首页> 外国专利> SQL INJECTION VULNERABILITY DETECTION METHOD, APPARATUS AND DEVICE, AND READABLE STORAGE MEDIUM

SQL INJECTION VULNERABILITY DETECTION METHOD, APPARATUS AND DEVICE, AND READABLE STORAGE MEDIUM

机译:SQL注入漏洞检测方法,装置和设备以及可读存储介质

摘要

An SQL injection vulnerability detection method, apparatus and device, and a readable storage medium, the method comprising the steps of: determining a detection point of a uniform resource locator (URL) request for a website to be tested after obtaining the URL request, and constructing a sequence request for Boolean logic parameters corresponding to the detection point (S10); acquiring response pages obtained after executing the URL request and the sequence request, and performing similarity analysis on the response pages to obtain a similarity value between the response page corresponding to the URL request and a response page corresponding to each request in the sequence request (S20); and if the similarity value satisfies a preset condition, determining that an SQL injection vulnerability exists in the URL request (S30). With the present method, whether the SQL injection vulnerability exists in the URL request or not is determined according to the similarity between the response pages, and the accuracy rate of detecting SQL injection vulnerability is thus improved.
机译:一种SQL注入漏洞检测方法,装置和设备以及可读存储介质,该方法包括以下步骤:在获得URL请求后,为待测试网站确定统一资源定位符URL请求的检测点;构造对与检测点相对应的布尔逻辑参数的序列请求(S10);获取执行URL请求和序列请求后获得的响应页面,对响应页面进行相似度分析,得到URL请求对应的响应页面与序列请求中每个请求对应的响应页面之间的相似度值(S20) );如果相似度值满足预设条件,则确定URL请求中存在SQL注入漏洞(S30)。采用本方法,根据响应页面之间的相似性,确定URL请求中是否存在SQL注入漏洞,从而提高了SQL注入漏洞的检测准确率。

著录项

  • 公开/公告号WO2020073493A1

    专利类型

  • 公开/公告日2020-04-16

    原文格式PDF

  • 申请/专利权人 PING AN TECHNOLOGY(SHENZHEN)CO. LTD.;

    申请/专利号WO2018CN122811

  • 发明设计人 HE SHUANGNING;

    申请日2018-12-21

  • 分类号G06F21/57;

  • 国家 WO

  • 入库时间 2022-08-21 11:12:03

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号