JR/T 0191-2020 in English
VALIDGuide for securities and futures industry software test—Software security testing
- Issued on:2020-07-10
- Implemented on:2020-07-10
- File Format:PDF
- Delivery:Via email within 5 business days
$321.00
本标准给出了证券期货行业信息系统建设过程中的软件安全测试目标及流程、软件安全测试技术、软件安全测试基本测试方法及移动应用安全测试特定测试方法。
本标准适用于指导证券期货行业市场核心机构、证券期货基金经营机构以及证券期货信息技术服务机构实施证券期货业计算机软件和外部信息系统的安全测试。
注1:核心机构,如证券期货交易所、证券登记结算机构、期货市场监控中心等;
注2:经营机构,如证券公司、期货公司、基金公司等;
注3:服务机构为软件开发商、信息商、服务商。
Introduction
Analysis of the Standard Core Framework
| Test Dimensions | Traditional Testing | Security Testing Requirements | Level 3 Security Enhancement Items |
|---|---|---|---|
| Identity Authentication | Single-Factor Verification | Two-Factor/Multi-Factor Authentication | Dynamic Token+Biometrics |
| Data Communication | HTTP Plaintext Transmission | TLS1.2+Encryption | National Secret Algorithm SM Series |
| Vulnerability Protection | Basic Input Verification | OWASP TOP10 Protection | Real-time Threat Intelligence Linkage |
Key Technology Implementation Points
Practical Penetration Test Cases
Taking Hang Seng Electronic Trading System as an example, through the STRIDE model analysis, it was found that:
- Session Fixation Vulnerability: Attackers can hijack authenticated sessions
- Business Logic Bypass: Modify request parameters to achieve unauthorized transactions
- XXE Injection: Obtain server configuration through XML parsing
Repair solution: session token dynamic refresh + business request signature verification + XML entity disabling strategy
Special Requirements for Mobile Applications
- Environment detection: Root/jailbreak environment identification and blocking must be implemented
- Component protection: Activity components must explicitly set android:exported="false"
- Package verification: Use V1/V2/V3 multi-signature verification
Standard evolution trend
Compared with the 2019 version of the Software Testing Specification, this standard adds:
- Fuzz Testing technical requirements
- Mobile application-specific permission abuse detection
- Test case design method based on threat modeling

Loading PDF document...
Error loading PDF. Please make sure the file is valid and try again.
We also recommend
-

JR/T 0305-2025 in English
Standardization of the insurance industry information technology performance evaluation index system
2025-02-17 -

JR/T 0067-2021 in English
The cybersecurity graded protection evaluation requirements for securities and futures industries
2021-08-30 -

JR/T 0320-2024 in English
Securities and fund management institutions operation and maintenance automation capability maturity specification
2024-11-20