A network protocol fuzz testing method and device based on state guidance and seed mutation

By building basic seeds and real-time monitoring mapped to states, and combining state guidance and seed mutation algorithms, high-quality test cases are generated, which solves the problem of insufficient utilization of protocol state information in traditional fuzz testing and improves the efficiency and coverage of network protocol vulnerability detection.

CN119402400BActive Publication Date: 2025-10-03ZHEJIANG UNIV OF TECH
2 Cites 0 Cited by

Patent Information

Application Number
CN202411548590.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-01
Publication Date
2025-10-03
Estimated Expiration
2044-11-01

AI Technical Summary

Technical Problem

Traditional fuzz testing technology fails to effectively utilize protocol state information in network protocol vulnerability detection, resulting in low test coverage and vulnerability discovery rate. It also lacks an intelligent feedback mechanism and is unable to cope with the complex and changing network protocol environment.

Method used

By constructing a basic seed and mapping it to the protocol state, monitoring state transitions and coverage in real time, selecting high-coverage seeds for mutation, generating state-guided message sequences, and optimizing the test strategy using protocol state code feedback, we use mutation algorithms such as bit flipping, field replacement, random insertion, and deletion to generate test cases.

Benefits of technology

It improves test efficiency and coverage, reduces invalid test cases, increases the speed and number of vulnerability discovery, and achieves more efficient network protocol vulnerability detection.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader

Abstract

A network protocol fuzz testing method and device based on state guidance and seed mutation, the method comprising: 1) manually constructing a high-quality basic seed based on official RFC protocol documents and mapping the seed to the corresponding state; 2) inputting a message sequence into a target program for fuzz testing, interacting with the target program while monitoring the program state and obtaining feedback; 3) selecting a seed with high coverage for information-preserving mutation based on the protocol state code and path coverage feedback, preserving the seed's state transition function to reduce the number of invalid seeds; 4) state-guided message sequence generation: selecting a target test state based on the current state and the returned protocol status code, prioritizing states that have not been reached or have been reached less frequently as targets, and then generating a message sequence that can reach or approach the target state based on the basic seed. The method proposed in the present invention fully utilizes the protocol state information and preserves the seed's state transition capability during the seed mutation process. Through state guidance and targeted message sequence generation, the efficiency and quality of network protocol fuzz testing are improved.
Need to check novelty before this filing date? Find Prior Art