Research and Application of Automated Testing Technology for Data Security Vulnerabilities
Xiaolu Zhang, Wuqiang Shen, Zheheng Liang, Lei Cui, Yechao Wang · 2024
As data security vulnerability detection becomes increasingly important, traditional manual testing techniques face the problem of low detection rates. To solve this problem, this study adopts a variety of automated testing methods, including fuzz testing, static code analysis, and dynamic analysis. First, a large number of random inputs are generated through fuzz testing to evaluate the system's ability to handle abnormal inputs; secondly, static code analysis tools are used to scan the source code to identify potential security vulnerabilities; finally, dynamic analysis is used to monitor the running program to identify vulnerabilities and security issues in real time. risk. After combining these three methods, the detection rate of system vulnerabilities increased by approximately 35%. Of the 100 samples tested, fuzz testing discovered 25 new vulnerabilities, static analysis identified 30 potential risks, and dynamic analysis revealed 15 runtime vulnerabilities. In addition, the system performs well when handling high concurrent requests, with an average response time of 200 milliseconds, ensuring effective monitoring of real-time data flows. The use of automated testing methods can significantly improve the detection efficiency of data security vulnerabilities and provide strong support for subsequent security protection.