web applications for parameter tampering exploit construction | |
CN110532176B (zh) | 一种智能合约的形式化验证方法、电子装置及存储介质 | |
CN105302710A (zh) | 一种确定需要回归测试的测试用例的方法和装置 | |
US11348597B2 (en) | Intent-based network validation | |
KR101554424B1 (ko) | 테스트 케이스 생성 자동화 방법 및 장치 | |
CN101268468A (zh) | 认证脚本代码源的方法和设备 | |
CN112182037B (zh) | 数据校验方法、装置、设备以及存储介质 | |
RU2652451C2 (ru) | Способы обнаружения аномальных элементов веб-страниц | |
Zhuo et al. | Long short‐term memory on abstract syntax tree for SQL injection detection | |
US11947976B2 (en) | System and method for semantic metadata extensions in API governance using validation rulesets | |
Sakai et al. | Rough set‐based rule generation and Apriori‐based rule generation from table data sets: a survey and a combination | |
CN111488287B (zh) | 注入漏洞测试用例的生成方法、装置、介质及电子设备 | |
Zhang et al. | Flow Chart Generation‐Based Source Code Similarity Detection Using Process Mining | |
Jekjantuk et al. | Modelling and reasoning in metamodelling enabled ontologies | |
US8909579B2 (en) | Identifying invariant candidates based on proofs | |
US20080022353A1 (en) | Framework to simplify security engineering | |
US10733303B1 (en) | Polymorphic code translation systems and methods | |
KR101244945B1 (ko) | 메타 패턴을 이용한 웹쉘 탐지 장치 | |
Ren et al. | Verification using counterexample fragment based specification relaxation: case of modular/concurrent linear hybrid automata | |
US10515219B2 (en) | Determining terms for security test | |
Kolomeets et al. | Using models of finite transition systems for checking web-service security |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
PB01 | Publication | ||
PB01 | Publication | ||
SE01 | Entry into force of request for substantive examination | ||
SE01 | Entry into force of request for substantive examination | ||
TA01 | Transfer of patent application right | ||
TA01 | Transfer of patent application right |
Effective date of registration: 20210202 Address after: No.38, Tongyan Road, Haihe Education Park, Jinnan District, Tianjin Applicant after: NANKAI University Applicant after: STATE GRID TIANJIN ELECTRIC POWER Co. Applicant after: STATE GRID CORPORATION OF CHINA Address before: No.38, Tongyan Road, Haihe Education Park, Jinnan District, Tianjin Applicant before: NANKAI University Applicant before: STATE GRID TIANJIN ELECTRIC POWER Co. |
|
GR01 | Patent grant | ||
GR01 | Patent grant | ||
TR01 | Transfer of patent right | ||
TR01 | Transfer of patent right |
Effective date of registration: 20240220 Address after: 300384 No. 8, Haitai Huake 4th Road, Binhai New Area, Tianjin Patentee after: ELECTRIC POWER SCIENCE & RESEARCH INSTITUTE OF STATE GRID TIANJIN ELECTRIC POWER Co. Country or region after: China Patentee after: STATE GRID TIANJIN ELECTRIC POWER Co. Patentee after: STATE GRID CORPORATION OF CHINA Patentee after: NANKAI University Address before: No.38, Tongyan Road, Haihe Education Park, Jinnan District, Tianjin Patentee before: NANKAI University Country or region before: China Patentee before: STATE GRID TIANJIN ELECTRIC POWER Co. Patentee before: STATE GRID CORPORATION OF CHINA |