Fuzzy test method, system and equipment for unknown protocol of industrial Internet of Things and medium

By constructing a tree characterization structure and information theory measurement method in a virtual environment, identifying unknown protocol field types and generating fuzzy test data, the problem of inefficient testing of unknown protocols in the existing technology is solved, and efficient IoT protocol security detection is achieved.

CN120528835APending Publication Date: 2025-08-22CHINA ELECTRIC POWER RESEARCH INSTITUTE CO LTD
View PDF 9 Cites 0 Cited by

Patent Information

Application Number
CN202510657955.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-21
Publication Date
2025-08-22

AI Technical Summary

Technical Problem

The existing industrial IoT protocol fuzz testing methods cannot effectively identify unknown protocols, rely on documents or expert knowledge, resulting in inefficient testing and low accuracy.

Method used

By obtaining the protocol stack execution process log in a virtual environment, building a tree characterization structure, identifying field types using information theory measurement methods, and generating fuzzy test data based on the field types, efficient testing of unknown protocols is achieved.

Benefits of technology

It does not rely on protocol documents and expert knowledge, and can accurately identify unknown protocol fields and types, implement efficient fuzz testing, and discover security vulnerabilities in IoT devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120528835A_ABST
    Figure CN120528835A_ABST
Patent Text Reader

Abstract

The invention belongs to the field of network space security, and discloses an industrial Internet of Things unknown protocol fuzzy test method, system, device and medium, and the method comprises the steps: obtaining an execution process log of unknown protocol data in a protocol stack based on a virtual environment; according to the execution process log, establishing a tree representation structure of each bit of the unknown protocol data; obtaining the similarity of the tree representation structures of the adjacent bits, and obtaining each field of the unknown protocol data according to the similarity of the tree representation structures of the adjacent bits; obtaining the field type of each field of the unknown protocol data through an information theory measurement method; and according to a preset variation rule of the field type, generating fuzzy test data of each field of the unknown protocol data, and according to the fuzzy test data, performing a fuzzy test of the industrial Internet of Things unknown protocol. The method does not depend on industrial Internet of Things protocol documents and expert priori knowledge, efficient fuzzy testing can be carried out on unknown Internet of Things protocols, security detection is carried out on the unknown Internet of Things protocols, and security vulnerabilities in Internet of Things equipment are found.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of cyberspace security and relates to a method, system, equipment and medium for fuzzy testing of unknown protocols in the industrial Internet of Things. Background Art

[0002] The Industrial Internet of Things (IIoT) industry often uses proprietary, undisclosed network communication protocols. These protocols are typically modified from traditional network communication protocols to facilitate intercommunication between specific IIoT systems. To ensure secure and stable communication within IIoT systems, ensuring the robustness and security of the IIoT communication protocols used is crucial. Fuzz testing is an important vulnerability detection technique and is widely used in software testing. Fuzz testing primarily generates test samples based on specific rules and automatically sends these test samples to the target to induce anomalies. Fuzz testing can also be applied to IIoT protocol security testing for vulnerability detection.

[0003] Currently, there are three main methods for fuzz testing of industrial Internet of Things protocols. (1) Obtain the description document of the industrial Internet of Things protocol in advance to know the specific format of the protocol, and set different mutation rules for different fields in the protocol to achieve mutation of protocol data and generation of test samples. (2) In the absence of industrial Internet of Things protocol documents, use the fingerprint matching information and network protocol matching rule information of existing network protocols to identify the fields in the Internet of Things protocol, and generate fuzzy test samples based on the identification results. (3) In the absence of industrial Internet of Things protocol documents, use tools such as Wireshark to capture network communication traffic in real time, and use methods such as keyword clustering to identify field boundaries in protocol messages, so as to select candidate keywords, mutate them, and generate fuzzy test samples.

[0004] However, the first existing method mentioned above relies on the industrial Internet of Things protocol documentation and cannot perform fuzz testing on unknown industrial Internet of Things protocols; the second existing method requires the prior knowledge of experts, and the effect of fuzz testing is highly dependent on the expert's technical level and is unstable; although the third existing method does not rely on the industrial Internet of Things protocol documentation and the expert's prior knowledge, the accuracy of field boundary recognition for unknown industrial Internet of Things protocols is not high, which will generate a large number of invalid test cases and low testing efficiency. Summary of the Invention

[0005] The purpose of the present invention is to overcome the shortcomings of the above-mentioned prior art and provide an industrial Internet of Things unknown protocol fuzzy testing method, system, equipment and medium.

[0006] In order to achieve the above object, the present invention adopts the following technical solutions:

[0007] In a first aspect, the present invention provides a fuzzy testing method for an unknown protocol of an industrial Internet of Things, comprising: obtaining an execution process log of unknown protocol data in a protocol stack based on a virtual environment; establishing a tree representation structure for each bit of the unknown protocol data according to the execution process log; obtaining and obtaining each field of the unknown protocol data based on the similarity of the tree representation structures of adjacent bits; obtaining the field type of each field of the unknown protocol data through an information theory measurement method; generating fuzzy test data for each field of the unknown protocol data according to a mutation rule preset for the field type, and performing fuzzy testing of the unknown protocol of the industrial Internet of Things based on the fuzzy test data.

[0008] Optionally, the method of obtaining an execution process log of unknown protocol data in a protocol stack based on a virtual environment includes: constructing a virtual environment for running a protocol stack and running an unknown protocol of the industrial Internet of Things, and using a plug-in technology to plug all CPU instructions of a virtual machine in the virtual environment, and recording the name of the instruction and the addresses of all operands for all instructions involving memory operations to obtain a protocol stack execution process log; obtaining an initial storage address of the unknown protocol data flowing into the protocol stack, and searching for a log entry with the initial storage address as a source operand in the protocol stack execution process log, and recursively finding all log entries related to the unknown protocol data flowing into the protocol stack based on the destination operand address recorded in the found log entry to obtain an execution process log of the unknown protocol data in the protocol stack.

[0009] Optionally, the method of establishing a tree representation structure for each bit of the unknown protocol data based on the execution process log includes: obtaining the initial storage address of the unknown protocol data flowing into the protocol stack, and constructing the root node of the tree based on the initial storage address of the unknown protocol data flowing into the protocol stack; traversing each log entry of the execution process log, and when the source operand address in the current log entry is equal to the value of an existing node in the tree, creating a new node and setting the value of the new node to the destination operand address in the log entry, and establishing a branch between the new node and the node with the equal value; after the traversal is completed, a tree representation structure for each bit of the unknown protocol data is obtained.

[0010] Optionally, the obtaining and obtaining of each field of the unknown protocol data based on the similarity of the tree representation structures of adjacent bits includes: using a branch sequence alignment algorithm to obtain the number of branches that can be aligned between the tree representation structures of adjacent bits as a first number, and obtaining the ratio of the first number to the total number of branches of the tree representation structures of adjacent bits to obtain the similarity of the tree representation structures of adjacent bits; obtaining each field of the unknown protocol data according to the following judgment rule: when the similarity of the tree representation structures of adjacent bits is less than a preset similarity threshold, it is determined that the adjacent bits do not belong to the same field; otherwise, it is determined that the adjacent bits belong to the same field.

[0011] Optionally, the method of obtaining the field type of each field of the unknown protocol data by the information theory measurement method includes: traversing each field of the unknown protocol data: when the field value of the current field has a linear relationship with the total data length of the unknown protocol data, determining that the field type of the current field is a total data length field; when the field value of the current field has a linear relationship with the length of the next field of the unknown protocol data, determining that the field type of the current field is a next field length field; when the field value of the current field takes a value within a limited range, determining that the field type of the current field is a function code field; when the field value of the current field is a constant in each unknown protocol data of the same function code, determining that the field type of the current field is a flag field; wherein the function code is the field value of the function code field; when the field values ​​of the current fields of different unknown protocol data after sorting the unknown protocol data in the order of flowing into the protocol stack show an increasing trend and the difference between the information entropy of the field value change value and 0 meets a preset difference threshold, determining that the field type of the current field is a serial number field; when the data of the current field are all numbers, determining that the field type of the current field is a limited change field; and determining the field type of the unrecognized field as a random change field.

[0012] Optionally, the field value of the current field is taken within a limited range: the randomness w(V) of the field value V of the current field is between 0.2 and 0.8:

[0013]

[0014] Among them, H(V) is the field value information entropy of the current field; |V| is the number of field values ​​of the current field.

[0015] The field value of the current field is a constant in each unknown protocol data of the same function code. Specifically, the field value information entropy of the field value of the current field in each unknown protocol data of the same function code is 0.

[0016] Optionally, the mutation rules preset for the field type include: when the field type is a total data length field, when generating fuzzy test data, the field value is set to the total length of the fuzzy test data; when the field type is a next field length field, when generating fuzzy test data, the field value is set to the length of the next field adjacent to the current field; when the field type is a function code field, when generating fuzzy test data, the field value is set to the corresponding function code preset according to the function of the fuzzy test data; when the field type is a flag field, when generating fuzzy test data, the field value is set to any one of the field values ​​of all preset flag fields; when the field type is a serial number field, when generating multiple fuzzy test data, the field value of each fuzzy test data is set to an increasing σ relationship; wherein σ is the field value change value of the preset serial number field; when the field type is a finite change field, when generating fuzzy test data, the field value is set to any value between the field maximum value and the field minimum value of the preset finite change field; when the field type is a random change field, when generating fuzzy test data, the field value is set to a random value.

[0017] According to a second aspect of the present invention, a fuzzy testing system for unknown protocols in an industrial Internet of Things is provided, comprising: a log module for obtaining an execution process log of unknown protocol data in a protocol stack based on a virtual environment; a tree construction module for establishing a tree representation structure of each bit of the unknown protocol data according to the execution process log; a field boundary module for obtaining and obtaining each field of the unknown protocol data based on the similarity of the tree representation structures of adjacent bits; a field identification module for obtaining the field type of each field of the unknown protocol data through an information theory measurement method; a testing module for generating fuzzy test data for each field of the unknown protocol data according to a mutation rule preset for the field type, and performing fuzzy testing of the unknown protocol of the industrial Internet of Things based on the fuzzy test data.

[0018] In a third aspect of the present invention, a computer device is provided, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the steps of the above-mentioned industrial Internet of Things unknown protocol fuzz testing method are implemented.

[0019] In a fourth aspect, the present invention provides a computer-readable storage medium storing a computer program. When the computer program is executed by a processor, the computer program implements the steps of the above-mentioned industrial Internet of Things unknown protocol fuzz testing method.

[0020] Compared with the prior art, the present invention has the following beneficial effects:

[0021] The invention discloses an unknown protocol fuzz testing method for the industrial Internet of Things. First, an execution process log of unknown protocol data in a protocol stack is obtained based on a virtual environment. Then, a tree representation structure of each bit of the unknown protocol data is established according to the execution process log. Based on the tree representation structure, each field of the unknown protocol data is obtained according to the similarity of the tree representation structures of adjacent bits. Then, an information theory measurement method is used to obtain the field type of each field of the unknown protocol data. Finally, fuzzy test data of each field of the unknown protocol data is generated according to a mutation rule preset for the field type. Fuzzy testing of unknown protocols of the industrial Internet of Things is performed based on the fuzzy test data. The method does not rely on industrial Internet of Things protocol documents and expert prior knowledge, can accurately identify unknown protocol fields and types, can perform efficient fuzz testing on unknown protocols of the Internet of Things, can help network security engineers perform security testing on unknown Internet of Things protocols, and discover security vulnerabilities in Internet of Things devices. BRIEF DESCRIPTION OF THE DRAWINGS

[0022] Figure 1 This is a flow chart of the unknown protocol fuzz testing method for the industrial Internet of Things according to an embodiment of the present invention.

[0023] Figure 2 This is a detailed flow chart of the industrial Internet of Things unknown protocol fuzz testing method according to an embodiment of the present invention.

[0024] Figure 3 This is a schematic diagram of the principle of the unknown protocol fuzz testing method for the industrial Internet of Things according to an embodiment of the present invention.

[0025] Figure 4 This is a structural block diagram of the industrial Internet of Things unknown protocol fuzzy testing system according to an embodiment of the present invention. DETAILED DESCRIPTION

[0026] In order to enable those skilled in the art to better understand the solutions of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the embodiments described are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of the present invention.

[0027] It should be noted that the terms "first", "second", etc. in the description and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that the numbers used in this way can be interchanged where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.

[0028] The present invention is described in further detail below with reference to the accompanying drawings:

[0029] See also Figure 1 In one embodiment of the present invention, a fuzzy testing method for unknown protocols of the Industrial Internet of Things is provided, which does not rely on the Industrial Internet of Things protocol documents and expert prior knowledge, and realizes efficient fuzz testing.

[0030] Specifically, the fuzzy testing method for unknown protocols of the industrial Internet of Things of the present invention includes the following steps:

[0031] S1: Obtain the execution process log of unknown protocol data in the protocol stack based on the virtual environment.

[0032] S2: Based on the execution process log, establish a tree representation structure for each bit of the unknown protocol data.

[0033] S3: Obtain each field of the unknown protocol data based on the similarity of the tree representation structure of adjacent bits.

[0034] S4: Obtain the field type of each field of the unknown protocol data through information theory measurement method.

[0035] S5: Generate fuzzy test data for each field of the unknown protocol data according to the mutation rules preset by the field type, and perform fuzzy testing of the unknown protocol of the industrial Internet of Things based on the fuzzy test data.

[0036] The invention discloses an unknown protocol fuzz testing method for the industrial Internet of Things. First, an execution process log of unknown protocol data in a protocol stack is obtained based on a virtual environment. Then, a tree representation structure of each bit of the unknown protocol data is established according to the execution process log. Based on the tree representation structure, each field of the unknown protocol data is obtained according to the similarity of the tree representation structures of adjacent bits. Then, an information theory measurement method is used to obtain the field type of each field of the unknown protocol data. Finally, fuzzy test data of each field of the unknown protocol data is generated according to a mutation rule preset for the field type. Fuzzy testing of unknown protocols of the industrial Internet of Things is performed based on the fuzzy test data. The method does not rely on industrial Internet of Things protocol documents and expert prior knowledge, can accurately identify unknown protocol fields and types, can perform efficient fuzz testing on unknown protocols of the Internet of Things, can help network security engineers perform security testing on unknown Internet of Things protocols, and discover security vulnerabilities in Internet of Things devices.

[0037] In one possible implementation, the virtual environment-based acquisition of an execution process log of unknown protocol data in a protocol stack includes: constructing a virtual environment for running a protocol stack and running an unknown industrial Internet of Things protocol, and using a plug-in technology to plug all CPU instructions of a virtual machine in the virtual environment, and for all instructions involving memory operations, recording the name of the instruction and the addresses of all operands to obtain a protocol stack execution process log; obtaining an initial storage address of the unknown protocol data flowing into the protocol stack, and searching for a log entry in the protocol stack execution process log that uses the initial storage address as a source operand, and recursively finding all log entries related to the unknown protocol data flowing into the protocol stack based on the destination operand address recorded in the found log entry, to obtain an execution process log of the unknown protocol data in the protocol stack.

[0038] Explanatory, see Figure 2 and 3 In this embodiment, a virtual environment for analyzing the execution process of the protocol stack is first constructed, and then all CPU instructions of the virtual machine are instrumented using the instrumentation technology. Within the instrumentation function, for all instructions involving memory operations, the name of the operation instruction and the addresses of all operands are recorded to form a protocol stack execution process log. At the same time, the initial storage address of all unknown protocol data flowing into the protocol stack is recorded, and then the instruction log entry with the initial storage address as the source operand is searched in the protocol stack execution process log. Based on the destination operand address recorded in the log entry, all log barcodes related to the unknown protocol data flowing into the protocol stack are recursively found, and irrelevant logs are removed.

[0039] For example, a Qemu virtual machine is used to construct a virtual environment capable of running a protocol stack, and by monitoring the execution of network system calls such as sys_socket, the initial storage address of all unknown protocol data flowing into the IoT protocol stack is recorded. At the same time, all CPU instructions are instrumented. In the instrumentation function, the type of instruction is first determined: if the instruction involves memory operations, the name of the operation instruction and the addresses of all operands are recorded to form a protocol stack execution process log. Specifically, for instructions with 1 source operand, the format of the protocol stack execution process log is recorded as "addr src →addr dst "; For instructions with two source operands, the protocol stack execution process log is recorded in the format of "addr src1 +addr src2 →addr dst After processing the unknown protocol data currently flowing into the protocol stack, the recorded initial storage address is first used as the search target. The protocol stack execution process log is searched for log entries with the same source operand address as the search target. Then, the destination operand address in the found log entry is used as the search target and the above process is repeated. Finally, all log entries related to the unknown protocol data are retained and irrelevant log entries are removed to form a filtered execution process log, that is, the execution process log of the unknown protocol data in the protocol stack.

[0040] In one possible implementation, establishing a tree representation structure for each bit of unknown protocol data based on the execution process log includes: obtaining the initial storage address of the unknown protocol data flowing into the protocol stack, and constructing a root node of the tree based on the initial storage address of the unknown protocol data flowing into the protocol stack; traversing each log entry of the execution process log, and when the source operand address in the current log entry is equal to the value of an existing node in the tree, creating a new node and setting the value of the new node to the destination operand address in the log entry, and establishing a branch between the new node and the node with the equal value; after the traversal is completed, a tree representation structure for each bit of the unknown protocol data is obtained.

[0041] Explanatory, a value-equal node is a node in the tree whose value is the same as the source operand address in the current log entry. See again Figure 2 and 3In this embodiment, the root node of the tree is constructed based on the initial storage address of the unknown protocol data flowing into the protocol stack. The initial storage address is the value of the root node. By traversing each log entry in the execution process log of the unknown protocol data in the protocol stack, if the source operand address in the log entry is equal to the value of an existing node in the tree, a new node is created with the destination operand address in the log entry as the value of the new node. A branch is established between the new node and the new node, ultimately establishing a tree representation structure for each bit of the unknown protocol data flowing into the protocol stack.

[0042] For example, the tree representation structure consists of a root node and several intermediate nodes / leaf nodes. Different nodes are connected by branches. Each node has a value, which is used to record the address of the data. During the conversion process, the root node of the tree is first constructed according to the initial storage address of the unknown protocol data flowing into the protocol stack. Then, a log entry "addr" is read from the execution process log of the unknown protocol data in the protocol stack. src →addr dst If the source operand address addr in the log entry src If the value of an existing node in the tree is equal, a new node is created, and the value of the new node is the destination operand address addr in the log entry. dst , and establish a branch between this node and the newly created node; otherwise, continue to read the next record and repeat the above process. After traversing all the execution process logs of the unknown protocol data in the protocol stack, a tree representation structure will be established for each bit of the unknown protocol data flowing into the protocol stack.

[0043] In one possible embodiment, the obtaining and obtaining each field of the unknown protocol data based on the similarity of the tree representation structure of adjacent bits includes: using a branch sequence alignment algorithm to obtain the number of branches that can be aligned between the tree representation structures of adjacent bits as a first number, and obtaining the ratio of the first number to the total number of branches of the tree representation structure of adjacent bits to obtain the similarity of the tree representation structure of adjacent bits; obtaining each field of the unknown protocol data according to the following judgment rule: when the similarity of the tree representation structure of adjacent bits is less than a preset similarity threshold, it is determined that the adjacent bits do not belong to the same field; otherwise, it is determined that the adjacent bits belong to the same field.

[0044] Interpretive, see again Figure 2 and 3In this implementation, every two adjacent bits of unknown protocol data flowing into the protocol stack are grouped into a discriminant group. Two tree representations corresponding to the two bits in a discriminant group are then found. Finally, a sequence alignment algorithm is used to calculate the similarity between the two tree representations. If the similarity falls below a threshold (for example, the number of aligned nodes is less than 70% of the total number of nodes in the tree), the two bits in the discriminant group are considered to not belong to the same field, indicating that the field boundary has been found.

[0045] For example, every two adjacent bits of the unknown protocol data flowing into the protocol stack are grouped into a discrimination group. Then, two tree representation structures corresponding to two bits in a discrimination group are found. Then, the branch sequence alignment algorithm is used to find branches that can be aligned between the branches of the two tree representation structures. In the branch sequence alignment process, for two branches to be aligned, traversal starts from the root node: if two nodes (x i ,y i ) values ​​are less than 1, then the two nodes are considered aligned; otherwise, try to add an empty node to a branch and re-verify whether they can be aligned, that is, verify (x i with y i+1 ) or (x i+1 with y i ) is less than 1. If alignment is possible, continue to try to align subsequent nodes; if alignment is still not possible after adding an empty node, it is considered that the two nodes at the corresponding positions cannot be aligned. After skipping the nodes that cannot be aligned, continue to try to align subsequent nodes, that is, continue to try to align x i+1 with y i+1 . When the two branches are aligned, calculate the number of nodes that can be aligned in the two branches. If the number of nodes that can be aligned is less than 70% of the total number of nodes in the two branches, the two branches cannot be aligned. Repeat the above process until all branches that can be aligned are found. Then, calculate the number of alignable branches and divide it by the total number of branches in the two tree representation structures to obtain the similarity of the two tree representation structures. Finally, determine whether two adjacent bits in the judgment group belong to the same field based on the similarity. For example, set the similarity threshold to 70%. If the similarity of the tree representation structures of two adjacent bits in the judgment group is less than 70%, it is considered that the two bits in this judgment group do not belong to the same field, that is, there is a field boundary between the bits.

[0046] In a possible implementation, obtaining the field type of each field of the unknown protocol data by using an information theory measurement method includes: traversing each field of the unknown protocol data:

[0047] When the field value of the current field has a linear relationship with the total data length of the unknown protocol data, the field type of the current field is determined to be the total data length field; when the field value of the current field has a linear relationship with the length of the next field of the unknown protocol data, the field type of the current field is determined to be the next field length field; when the field value of the current field takes values ​​within a limited range, the field type of the current field is determined to be the function code field; when the field value of the current field is a constant in each unknown protocol data of the same function code, the field type of the current field is determined to be the flag field; wherein the function code is the field value of the function code field; when the field values ​​of the current fields of different unknown protocol data show an increasing trend after sorting the unknown protocol data in the order of flowing into the protocol stack and the difference between the information entropy of the field value change value and 0 meets the preset difference threshold, the field type of the current field is determined to be the serial number field; when the data of the current field are all numbers, the field type of the current field is determined to be a limited change field; the field type of the unrecognized field is determined to be a random change field.

[0048] Interpretive, see again Figure 2 and 3 In this embodiment, for field type identification, if the field value of a certain field has a linear relationship with the total length of the unknown protocol data, that is, it satisfies the following formula, then the field type of the field is inferred to be the total length field:

[0049] MsgLen=α×V+β

[0050] Wherein, MsgLen is the total length of the unknown protocol data, V is the field value of the field, and α and β are both real numbers.

[0051] If the field value of a field has a linear relationship with the length of the next field of the unknown protocol data, that is, it satisfies the following formula, then the field type of the field is inferred to be the next field length field:

[0052] FieldLen=α1×V+β1

[0053] Where FieldLen is the length of the next field, and α1 and β1 are both real numbers.

[0054] If the field value of a certain field is only within a limited range, for example, if the field value randomness w(V) of a certain field is between 0.2 and 0.8 after calculation using the following formula, it is inferred that the field type of the field is a function code field:

[0055]

[0056] Among them, H(V) is the field value information entropy of the current field; |V| is the number of field values ​​of the current field.

[0057] Illustratively, in this embodiment, all field values ​​that have appeared in all unknown protocol data whose field type is a function code field are also recorded and used as different function codes to correspond to different functions.

[0058] According to the identified function code field, all unknown protocol data flowing into the protocol stack are grouped. Unknown protocol data belonging to the same function code are grouped together. For each group of unknown protocol data, each field is traversed from left to right. If the value of a field is a constant, for example, the field value information entropy H(V) calculated by the following formula is 0, then the field type of the field is inferred to be a flag field:

[0059]

[0060] Among them, p(x) is the probability of the field value appearing.

[0061] Illustratively, in this embodiment, all the field values ​​that have appeared in all unknown protocol data whose field type is a flag field are also recorded as the subsequent preset field values ​​of all flag fields.

[0062] Because the sequence number field is strongly correlated with the order in which data flows into the protocol stack, the unknown protocol data is sorted according to the order in which it flows into the protocol stack. If a field shows an increasing trend, the change value σ of all field values ​​of the field is calculated, and the information entropy H(σ) of σ is calculated. If H(σ) is close to 0 (for example, the difference between H(σ) and 0 meets the preset difference threshold), that is, the growth value of the field value of the field is constant, then the field type of the field is inferred to be a sequence number field.

[0063] Illustratively, in this embodiment, the field value change values ​​of all unknown protocol data whose field type is the sequence number field are also recorded as the subsequent preset field value change values ​​of the sequence number field.

[0064] For fields whose values ​​are all numbers, the field type is inferred to be a finite-variance field.

[0065] Exemplarily, in this embodiment, the maximum and minimum values ​​of the field values ​​of all unknown protocol data whose field type is a limited change field are also recorded as the subsequent preset maximum and minimum field values ​​of the limited change field.

[0066] Except for the above fields, the field types of unrecognized fields are determined to be randomly changing fields.

[0067] Exemplarily, when identifying the field type of a field, identification is performed in the order of the total data length field, the next field length field, the function code field, the flag field, the serial number field, the limited change field, and the random change field.

[0068] In one possible embodiment, the mutation rules preset for the field type include: when the field type is a total data length field, when generating fuzzy test data, the field value is set to the total length of the fuzzy test data; when the field type is a next field length field, when generating fuzzy test data, the field value is set to the length of the next field adjacent to the current field; when the field type is a function code field, when generating fuzzy test data, the field value is set to the corresponding function code preset according to the function of the fuzzy test data; when the field type is a flag field, when generating fuzzy test data, the field value is set to any one of the field values ​​of all preset flag fields; when the field type is a serial number field, when generating multiple fuzzy test data, the field value of each fuzzy test data is set to an increasing relationship of σ; wherein σ is a preset field value variation value of the serial number field; when the field type is a finite variation field, when generating fuzzy test data, the field value is set to any value between the field maximum value and the field minimum value of the preset finite variation field; when the field type is a random variation field, when generating fuzzy test data, the field value is set to a random value.

[0069] Interpretive, see again Figure 2 and 3 In this embodiment, different mutation strategies are formulated for fields of different field types, and fuzzy test data is generated by mutating unknown protocol data. For specific mutation strategies, please refer to the mutation rules preset for the above field types.

[0070] Finally, the generated fuzz testing data is sent to the target to be tested, and the running results of the target to be tested are monitored, thereby realizing fuzz testing for unknown protocols of the Industrial Internet of Things.

[0071] In general, the fuzz testing method for unknown protocols of the industrial Internet of Things of the present invention is based on the goal of being independent of industrial Internet of Things protocol documents and expert prior knowledge and achieving efficient fuzz testing. First, the protocol stack of the unknown protocol of the industrial Internet of Things is placed in a virtual environment for execution, and the binary instrumentation technology is used to obtain the execution process log of the unknown protocol data in the protocol stack; then, a customized tree structure is used to represent the execution process of the unknown protocol data in the protocol stack, and the field boundaries of the unknown protocol data are identified through tree similarity calculation technology to realize field division; subsequently, the field type of each field is inferred through an information theory measurement method; finally, specific mutation rules are formulated for each field according to the field boundaries and the field types of the fields, and fuzz testing cases of the unknown protocol of the industrial Internet of Things are generated according to the mutation rules.

[0072] This method does not rely on industrial IoT protocol documentation and expert prior knowledge, and can perform efficient fuzz testing on unknown IoT protocols. This method can help network security engineers perform security testing on unknown IoT protocols and discover security vulnerabilities in IoT devices.

[0073] Exemplarily, the present invention can be applied to examples such as fuzz testing tools, vulnerability mining systems, and penetration testing tools. For example, in the fuzz testing tool example, security testers can use mature products to perform fuzz testing on known IoT protocols, and at the same time use the method of the present invention to test unknown IoT protocols. The two complement each other to improve the coverage of the test. In the vulnerability mining system example, security experts can use the method of the present invention to perform fuzz testing on unknown IoT protocols, and further analyze the data that can cause abnormalities in the IoT protocol stack to discover network security vulnerabilities in the test target. In the penetration testing tool example, penetration testers can use the method of the present invention to discover data that causes abnormalities in the IoT protocol stack, and use the data as attack payload to complete the penetration test.

[0074] The following are device embodiments of the present invention, which can be used to implement the method embodiments of the present invention. For details not disclosed in the device embodiments, please refer to the method embodiments of the present invention.

[0075] See also Figure 4 In another embodiment of the present invention, an industrial Internet of Things unknown protocol fuzzy testing system is provided, which can be used to implement the above-mentioned industrial Internet of Things unknown protocol fuzzy testing method. Specifically, the industrial Internet of Things unknown protocol fuzzy testing system includes a log module, a tree construction module, a field boundary module, a field identification module and a test module.

[0076] Among them, the log module is used to obtain the execution process log of unknown protocol data in the protocol stack based on the virtual environment; the tree construction module is used to establish a tree representation structure of each bit of the unknown protocol data according to the execution process log; the field boundary module is used to obtain and obtain each field of the unknown protocol data based on the similarity of the tree representation structure of adjacent bits; the field identification module is used to obtain the field type of each field of the unknown protocol data through the information theory measurement method; the testing module is used to generate fuzzy test data for each field of the unknown protocol data according to the mutation rules preset by the field type, and to perform fuzzy testing of unknown protocols of the industrial Internet of Things based on the fuzzy test data.

[0077] All relevant contents of each step involved in the embodiment of the aforementioned industrial Internet of Things unknown protocol fuzzy testing method can be referred to the functional description of the functional module corresponding to the industrial Internet of Things unknown protocol fuzzy testing system in the embodiment of the present invention, and will not be repeated here.

[0078] The module division in the embodiments of the present invention is illustrative and represents only one logical functional division. In actual implementation, other division methods may be used. Furthermore, the functional modules in various embodiments of the present invention may be integrated into a single processor, exist physically as separate modules, or two or more modules may be integrated into a single module. The integrated modules may be implemented in either hardware or software functional modules.

[0079] In another embodiment of the present invention, a computer device is provided, which includes a processor and a memory, wherein the memory is used to store a computer program, the computer program includes program instructions, and the processor is used to execute the program instructions stored in the computer storage medium. The processor may be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, etc. It is the computing core and control core of the terminal, which is suitable for implementing one or more instructions, specifically suitable for loading and executing one or more instructions in the computer storage medium to implement the corresponding method flow or corresponding function; the processor described in the embodiment of the present invention can be used for the operation of the unknown protocol fuzz testing method of the industrial Internet of Things.

[0080] In another embodiment of the present invention, the present invention further provides a storage medium, specifically a computer-readable storage medium (Memory), which is a memory device in a computer device for storing programs and data. It is understandable that the computer-readable storage medium here can include both built-in storage media in the computer device and, of course, extended storage media supported by the computer device. The computer-readable storage medium provides a storage space that stores the operating system of the terminal. In addition, one or more instructions suitable for being loaded and executed by the processor are also stored in the storage space. These instructions can be one or more computer programs (including program codes). It should be noted that the computer-readable storage medium here can be a high-speed RAM memory or a non-volatile memory, such as at least one disk memory. The processor can load and execute one or more instructions stored in the computer-readable storage medium to implement the corresponding steps of the unknown protocol fuzz testing method for the industrial Internet of Things in the above embodiment.

[0081] It will be understood by those skilled in the art that embodiments of the present invention may be provided as methods, systems, or computer program products. Thus, the present invention may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware. Furthermore, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0082] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowcharts and / or block diagrams, as well as combinations of processes and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowcharts and / or block diagrams. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0083] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.

[0084] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.

[0085] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit it. Although the present invention has been described in detail with reference to the above embodiments, ordinary technicians in the field should understand that the specific implementation methods of the present invention can still be modified or replaced by equivalents. Any modification or equivalent replacement that does not depart from the spirit and scope of the present invention should be covered by the scope of protection of the claims of the present invention.

Claims

1. A fuzzy testing method for unknown protocols in industrial Internet of Things, characterized by: include: Obtain the execution process log of unknown protocol data in the protocol stack based on the virtual environment; According to the execution process log, a tree representation structure of each bit of unknown protocol data is established; Obtaining and obtaining each field of the unknown protocol data based on the similarity of the tree representation structure of adjacent bits; Obtain the field type of each field of the unknown protocol data through information theory measurement methods; According to the mutation rules preset by the field type, fuzzy test data of each field of the unknown protocol data is generated, and fuzzy testing of the unknown protocol of the industrial Internet of Things is performed based on the fuzzy test data.

2. The method for fuzz testing unknown protocols of the industrial Internet of Things according to claim 1 is characterized in that: The step of obtaining the execution process log of the unknown protocol data in the protocol stack based on the virtual environment includes: Construct a virtual environment to run the protocol stack and run an unknown IIoT protocol. Use instrumentation technology to instrument all CPU instructions of the virtual machine in the virtual environment. For all instructions involving memory operations, record the instruction name and the addresses of all operands to obtain a log of the protocol stack execution process. The initial storage address of the unknown protocol data flowing into the protocol stack is obtained, and the log entry with the initial storage address as the source operand is searched in the protocol stack execution process log. Based on the destination operand address recorded in the found log entry, all log entries related to the unknown protocol data flowing into the protocol stack are recursively searched to obtain the execution process log of the unknown protocol data in the protocol stack.

3. The method for fuzz testing unknown protocols of the industrial Internet of Things according to claim 1 is characterized in that: The step of establishing a tree representation structure for each bit of the unknown protocol data according to the execution process log includes: Obtaining an initial storage address of the unknown protocol data flowing into the protocol stack, and constructing a root node of the tree according to the initial storage address of the unknown protocol data flowing into the protocol stack; Traverse each log entry in the execution process log, and when the source operand address in the current log entry is equal to the value of an existing node in the tree, create a new node and set the value of the new node to the destination operand address in the log entry, and establish a branch between the new node and the node with the same value; After the traversal is completed, a tree representation structure of each bit of the unknown protocol data is obtained.

4. The method for fuzz testing unknown protocols of the industrial Internet of Things according to claim 1 is characterized in that: The obtaining of each field of the unknown protocol data based on the similarity of the tree representation structure of adjacent bits includes: Using a branch sequence alignment algorithm to obtain the number of branches that can be aligned between the tree representation structures of adjacent bits as a first number, and obtaining a ratio of the first number to the total number of branches in the tree representation structures of the adjacent bits to obtain the similarity of the tree representation structures of the adjacent bits; The fields of the unknown protocol data are obtained according to the following judgment rules: when the similarity of the tree representation structure of adjacent bits is less than a preset similarity threshold, the adjacent bits are judged not to belong to the same field; otherwise, the adjacent bits are judged to belong to the same field.

5. The method for fuzz testing unknown protocols of the industrial Internet of Things according to claim 1 is characterized in that: The field types of each field of the unknown protocol data obtained by the information theory measurement method include: Traverse the fields of unknown protocol data: When the field value of the current field has a linear relationship with the total length of the unknown protocol data, the field type of the current field is determined to be a total data length field; When the field value of the current field has a linear relationship with the length of the next field of the unknown protocol data, the field type of the current field is determined to be the next field length field; When the field value of the current field is within a limited range, the field type of the current field is determined to be a function code field; When the field value of the current field is a constant in each unknown protocol data of the same function code, the field type of the current field is determined to be a flag field; wherein the function code is the field value of the function code field; When the field values ​​of the current fields of different unknown protocol data show an increasing trend after sorting the unknown protocol data according to the order of flowing into the protocol stack and the difference between the information entropy of the field value change value and 0 meets the preset difference threshold, the field type of the current field is determined to be a sequence number field; When the data of the current field are all numbers, the field type of the current field is determined to be a limited change field; The field type of the unrecognized field is determined to be a random change field.

6. The method for fuzz testing unknown protocols of the industrial Internet of Things according to claim 5 is characterized in that: The field value of the current field is specifically within a limited range: The randomness of the field value V of the current field is between 0.2 and 0.8: Among them, H(V) is the field value information entropy of the current field; |V| is the number of field values ​​of the current field; The field value of the current field is a constant in each unknown protocol data of the same function code. Specifically, the field value information entropy of the field value of the current field in each unknown protocol data of the same function code is 0.

7. The method for fuzz testing unknown protocols of the industrial Internet of Things according to claim 1, characterized in that: The preset mutation rules for the field type include: When the field type is the total length field of the data, when generating the fuzzy test data, the field value is set to the total length of the fuzzy test data; When the field type is the next field length field, when generating fuzzy test data, the field value is set to the length of the next field adjacent to the current field; When the field type is a function code field, when generating fuzzy test data, the field value is set to the corresponding function code preset according to the function of the fuzzy test data; When the field type is a flag field, when generating fuzzy test data, the field value is set to any one of the field values ​​of all preset flag fields; When the field type is a serial number field, when generating multiple fuzzy test data, the field values ​​of each fuzzy test data are set to an increasing relationship of σ; where σ is the preset field value change value of the serial number field; When the field type is a limited-variation field, when generating fuzzy test data, the field value is set to any value between the maximum value and the minimum value of the preset limited-variation field; When the field type is a random change field, the field value is set to a random value when generating fuzzy test data.

8. An industrial Internet of Things unknown protocol fuzzy testing system, characterized by: include: The log module is used to obtain the execution process log of unknown protocol data in the protocol stack based on the virtual environment; A tree construction module is used to build a tree representation structure of each bit of unknown protocol data based on the execution process log; A field demarcation module is used to obtain and obtain each field of the unknown protocol data based on the similarity of the tree representation structure of adjacent bits; A field identification module is used to obtain the field type of each field of the unknown protocol data through an information theory measurement method; The testing module is used to generate fuzzy test data for each field of unknown protocol data according to the mutation rules preset by the field type, and to perform fuzzy testing of unknown protocols of the industrial Internet of Things based on the fuzzy test data.

9. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the computer program, the steps of the industrial Internet of Things unknown protocol fuzz testing method according to any one of claims 1 to 7 are implemented.

10. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the steps of the industrial Internet of Things unknown protocol fuzz testing method as claimed in any one of claims 1 to 7 are implemented.

Citation Information

Patent Citations

  • Industrial control system security detection method and device

    CN107404487A

  • Modbus TCP protocol fuzzy test method based on abnormal field positioning

    CN110336827A

  • Industrial control protocol reverse analysis method and device

    CN112311755A

  • Industrial control equipment black box fuzzy test method based on protocol reversal

    CN116991743A

  • Flow-based application layer cloud protocol optimization identification method

    CN117614874A