Protocol logic vulnerability mining method based on program multi-dimensional variation

By conducting content-level and sequence-level multi-dimensional variation testing on the protocol, combined with RFC standard state machine insertion monitoring, and automated detection of protocol vulnerabilities, the problems of single variation dimension, insufficient effectiveness and low degree of automation in the existing technology are solved, and efficient protocol vulnerability detection is achieved.

CN120301655APending Publication Date: 2025-07-11SOUTHEAST UNIV
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510471959.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-15
Publication Date
2025-07-11

AI Technical Summary

Technical Problem

The existing protocol testing methods are single in the mutation dimension, insufficient mutation effectiveness, and low degree of automation, making it difficult to effectively detect vulnerabilities in the protocol implementation.

Method used

By conducting multi-dimensional variation testing at content-level and sequence-level configuration, combining protocol state machine instrumentation monitoring and consistency testing defined by the RFC standard, we automatically detect protocol vulnerabilities.

Benefits of technology

It significantly improves the effectiveness and automation of protocol vulnerability detection, can cover a wider range of vulnerability types, reduces labor costs, and the generated exception packets can go deep into the protocol logic processing stage and discover inconsistent behaviors in multiple protocol implementations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120301655A_ABST
    Figure CN120301655A_ABST
Patent Text Reader

Abstract

The invention discloses a protocol logic vulnerability mining method based on program multi-dimensional variation. The method comprises the following steps: firstly, based on an RFC protocol standard, automatically positioning a buffer write function responsible for writing a message and a state variable used for identifying a protocol state in a program; then, multi-dimensional variation is carried out, including content level variation (field replacement, field multiplexing and field deletion) and sequence level variation (message repetition and message skipping), and a variation message with legal grammar and abnormal semantics is generated; and finally, monitoring state variables of a protocol state machine and an instrumentation program defined based on the RFC standard, detecting the difference of behaviors of a plurality of protocol implementation state machines under the same variation input by using a consistency test method, automatically discovering violation of protocol implementation on the RFC standard, and classifying the violation into logic vulnerabilities. According to the method, typical vulnerabilities such as degradation attacks, repeated extension and missing extension in cryptographic protocol implementation can be automatically mined, and 49 logic problems are found in multiple protocol implementation.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of network security and protocol testing, and specifically relates to a protocol logic vulnerability mining method based on program multi-dimensional variation, and is particularly suitable for automatic vulnerability detection in the implementation of cryptographic protocols such as TLS. Background Art

[0002] Vulnerability detection in protocol implementations (such as TLS) faces the following challenges:

[0003] (1) Single mutation dimension: Existing protocol testing methods usually only mutate the content of protocol messages, ignoring the vulnerabilities that may be caused by abnormal message sequences. For example, sequence anomalies such as repeated message sending or message skipping may lead to problems such as identity authentication bypass, but traditional testing methods are difficult to cover these scenarios.

[0004] (2) Insufficient mutation effectiveness: Existing methods often modify message fields through simple random or extreme mutation methods, which can easily destroy the message syntax structure and cause the message to be directly discarded by the receiver. As a result, it is impossible to go deep into the semantic processing flow of the protocol and it is difficult to trigger deep-level vulnerabilities in the protocol.

[0005] (3) Low degree of automation: Existing protocol vulnerability detection methods usually rely on manual definition of test cases and detection rules based on RFC protocol standards, which requires a lot of manual intervention, has low efficiency and high maintenance costs, and is difficult to automatically adapt when the protocol is updated or there are large differences between different implementations.

[0006] Therefore, there is an urgent need for an automated protocol vulnerability mining method that can support multi-dimensional variations of message content and message sequences, has a high degree of automation, and does not require a lot of human intervention, so as to improve the efficiency and accuracy of vulnerability detection in protocol implementation. Summary of the invention

[0007] The purpose of the present invention is to propose a protocol logic vulnerability mining method based on program multi-dimensional mutation in view of the above-mentioned problems in the prior art. The present invention automatically performs content-level and sequence-level multi-dimensional mutation tests on the protocol implementation, combines the protocol state machine plugging monitoring and consistency test analysis based on the RFC standard definition, and automatically detects and discovers vulnerabilities in the protocol implementation, significantly improving the effectiveness and automation of protocol vulnerability detection.

[0008] To achieve the above purpose, the technical solution proposed by the present invention is as follows: a method for mining protocol logic vulnerabilities based on program multi-dimensional variation, comprising the following steps:

[0009] Step 1: Protocol analysis phase:

[0010] Based on the RFC protocol standard, automatically locate the buffer write function responsible for writing messages in the protocol implementation, as well as the status variables used to identify protocol state transitions;

[0011] Step 2, Multi-dimensional Mutation Stage:

[0012] Perform content-level mutation and sequence-level mutation on the protocol message. Content-level mutation includes field replacement, field reuse, and field deletion. Sequence-level mutation includes message repetition and message skipping, generating protocol messages that are syntactically legal but semantically abnormal;

[0013] Step 3, Consistency Testing Stage:

[0014] Based on the protocol state machine defined by the RFC standard, instrument and monitor the status variables of multiple protocol implementations to automatically extract and unify the protocol implementation state machine model, and detect the inconsistencies in the behavior of different protocol implementation state machines under the same mutation input through consistency testing, thereby automatically discovering protocol logic vulnerabilities that violate the RFC specification.

[0015] Furthermore, the content-level mutation in Step 2 specifically includes:

[0016] Field Replacement Strategy: Based on the legal field value range defined by the RFC, replace the value of a field in the message with another legal but semantically contradictory value to the protocol context to trigger protocol logic errors;

[0017] Field Reuse Strategy: Replace the value of a field in the message with the value of another field in the same message or a different message to generate a message with logical anomalies;

[0018] Field Deletion Strategy: Remove a certain key field from the message and adjust the message length field to ensure the syntactic legality of the message.

[0019] Furthermore, the sequence-level mutation in Step 2 specifically includes:

[0020] Message Repetition Strategy: Repeatedly send a specific message in the protocol sequence to disrupt the normal flow of the protocol state machine to test the robustness of the implementation to abnormal sequences;

[0021] Message Skipping Strategy: Skip a specific message in the protocol sequence to cause an unexpected transition of the protocol state and test the handling of the implementation for the absence of key messages.

[0022] Furthermore, the consistency testing in Step 3 specifically includes:

[0023] Instrument and monitor the status variables in the protocol implementation, and automatically extract and construct the state machine model of the protocol implementation;

[0024] Align the state machines extracted from different protocol implementations to the standard state machine defined by RFC to achieve the unity of cross - protocol implementation states; perform consistency test analysis on the unified state machine to detect and report implementation behaviors that violate RFC specifications.

[0025] Among them, aligning the state machines of different protocol implementations to the state machine defined by the RFC standard is as follows:

[0026] Automatically extract the standard state machine according to the handshake process and state transition sequence defined in the RFC protocol standard;

[0027] Align the states of the state machines extracted from different protocol implementations and uniformly map them to the corresponding states of the standard state machine;

[0028] Based on the unified state machine, perform subsequent consistency comparison analysis.

[0029] Furthermore, the method is applied to vulnerability mining of TLS protocol implementation, and the vulnerability types include downgrade attack, duplicate extension attack, and missing extension attack.

[0030] An electronic device includes a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, it implements the protocol logic vulnerability mining method based on program multi - dimensional mutation.

[0031] A computer - readable storage medium stores computer instructions, and when the computer instructions are executed by a processor, they implement the protocol logic vulnerability mining method based on program multi - dimensional mutation.

[0032] Compared with the prior art, the present invention has the following beneficial effects:

[0033] (1) High degree of automation: The method of the present invention automatically locates buffer write functions and state variables by automatically analyzing protocol implementation code, and can automatically perform multi - dimensional mutation of the protocol and extract the state machine without the need to manually define a large number of rules, greatly reducing the labor cost;

[0034] (2) Multi - dimensional mutation strategy: The present invention not only focuses on the mutation of protocol message field content, but also on the abnormal mutation of message sequences, covering a more comprehensive range of vulnerability types, such as protocol downgrade attack, message duplicate extension attack, key message missing attack, etc.; (3) Syntactically legal mutated messages: The mutation operation of the present invention is within the RFC legal range through semantic constraints, enabling the generated abnormal messages to be accepted by the protocol implementation and further processed at the protocol logic stage, significantly enhancing the ability to trigger protocol implementation vulnerabilities.

[0035] (4) Cross-implementation Consistency Detection: The method of the present invention automatically detects inconsistent behaviors between multiple protocol implementations through instrumentation and consistency testing based on the RFC standard protocol state machine, and can effectively discover vulnerabilities that are difficult to reach by existing methods. BRIEF DESCRIPTION OF THE DRAWINGS

[0036] Figure 1 It is an architecture diagram of the logic vulnerability mining framework of the present invention.

[0037] Figure 2 It is a schematic diagram of the test process;

[0038] Figure 3 It is the implementation of the multi-dimensional mutation algorithm;

[0039] Figure 4 It is a schematic diagram of the state machine alignment process. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0040] To deepen the understanding of the present invention, the following will give a detailed description of this embodiment with reference to the accompanying drawings. Refer to Figure 1 , the present invention provides a protocol logic vulnerability mining method based on program multi-dimensional mutation, and the implementation process includes the following three stages:

[0041] 1. Protocol Analysis Stage:

[0042] Automatically analyze the source code of the protocol client program according to the RFC standard document of the protocol, and extract key functions and state variables; 2. Multi-dimensional Mutation Stage:

[0043] Implement content mutation and sequence mutation in the client program to generate protocol messages that are syntactically legal but semantically abnormal;

[0044] 3. Consistency Testing Stage:

[0045] Based on the protocol state machine defined by RFC, instrument and monitor the state variables of the server, automatically extract the state machine, and use consistency testing to detect the differences in the behaviors of different server state machines to discover logical vulnerabilities in the protocol implementation.

[0046] Taking the TLS protocol test as an example, the specific implementation processes of the above three stages will be described in detail:

[0047] (1) Protocol Analysis Stage:

[0048] The goal of this stage is to automatically locate the key functions in the TLS protocol client for generating protocol messages, and the state variables for representing the protocol state. The specific implementation steps include:

[0049] (1) Key Function Location:

[0050] According to the RFC standard document, automatically extract the names and integer enumeration values of the extension fields that must exist in the TLS protocol, as shown in Table 1. Use string and parameter matching methods to confirm the buffer write function in the function for constructing the extension field of the message, for subsequent content-level mutation.

[0051]

[0052] Table 1 Some Extensions Defined in TLS RFC

[0053] For example, for the matching of the supported_groups(10) extension in OpenSSL, in the tls_construct_supported_groups function, the WPACKET_put function with the parameter 10 was matched and confirmed as the buffer write function. At the same time, other extensions can be used for verification.

[0054] (2) Status Variable Location:

[0055] Protocols usually use enumeration variables to identify protocol states, such as the hand_state variable in OpenSSL. Automatically identify the protocol state enumeration variables at the source code level through the following three heuristic rules:

[0056] The status enumeration variable is a global variable;

[0057] Protocols usually use switch...case... statements to control state transitions, and the status enumeration variable will exist in the switch...case... statements;

[0058] The status enumeration variable in the switch...case... statement will be read and stored because it needs to be read and written during the protocol state transition.

[0059] Finally, the status variables used to control the protocol state transition are automatically identified, as shown in Table 2.

[0060]

[0061]

[0062] Table 2 Automatic Location of Status Variables for Six Targets, and the Protocol Status Variables Can All Be Successfully Located

[0063] (2) Multidimensional Mutation Stage:

[0064] The goal of this stage is to generate syntactically legal but semantically abnormal protocol messages by implementing content mutation and sequence mutation on the protocol client program. The specific implementation steps include:

[0065] (1) Content - level mutation:

[0066] Field replacement strategy (Replace):

[0067] Insert mutation code at the parameter of the buffer write function, automatically extract the legal value range using the RFC document (such as the supported_versions extension in TLS), and replace the field value with a value allowed by another protocol but with a contradictory context semantics;

[0068] For example: Replace the supported_versions field in TLS 1.3 from 0x0304 (TLS 1.3) to 0x0303 (TLS 1.2) to simulate a downgrade attack.

[0069] Field reuse strategy (Reuse):

[0070] Insert mutation code at the parameter of the buffer write function, and replace the data of one field with the data of another existing field;

[0071] For example: When constructing a ClientHello message, copy the value of the extension field signature_algorithms to the value of the extension field key_share, thus triggering a logical vulnerability of duplicate extension fields.

[0072] Field deletion strategy (Remove):

[0073] During the execution of the buffer write function, delete the data of a certain key field, and automatically repair the corresponding message length field to keep the message syntax legal;

[0074] For example: Remove the signature data from the client's CertificateVerify message to test the server's handling ability for missing authentication information.

[0075] (2) Sequence - level mutation:

[0076] Message repetition strategy (Repeat):

[0077] Insert code in the switch - case structure of the protocol client state machine to mutate the status variable to other values, so that a specific message status is executed multiple times;

[0078] For example: Repeatedly send the Finished message in the TLS protocol to test the server's handling mechanism for repeated messages.

[0079] Message skip strategy (Remove):

[0080] In the switch-case structure of the protocol client state machine, insert code to mutate the current value, causing the state machine of the protocol client to skip specific states, resulting in the corresponding messages not being sent;

[0081] For example: Skip the Certificate message sending state in the TLS handshake and observe the server's handling mechanism for the missing certificate.

[0082] Through the above two mutation dimensions (content and sequence), a wider range of protocol vulnerability scenarios can be effectively covered. The algorithm implementation is as Figure 3 shown.

[0083] (3) Consistency testing phase:

[0084] The goal of this phase is to automatically extract the protocol state machine and perform consistency analysis by instrumenting and monitoring the state variables of the server based on the state machine defined by the RFC standard. The specific implementation steps include:

[0085] (1) Instrumentation and monitoring of state variables:

[0086] Insert lightweight instrumentation code at the position where the state variables of the server are assigned values. Whenever the state variables change, record the current state value and state name in the log file;

[0087] For example: The hand_state variable of the OpenSSL server is monitored, and a log is recorded each time the state changes.

[0088] (2) Automatic extraction and alignment of state machines:

[0089] Automatically construct the state machine of each server according to the state logs recorded by the monitoring;

[0090] According to the standard state machine defined by the RFC, perform unified mapping and alignment on the state machines of different implementations, so that the state transitions of different implementation state machines are comparable;

[0091] For example: The state machines of OpenSSL and wolfSSL are both mapped to the TLS standard handshake process state machine defined by the RFC, facilitating the analysis of differences between cross-implementation state machines, as Figure 4 shown.

[0092] (3) Consistency difference detection:

[0093] Send the same mutated client messages to each protocol server under test respectively, and obtain the corresponding state transition sequences of each server;

[0094] Compare the server - side state transition sequence step - by - step on the RFC standard state machine. If the state sequence of a certain server is inconsistent with other implementation state sequences or does not conform to the RFC definition, it is determined that a vulnerability in the protocol implementation is found;

[0095] For the discovered inconsistent situations, trace back to the specific mutation points and strategies that triggered them, and automatically generate a vulnerability report.

[0096] The RFC coverage rate is a key indicator to measure the completeness of the coverage of the semantic rules of the protocol specification by test cases. Since the essence of logical vulnerabilities is that the protocol implementation deviates from the semantic constraints defined in the RFC, the RFC coverage rate can effectively show whether the automated logical mutation can still maintain the efficiency of logical vulnerability mining. The present invention extracts two types of explicit and implicit constraint rules from two important RFC documents of the TLS1.2 and 1.3 TLS protocols.

[0097] Explicit rules refer to the mandatory rules explicitly declared in the RFC document using normative terms (such as MUST / SHALL / REQUIRED or MUST NOT / SHALL NOT). Such rules directly constrain the behavior of the protocol implementation and constitute the core target of logical vulnerability detection. Finally, there are 136 explicit rules in TLS1.2 and 328 in TLS1.3, a total of 464; Implicit rules refer to the necessary constraints derived through the protocol state machine and error - handling logic without using term markers, a total of 73.

[0098] To reasonably quantify the RFC coverage rate, this article maps the test cases generated by each mutation to the above two types and calculates the coverage rate using the following formula. The experimental results are shown in Table 3.

[0099] RFC coverage rate = Triggered {explicit}{implicit} rules / Total {explicit}{implicit} rules × 100%

[0100]

[0101] Table 3 RFC coverage rate

[0102] Through consistency testing, this article identified 49 problems in a total of six TLS protocol implementations. The distribution of RFC rule violations is as Figure 4 . This invention of this article reports the discovered problems to relevant developers.

[0103] RFC 8446 (TLS 1.3) 5246 (TLS 1.2) Violation quantity 27 19

[0104] Table 4 Distribution of RFC rule violations

[0105] This invention lists three types of discovered vulnerabilities for explanation:

[0106] Server degradation. When the MbedTLS server is configured to force the use of TLS 1.3, the client can still successfully establish a connection by sending a TLS 1.2 ClientHello. At this time, an attacker can use a weak cipher suite of TLS 1.2 (such as TLS_RSA_WITH_AES_128_CBC_SHA) to implement the LUCKY13 attack to decrypt data, causing a man-in-the-middle attack. To fix this problem, the server should implement cross-verification of the legacy_session_id and supported_versions fields. If an error occurs, return the corresponding alert message and abort the handshake.

[0107] Duplicate extensions. RFC 5246 clearly states that There MUST NOT be more than one extension of the same type, but neither GnuTLS, MatrixSSL, nor MbedTLS follow this rule. Among them, MatrixSSL and MbedTLS can even duplicate any extension, and the peer will still continue to establish a connection. Duplicate extensions may lead to the accumulation of unreleased memory blocks, eventually causing the service to crash. CVE-2022-42905

[15] is a vulnerability caused by duplicate extensions. A malicious client sends a ClientHello message carrying 12 key_share extensions, causing a stack overflow in the wolfSSL server. To fix this problem, the implementation should traverse all extensions and check the uniqueness of types when parsing ClientHello and ServerHello.

[0108] Missing Extension. RFC 8446 clearly states that If client has not sent a "signature_algorithms" extension, then the server MUST abort the handshake with a "missing_extension" alert, while the servers of wolfSSL, MatrixSSL, and LibreSSL all allow the connection to be established. Although this attack is unlikely to cause a fatal error, it still violates the mandatory specification. In wolfSSL, it checks whether the client has sent the signature_algorithms extension through TLSX_Find(ssl->extensions, TLSX_SIGNATURE_ALGORITHMS). Since TLSX_PopulateExtensions unconditionally sets signature_algorithms, the extension TLSX_SIGNATURE_ALGORITHMS always exists in ssl->extensions even if the client has not sent it. The fix is shown in the following code: Instead of checking ssl->extensions, it determines whether the client has sent the signature_algorithms extension by checking whether args->clSuites->hashSigAlgoSz is 0. args->clSuites->hashSigAlgoSz represents the size of the list of signature algorithms supported by the client. If this value is 0, it means the client has not sent

[0109] the signature_algorithms extension, thus preventing the problem from occurring.

[0110]

[0111] It should be noted that the above embodiments are not intended to limit the protection scope of the present invention. Any equivalent transformation or substitution made on the basis of the above technical solutions falls within the protection scope of the claims of the present invention.

Claims

1. A method for mining protocol logic vulnerabilities based on multi-dimensional mutation of programs, characterized in that, The method includes the following steps: Step 1, program analysis phase: Based on the RFC protocol standard, automatically locate the buffer write function in the program responsible for writing messages and the status variables used to identify the protocol state; Step 2, multi-dimensional mutation phase: Perform content-level mutation and sequence-level mutation on the protocol message. Among them, content-level mutation includes field replacement, field reuse, and field deletion, and sequence-level mutation includes message repetition and message skipping to generate protocol messages that are syntactically legal but semantically abnormal; Step 3, consistency testing phase: Based on the protocol state machine defined by the RFC standard, monitor the protocol implementation state machine by instrumenting the program status variables, use the consistency testing method to detect the differences in the behaviors of multiple protocol implementation state machines under the same mutation input, and automatically discover violations of the RFC specification by the protocol implementation.

2. The method for mining protocol logic vulnerabilities based on program multi-dimensional mutation according to claim 1, characterized in that Step 1 is specifically as follows: 1-1. Based on the RFC protocol standard, automatically analyze the protocol implementation source code, and identify the function responsible for writing data to the message buffer as the buffer write function; 1-2. Through static analysis of the program source code, automatically identify the status variables used to identify the state changes in the protocol handshake process.

3. The protocol logic vulnerability mining method based on program multi-dimensional mutation according to claim 1, characterized in that The content-level mutation in Step 2 is specifically as follows: 2-1. Field replacement strategy: Based on the legal field value range defined by the RFC, replace the value of a field in the message with another legal but semantically contradictory value in the protocol context; 2-2. Field reuse strategy: Replace the value of a field in the message with the value of another field in the same message or a different message to generate a message with semantic anomalies; 2-3. Field deletion strategy: Remove a certain key field in the message and adjust the message length field to ensure the syntactic legality of the message.

4. The method for mining protocol logic vulnerabilities based on program multi-dimensional mutation according to claim 1, characterized in that, The sequence-level mutation in Step 2 is specifically as follows: 2-4. Message repetition strategy: Repeatedly send a specific message in the protocol sequence to disrupt the normal flow of the protocol state machine; 2-5. Message skipping strategy: Skip a specific message in the protocol sequence to cause an unexpected transition of the protocol state.

5. The method for mining protocol logic vulnerabilities based on program multi-dimensional mutation according to claim 1, wherein Step 3 is specifically as follows: 3-1. Based on the state machine defined by the RFC standard, instrument and monitor the status variables in the program, and automatically extract the state machine of the protocol implementation; 3-2. Unify the state machines of different protocol implementations to the state machine defined by the RFC standard for easy state comparison in consistency testing; 3-3. Perform consistency testing on the unified state machine, and identify and report the protocol implementation behaviors that violate the RFC specification.

6. The method for mining protocol logic vulnerabilities based on program multi-dimensional mutation according to claim 5, wherein Step 3-2 is specifically as follows: 3-2-1. According to the handshake process and state transition sequence defined in the RFC protocol standard, automatically extract the standard state machine; 3-2-2. Align the states of the state machines extracted from different protocol implementations and uniformly map them to the corresponding states of the standard state machine; 3-2-3. Based on the unified state machine, perform subsequent consistency comparison and analysis.

7. The method for mining protocol logic vulnerabilities based on program multi-dimensional mutation according to claim 1, wherein The method is applied to vulnerability mining of TLS protocol implementation, and the vulnerability types include downgrade attack, duplicate extension attack, and missing extension attack.

8. An electronic device, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, wherein: When the processor executes the program, it implements the protocol logic vulnerability mining method based on program multi-dimensional mutation as described in any one of claims 1 to 7 above.

9. A computer-readable storage medium having computer instructions stored thereon, characterized in that: When the computer instructions are executed by a processor, the method for mining protocol logic vulnerabilities based on program multi-dimensional mutation as described in any one of claims 1 to 7 is implemented.

Citation Information

Cited By

  • Visual mining and analyzing system for network vulnerabilities

    CN121530758A