Kernel fuzzy test case generation method and device based on shuffling algorithm

By generating kernel fuzzy test cases through shuffling algorithm and chi-square test, the problems of diversity and low efficiency in existing technologies are solved, and the effect of efficiently discovering kernel vulnerabilities is achieved.

CN120803957AActive Publication Date: 2025-10-17KYLIN CORP
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
CN202511277552.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-09
Publication Date
2025-10-17
Estimated Expiration
2045-09-09

AI Technical Summary

Technical Problem

Existing fuzz test case generation methods are highly dependent on corpora, resulting in a decrease in test case diversity and an inability to fully exploit deep-seated vulnerabilities in kernel code. In addition, they have high time complexity and cannot accurately predict the order of kernel system call interfaces.

Method used

A shuffling algorithm is used to mutate kernel test cases to generate fuzzy test cases, and the chi-square test is used to ensure the randomness of the test cases, reduce the dependence on the corpus, and improve diversity and efficiency.

Benefits of technology

The efficiency and diversity of fuzz test case generation are improved, more potential kernel defects are discovered, and the reliability and security of the kernel are improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120803957A_ABST
    Figure CN120803957A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of information, and provides a shuffling algorithm-based kernel fuzz test case generation method and device, and the method comprises the steps: randomly taking out a kernel test case p from a corpus, and carrying out the mutation of the kernel test case p through a shuffling algorithm shuffling algorithm mathematical model to generate a fuzz test case; generating m fuzzy test cases to generate m fuzzy test cases,..., and forming a fuzzy test case set; performing chi-square test on the generated fuzzy test case set; and judging a chi-square test result, starting a test environment by using the kernel to be tested and a specified file system, and inputting the fuzz test case set into the test environment for execution. According to the method, the system calling sequence in the test case can be disrupted, the new fuzzy test case can be generated, the diversity of the fuzzy test case is increased, high dependence on an original corpus is avoided, the time complexity of the variation test case is small, and the generation time is not increased.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application belongs to the field of information technology, and particularly relates to a kernel fuzzing test case generation method and device based on a shuffle algorithm. BACKGROUND

[0002] The kernel is the core component of a modern operating system, responsible for managing system resources, providing hardware abstraction, and ensuring the stability and security of the system. Due to the complexity and high-privilege nature of the kernel, vulnerabilities within it often pose a high risk. Once the kernel is exploited by an attacker, it can lead to system crashes, data leaks, or privilege escalation, among other serious consequences. Therefore, rigorous testing of the kernel, particularly fuzzing, is crucial for ensuring the security of the operating system.

[0003] Kernel fuzzing requires the ability to automatically generate random test cases, run test cases, monitor system crashes and exceptions, collect and analyze test results, and other functions, specifically for detecting and reporting software vulnerabilities and errors in the operating system kernel. If the number and diversity of fuzzing test cases generated per unit of time can be improved, the ability to discover problems through fuzzing can be enhanced, which is of great significance in maintaining the quality of the kernel.

[0004] The generation of kernel fuzzing test cases mainly involves using various algorithms to generate corresponding test cases based on the combination of kernel system call interfaces, forming a corpus. Each test case in the corpus is a sequence of system calls. By randomly mutating the test cases in the corpus, a variety of different fuzzing test cases are generated, which are then input into the test environment for testing, achieving fuzzing of the kernel and discovering potential problems in the kernel.

[0005] The current problem with the fuzzing test case generation method is that the method of randomly mutating test cases in the corpus is highly dependent on the corpus, which can lead to a decrease in the diversity of generated test cases when the corpus lacks the desired system calls, a decrease in the coverage of kernel code, and the inability to fully uncover deep-seated kernel code vulnerabilities. Moreover, the time complexity of multiple test case mutation methods is greater than or equal to O(len(p.Calls)), where len(p.Calls) represents the number of system calls in the test case p. Additionally, due to the inability to accurately predict the order of kernel system call interfaces in the application layer, the order of kernel system call interfaces in the fuzzing test case becomes extremely important.

[0006] How to generate new fuzzing test cases while ensuring the diversity of fuzzing test cases, uncovering potential vulnerabilities, and continuously improving the fuzzing test cases in the corpus is a problem that must be addressed. SUMMARY

[0007] The application aims to provide a kernel fuzz test case generation method and device based on a shuffling algorithm, which can shuffle the order of system calls in test cases, generate new fuzz test cases, increase the diversity of fuzz test cases, avoid high dependence on a corpus, and has small time complexity of the mutated test cases and will not increase the fuzz test case generation time.

[0008] In order to achieve the above-mentioned purpose, the technical scheme of the application is as follows: A kernel fuzz test case generation method based on a shuffling algorithm, comprising: S1, shuffling algorithm initialization; S2: randomly taking a kernel test case p from a corpus, and applying a shuffling algorithm mathematical model to the kernel test case p to generate a fuzz test case; S3: generating m fuzz test cases through m steps S2 、 、 … , to form a fuzz test case set ; S4: performing chi-square test on the generated fuzz test case set ; S5: judging the result of the chi-square test, if the fuzz test case has randomness, jumping to step S6; if the fuzz test case does not have randomness, jumping back to step S1; S6: starting a test environment with a to-be-tested kernel and a specified file system, inputting the fuzz test case set obtained in step S3 into the test environment for execution, each fuzz test case calling an interface of the to-be-tested kernel to implement the fuzz test on the kernel, and when the test environment crashes, generating relevant log to explain the crash information for analysis.

[0009] Further, the method for generating a fuzz test case in step S2 comprises: S21: generating a test case g after deep cloning the kernel test case p; S22: generating a fuzz test case by shuffling the test case g generated by deep cloning.

[0010] Further, the specific process of step S21 is as follows: S211: creating a new Prog structure object p1; S212: assigning p.Target of the kernel test case p to p1.Target; S213: copying p.Calls of the kernel test case p and assigning the result to p1.Calls; S214: Create a new Call structure pointer slice calls, whose length is the same as the original Call structure pointer slice origCalls; S215: Traverse origCalls, copy each element, and store the result in the corresponding position of calls, and assign calls to the Calls of the new Prog structure object p1; S216: Copy the single Call structure, create a new Call structure object c1; S217: Assign the Meta field value of the original Call structure object directly to the Meta field of c1; S218: Check if the Ret field of the original Call structure object is nil; if not, copy Ret and convert the result to type and assign it to the Ret field of c1; S219: Traverse the Args field of the original Call structure object, copy each Arg type parameter method, and store the copied result in the corresponding position of the new slice c1.Args; S2110: Assign the Props field value of the original Call structure object directly to the Props field of c1; S2111: Return the pointer of the newly created Call structure object c1; S2112: Complete the deep cloning of the kernel test case p to obtain the test case g through the above steps.

[0011] Further, the specific process of step S22 is as follows: S221: Consider the test case g as a set S, and the system calls in the test case g correspond to the elements in the set. The number of system calls in the test case g, len(g.Calls), is considered as the number of elements n in the set. S222: Start from the last element of the set S, for each element (i from n to 2), generate a random index based on uniform distribution , then exchange the positions of elements and , to form an iterative random transformation: ; where U(1,i): represents a uniform distribution random variable on the interval [1,i], represents that j follows a uniform distribution on the interval [1, i]; represents the set S before the i-th exchange, S represents the set S after the i-th exchange, S represents the exchange of two elements with indexes i and j in the set S, and returns a new set ; S223: After n-1 random exchange operations, the elements of the set S are completely disordered; S224: According to the element order of the disordered set S, the system call order is adjusted to generate a fuzz test case.

[0012] Further, the chi-square test method in step S4 includes: S41: The fuzz test case set is composed of m fuzz test cases, each of which is composed of an uncertain number of system calls. The actual frequency of each adjacent system call pair in the m fuzz test cases is counted. When a shuffling algorithm is completed, the frequency of each adjacent system call pair in the generated fuzz test case is counted, and the frequency data of the adjacent system call pair is quickly stored in a hash table. S42: After m times of counting, the chi-square statistic is calculated; the chi-square statistic , k represents the number of adjacent system call pairs; first, the theoretical frequency , is calculated; combined with the actual frequency of each adjacent system call pair , the contribution value of each adjacent system call pair is calculated , and the contribution values of all adjacent system call pairs are added to obtain the chi-square statistic; the critical value is obtained by consulting the chi-square distribution table , represents the significance level, and k-1 represents the value of the degree of freedom. The chi-square statistic and the critical value are compared.

[0013] Further, the judgment on the result of the chi-square test in step S5 includes: S51: If , it is considered that the fuzz test case set obeys the uniform distribution, and the fuzz test case has randomness. The test case set is input into the test environment for kernel testing, and step S6 is jumped to; S52: If , it is considered that the fuzz test case does not have randomness, and step S1 is jumped to.

[0014] Further, in step S52, if the fuzz test case set If the actual frequency of adjacent system call pairs is significantly higher than the theoretical frequency, the test cases generated by this shuffling algorithm are overly biased towards specific combinations. When jumping to step S1 for the next m rounds of shuffling, the high-frequency system call pairs in the hash table storing the frequency data of adjacent system call pairs are given a lower mutation priority, forcing the shuffling algorithm to explore the low-frequency area and increase the randomness of the test cases after mutation.

[0015] On the other hand, the present invention also proposes a kernel fuzzy test case generation device based on a shuffling algorithm, comprising: Initialization module: shuffling algorithm initialization; Shuffling module: randomly takes a kernel test case p from the corpus, applies the shuffling algorithm mathematical model to mutate the kernel test case p to generate a fuzzy test case; Use case set module: After m steps S2, generate m fuzzy test cases 、 、 … , forming a fuzzy test case set ; Chi-square test module: for the generated fuzzy test case set Conduct a chi-square test; Judgment module: judges the result of the chi-square test. If the fuzzy test case is random, it jumps to the test module; if the fuzzy test case is not random, it jumps back to the initialization module; Test module: Use the kernel to be tested and the specified file system to start the test environment, input the fuzzy test case set obtained by the use case set module into the test environment for execution, and each fuzzy test case calls the interface of the kernel to be tested to implement fuzz testing of the kernel. When the test environment crashes, relevant logs are generated to describe the crash information for analysis.

[0016] On the other hand, the present invention also proposes a computer-readable storage medium, which stores a computer program, and the computer program is used to execute the above-mentioned kernel fuzzy test case generation method based on the shuffling algorithm.

[0017] On the other hand, the present invention also proposes a computer program product, including a computer program, which implements the above-mentioned kernel fuzzy test case generation method based on the shuffling algorithm when executed by a processor.

[0018] Compared with the prior art, the present invention has the following beneficial effects: 1、The shuffling algorithm is applied to the test case variation of the fuzzy test by introducing the shuffling algorithm, new test cases can be efficiently generated, the test cases that need to be varied multiple times in the original variation algorithm can be obtained only once by the shuffling algorithm, the variation time is reduced, the fuzzy test case generation efficiency is improved, the diversity of the fuzzy test cases generated in unit time is increased, and the problem discovery efficiency and capability of the fuzzy test are improved.

[0019] 2、The test cases obtained by the shuffling algorithm are verified whether they are completely random by introducing the chi-square test, the newly generated test cases are merged into a test case set, the chi-square test is performed on the set, only the test cases that pass the test are input into the test environment for testing, the randomness of system call ordering is ensured, and the diversity of the test cases is ensured.

[0020] 3、The shuffling algorithm, the chi-square test method, the fuzzy test, the correctness and randomness of the shuffling algorithm are combined, new test cases can be efficiently generated, the diversity of the fuzzy test cases is improved, the fuzzy test case generation is accelerated, more potential kernel defects are found, and the reliability and safety of the kernel are improved. BRIEF DESCRIPTION OF DRAWINGS

[0021] Figure 1 It is the flowchart of the embodiment 1 of the present application.

[0022] Figure 2 It is the flowchart of the shuffling algorithm and the chi-square test for generating fuzzy test cases in the embodiment 2 of the present application.

[0023] Figure 3 It is the effect comparison diagram of the technical scheme in the embodiment 3 of the present application. DETAILED DESCRIPTION

[0024] It should be noted that the embodiments in the present application and the features in the embodiments can be combined with each other without conflict.

[0025] Firstly, the abbreviations and key terms involved in the embodiments are explained.

[0026] Fuzzy test: the fuzzy test discovers potential vulnerabilities by providing unexpected, random or abnormal inputs to the target system and monitoring the response of the system. The basic idea is to input a large amount of random data to the application program, observe and record the behavior of the program after receiving these inputs, so as to discover potential vulnerabilities such as memory leakage, null pointer reference, deadlock and other abnormal or crash conditions.

[0027] Corpus ctx.corpus: used to store and manage test cases generated during the fuzz testing process. These fuzz test cases consist of a series of kernel system calls and are used to fuzz the kernel to find potential vulnerabilities and errors.

[0028] shuffling algorithm: shuffling algorithm name.

[0029] len(g.Calls): The number of system calls in the fuzz test case g.

[0030] g.Calls[i]: the i-th system call in the fuzz test case g.

[0031] Time complexity: An important indicator to measure the efficiency of an algorithm, which describes the trend of the algorithm's running time increasing as the input size grows.

[0032] O(x): The symbol of time complexity, x is a variable.

[0033] newargs: is a map whose key and value are pointers to ResultArg types.

[0034] ResultArg: A parameter type used to describe the return value of a system call.

[0035] Chi-square test: used to test whether the system calls in the test case are completely random.

[0036] The present invention will be described in detail below with reference to specific embodiments and accompanying drawings.

[0037] Example 1: like Figure 1 As shown, the kernel fuzzy test case generation method based on the shuffling algorithm proposed in this embodiment 1 includes: S1, shuffling algorithm initialization; In this step, the counter count is initialized to 0. Count is used to record the number of fuzzy test cases generated by mutation. In this embodiment, the kernel fuzzy test requires m fuzzy test cases, where m can be 100. When the counter count is 100, a fuzzy test case set is formed for chi-square test.

[0038] S2: Randomly take a kernel test case p from the corpus, apply the shuffling algorithm mathematical model to mutate the kernel test case p to generate a fuzzy test case; Each test case of the corpus ctx.corpus in the embodiment is a system call sequence, which is generated based on the combination of kernel system call interfaces. A test case p is randomly taken from the corpus ctx.corpus to generate a fuzzy test case through mutation.

[0039] The method for generating a fuzzy test case through mutation is as follows: S21: First, a test case g is generated after deep cloning of the test case p, and the specific process is as follows: S211: A new Prog structure object p1 is created; S212: p.Target is assigned to p1.Target; S213: cloneCalls(p.Calls, newargs) is called to copy p.Calls, and the result is assigned to p1.Calls; S214: A new Call structure pointer slice calls is created, and the length of the new Call structure pointer slice calls is the same as that of the original Call structure pointer slice origCalls; S215: The original Call structure pointer slice origCalls is traversed, cloneCall(c, newargs) is called for each element c to copy, the result is stored in the corresponding position of the new Call structure pointer slice calls, and calls is assigned to the Calls of the new Prog; S216: cloneCall copies a single Call structure, and a new Call structure object c1 is created; S217: The Meta field value of the original Call structure object c is directly assigned to the Meta field of c1; S218: It is checked whether the Ret field of the original Call structure object c is nil. If not, the clone method is called to copy c.Ret, and the result is converted to type after assignment to the Ret field of c1. The clone method performs the following copy operation: a new Arg type slice c1.Args is created, and the length of the new Arg type slice c1.Args is the same as that of the Args field of the original Call structure object c; S219: The Args field of the original Call structure object c is traversed, the clone method is called for each Arg type parameter to copy, and the copied result is stored in the corresponding position of the new slice c1.Args; S2110: The Props field value of the original Call structure object c is directly assigned to the Props field of c1; S2111: return the pointer of the newly created Call structure object c1; S2112: complete the deep cloning of the test case p to obtain the test case g through the above steps, and the deep cloning is used to avoid the influence of the subsequent shuffling algorithm mutation on the original test case in the corpus.

[0040] S22: secondly, the shuffling algorithm is used to generate a fuzzy test case for the test case g generated by deep cloning, and the specific process is as follows: S221: regarding the test case g as a set S, the system calls in the test case correspond to the elements in the set, and the number of system calls len(g.Calls) in the test case g is regarded as the number n of elements in the set; S222: starting from the last element of the set S , for each element (i from n to 2), the time.Now().UnixNano() function is used to obtain the nanosecond number of the current time as a random seed, the rand.Seed function is used to initialize the random number generator in the standard library, and the rand.Intn(i+1) function is used to convert the random time seed into a random integer j in the range of 1 to i; , then the positions of the elements and are exchanged, and this process can be formally described as an iterative random transformation: ; S223: the step of exchanging the elements g.Calls[i] and g.Calls[j] is implemented through multiple assignment syntax g.Calls[i], g.Calls[j]=g.Calls[j], g.Calls[i], and after n-1 times of random exchange operation, the order of the elements in the set S is completely disordered. According to the equal probability principle in probability theory, the probability of each element being in any position in the final arrangement is , so as to ensure that the generated test data has uniform distribution characteristics in all possible arrangement spaces, greatly improving the randomness and diversity of the test case; S224: adjust the order of the corresponding system calls according to the order of the elements in the disordered set S, and obtain the test case as a fuzzy test case, and the test case counter count=count+1; S3: after m times of step S2, m fuzzy test cases , , …… are generated to form a fuzzy test case set ; After m steps of S2, i.e. when count equals m, the m generated fuzz test cases constitute a fuzz test case set.

[0041] S4: Perform chi-square test on the generated fuzz test case set ; S5: Judge the result of the chi-square test. If the fuzz test cases are random, go to step S6; if the fuzz test cases are not random, go back to step S1. S6: Start a test environment with the to-be-tested kernel and a specified file system, input the fuzz test case set obtained in step S3 into the test environment for execution, and each fuzz test case calls an interface of the to-be-tested kernel to implement fuzz testing on the kernel. When the test environment crashes, generate relevant logs to explain the crash information for analysis.

[0042] In this embodiment, the shuffling algorithm is applied to the mutation of the test cases of the fuzz testing, so that new test cases can be efficiently generated. The test cases that need to be mutated multiple times by the original mutation algorithm can be obtained by only one mutation by the shuffling algorithm, thereby reducing the mutation time, improving the generation efficiency of the fuzz test cases, increasing the diversity of the fuzz test cases generated in a unit of time, and improving the efficiency and capability of the fuzz testing to find problems.

[0043] Embodiment 2 This embodiment is a further optimization based on the method described in embodiment 1, and the method of chi-square test is described in detail.

[0044] The kernel fuzz test case generation method based on the shuffling algorithm in this embodiment includes the following steps: S1, shuffling algorithm initialization; S2: Randomly take a kernel test case p from the corpus, and apply the shuffling algorithm mathematical model to mutate the kernel test case p to generate a fuzz test case; S3: After m steps of S2, m fuzz test cases are generated 、 、 … , to constitute a fuzz test case set ; The method steps specifically included in the above steps S1-S3 are the same as those of embodiment 1, and the specific steps can be referred to embodiment 1 and will not be repeated.

[0045] S4: Perform chi-square test on the generated fuzz test case set ; S41: Test the case set The m fuzzy test cases are composed of an uncertain number of system calls, the actual frequency of each adjacent system call pair in the m fuzzy test cases is counted, the counting method is that when the shuffling algorithm is completed once in each step S224, the frequency of each adjacent two system calls in the generated fuzzy test case is counted, the frequency data of the adjacent system call pairs are quickly stored in a hash table, the key value of the hash table stores two system calls, and the value value stores the adjacent frequency of the two system calls, after m times of counting, the chi-square statistic is calculated.

[0046] S42: chi-square statistic , k represents the number of adjacent system call pairs; first, the theoretical frequency , ; the actual frequency of each adjacent system call pair , that is, the value value in the hash table, is combined to calculate the contribution value of each adjacent system call pair , and then the contribution values of all adjacent system call pairs are added to obtain the chi-square statistic. Wherein: if the test case set contains e system calls in total, then the number r of possible adjacent system call pairs is: ; the total number o of adjacent system call pairs is the number of keys in the hash table (the number of keys can be found in the above hash table), which is actually the number k of adjacent system call pairs; After obtaining the chi-square statistic, the critical value is calculated, the significance level is a probability value preset when performing hypothesis testing, and this time = 0.05; the value of the degree of freedom is determined because the number of keys in the hash table storing adjacent system call pairs is k, so the degree of freedom df is known; according to the significance level and the degree of freedom df, the critical value is obtained from the chi-square distribution table.

[0047] S5: judging the result of the chi-square test, if the fuzzy test cases have randomness, jumping to step S6; if the fuzzy test cases do not have randomness, jumping back to step S1; The specific method of this step includes: S51: if , the original hypothesis is accepted, that is, it is considered that the fuzzy test case set is subject to uniform distribution, which indicates that the generated fuzzy test cases have randomness, and the fuzzy test case set is input into the test environment for kernel testing, and jumping to step S6; S52: if , it is considered that the fuzzy test cases do not have randomness, and the test case set The actual frequency of adjacent system call pairs is significantly higher than the theoretical frequency, which indicates that the use cases generated by the shuffling algorithm may be biased towards specific combinations. In the next round of m shuffles, the adjacent system call pairs with high frequency in the hash table are given a lower mutation priority, forcing the shuffling algorithm to explore the low-frequency region. This can effectively increase the randomness of the test cases after mutation, and then jump to step S1.

[0048] S6: Start the test environment with the to-be-tested kernel and the specified file system, and input the fuzz test case set obtained in step S3 into the test environment for execution. Each fuzz test case calls the interface of the to-be-tested kernel to implement the fuzz test on the kernel. When the test environment crashes, generate relevant logs to explain the crash information for analysis.

[0049] The complete flow of the embodiment is shown in Figure 2 Based on embodiment 1, the chi-square test is introduced to verify whether the test cases obtained by the shuffling algorithm are completely random. The newly generated test cases are merged into a test case set, and the chi-square test is performed on the set. Only if the test passes will the test cases be input into the test environment for testing, ensuring the randomness of the system call ordering and the diversity of the test cases.

[0050] Embodiment 3: This embodiment is a technical effect display of the practical application of the method described in embodiment 2.

[0051] As shown in Figure 3 The figure shows the comparison results of kernel fuzz testing before optimization (existing scheme) and after optimization (scheme described in embodiment 2), including running time, types of problems found, number of problems found, number of test cases generated, and total number of system calls executed.

[0052] As can be seen from the comparison, the optimized scheme can save 4 days while discovering the same number of 9000+ crashes. The optimized scheme and the pre-optimization scheme are tested together for 11 days. The optimized scheme generates 40000+ more test cases, discovers 7000+ more problems, and improves by 76%. The number of problem types increases by nearly 40, an increase of 55%. Four million more system calls are executed.

[0053] The above comparison shows that by combining fuzz testing, shuffling algorithm, and chi-square test method, new test cases can be efficiently generated, and the correctness and randomness of the shuffling algorithm can be ensured, thereby improving the diversity of fuzz test cases, accelerating the generation of fuzz test cases, discovering more potential kernel defects, and improving the reliability and security of the kernel.

[0054] Embodiment 4: This embodiment proposes a kernel fuzz test case generation device based on a shuffling algorithm, which includes: Initialization module: shuffle algorithm initialization; Shuffling module: randomly take a kernel test case p from the corpus, apply the shuffle algorithm mathematical model to the kernel test case p to generate a fuzz test case; Use case set module: after m steps S2, generate m fuzz test cases 、 、 … , form a fuzz test case set ; Chi-square test module: perform chi-square test on the generated fuzz test case set ; Judgment module: judge the results of the chi-square test. If the fuzz test case has randomness, jump to the test module; if the fuzz test case does not have randomness, jump back to the initialization module; Test module: start the test environment with the kernel to be tested and the specified file system, input the fuzz test case set obtained by the use case set module into the test environment for execution, each fuzz test case calls the interface of the kernel to be tested to implement the fuzz test of the kernel, and when the test environment crashes, generate relevant log to explain the crash information for analysis.

[0055] The shuffling module includes: Deep cloning unit: deep clone the kernel test case p to generate a test case g; Shuffling unit: generate a fuzz test case by shuffling the test case g generated by deep cloning.

[0056] The deep cloning unit includes: Create a new Prog structure object p1; Assign the value of p.Target of the kernel test case p to p1.Target; Copy p.Calls of the kernel test case p and assign the result to p1.Calls; Create a new Call structure pointer slice calls with the same length as the original Call structure pointer slice origCalls; Iterate over origCalls, copy each element, and store the result in the corresponding position of calls, and assign calls to the Calls of the new Prog structure object p1; Copy the single Call structure, create a new Call structure object c1; Assign the value of the Meta field of the original Call structure object directly to the Meta field of c1; Check if the Ret field of the original Call struct object is nil; if not, copy Ret and convert the result to the Ret field of c1; Iterate through the Args field of the original Call struct object, copy each Arg type parameter method, and store the copied result in the corresponding position of the new slice c1.Args; Assign the Props field value of the original Call struct object directly to the Props field of c1; Return the pointer of the newly created Call struct object c1; The kernel test case p is cloned in depth to obtain the test case g through the above steps.

[0057] The shuffling unit includes: Consider the test case g as a set S, the system calls in the test case g correspond to the elements in the set, and the number of system calls in the test case g len(g.Calls) is considered as the number of elements n in the set; From the last element of the set S Start, for each element (i from n to 2), generate a random index based on uniform distribution Then exchange the positions of elements and to form an iterative random transformation: ; Where U(1,i): represents a uniform distribution random variable on the interval [1,i], represents that j follows a uniform distribution on the interval [1,i]; represents the set S before the i-th exchange, represents the set S after the i-th exchange, represents the exchange of the two elements with indices i and j in ; After n-1 random exchange operations, the order of elements in the set S is completely shuffled; Adjust the order of system calls according to the shuffled order of elements in the set S to generate a fuzz test case.

[0058] The chi-square test module includes: a set of fuzz test cases The m fuzzy test cases are composed of an uncertain number of system calls, and the actual frequency of each adjacent system call pair in the m fuzzy test cases is counted, and the counting method is that when a shuffling algorithm is completed, the frequency of each adjacent two system calls in the generated fuzzy test case is counted, and the frequency data of the adjacent system call pairs are quickly stored in a hash table; After m times of counting, the chi-square statistic is calculated; the chi-square statistic , k represents the number of adjacent system call pairs; first, the theoretical frequency , is calculated; the contribution value of each adjacent system call pair is calculated combined with the actual frequency of each adjacent system call pair , and then the contribution values of all adjacent system call pairs are added to obtain the chi-square statistic; the critical value is obtained by consulting the chi-square distribution table , represents the significance level, and k-1 represents the value of the degree of freedom. The chi-square statistic and the critical value are compared.

[0059] The judging module comprises: If , it is considered that the fuzzy test case set conforms to the uniform distribution, and the fuzzy test case has randomness. The test case set is input into the test environment for kernel testing, and the test module is jumped to; If , it is considered that the fuzzy test case does not have randomness, and the initialization module is jumped to.

[0060] If the fuzzy test case set has an adjacent system call pair whose actual frequency is significantly higher than the theoretical frequency, it is considered that the test case generated by the shuffling algorithm is excessively biased towards a specific combination. When the shuffling algorithm is jumped to step S1 for the next m times of shuffling, the high-frequency system call pairs in the hash table storing the frequency data of the adjacent system call pairs are given a lower mutation priority, and the shuffling algorithm is forced to explore the low-frequency area, thereby increasing the randomness of the test case after mutation.

[0061] The kernel fuzzy test case generation device based on the shuffling algorithm proposed in the embodiment can implement the kernel fuzzy test case generation method based on the shuffling algorithm proposed in any one of embodiments 1 and 2, and has the same technical effects as embodiments 1 and 2.

[0062] The above-described embodiments are only preferred embodiments of the present application, and are only used to help understand the method and its core idea of the present application. The protection scope of the present application is not limited to the above-described embodiments. Any technical scheme falling within the idea of the present application belongs to the protection scope of the present application. It should be noted that, for ordinary skilled in the art, some improvements and refinements without departing from the principle of the present application are also considered to be within the protection scope of the present application.

Claims

1. A kernel fuzzy test case generation method based on shuffling algorithm, characterized in that: include: S1, shuffling algorithm initialization; S2: Randomly take a kernel test case p from the corpus, apply the shuffling algorithm mathematical model to mutate the kernel test case p to generate a fuzzy test case; S3: After m steps of S2, generate m fuzzy test cases 、 、 … , forming a fuzzy test case set ; S4: Generated fuzz test case set Conduct a chi-square test; S5: Judge the result of the chi-square test. If the fuzzy test case is random, jump to step S6; if the fuzzy test case is not random, jump back to step S1; S6: Start the test environment with the kernel to be tested and the specified file system, input the fuzzy test case set obtained in step S3 into the test environment for execution, and each fuzzy test case calls the interface of the kernel to be tested to implement fuzz testing of the kernel. When the test environment crashes, relevant logs are generated to describe the crash information for analysis.

2. The kernel fuzzy test case generation method based on the shuffling algorithm according to claim 1 is characterized in that: The method for generating fuzzy test cases by mutation in step S2 includes: S21: Deeply clone the kernel test case p to generate a test case g; S22: For the test case g generated by deep cloning, a shuffling algorithm is performed to generate a fuzzy test case.

3. The kernel fuzzy test case generation method based on the shuffling algorithm according to claim 2 is characterized in that: The specific process of step S21 is as follows: S211: Create a new Prog structure object p1; S212: assign p.Target of kernel test case p to p1.Target; S213: Copy p.Calls of kernel test case p and assign the result to p1.Calls; S214: Create a new Call structure pointer slice calls, whose length is the same as the original Call structure pointer slice origCalls; S215: traverse origCalls, copy each element, store the result in the corresponding position of calls, and assign calls to Calls of the new Prog structure object p1; S216: Copy a single Call structure and create a new Call structure object c1; S217: Assign the Meta field value of the original Call structure object directly to the Meta field of c1; S218: Check whether the Ret field of the original Call structure object is nil; if it is not nil, copy Ret and convert the result to After type, assign it to the Ret field of c1; S219: Traverse the Args field of the original Call structure object, copy each parameter method of the Arg type, and store the copied result in the corresponding position of the new slice c1.Args; S2110: Assign the Props field value of the original Call structure object directly to the Props field of c1; S2111: Returns the pointer of the newly created Call structure object c1; S2112: Through the above steps, deep cloning of the kernel test case p is completed to obtain the test case g.

4. The kernel fuzzy test case generation method based on the shuffling algorithm according to claim 2 is characterized in that: The specific process of step S22 is as follows: S221: Consider the test case g as a set S, the system calls in the test case g correspond to the elements in the set, and the number of system calls in the test case g, len(g.Calls), is considered the number of elements in the set n; S222: The last element from the set S First, for each element , i decreases from n to 2, and an index is randomly generated based on uniform distribution , then swap the elements and The positions of , constitute an iterative random transformation: ; Where U(1,i): represents a uniformly distributed random variable on the interval [1,i], Indicates that j obeys the uniform distribution on the interval [1,i]; represents the set S before the i-th exchange, represents the set S after the i-th exchange, Indicates exchange The two elements indexed by i and j in the set are returned as a new set. ; S223: After n-1 random swap operations, the order of elements in set S is completely disrupted; S224: Adjust the order of system calls according to the order of elements in the scrambled set S to generate a fuzzy test case.

5. The kernel fuzzy test case generation method based on the shuffling algorithm according to claim 1 is characterized in that: The chi-square test method in step S4 includes: S41: Fuzz test case set The algorithm consists of m fuzz test cases, each of which consists of an indeterminate number of system calls. The actual frequency of each adjacent system call pair in these m fuzz test cases is counted. The statistical method is as follows: when the shuffling algorithm completes one time, the frequency of each adjacent two system calls in the generated fuzz test case is counted, and the frequency data of adjacent system call pairs is quickly stored in a hash table. S42: After completing m statistics, calculate the chi-square statistic; chi-square statistic , k represents the number of adjacent system call pairs; first calculate the theoretical frequency , ; Combine the actual frequency of each adjacent system call pair , calculate the contribution value of each adjacent system call pair , then add up the contribution values ​​of all adjacent system calls to get the chi-square statistic; check the chi-square distribution table to get the critical value , Represents the significance level, k-1 represents the value of the degrees of freedom, and compares the chi-square statistic and the critical value.

6. The kernel fuzzy test case generation method based on the shuffling algorithm according to claim 1 is characterized in that: The judgment on the result of the chi-square test in step S5 includes: S51: If , then the fuzzy test case set is considered to obey uniform distribution and the fuzzy test case is random. Enter the test environment to perform kernel testing and jump to step S6; S52: If , then the fuzzy test case is considered not random and jump to step S1.

7. The kernel fuzzy test case generation method based on the shuffling algorithm according to claim 6 is characterized in that: In step S52, if the fuzzy test case set If the actual frequency of adjacent system call pairs is significantly higher than the theoretical frequency, the test cases generated by this shuffling algorithm are overly biased towards specific combinations. When jumping to step S1 for the next m rounds of shuffling, the high-frequency system call pairs in the hash table storing the frequency data of adjacent system call pairs are given a lower mutation priority, forcing the shuffling algorithm to explore the low-frequency area and increase the randomness of the test cases after mutation.

8. A kernel fuzzy test case generation device based on shuffling algorithm, characterized in that: include: Initialization module: shuffling algorithm initialization; Shuffling module: randomly takes a kernel test case p from the corpus, applies the shuffling algorithm mathematical model to mutate the kernel test case p to generate a fuzzy test case; Use case set module: After m steps S2, generate m fuzzy test cases 、 、 … , forming a fuzzy test case set ; Chi-square test module: for the generated fuzzy test case set Conduct a chi-square test; Judgment module: judges the result of the chi-square test. If the fuzzy test case is random, jump to the test module; If the fuzz test case is not random, jump back to the initialization module; Test module: Use the kernel to be tested and the specified file system to start the test environment, input the fuzzy test case set obtained by the use case set module into the test environment for execution, and each fuzzy test case calls the interface of the kernel to be tested to implement fuzz testing of the kernel. When the test environment crashes, relevant logs are generated to describe the crash information for analysis.

9. A computer-readable storage medium storing a computer program, characterized in that: The computer program is used to execute the kernel fuzzy test case generation method based on the shuffling algorithm as described in any one of claims 1 to 7.

10. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the kernel fuzzy test case generation method based on the shuffling algorithm as described in any one of claims 1 to 7 is implemented.

Citation Information

Patent Citations

  • Fuzzy test case adaptive variation method and device based on reinforcement learning

    CN110175120A

  • Industrial control protocol fuzz testing system and method based on reinforcement learning

    CN114661621A

  • Operating system kernel fuzzy test seed evaluation and distribution method

    CN114840437A

  • Context-aware dependency-guided kernel fuzz test case variation method and system

    CN116541268A

  • Smart contract security detection method based on hybrid fuzzy test

    CN118503083A