Automatic feedback method based on protocol fuzz test and related equipment

By acquiring and analyzing dynamic configuration files and real-time data flows of protocol fuzz testing, and generating and sending exception notification emails, the problem of lack of instant feedback in the prior art is solved and the testing efficiency is improved.

CN120216377APending Publication Date: 2025-06-27SECZONE TECH CO LTD
View PDF 0 Cites 7 Cited by

Patent Information

Application Number
CN202510321694.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-18
Publication Date
2025-06-27

AI Technical Summary

Technical Problem

The existing protocol fuzz testing tools lack instant feedback mechanisms, which leads to testers need to regularly check the test progress, affecting testing efficiency.

Method used

By obtaining the dynamic configuration file of protocol fuzz testing, monitoring protocol fuzz testing in real time, analyzing real-time data flow, judging exception events, generating feedback instructions, and sending exception notification emails to the user terminal.

Benefits of technology

An automated instant feedback mechanism is realized to ensure that testers can receive notifications in a timely manner when the test task fails, reducing the workload of manual monitoring and improving testing efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120216377A_ABST
    Figure CN120216377A_ABST
Patent Text Reader

Abstract

The invention provides an automatic feedback method based on a protocol fuzz test and related equipment. The method comprises the following steps: acquiring a dynamic configuration file of the protocol fuzz test; performing real-time monitoring on the protocol fuzz test according to the protocol characteristic parameters of the dynamic configuration file, and determining a real-time data stream of the protocol fuzz test; performing multi-level feature analysis on the real-time data stream to judge an abnormal event existing in the protocol fuzz test; generating a feedback instruction corresponding to the abnormal event by performing multi-dimensional correlation analysis based on a knowledge graph on the abnormal event; and sending an exception notification mail to the user terminal according to the feedback instruction. Through an automatic mail notification mechanism, it is ensured that a tester can receive a notification immediately when a test task fails, the workload of manual monitoring is reduced, and the test efficiency is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of data processing, and in particular to an automatic feedback method and related devices based on protocol fuzz testing. Background Art

[0002] Protocol fuzz testing is a software testing method used to discover vulnerabilities and defects in the system under test. Protocol fuzz testing tasks may fail due to various abnormal reasons, such as problems like the proxy going offline. When the testing task fails, it is very necessary to notify the testers in a timely manner so that they can respond and handle the problem quickly. Traditional protocol fuzz testing tools often lack an immediate feedback mechanism when the testing task fails. Testers need to regularly check the testing progress and analyze the failure reasons through logs, which not only wastes time but also affects the testing efficiency. Summary of the Invention

[0003] This application provides an automatic feedback method and related devices based on protocol fuzz testing, which is used to solve the problem of affecting the testing efficiency due to the lack of an immediate feedback mechanism in the related art.

[0004] In the first aspect of this application, an automatic feedback method based on protocol fuzz testing is provided. The automatic feedback method based on protocol fuzz testing includes: Obtain the dynamic configuration file of the protocol fuzz testing; Monitor the protocol fuzz testing in real time according to the protocol feature parameters of the dynamic configuration file, and determine the real-time data stream of the protocol fuzz testing; Judge the abnormal events existing in the protocol fuzz testing by performing multi-level feature analysis on the real-time data stream; Generate a feedback instruction corresponding to the abnormal event by performing multi-dimensional correlation analysis based on a knowledge graph on the abnormal event; Send an abnormal notification email to the user terminal according to the feedback instruction.

[0005] Optionally, in the first implementation manner of the first aspect of this application, the step of obtaining the dynamic configuration file of the protocol fuzz testing includes: Perform structured processing on the target protocol specification document through a protocol syntax parser to determine the protocol field set and the state transition rule set; Construct a protocol syntax tree model according to the protocol field set, and generate a protocol state machine model in combination with the state transition rule set; Perform topological mapping on the fuzz testing seed library through the protocol state machine model to determine the mutation priority coefficient of each protocol field; Input the mutation priority coefficient into a constraint solver for dynamic parameter optimization to generate a multi-dimensional configuration file framework; Perform logical verification on the multi-dimensional profile framework based on the feedback results of the historical test data set to determine the dynamic profile for protocol fuzz testing.

[0006] Optionally, in the second implementation manner of the first aspect of the present application, the step of performing real-time monitoring on the protocol fuzz testing according to the protocol characteristic parameters of the dynamic profile and determining the real-time data stream of the protocol fuzz testing includes: Deconstruct the protocol characteristic parameters in the dynamic profile through a protocol syntax parser to determine the corresponding protocol syntax rule set; Deploy a packet capture probe at the test agent node according to the protocol syntax rule set; Determine the real-time data stream of the protocol fuzz testing by performing time-series splicing on the interactive packet stream intercepted by the packet capture probe.

[0007] Optionally, in the third implementation manner of the first aspect of the present application, the step of judging the abnormal events existing in the protocol fuzz testing by performing multi-level feature analysis on the real-time data stream includes: Decompose the real-time data stream into an orthogonal dimension data set; wherein, the real-time orthogonal dimension data set includes a network traffic feature set, a protocol field mutation trajectory set, and a system response delay sequence set; Perform sliding window difference processing on the network traffic feature set through the preset mutation detection threshold in the dynamic profile to generate an abnormal fluctuation index set; Based on the protocol state machine model, compare the deviation degree between the actual jump path and the specification-allowed path of the protocol field mutation trajectory set in real time to determine the protocol semantic abnormal probability; Perform time-series pattern analysis on the system response delay sequence set to generate an abnormal deviation coefficient; Perform multi-dimensional evidence weighting on the abnormal fluctuation index set, the protocol semantic abnormal probability, and the abnormal deviation coefficient through the rule weight configuration table in the dynamic profile to generate a comprehensive abnormal score matrix; Perform interval partitioning on the comprehensive abnormal score matrix according to the abnormal determination threshold in the dynamic profile to determine the abnormal events exceeding the abnormal determination threshold.

[0008] Optionally, in the fourth implementation manner of the first aspect of the present application, the step of generating a feedback instruction corresponding to the abnormal event by performing multi-dimensional association analysis on the abnormal event based on a knowledge graph includes: Perform graph neural network matching on the abnormal event with protocol vulnerability nodes, network topology nodes, and historical fault case nodes in the knowledge graph to obtain an associated entity set; The causal inference engine of the knowledge graph performs reverse path tracing on the set of associated entities, and generates a set of causal paths based on the graph traversal algorithm; Based on the key node weight coefficients of the set of causal paths, a feedback policy tree is dynamically constructed through a policy decision tree model; The feedback policy tree is input into a simulation test environment for instruction pre-verification, and a feedback instruction for the abnormal event is generated according to the verification result.

[0009] Optionally, in the fifth implementation manner of the first aspect of the present application, the step of sending an abnormal notification email to the user terminal according to the feedback instruction includes: According to the email notification level and the test parameter correction plan in the feedback instruction set, an initial email message is generated through an email template engine; The encrypted email payload of the initial email message is determined through security sandbox processing; According to the online status identifier and network delay parameters in the user terminal registration information, a priority queue for email distribution is determined; The encrypted email payload is distributed to the corresponding user terminal according to the priority queue; The reception status code of the user terminal is captured based on the ACK verification mechanism; If the reception status code is not received, a redirected encrypted tunnel is triggered for redundant delivery.

[0010] Optionally, in the sixth implementation manner of the first aspect of the present application, the method further includes: A protocol proxy injector captures a status snapshot of the system under test after executing the feedback instruction, and obtains a set of system response data packets with the protocol context state vector corrected; The set of system response data packets is subjected to difference analysis with the protocol transaction template in the historical normal baseline library to determine a behavior deviation vector; A feedback effect evaluation matrix is constructed based on the behavior deviation vector; The execution effectiveness score of each feedback instruction in the feedback effect evaluation matrix is determined through a fuzzy membership function; According to the execution effectiveness score, the dynamic update module of the knowledge graph is activated, the node confidence weights in the abnormal event association graph are iteratively adjusted, and the node splitting threshold of the feedback policy tree is reconstructed through a policy decision tree model.

[0011] The second aspect of the present application provides an automatic feedback device based on protocol fuzz testing, and the automatic feedback device based on protocol fuzz testing includes: An acquisition module, configured to acquire a dynamic configuration file of protocol fuzz testing; A monitoring module, configured to perform real-time monitoring on protocol fuzz testing according to protocol feature parameters of the dynamic configuration file, and determine real-time data streams of the protocol fuzz testing; A judgment module, configured to judge abnormal events existing in the protocol fuzz testing by performing multi-level feature analysis on the real-time data streams; A generation module, configured to generate feedback instructions corresponding to the abnormal events by performing multi-dimensional association analysis on the abnormal events based on a knowledge graph; A sending module, configured to send an abnormal notification email to a user terminal according to the feedback instructions.

[0012] A third aspect of an embodiment of the present application provides an electronic device, including a memory and a processor. The processor is configured to execute a computer program stored on the memory. When the processor executes the computer program, each step in the automatic feedback method based on protocol fuzz testing provided in the first aspect of the embodiment of the present application is implemented.

[0013] A fourth aspect of an embodiment of the present application provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, each step in the automatic feedback method based on protocol fuzz testing provided in the first aspect of the embodiment of the present application is implemented.

[0014] In summary, according to an automatic feedback method and related devices based on protocol fuzz testing provided by the solution of the present application, a dynamic configuration file of protocol fuzz testing is obtained; real-time monitoring is performed on protocol fuzz testing according to protocol feature parameters of the dynamic configuration file, and real-time data streams of the protocol fuzz testing are determined; by performing multi-level feature analysis on the real-time data streams, abnormal events existing in the protocol fuzz testing are judged; by performing multi-dimensional association analysis on the abnormal events based on a knowledge graph, feedback instructions corresponding to the abnormal events are generated; and an abnormal notification email is sent to a user terminal according to the feedback instructions. Through an automated email notification mechanism, it is ensured that testers can receive notifications immediately when a test task fails, reducing the workload of manual monitoring and improving test efficiency. Description of the Drawings

[0015] Figure 1 is a schematic flowchart of an automatic feedback method based on protocol fuzz testing provided by an embodiment of the present application; Figure 2 is a schematic diagram of program modules of an automatic feedback device based on protocol fuzz testing provided by an embodiment of the present application; Figure 3 is a schematic structural diagram of an electronic device provided by an embodiment of the present application. Detailed Embodiments

[0016] To make the invention objectives, features, and advantages of this application more obvious and understandable, the following will clearly and completely describe the technical solutions in the embodiments of this application in conjunction with the accompanying drawings in the embodiments of this application. Obviously, the described embodiments are only a part of the embodiments of this application, rather than all embodiments. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without creative efforts belong to the scope of protection of this application.

[0017] To solve the problem in the related art that the lack of an instant feedback mechanism affects the test efficiency, the embodiments of this application provide an automatic feedback method based on protocol fuzz testing, as Figure 1 FIG. is a schematic flowchart of the automatic feedback method based on protocol fuzz testing provided in this embodiment. The automatic feedback method based on protocol fuzz testing includes the following steps: Step 110, obtain a dynamic configuration file for protocol fuzz testing.

[0018] Specifically, the dynamic configuration file defines the interaction rules of the protocol under test, field constraint conditions, and test case generation strategies. Its content includes, but is not limited to, protocol type identifiers, fuzz testing engine parameters (such as mutation rate, concurrent thread count), and legal jump path templates of the protocol state machine, etc. By parsing this file, the system can dynamically adapt to the test requirements of different protocols.

[0019] In an optional implementation manner of this embodiment, the step of obtaining a dynamic configuration file for protocol fuzz testing includes: performing a structured process on the target protocol specification document through a protocol syntax parser to determine a protocol field set and a state transition rule set; constructing a protocol syntax tree model based on the protocol field set, and generating a protocol state machine model in combination with the state transition rule set; performing a topological mapping on the fuzz testing seed library through the protocol state machine model to determine the mutation priority coefficients of each protocol field; inputting the mutation priority coefficients into a constraint solver for dynamic parameter optimization to generate a multi-dimensional configuration file framework; performing a logical verification on the multi-dimensional configuration file framework based on the feedback results of the historical test data set to determine the dynamic configuration file for protocol fuzz testing.

[0020] Specifically, in this embodiment, the target protocol specification document is structured by a protocol syntax parser. First, the syntax rules described in the protocol specification document need to be converted into a format that can be understood and operated by a computer. The protocol specification document usually describes the various fields of the protocol and their types in a standard format (such as ASN.1, XML, or Protobuf, etc.). The role of the protocol syntax parser is to extract these fields and construct a normalized protocol model based on their structure and interrelationships. The protocol field set is a set obtained in this process, which contains information such as all the defined fields in the protocol, their types, value ranges, etc. The state transition rule set clearly describes how to respond to different inputs in a specific state, and the type and content of the input determine the state transition.

[0021] Construct a protocol syntax tree model according to the protocol field set. The syntax tree is a tree structure, where each node represents a field or a set of fields in the protocol, and the connections between the nodes represent the syntax relationships between the fields. By constructing the protocol syntax tree, the hierarchical structure and logical relationships of the protocol fields can be intuitively displayed. Combining with the state transition rule set, a protocol state machine model is generated. The state machine model is used to describe the transition logic of the protocol between different states. During a protocol communication process, the state of the protocol usually changes according to different input data. For example, in certain specific situations, the protocol may transfer from the "connection established" state to the "data transmission" state, and then to the "connection closed" state. Through the combination of states and state transition rules, the state machine model can accurately simulate the behavior and response of the protocol, providing a comprehensive understanding of the dynamic changes of the protocol.

[0022] Perform a topological mapping on the fuzz testing seed library through the protocol state machine model, mainly by matching various types of test data in the fuzz testing seed library with different states in the protocol state machine. Fuzz testing discovers potential vulnerabilities or defects in the protocol by randomly or semi-randomly generating test cases (i.e., seeds). In this process, the state machine model is used as a constraint condition to ensure that each generated test case conforms to the state transition rules of the protocol. Each seed in the fuzz testing seed library is a possible input data. Through the topological mapping, these input data will be mapped to specific states of the protocol and assigned different mutation priority coefficients. The role of the mutation priority coefficient is to weight different fields, indicating which fields should be preferentially modified in fuzz testing.

[0023] Inputting the mutation priority coefficient into the constraint solver for dynamic parameter optimization aims to perform more precise parameter adjustment for fuzz testing. The task of the constraint solver is to dynamically adjust various parameters in the test cases according to the preset optimization goals, so as to maximize the coverage of all parts of the protocol while ensuring the protocol syntax rules and state machine transition rules. Through dynamic parameter optimization, a multi-dimensional configuration file framework is generated, which contains multi-dimensional test parameters, such as the mutation range, priority, test conditions, etc. of each protocol field. These parameters will directly affect the effect and efficiency of fuzz testing.

[0024] Based on the feedback results of the historical test data set, perform logical verification on the multi-dimensional configuration file framework to ensure the rationality and effectiveness of the configuration file. The historical test data set usually contains a large amount of test results and discovered vulnerability information, which can provide valuable references for new test configurations. By analyzing the historical data, the system can identify which configuration parameters and test strategies perform well in actual tests and which may lead to incomplete test coverage or false positives. In this process, the purpose of logical verification is to make necessary adjustments to the framework based on the feedback of historical tests. For example, correct the value range of certain parameters, re-evaluate the mutation priority coefficient, etc. Finally, the verified configuration file will become the dynamic configuration file for protocol fuzz testing and can be used in the actual test environment to ensure that the test process is more efficient and accurate.

[0025] Step 120: Perform real-time monitoring on the protocol fuzz testing according to the protocol feature parameters of the dynamic configuration file, and determine the real-time data stream of the protocol fuzz testing.

[0026] Specifically, a data acquisition channel is constructed based on the real-time monitoring of the protocol feature parameters. The protocol feature parameters are extracted from the dynamic configuration file, including but not limited to core indicators such as field length threshold, checksum algorithm type, state transition timing constraint, etc. During the monitoring process, the fuzz testing engine synchronously captures the injected abnormal data packets and the response behavior of the system under test, generating a real-time data stream containing the original request message, response content, and system resource occupancy rate. For example, in the TCP protocol test, the real-time data stream can record key information such as the number of SYN packet retransmissions and abnormal fluctuations in the receive window size, providing input for multi-level analysis.

[0027] In an optional implementation manner of this embodiment, the step of performing real-time monitoring on the protocol fuzz testing according to the protocol feature parameters of the dynamic configuration file and determining the real-time data stream of the protocol fuzz testing includes: deconstructing the protocol feature parameters in the dynamic configuration file through a protocol syntax parser to determine the corresponding protocol syntax rule set; deploying a message capture probe at the test proxy node according to the protocol syntax rule set; determining the real-time data stream of the protocol fuzz testing by performing timing splicing on the interactive message stream intercepted by the message capture probe.

[0028] Specifically, in this embodiment, the protocol grammar parser deconstructs the protocol feature parameters in the dynamic configuration file. First, it is necessary to parse various protocol parameters in the dynamic configuration file, which usually include protocol fields, field types, value ranges, protocol state transition rules, and other contents. The protocol grammar parser is responsible for extracting these parameters from the configuration file and converting them into structured data that can be understood by a computer. Through the parsing process, the field types of the protocol, the dependencies between fields, and the behavior patterns of the protocol are clearly represented. The protocol grammar rule set is formed during this process. It contains the protocol's structure and behavior specifications, describing how each protocol field interacts with each other and how to perform state transitions based on different inputs. According to these grammar rule sets, the process of deploying packet capture probes at the test agent node becomes crucial. The test agent node is usually located in the middle of the network, acting as a bridge between the two parties of the protocol interaction. The role of the packet capture probe is to monitor and capture all data packets transmitted through the network in real time, especially the packet streams generated during the protocol interaction. The deployment of the probe needs to be configured according to the protocol grammar rules to ensure that it can capture all data streams that conform to the protocol rules and can identify the specific protocol fields and their states in each data packet. The purpose of time series splicing is to recombine the scattered packet data streams into a complete protocol interaction sequence in the order of transmission. In an actual network environment, protocol interaction packets may be split into multiple data packets and transmitted in batches, so a single data packet often cannot fully represent an interaction. Through time series splicing, these split data packets can be spliced together in chronological order to restore the complete interaction process. Time series splicing needs to rely on the protocol grammar rule set because different protocols have different conventions when splitting and recombining data packets. For example, in the TCP protocol, segmented packets are sorted by sequence numbers, and the correct packet order needs to be restored according to the sequence numbers during splicing. In the HTTP protocol, the entire request or response packet may be split into multiple small data packets. By analyzing the packet headers and contents, the probe can confirm that these data packets belong to the same request and thus perform time series splicing. Through this time series splicing process, the obtained real-time data stream not only accurately reflects the complete process of protocol interaction but also provides the original input data for subsequent protocol fuzz testing. These data streams will be passed as inputs to the fuzz testing tool to test the response behavior of the protocol under various abnormal input conditions, thereby discovering potential protocol vulnerabilities or defects.

[0029] Step 130: Determine the abnormal events existing in the protocol fuzz testing by performing multi-level feature analysis on the real-time data stream.

[0030] Specifically, when performing multi-level feature analysis, a protocol syntax tree parser is used to verify the field structure of the tokenized message set, and a protocol state machine model is used to verify the state transition of the real-time data stream to detect abnormal trajectories that deviate from the preset rules. At the same time, the Hidden Markov Model (HMM) is used to analyze the mutation trajectories of protocol fields to identify potential protocol semantic anomalies. These anomaly markers and abnormal trajectories are input into the multi-modal fusion engine to form an anomaly event association graph, and anomaly events in protocol fuzz testing are found through pattern matching.

[0031] In an optional implementation manner of this embodiment, the steps of determining abnormal events existing in protocol fuzz testing by performing multi-level feature analysis on the real-time data stream include: using a protocol syntax tree parser to verify the field structure of the tokenized message set in the real-time data stream, and generating a syntax anomaly marker set according to the protocol syntax constraints in the dynamic configuration file; performing finite state verification on the protocol context state vector in the real-time data stream based on the protocol state machine model, detecting the deviation degree of the state transition path from the preset rule set, and generating a state anomaly trajectory set; performing Hidden Markov Model analysis on the field mutation trajectory of the real-time data stream to determine the protocol semantic anomaly feature vector; inputting the syntax anomaly marker set and the state anomaly trajectory set into the multi-modal fusion engine to construct an anomaly event association graph; and determining the abnormal events existing in protocol fuzz testing by performing pattern matching on the anomaly event association graph and the protocol semantic anomaly feature vector.

[0032] Specifically, in this embodiment, the protocol syntax tree parser is used to perform field structure verification on the tokenized message set in the real-time data stream. First, the captured message stream needs to be tokenized, that is, each field in the message is extracted and marked. The tokenized message set contains various protocol fields and their corresponding values, and these fields are classified and sorted according to the protocol specifications. The protocol syntax tree parser is a tool for parsing and processing protocol data, which parses the protocol data into a tree-like structure. The role of the protocol syntax tree parser is to check whether these fields meet the structural requirements of the protocol according to the protocol syntax rules. For example, in the HTTP protocol, the request line of the message includes fields such as method, URL, and protocol version. The protocol syntax tree parser will check whether these fields appear in the correct order and ensure that the value range and format of each field are correct. If a certain field violates the protocol syntax constraints, the parser will generate a set of syntax exception markers, which can help the subsequent analysis steps quickly locate the problem area. Based on the protocol state machine model, finite state verification is performed on the protocol context state vector in the real-time data stream. First, it is necessary to clarify the different states of the protocol and the transition rules between states. When the real-time data stream is fed into the state machine model, the state vector is updated according to the context state of each message. The process of finite state verification is to check the deviation degree between the current state and the preset rule set, and identify whether there are abnormal state transition paths. If the state transition in the data stream does not conform to the predetermined rules (such as starting data transmission without completing the connection establishment), a set of state exception trajectories will be generated. Further, hidden Markov model analysis is performed on the field mutation trajectories of the real-time data stream to identify protocol semantic anomaly feature vectors. The hidden Markov model (HMM) is a probabilistic model for analyzing time series data, which can handle the implicit dependencies between states. In protocol fuzz testing, the fields of the message may mutate over time, and these mutation trajectories can be modeled by HMM to analyze the change patterns between different fields. For example, when performing fuzz testing on the SSL / TLS protocol, mutations may be made to the certificate field or the encryption algorithm field. By analyzing the mutation trajectories of these fields through HMM, it can be determined whether they conform to the semantic logic of the protocol. Through this analysis, abnormal mutations between fields can be identified, such as field combinations that do not conform to the protocol specifications or unreasonable changes in field values, thereby generating protocol semantic anomaly feature vectors. Finally, the set of syntax exception markers and the set of state exception trajectories are input into the multimodal fusion engine to construct an abnormal event association graph. The role of the multimodal fusion engine is to integrate the results from different analysis modules, combine syntax exceptions and state exceptions, and form a comprehensive abnormal event graph. In this graph, each abnormal event contains detailed abnormal information, such as abnormal protocol fields, abnormal state transition paths, and semantic features of field mutations.By performing correlation analysis on these abnormal events, potential vulnerabilities or defects in the protocol can be revealed. For example, abnormal mutations in a certain field may cause the protocol to enter an unconventional state, perhaps due to some attack behavior triggering abnormal behavior of the protocol. By performing pattern matching between the abnormal event correlation graph and the protocol semantic anomaly feature vector, the abnormal events existing in the protocol fuzz testing can be determined. The purpose of the pattern matching technology is to identify abnormal events in the abnormal graph that match known attack patterns or vulnerability characteristics, which can efficiently identify and locate abnormal events in the protocol fuzz testing and provide a basis for subsequent vulnerability repair and security reinforcement.

[0033] Step 140: Generate feedback instructions for the corresponding abnormal events by performing multi-dimensional correlation analysis on the abnormal events based on the knowledge graph.

[0034] Specifically, after an abnormal event occurs, multi-dimensional correlation analysis based on the knowledge graph performs in-depth reasoning on the abnormal event. Through the Graph Neural Network (GNN), the abnormal event is matched with protocol vulnerability nodes, network topology nodes, and historical fault case nodes to obtain a set of associated entities. Then, the causal reasoning engine in the knowledge graph is used to perform reverse path tracing on these entities to construct a set of causal paths. According to the key node weight coefficients of the causal path set, a feedback strategy tree is dynamically constructed and input into the simulation test environment for verification. According to the verification results, feedback instructions for the abnormal event are generated.

[0035] In an optional implementation manner of this embodiment, the step of generating feedback instructions for the corresponding abnormal events by performing multi-dimensional correlation analysis on the abnormal events based on the knowledge graph includes: performing graph neural network matching on the abnormal event with protocol vulnerability nodes, network topology nodes, and historical fault case nodes in the knowledge graph to obtain a set of associated entities; performing reverse path tracing on the set of associated entities through the causal reasoning engine of the knowledge graph and generating a set of causal paths based on the graph traversal algorithm; dynamically constructing a feedback strategy tree through a policy decision tree model based on the key node weight coefficients of the causal path set; inputting the feedback strategy tree into the simulation test environment for instruction pre-verification, and generating feedback instructions for the abnormal event according to the verification results.

[0036] Specifically, in this embodiment, first, a knowledge graph including protocol vulnerabilities, network topologies, and historical fault cases is constructed. A knowledge graph is a data structure that organizes knowledge in the form of a graph, where nodes represent entities or concepts in the knowledge, and edges represent the relationships between them. The protocol vulnerability nodes contain information about known protocol vulnerabilities, the network topology nodes represent various devices, communication links, and their connection relationships in the network, and the historical fault case nodes record past faults and their causes and consequences. When an abnormal event is captured, the graph neural network matches the event with various nodes in the knowledge graph, attempting to find relevant historical vulnerabilities, network topologies, or similar faults that have occurred. The graph neural network can effectively process graph-structured data, utilize the node and edge information in the graph, and automatically identify the similarity or correlation between the event and the nodes in the graph. For example, if the abnormal event involves a mutation in a specific protocol field, the graph neural network will search the knowledge graph to see if there are similar protocol vulnerability nodes or relevant historical fault cases, forming a set of associated entities. The causal inference engine of the knowledge graph performs backward path tracing on the set of associated entities. The task of the causal inference engine is to infer the possible causes of the event based on the nodes and edges in the knowledge graph. Backward path tracing starts from the node of the abnormal event and traces back along the edges in the graph to find the root cause that may have led to the abnormality. In this way, it can be determined which network topology changes, protocol vulnerabilities, or historical fault cases may have caused the current abnormal event. The role of the graph traversal algorithm here is to traverse the nodes in the knowledge graph, identify and collect all paths related to the abnormal event, and generate a set of causal paths based on these paths. Based on the weight coefficients of the key nodes in the set of causal paths, a feedback policy tree is dynamically constructed through a policy decision tree model. The key nodes in each causal path represent the key factors that may have caused the abnormal event, and these key nodes have different importance levels in the decision-making process. By assigning weight coefficients to these key nodes, their contribution degrees to the occurrence of the abnormal event can be evaluated. The decision tree model is used here to construct a feedback policy tree based on these weight coefficients. The feedback policy tree describes how to take corresponding response measures according to different abnormal paths. The core idea of the policy decision tree model is to select an appropriate processing method through conditional judgment, so as to take effective repair measures in a timely manner when an abnormality occurs. Finally, the feedback policy tree is input into the simulation test environment for instruction pre-verification, which means that the feedback measures in the policy tree need to be converted into specific operation instructions and simulated and verified in the test environment. The purpose of this process is to ensure that the generated feedback policy is effective and can solve the abnormal event. In the simulation test environment, the system will execute the instructions defined in the policy tree, simulate the system behavior after applying these feedback measures, and check whether it can effectively repair the abnormality or reduce the risk of the system.According to the simulation results, the actual effects of these instructions can be evaluated. If the verification passes, corresponding feedback instructions are generated.

[0037] Step 150: Send an exception notification email to the user terminal according to the feedback instructions.

[0038] Specifically, according to the email notification level and test parameter correction plan in the feedback instruction set, an initial email message is generated through the email template engine and processed by the security sandbox to ensure the security of the email content. The email is sent to the user terminal according to the priority queue to ensure that critical notifications are delivered in a timely manner. The system confirms the receiving status of the email through the ACK verification mechanism. If the confirmation is not received, the redundant delivery mechanism is triggered to ensure the reliable transmission of information. In addition, a state snapshot of the system under test after executing the feedback instruction is taken through the protocol proxy injector, the system response data packet is captured, and a difference analysis is performed with the historical normal baseline library to evaluate the effectiveness of the feedback effect. These evaluation results will be used to further optimize the feedback strategy and improve the automated response ability of the system.

[0039] In an optional implementation manner of this embodiment, the step of sending an exception notification email to the user terminal according to the feedback instructions includes: generating an initial email message through the email template engine according to the email notification level and test parameter correction plan in the feedback instruction set; determining the encrypted email payload of the initial email message through the security sandbox processing; determining the priority queue for email distribution according to the online status identifier and network delay parameters in the user terminal registration information; distributing the encrypted email payload to the corresponding user terminal according to the priority queue; capturing the receiving status code of the user terminal based on the ACK verification mechanism; if the receiving status code is not received, triggering a redirected encrypted tunnel for redundant delivery.

[0040] Specifically, in this embodiment, a suitable email content is dynamically generated based on the notification level, urgency, and correction plan included in the feedback instruction. The role of the email template engine is to automatically fill in the content of the email according to the preset template structure and the input parameters, such as the title of the notification, the detailed description, the correction suggestions, etc. The notification level of the email is usually determined by the priority and importance in the feedback instruction. For example, if an abnormal event has a significant impact on the system security, the notification level of the email may be "urgent", and the correction plan may involve major changes to the system configuration. In the template engine, the email content is dynamically adjusted to reflect these characteristics, and an initial email message that meets the requirements is generated. The initial email message needs to be processed through a security sandbox to generate an encrypted email payload. The security sandbox is an isolated environment used to check whether the email content contains potential security threats, such as malicious attachments, viruses, or scripts. In this environment, the initial email message will undergo strict security checks, and the email content will be encrypted to ensure the security of the email during transmission. The email content may contain sensitive information, so encryption measures must be taken to prevent information leakage. The encrypted email payload refers to the data block obtained by encrypting the email body and attachments. In this way, even if the email is intercepted in the network, it cannot be read by unauthorized third parties. Through the processing of the security sandbox, not only can the security of the email content be ensured, but also additional security protection can be provided for the email distribution process. After the email is encrypted, the priority queue for email distribution is determined according to the online status identifier and network latency parameters in the user terminal registration information. The online status identifier of the user terminal indicates whether the terminal is online and can receive emails, and the network latency parameter indicates the impact of the current network environment on the email transmission speed. For those terminals that are online and have a low network latency, the emails will be given a higher priority to ensure that these users can receive the notification in the first place. On the contrary, for terminals with a high network latency, the emails may be placed in a lower priority queue and wait to be delivered after the network condition improves. In this way, the distribution efficiency of the emails can be optimized, ensuring that the system can notify the users who need it most first and reducing the risk of information lag. When distributing the encrypted email payload to the corresponding user terminals according to the priority queue, the email system will first send the email to the terminals with better network conditions according to the sorting order in the priority queue. If multiple user terminals have the same priority, the sending order will be determined according to other factors (such as the priority setting in the registration information). Through the priority queue method, the email distribution not only ensures that the information can be quickly conveyed to the most important users, but also can reasonably schedule network resources to avoid delays or losses caused by excessive concurrent email sending.

[0041] After the email is sent, the receiving status code of the user terminal is captured based on the ACK verification mechanism. ACK (Acknowledgement) is the confirmation response from the receiver to the sender, indicating that the email has been successfully received. The receiving status code usually includes statuses such as successful reception, delayed reception, or failed reception. The system determines whether the email has been successfully received by detecting the ACK response. If a confirmation message is received, the email system considers that the email has been successfully delivered to the user terminal and the sending process can be completed. If the receiving status code is not received, it means that the email may not have been successfully delivered, possibly due to network failures, user terminal problems, or other reasons for the failure to receive successfully. In this case, the system will trigger a redirected encrypted tunnel for redundant delivery. An encrypted tunnel is a channel that uses encryption protection when transmitting data over a network. Through this tunnel, the email content can be transmitted again to ensure the security and integrity of the email. Redundant delivery refers to the re-attempt to send the email to the user terminal, usually when the original delivery fails. Through the encrypted tunnel, the email content remains encrypted when re-sent, ensuring the security of the information during transmission over the network. This process ensures that the email can reach the user terminal successfully after multiple attempts, avoiding the interruption of information transmission due to a single email delivery failure. Through this mechanism, the email system can improve the success rate of email delivery and ensure that critical notifications and feedback can be conveyed to users in a timely and reliable manner.

[0042] In an optional implementation manner of this embodiment, a state snapshot of the system under test after executing the feedback instruction is captured by a protocol proxy injector, and a set of system response data packets after correcting the protocol context state vector is obtained; a difference analysis is performed between the set of system response data packets and the protocol transaction templates in the historical normal baseline library to determine the behavior deviation degree vector; a feedback effect evaluation matrix is constructed based on the behavior deviation degree vector; the execution effectiveness score of each feedback instruction in the feedback effect evaluation matrix is determined through a fuzzy membership function; the dynamic update module of the knowledge graph is activated according to the execution effectiveness score, the node confidence weights in the abnormal event association graph are iteratively adjusted, and the node splitting threshold of the feedback policy tree is reconstructed through a policy decision tree model.

[0043] Specifically, in this embodiment, a protocol proxy injector is inserted into the system under test. The protocol proxy injector is responsible for inserting test instructions during the operation of the system and capturing the current state information of the system. The protocol proxy injector captures the state vector of the current protocol context by monitoring the protocol interaction process. After the feedback instruction is executed, the system response data packets will change. The proxy injector records these changes and extracts the set of corrected data packets. These data packets contain the system responses affected by the feedback instruction and reflect whether the feedback operation has successfully corrected the system state.

[0044] By performing a differential analysis on the set of these response data packets and the protocol transaction templates in the historical normal baseline library, the degree of deviation of the system behavior can be identified. The baseline library contains historical normal protocol transaction templates, which record the behavior patterns of the protocol under normal operation. By comparing the corrected system responses with the templates in the baseline library, it can be analyzed which fields or states have deviated, thereby generating a behavior deviation vector. The behavior deviation vector represents the difference between the system response and the normal mode, and can quantify whether the performance of the system after the feedback instruction meets the expectations.

[0045] Based on the behavior deviation vector, a feedback effect evaluation matrix can be constructed. The evaluation matrix quantifies the effects of various feedback instructions and compares their actual impacts on the system behavior. Each element in the evaluation matrix represents the effect score of a feedback instruction, reflecting the effectiveness of the instruction in correcting the system behavior. Through the fuzzy membership function, the evaluation matrix can be further processed. The membership function is usually used in fuzzy logic to represent the degree to which an event or data belongs to a specific category. Here, the membership function determines the execution effectiveness score of each feedback instruction according to the value of the behavior deviation vector. If the deviation is small, it indicates that the feedback instruction is effective and the membership is high; on the contrary, when the deviation is large, the effectiveness of the instruction is low and the membership is low.

[0046] According to the execution effectiveness score, the dynamic update module of the knowledge graph can be activated to iteratively adjust the confidence weight of the nodes in the abnormal event association graph. The knowledge graph contains information such as protocol vulnerabilities, network topologies, and historical fault cases. The confidence weight of a node represents the importance of the node in an abnormal event. Through the feedback effect evaluation, the weights of these nodes can be dynamically adjusted, so that important nodes get higher weights, reflecting their impact on system anomalies. As the feedback instructions are executed and the system behavior is adjusted, the knowledge graph will be gradually updated, thereby improving the accuracy of anomaly detection and fault location. Finally, the node splitting threshold of the feedback policy tree is reconstructed through the policy decision tree model. The policy decision tree model is used to determine the feedback measures to be taken under different conditions. The node splitting threshold in the tree indicates when to select different feedback paths. According to the evaluated feedback effectiveness score, the node splitting threshold of the policy tree is adjusted to ensure that more effective decisions can be made based on the new feedback information in subsequent abnormal events. This dynamic adjustment enables the system to continuously optimize the feedback policy and improve the effect and efficiency of fault repair.

[0047] An automatic feedback method based on protocol fuzz testing provided by the solution of this application obtains a dynamic configuration file for protocol fuzz testing; monitors the protocol fuzz testing in real time according to the protocol characteristic parameters of the dynamic configuration file, and determines the real-time data stream of the protocol fuzz testing; determines abnormal events existing in the protocol fuzz testing by performing multi-level feature analysis on the real-time data stream; generates a feedback instruction corresponding to the abnormal event by performing multi-dimensional correlation analysis based on a knowledge graph on the abnormal event; and sends an abnormal notification email to a user terminal according to the feedback instruction. Through the automatic email notification mechanism, it is ensured that testers can receive notifications immediately when the test task fails, reducing the workload of manual monitoring and improving the test efficiency.

[0048] Figure 2 An automatic feedback device based on protocol fuzz testing provided by an embodiment of this application can be used to implement the automatic feedback method based on protocol fuzz testing in the foregoing embodiment. As Figure 2 shown, the automatic feedback device based on protocol fuzz testing mainly includes: An acquisition module 10, configured to acquire a dynamic configuration file for protocol fuzz testing; A monitoring module 20, configured to monitor the protocol fuzz testing in real time according to the protocol characteristic parameters of the dynamic configuration file, and determine the real-time data stream of the protocol fuzz testing; A judgment module 30, configured to determine abnormal events existing in the protocol fuzz testing by performing multi-level feature analysis on the real-time data stream; A generation module 40, configured to generate a feedback instruction corresponding to the abnormal event by performing multi-dimensional correlation analysis based on a knowledge graph on the abnormal event; A sending module 50, configured to send an abnormal notification email to a user terminal according to the feedback instruction.

[0049] In an optional implementation manner of this embodiment, the acquisition module is specifically configured to: perform structured processing on a target protocol specification document through a protocol syntax parser to determine a protocol field set and a state transition rule set; construct a protocol syntax tree model according to the protocol field set, and generate a protocol state machine model in combination with the state transition rule set; perform topological mapping on a fuzz testing seed library through the protocol state machine model to determine the mutation priority coefficient of each protocol field; input the mutation priority coefficient into a constraint solver for dynamic parameter optimization to generate a multi-dimensional configuration file framework; and perform logical verification on the multi-dimensional configuration file framework based on the feedback results of a historical test data set to determine the dynamic configuration file for protocol fuzz testing.

[0050] In an alternative implementation of this embodiment, the monitoring module is specifically configured to: deconstruct the protocol feature parameters in the dynamic configuration file through a protocol syntax parser to determine the corresponding protocol syntax rule set; deploy a packet capture probe at the test agent node according to the protocol syntax rule set; and determine the real-time data stream for protocol fuzz testing by performing temporal stitching on the interactive packet stream intercepted by the packet capture probe.

[0051] In an alternative implementation of this embodiment, the judgment module is specifically configured to: decompose the real-time data stream into an orthogonal dimension data set; where the real-time orthogonal dimension data set includes a network traffic feature set, a protocol field mutation trajectory set, and a system response delay sequence set; perform a sliding window difference process on the network traffic feature set through a preset mutation detection threshold in the dynamic configuration file to generate an abnormal fluctuation index set; compare the deviation degree between the actual jump path and the specification-allowed path of the protocol field mutation trajectory set in real time based on the protocol state machine model to determine the protocol semantic anomaly probability; perform a temporal pattern analysis on the system response delay sequence set to generate an abnormal deviation coefficient; perform multi-dimensional evidence weighting on the abnormal fluctuation index set, the protocol semantic anomaly probability, and the abnormal deviation coefficient through a rule weight configuration table in the dynamic configuration file to generate a comprehensive anomaly score matrix; and determine abnormal events exceeding the abnormal determination threshold by performing interval division on the comprehensive anomaly score matrix according to the abnormal determination threshold in the dynamic configuration file.

[0052] In an alternative implementation of this embodiment, the generation module is specifically configured to: perform graph neural network matching on the abnormal events with protocol vulnerability nodes, network topology nodes, and historical fault case nodes in the knowledge graph to obtain an associated entity set; perform reverse path tracing on the associated entity set through the causal reasoning engine of the knowledge graph, and generate a causal path set based on the graph traversal algorithm; dynamically construct a feedback policy tree through a policy decision tree model based on the key node weight coefficients of the causal path set; input the feedback policy tree into the simulation test environment for instruction pre-verification, and generate a feedback instruction for the abnormal event according to the verification result.

[0053] In an alternative implementation of this embodiment, the sending module is specifically configured to: generate an initial email message through an email template engine according to the email notification level and the test parameter correction plan in the feedback instruction set; determine the encrypted email payload of the initial email message through security sandbox processing; determine the priority queue for email distribution according to the online status identifier and network delay parameters in the user terminal registration information; distribute the encrypted email payload to the corresponding user terminal according to the priority queue; capture the received status code of the user terminal based on the ACK verification mechanism; and if the received status code is not received, trigger a redirected encrypted tunnel for redundant delivery.

[0054] In an optional implementation manner of this embodiment, the automatic feedback device further includes: an update module. The update module is used to: capture a status snapshot of the system under test after executing the feedback instruction through a protocol proxy injector, and obtain a set of system response data packets with the protocol context state vector corrected; perform a difference analysis between the set of system response data packets and the protocol transaction templates in the historical normal baseline library to determine the behavior deviation vector; construct a feedback effect evaluation matrix based on the behavior deviation vector; determine the execution effectiveness scores of each feedback instruction in the feedback effect evaluation matrix through a fuzzy membership function; activate the dynamic update module of the knowledge graph according to the execution effectiveness scores, iteratively adjust the node confidence weights in the abnormal event association graph, and reconstruct the node splitting threshold of the feedback policy tree through a policy decision tree model.

[0055] An automatic feedback device based on protocol fuzz testing provided by the solution of this application obtains a dynamic configuration file of protocol fuzz testing; monitors protocol fuzz testing in real time according to the protocol characteristic parameters of the dynamic configuration file, and determines the real-time data stream of protocol fuzz testing; judges abnormal events existing in protocol fuzz testing by performing multi-level feature analysis on the real-time data stream; generates feedback instructions for corresponding abnormal events through multi-dimensional association analysis based on a knowledge graph for the abnormal events; and sends an abnormal notification email to the user terminal according to the feedback instructions. Through the automated email notification mechanism, it is ensured that testers can receive notifications immediately when the test task fails, reducing the workload of manual monitoring and improving the test efficiency.

[0056] Provided by the solution of this application Figure 3 An electronic device provided for an embodiment of this application. This electronic device can be used to implement the automatic feedback method based on protocol fuzz testing in the foregoing embodiments, and mainly includes: A memory 301, a processor 302, and a computer program 303 stored on the memory 301 and executable on the processor 302. The memory 301 and the processor 302 are communicatively connected. When the processor 302 executes the computer program 303, it implements the automatic feedback method based on protocol fuzz testing in the foregoing embodiments. Among them, the number of processors can be one or more.

[0057] The memory 301 can be a high-speed random access memory (RAM, Random Access Memory) or a non-volatile memory, such as a disk memory. The memory 301 is used to store executable program codes, and the processor 302 is coupled to the memory 301.

[0058] Further, the embodiments of the present application also provide a computer-readable storage medium, which can be disposed in the electronic devices in the above embodiments, and the computer-readable storage medium can be the memory in the Figure 3 embodiments shown above.

[0059] A computer program is stored on the computer-readable storage medium, and when the program is executed by a processor, it implements the automatic feedback method based on protocol fuzz testing in the foregoing embodiments. Further, the computer-readable storage medium can also be various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a RAM, a magnetic disk, or an optical disc.

[0060] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the systems, devices, and units described above can refer to the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0061] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in the embodiments of the present application. The foregoing storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disc.

[0062] The above is the description. The above embodiments are only used to illustrate the technical solutions of the present application and are not intended to limit them. Although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features. And these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present application.

Claims

1. An automatic feedback method based on protocol fuzz testing, characterized in that: include: Get the dynamic configuration file for protocol fuzz testing; Performing real-time monitoring of the protocol fuzz test according to the protocol characteristic parameters of the dynamic configuration file, and determining the real-time data flow of the protocol fuzz test; By performing multi-level feature analysis on the real-time data stream, determining abnormal events existing in the protocol fuzzy test; Generate feedback instructions corresponding to the abnormal events by performing multi-dimensional association analysis on the abnormal events based on the knowledge graph; Send an abnormality notification email to the user terminal according to the feedback instruction.

2. The automatic feedback method based on protocol fuzz testing according to claim 1 is characterized in that: The step of obtaining a dynamic configuration file for the protocol fuzz test includes: The target protocol specification document is structured by a protocol syntax parser to determine a protocol field set and a state transition rule set; Constructing a protocol syntax tree model according to the protocol field set, and generating a protocol state machine model in combination with the state transition rule set; The fuzzy test seed library is topologically mapped through the protocol state machine model to determine the mutation priority coefficient of each protocol field; Inputting the mutation priority coefficient into a constraint solver for dynamic parameter optimization to generate a multi-dimensional profile framework; Based on the feedback results of the historical test data set, the multi-dimensional configuration file framework is logically checked to determine the dynamic configuration file of the protocol fuzz test.

3. The automatic feedback method based on protocol fuzz testing according to claim 2 is characterized in that: The step of monitoring the protocol fuzzy test in real time according to the protocol characteristic parameters of the dynamic configuration file and determining the real-time data flow of the protocol fuzzy test includes: Deconstructing the protocol characteristic parameters in the dynamic configuration file through a protocol syntax parser to determine a corresponding set of protocol syntax rules; Deploy a message capture probe on the test agent node according to the protocol grammar rule set; The real-time data stream of the protocol fuzz test is determined by performing time-sequential splicing on the interactive message stream intercepted by the message capture probe.

4. The automatic feedback method based on protocol fuzz testing according to claim 2 is characterized in that: The step of determining abnormal events existing in the protocol fuzzy test by performing multi-level feature analysis on the real-time data stream comprises: Performing field structure verification on the tokenized message set in the real-time data stream through the protocol syntax tree parser, and generating a syntax exception token set according to the protocol syntax constraints in the dynamic configuration file; Based on the protocol state machine model, a finite state verification is performed on the protocol context state vector in the real-time data stream, a deviation between a state transition path and a preset rule set is detected, and a state abnormality trajectory set is generated; Performing hidden Markov model analysis on the field variation trajectory of the real-time data stream to determine the protocol semantic anomaly feature vector; Inputting the grammatical anomaly tag set and the state anomaly trajectory set into a multimodal fusion engine to construct an abnormal event association map; By performing pattern matching on the abnormal event association map and the protocol semantic abnormal feature vector, abnormal events existing in the protocol fuzzy test are determined.

5. The automatic feedback method based on protocol fuzz testing according to claim 1 is characterized in that: The step of generating a feedback instruction corresponding to the abnormal event by performing a multi-dimensional association analysis on the abnormal event based on a knowledge graph includes: Performing graph neural network matching on the abnormal event with the protocol vulnerability node, network topology node, and historical failure case node in the knowledge graph to obtain a set of associated entities; Performing reverse path tracing on the associated entity set through the causal reasoning engine of the knowledge graph, and generating a causal path set based on a graph traversal algorithm; Based on the weight coefficients of the key nodes of the causal path set, dynamically construct a feedback strategy tree through a strategy decision tree model; The feedback strategy tree is input into a simulation test environment for instruction pre-verification, and a feedback instruction for the abnormal event is generated according to the verification result.

6. The automatic feedback method based on protocol fuzz testing according to claim 1 is characterized in that: The step of sending an abnormality notification email to the user terminal according to the feedback instruction includes: Generate an initial email message through an email template engine according to the email notification level and the test parameter correction plan in the feedback instruction set; Determining the encrypted email payload of the initial email message through security sandbox processing; Determine the priority queue for email distribution based on the online status identifier and network delay parameters in the user terminal registration information; Distributing the encrypted email payload to corresponding user terminals according to priority queues; Capturing a receiving status code of the user terminal based on an ACK verification mechanism; If the receiving status code is not received, the redirection encrypted tunnel is triggered to perform redundant delivery.

7. The automatic feedback method based on protocol fuzz testing according to claim 5 is characterized in that: The method further comprises: The state snapshot of the system under test after executing the feedback instruction is captured by the protocol proxy injector to obtain a set of system response data packets after the protocol context state vector is corrected; Perform difference analysis on the system response data packet set and the protocol transaction template in the historical normal baseline library to determine the behavior deviation vector; Constructing a feedback effect evaluation matrix based on the behavior deviation vector; Determining the execution effectiveness score of each feedback instruction in the feedback effect evaluation matrix through a fuzzy membership function; The dynamic update module of the knowledge graph is activated according to the execution effectiveness score, the node confidence weights in the abnormal event association graph are iteratively adjusted, and the node splitting threshold of the feedback strategy tree is reconstructed through the strategy decision tree model.

8. An automatic feedback device based on protocol fuzzy testing, characterized in that: The automatic feedback device based on protocol fuzzy testing includes: An acquisition module is used to obtain a dynamic configuration file for protocol fuzz testing; A monitoring module, used for real-time monitoring of the protocol fuzzy test according to the protocol characteristic parameters of the dynamic configuration file, and determining the real-time data flow of the protocol fuzzy test; A judgment module, used to judge abnormal events existing in the protocol fuzzy test by performing multi-level feature analysis on the real-time data stream; A generation module, configured to generate a feedback instruction corresponding to the abnormal event by performing a multi-dimensional association analysis on the abnormal event based on a knowledge graph; The sending module is used to send an abnormality notification email to the user terminal according to the feedback instruction.

9. An electronic device, characterized in that: The device comprises a memory and a processor, wherein: The processor is used to execute the computer program stored in the memory; When the processor executes the computer program, the steps of the automatic feedback method based on protocol fuzz testing described in any one of claims 1 to 7 are implemented.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps in the automatic feedback method based on protocol fuzz testing described in any one of claims 1 to 7 are implemented.

Citation Information

Cited By

  • Detection method fusing depth feature extraction and attack recognition

    CN120455178A

  • Internet of Things protocol analysis method and device based on multi-mode AI and medium

    CN120512486A

  • IoT protocol analysis method, equipment and media based on multimodal AI

    CN120512486B

  • Automatic use case construction method and system for private protocol test

    CN120785656A

  • Function test method and device for Internet of Things platform, and medium

    CN121357051A