A program detection method and device
Through mixed symbol execution and clustering technology, the program is divided into stage subprograms, which solves the problems of low code coverage and detection efficiency caused by path explosion in the existing technology, and achieves more efficient program detection.
Patent Information
- Application Number
- CN202110325581.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-03-26
- Publication Date
- 2025-06-20
- Estimated Expiration
- 2041-03-26
AI Technical Summary
Existing symbol execution tests are prone to path explosions when facing programs that contain multi-conditional judgments, loops or recursive instructions, resulting in low code coverage and low detection efficiency.
By inputting the seed file into the program to be tested for mixed symbol execution, determining the seed path, and recording the time series data of the basic block execution information, clustering and dividing it into stage subprograms, recording the seed state values of the test cases in the stage subprograms, and conducting symbolic execution tests according to the symbolic execution strategy.
This method can reach the input-related statement corresponding to the seed state value in a short time, avoiding inefficient detection caused by falling into loops or recursive instructions, and improve code coverage and program detection efficiency.
Smart Images

Figure CN112988587B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of software, and in particular to a program detection method and device. Background Art
[0002] With the development of science and technology, program detection technology continues to improve.
[0003] Currently, the existing technology can use symbolic execution testing to perform program detection. Among them, symbolic execution testing can detect program vulnerabilities by executing program code. Symbolic execution testing can specifically include static symbolic execution testing and dynamic symbolic execution testing.
[0004] However, when there are many conditional judgments, loops, or recursive instructions in the program to be tested, symbolic execution testing will inevitably produce path explosion during the process of program detection. In the case of path explosion, the existing symbolic execution test may have a low code coverage rate for the program to be tested, resulting in low program detection efficiency. Summary of the invention
[0005] In view of the above problems, the present invention provides a program detection method and device that overcomes the above problems or at least partially solves the above problems. The technical solution is as follows:
[0006] A program detection method, comprising:
[0007] Inputting a seed file into the program to be tested to perform hybrid symbolic execution to determine a seed path in the program to be tested, wherein the seed file includes a test case;
[0008] In the process of inputting the seed file into the program to be tested for hybrid symbolic execution, determining time series data of basic block execution information;
[0009] Clustering the time series data to divide a target subprogram into at least one stage subprogram, wherein the target subprogram is composed of basic blocks of the program to be tested on the seed path;
[0010] Recording a seed state value of the test case in at least one of the phase subroutines;
[0011] According to the symbolic execution strategy, at least one of the seed state values is input into the program to be tested to carry out symbolic execution testing.
[0012] Optionally, the determining of the time series data of the basic block execution information includes:
[0013] Determine basic block vectors corresponding to multiple consecutive time periods with equal durations respectively, where the basic block vectors include execution marking data of each path basic block within the corresponding time period and the code coverage rate at the end of the corresponding time period. The path basic block is the basic block of the program to be tested on the seed path, and the execution marking data is used to mark whether the path basic block is executed within the corresponding time period;
[0014] Determine each of the determined basic block vectors as the time series data.
[0015] Optionally, the determining basic block vectors corresponding to multiple consecutive time periods with equal durations respectively includes:
[0016] Record the execution marking data of each path basic block respectively within multiple consecutive time periods with equal durations;
[0017] Perform normalization processing on the execution marking data within each time period respectively to obtain the normalized data of each time period;
[0018] Calculate the code coverage rate at the end of each time period respectively;
[0019] Determine the normalized data of each time period and the corresponding code coverage rate as a basic block vector respectively.
[0020] Optionally, the clustering of the time series data to divide the target subroutine into at least one stage subroutine includes:
[0021] Cluster each of the basic block vectors;
[0022] Determine first marking data from the execution marking data of the basic block vectors within the same cluster. The first marking data is the execution marking data used to mark that the path basic block is executed;
[0023] Determine the path basic blocks corresponding to each of the first marking data within the same cluster as one stage subroutine.
[0024] Optionally, the recording of the seed state value of the test case in at least one stage subroutine includes:
[0025] Determine path branch statements in at least one stage subroutine;
[0026] Record the target symbolic path constraint expressions formed respectively when each path branch statement is executed for the first time;
[0027] Determine each of the target symbolic path constraint expressions as the seed state value of the test case in the corresponding stage subroutine.
[0028] Optionally, the step of performing symbolic execution testing by inputting at least one of the seed state values into the program under test according to the symbolic execution policy includes:
[0029] Inputting the corresponding seed state values into the program under test in sequence according to the position order of the respective stage subroutines in the program under test to perform symbolic execution testing.
[0030] A program detection device includes: a first determination unit, a second determination unit, a partitioning unit, a first recording unit, and a testing unit, where:
[0031] The first determination unit is configured to: input a seed file into the program under test for hybrid symbolic execution to determine the seed paths in the program under test, where the seed file includes test cases;
[0032] The second determination unit is configured to: during the process of inputting the seed file into the program under test for hybrid symbolic execution, determine the time series data of the basic block execution information;
[0033] The partitioning unit is configured to: perform clustering on the time series data to divide the target subroutine into at least one stage subroutine, where the target subroutine is composed of the basic blocks of the program under test on the seed paths;
[0034] The first recording unit is configured to: record the seed state values of the test cases in at least one of the stage subroutines;
[0035] The testing unit is configured to: according to the symbolic execution policy, input at least one of the seed state values into the program under test to perform symbolic execution testing.
[0036] Optionally, the second determination unit includes: a third determination unit and a fourth determination unit, where:
[0037] The third determination unit is configured to: during the process of inputting the seed file into the program under test for hybrid symbolic execution, respectively determine the basic block vectors corresponding to multiple consecutive time periods with equal durations, where the basic block vector includes the execution marking data of each path basic block within the corresponding time period and the code coverage rate at the end of the corresponding time period, the path basic block is the basic block of the program under test on the seed path, and the execution marking data is used to mark whether the path basic block is executed within the corresponding time period;
[0038] The fourth determination unit is configured to: determine the determined basic block vectors as the time series data.
[0039] Optionally, the third determination unit includes: a second recording unit, a processing unit, an obtaining unit, a calculation unit, and a fifth determination unit, where:
[0040] The second recording unit is configured to perform: during the process of inputting the seed file into the program to be tested for hybrid symbolic execution, record the execution mark data of each path basic block in a plurality of consecutive time periods with equal durations;
[0041] The processing unit is configured to perform: perform normalization processing on the execution mark data in each of the time periods respectively;
[0042] The obtaining unit is configured to perform: obtain the data after normalization processing of each of the time periods;
[0043] The calculation unit is configured to perform: calculate the code coverage rate at the end of each of the time periods respectively;
[0044] The fifth determination unit is configured to perform: determine the data after normalization processing of each of the time periods and the corresponding code coverage rate as a basic block vector respectively.
[0045] Optionally, the partitioning unit includes: a clustering unit, a sixth determination unit, and a seventh determination unit, where:
[0046] The clustering unit is configured to perform: cluster each of the basic block vectors;
[0047] The sixth determination unit is configured to perform: in the execution mark data of each of the basic block vectors within the same cluster, determine the first mark data, and the first mark data is the execution mark data used to mark that the path basic block is executed;
[0048] The seventh determination unit is configured to perform: determine the path basic blocks corresponding to the first mark data within the same cluster as one of the stage subroutines.
[0049] Optionally, the first recording unit includes: an eighth determination unit, a second recording unit, and a ninth determination unit, where:
[0050] The eighth determination unit is configured to perform: determine path branch statements in at least one of the stage subroutines;
[0051] The second recording unit is configured to perform: record the target symbolic path constraint expressions formed when each of the path branch statements is first executed respectively;
[0052] The ninth determination unit is configured to perform: respectively determining each of the target symbolic path constraint expressions as the seed state value of the test case in the corresponding stage subroutine.
[0053] Optionally, the test unit is configured to perform: sequentially inputting the corresponding seed state values into the program under test in the order of the positions of the stage subroutines in the program under test to perform symbolic execution testing.
[0054] The program detection method and device provided in this embodiment can input a seed file into the program under test for hybrid symbolic execution to determine the seed paths in the program under test. The seed file includes test cases. During the process of inputting the seed file into the program under test for hybrid symbolic execution, time series data of basic block execution information is determined, and the time series data is clustered to divide the target subroutine into at least one stage subroutine. The target subroutine is composed of basic blocks of the program under test on the seed paths. The seed state values of the test cases in at least one stage subroutine are recorded, and according to the symbolic execution strategy, at least one seed state value is input into the program under test to perform symbolic execution testing.
[0055] The present invention can input the seed state value as the initial state value of the test case into the program under test. When performing symbolic execution testing for the corresponding stage subroutine, it can enable symbolic execution to avoid complex path exploration. That is, it can reach the statement related to the input corresponding to the seed state value in a certain stage subroutine in a short time, and can continue to perform symbolic execution testing from that statement, avoiding being trapped in a certain stage subroutine due to executing loop or recursive instructions, etc. This enables symbolic execution to explore other branch paths that do not belong to the seed path for a longer time within a limited time, execute the code corresponding to other branch paths in the program under test, explore more or deeper paths in the program under test within a limited time, improve the code coverage rate of the program under test, and improve the program detection efficiency and detection quality.
[0056] The above description is only an overview of the technical solution of the present invention. In order to be able to understand the technical means of the present invention more clearly, it can be implemented according to the content of the specification. And in order to make the above and other purposes, features and advantages of the present invention more obvious and understandable, the following specifically describes the embodiments of the present invention. Description of the Drawings
[0057] By reading the detailed description of the preferred embodiments below, various other advantages and benefits will become clear to those of ordinary skill in the art. The drawings are only for the purpose of showing the preferred embodiments and are not considered to be a limitation of the present invention. And throughout the drawings, the same reference numerals are used to represent the same components. In the drawings:
[0058] Figure 1 Shows a flowchart of a program detection method proposed by an embodiment of the present invention;
[0059] Figure 2 Shows a flowchart of another program detection method proposed by an embodiment of the present invention;
[0060] Figure 3 Shows a flowchart of another program detection method proposed by an embodiment of the present invention;
[0061] Figure 4 Shows a schematic diagram of the execution flow of each path basic block in a target subroutine proposed by an embodiment of the present invention;
[0062] Figure 5 Shows a schematic diagram of the execution mark for a path basic block proposed by an embodiment of the present invention;
[0063] Figure 6 Shows a schematic diagram of obtaining a vector corresponding to a vertical long bar proposed by an embodiment of the present invention;
[0064] Figure 7 Shows a schematic diagram of obtaining a basic block vector corresponding to each vertical long bar proposed by an embodiment of the present invention;
[0065] Figure 8 Shows a schematic diagram of stage division for a target subroutine proposed by an embodiment of the present invention;
[0066] Figure 9 Shows a schematic diagram of the structure of the first program detection device proposed by an embodiment of the present invention. Detailed implementation manners
[0067] Hereinafter, exemplary embodiments of the present disclosure will be described in more detail with reference to the accompanying drawings. Although the exemplary embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure can be implemented in various forms and should not be limited by the embodiments set forth herein. On the contrary, these embodiments are provided so that the present disclosure can be more thoroughly understood and the scope of the present disclosure can be completely conveyed to those skilled in the art.
[0068] As Figure 1 shown, an embodiment of the present invention proposes a program detection method, which may include the following steps:
[0069] S101. Input a seed file into a program to be tested for hybrid symbolic execution to determine a seed path in the program to be tested, where the seed file includes test cases;
[0070] Among them, the seed file can be a file used to input the program to be tested to start the hybrid symbolic execution of the program to be tested. The seed file may include test cases for performing hybrid symbolic execution on the program to be tested. The test cases may include specific values and symbolic values.
[0071] Among them, the hybrid symbolic execution may include concrete execution and symbolic execution. Specifically, in the process of using test cases to perform hybrid symbolic execution on the program to be tested in the present invention, the program to be tested can be concretely executed using specific values, and the program to be tested can be symbolically executed using symbolic values.
[0072] Among them, the program to be tested can be a computer program that needs to be detected. The program to be tested can be a computer program with a complete structure, or a computer program with an incomplete structure. Among them, the computer program with an incomplete structure can be composed of partial codes in the computer program with a complete structure.
[0073] Specifically, the program to be tested may include subroutines on one path or multiple paths. Each subroutine on each path can be composed of basic blocks of the program to be tested on the corresponding path. For example, the program to be tested may include a subroutine on the first path and a subroutine on the second path. The subroutine on the first path can be composed of basic blocks of the program to be tested on the first path, and the subroutine on the second path can be composed of basic blocks of the program to be tested on the second path.
[0074] Among them, the seed path can be a certain path in the program to be tested. The seed path can correspond to the test cases in the seed file. The present invention can use the test cases to perform hybrid symbolic execution on the target subroutine of the program to be tested on the seed path. Specifically, in the process of using test cases to perform hybrid symbolic execution on the program to be tested in the present invention, the basic blocks where execution occurs can be identified and recorded, and the seed path corresponding to the test case can be determined according to the basic blocks where execution occurs.
[0075] Optionally, the present invention can, before executing Figure 1 the method shown, in a Low Level Virtual Machine (LLVM), use an existing symbolic execution engine to analyze and identify the basic blocks of the program to be tested, and divide and identify each basic block in the program to be tested. The present invention can also use the symbolic execution engine to perform hybrid symbolic execution on the seed file and the program to be tested, and can, during the hybrid symbolic execution process, identify and record the basic blocks where execution occurs in the program to be tested, and determine the seed path corresponding to the seed file (i.e., the seed path corresponding to the test cases in the seed file).
[0076] It should be noted that when the present invention performs symbolic execution on a program, it can perform symbolic execution on a subprogram on a certain path of the program to explore that path in the program. Among them, during the process of performing symbolic execution on the subprogram, the present invention can globally maintain two parameters. One parameter can be a symbolic state, and the other parameter can be a symbolic path constraint expression. Specifically, when the present invention performs symbolic execution on a subprogram, that is, explores the corresponding path in the program, it can collect branch conditions at each path branch point on that path (i.e., the branch statement on the subprogram) and continuously update the symbolic path constraint expression. At the end of the symbolic execution, the present invention can solve the finally obtained symbolic path constraint expression by using a constraint solver to generate a first specific value corresponding to the explored path. It can be understood that if the generated first specific value is input into the program for specific execution, the subprogram on the explored path during the symbolic execution process can be specifically executed.
[0077] Optionally, when the present invention selects test cases, it can select test cases from the input cases set for the program to be tested; optionally, the present invention can also select test cases in a random selection manner. At this time, the specific value can be randomly selected, and the symbolic state corresponding to the symbolic value can be a mapping initialized to be empty, and the symbolic path constraint expression can be initialized to true; optionally, the present invention can also determine the corresponding test case, that is, determine the corresponding specific value, and determine the symbolic state and symbolic path constraint expression corresponding to the symbolic value for a known seed path. It should be noted that the present invention does not limit the selection method of test cases.
[0078] It can be understood that when there are many conditional judgments, loops, or recursions in the program to be tested, in the process of executing the program to be tested in the prior art, it is very likely that the same or similar code blocks will be repeatedly executed, that is, the same or similar execution behaviors are likely to repeatedly occur during the execution process. Among them, for the code blocks that cause the same or similar execution behaviors, the present invention can determine them as the code blocks in the same stage of the program to be tested.
[0079] Among them, when there are code blocks in multiple stages in the program to be tested, and there are a large number of paths in one or more of the code blocks in these stages, if the prior art attempts to detect a subroutine at a deeper position in the program to be tested, that is, to explore a deeper path, it is necessary to search for a path from one stage to the next stage within a limited time, that is, to determine input data that meets certain conditions. However, the paths from one stage to the next stage are likely to be few. When the prior art executes the program to be tested, it may get stuck in a certain stage and it is difficult to search for a path to enter another stage within a limited time, that is, it is difficult to determine input data that meets certain requirements or formats within a limited time. As a result, the prior art cannot explore the deeper paths of the program to be tested within a limited time, cannot execute the subroutines at deeper positions, resulting in a low code coverage rate, low program detection efficiency, and low program detection quality.
[0080] Specifically, the present invention can perform a single hybrid symbolic execution on the target subroutine of the program to be tested on the seed path. During the hybrid symbolic execution process, relevant information on the execution of basic blocks on the seed path at different time periods is respectively recorded, that is, basic block execution information, and the target subroutine can be divided into stages according to the recorded basic block execution information in multiple time periods. Then, symbolic execution tests are respectively carried out for each stage of the target subroutine to achieve stage crossing of the program, explore deeper paths in the program to be tested, improve the code coverage rate of the program to be tested, and improve the program detection efficiency and detection quality.
[0081] Specifically, during the hybrid symbolic execution of the program to be tested, for each statement or instruction of the program to be tested on the seed path, the present invention can first perform specific execution on it, and then immediately perform symbolic execution on it. For example, when the present invention performs hybrid symbolic execution on the Nth statement (N is a positive integer) on the seed path, it can first use the specific value when the (N - 1)th statement is executed to perform specific execution on the Nth statement, and then immediately use the symbolic value when the (N - 1)th statement is executed to perform symbolic execution on the Nth statement.
[0082] S102. During the process of inputting the seed file into the program to be tested for hybrid symbolic execution, determine the time series data of the basic block execution information;
[0083] Among them, the time series data can be composed of multiple element data arranged in the order of occurrence time, and each element data can include the basic block execution information of the hybrid symbolic execution within a corresponding time period with a preset value. For example, the first element data can include the basic block execution information of the hybrid symbolic execution within the first time period of 0.2 seconds, and the second element data can include the basic block execution information of the hybrid symbolic execution within the second time period of 0.2 seconds adjacent to the first time period.
[0084] Among them, the present invention can record the basic block execution information of the hybrid symbolic execution within each time period during the process of performing hybrid symbolic execution on the program to be tested.
[0085] Among them, the basic block execution information can reflect the execution behavior of the hybrid symbolic execution on each path basic block (the path basic block is the basic block of the program to be tested on the seed path) within the corresponding time period. For example, the basic block execution information can include at least one of the information such as whether each path basic block is executed within the corresponding time period, whether there is a conditional judgment statement in each path basic block, whether there is a recursive statement in each path basic block, and the code coverage rate at the end of the corresponding time period. Optionally, the basic block execution information can include: the code coverage rate at the end of the corresponding time period of the hybrid symbolic execution, and the execution mark data (such as marking whether the path basic block is executed or not) for marking the execution situation of each path basic block within the corresponding time period.
[0086] Optionally, the execution mark data can include 1 and 0. 1 can be used to mark that a certain path basic block is executed, and 0 can be used to mark that a certain path basic block is not executed. It should be noted that the present invention does not limit the specific value or specific type of the execution mark data.
[0087] Among them, the code coverage rate can be the ratio of the number of path basic blocks that have been executed by the hybrid symbolic execution on the seed path to the total number of path basic blocks on the seed path.
[0088] It should be noted that the composition information in the element data can be arranged in the element data in the corresponding order. For better description of the composition information and arrangement of the basic block execution information, the present invention proposes and describes it in combination with Example 1.
[0089] Example 1: When the seed path includes a first path basic block, a second path basic block, and a third path basic block, and the basic block execution information includes the execution mark data and code coverage rate of each path basic block, the first element data (i.e., the basic block execution information in the first time period) may include: {the execution mark data of the first path basic block in the first time period, the execution mark data of the second path basic block in the first time period, the execution mark data of the third path basic block in the first time period, the code coverage rate at the end of the first time period}; the second element data (i.e., the basic block execution information in the second time period) may include: {the execution mark data of the first path basic block in the second time period, the execution mark data of the second path basic block in the second time period, the execution mark data of the third path basic block in the second time period, the code coverage rate at the end of the second time period}.
[0090] Specifically, when the present invention inputs a test case into the program to be tested for hybrid symbolic execution, it can, according to the cycle duration, count the basic block execution information of the hybrid symbolic execution on the seed path to obtain the element data corresponding to each time period with equal and continuous durations, so as to obtain time series data. For example, the present invention can count the basic block execution information within the first cycle duration, and then count the basic block execution information within the second cycle duration, determine the basic block execution information within the first cycle duration as the first element data, and determine the basic block execution information within the second cycle duration as the second element data.
[0091] Among them, the cycle duration can be formulated by those skilled in the art according to the actual situation, and the present invention does not limit this. For example, the present invention can use the time required to execute 1000 instructions as the cycle duration.
[0092] S103. Cluster the time series data to divide the target subroutine into at least one stage subroutine, where the target subroutine is composed of the basic blocks of the program to be tested on the seed path;
[0093] Among them, the target subroutine can be the subroutine of the program to be tested on the seed path.
[0094] Among them, the stage subroutine can be the code block of a certain stage in the target subroutine, that is, the code block with the same or similar execution behavior. It can be understood that the stage subroutine can also be a subroutine in the target subroutine.
[0095] Specifically, after obtaining the time series data, the present invention can cluster the element data in the time series data to divide the element data with the same or similar basic block execution information in continuous time periods into the same cluster, that is, divide the element data with the same or similar overall execution behavior in continuous time periods into the same cluster.
[0096] For example, for first element data, second element data, and third element data corresponding to consecutive first time period, second time period, and third time period respectively, if the basic block execution information in the first element data and the second element data is the same or similar, the present invention can divide the first element data and the second element data into the same cluster; if the basic block execution information in the first element data, the second element data, and the third element data is the same or similar, the present invention can divide the first element data, the second element data, and the third element data into the same cluster; wherein, the time periods corresponding to the first element data and the third element data are non - consecutive time periods. At this time, even if the basic block execution information in the first element data and the third element data is the same or similar, and the basic block execution information in the first element data and the second element data is not similar, or the basic block execution information in the second element data and the third element data is not similar, the present invention can also prohibit dividing the first element data and the third element data into the same cluster.
[0097] It should be noted that if a certain element data is not similar to adjacent element data, the present invention can divide this element data into a separate cluster. For example, for first element data, second element data, and third element data corresponding to consecutive first time period, second time period, and third time period respectively, if the basic block execution information of the second element data is not similar to that of the first element data, and the basic block execution information of the second element data is not similar to that of the third element data, the present invention can divide the second element data into a separate cluster.
[0098] Specifically, the present invention can use a clustering algorithm for the above - mentioned clustering process, such as the K - means algorithm.
[0099] Specifically, within the element data of the same cluster, the path basic blocks that have executed can be divided into code blocks of the same stage, that is, sub - programs of the same stage. For example, for the first element data and the second element data within the same cluster, if the first path basic block in the first element data has executed and the second path basic block in the second element data has executed, the present invention can divide the first path basic block and the second path basic block into code blocks of the same stage.
[0100] S104. Record the seed state value of the test case in at least one stage sub - program;
[0101] Among them, the seed state value can include the symbolic path constraint expression formed when the test case passes through the input - related statements in the stage sub - program.
[0102] Among them, the input - related statements can be statements that can generate path branches in the program, such as conditional judgment, error checking, or loop instructions, that is, path - branching statements.
[0103] Specifically, in the process of performing hybrid symbolic execution on the target subroutine using test cases, the present invention can record the symbolic path constraint expressions formed by the test cases when passing through the input-related statements.
[0104] It can be understood that when there are input-related statements in a stage subroutine, symbolic execution can enter other branch paths that do not belong to the seed path from the input-related statements. Therefore, the present invention can record the seed state values of the test cases, and subsequently use the seed state values as the initial state values of the test cases to input into the program to be tested for symbolic execution testing, which can enable symbolic execution to reach the corresponding input-related statements in a short time, and can explore other branch paths of non-seed paths in the case of achieving stage traversal, thereby improving code coverage.
[0105] Among them, for a stage subroutine with input-related statements, the presence of instructions such as conditional judgments and loops may cause the code blocks in the stage subroutine to be executed multiple times, and its input-related statements may also be executed multiple times. Therefore, there may be multiple symbolic constraint expressions recorded during the execution of the stage subroutine. Specifically, the present invention can determine the symbolic constraint expression formed when the input-related statements of the stage subroutine are first executed completely as the seed state value of the test case for subsequent symbolic execution testing, so that subsequent symbolic execution testing can start exploring other branch paths when it first reaches the input-related statements in the stage subroutine, which is beneficial to reducing the consumption of computer resources.
[0106] Optionally, step S104 may specifically include:
[0107] Determine path branch statements in at least one stage subroutine;
[0108] Respectively record the target symbolic path constraint expressions formed when each path branch statement is first executed completely;
[0109] Respectively determine each target symbolic path constraint expression as the seed state value of the test case in the corresponding stage subroutine.
[0110] Among them, the path branch statement may be the above-mentioned input-related statement.
[0111] Specifically, the present invention can record the target symbolic path constraint expression formed when symbolic execution first finishes executing the path branch statement after the path branch statement in the determination phase subroutine. For example, the present invention can record the target symbolic path constraint expression formed when symbolic execution first finishes executing the path branch statement in the first-phase subroutine after determining the path branch statement in the first-phase subroutine; after determining the path branch statement in the second-phase subroutine, record the target symbolic path constraint expression formed when symbolic execution first finishes executing the path branch statement in the second-phase subroutine.
[0112] Specifically, the present invention can determine the recorded target symbolic path constraint expression as the seed state value of the test case in the corresponding phase subroutine. For example, the present invention can determine the target symbolic path constraint expression recorded in the first-phase subroutine as the seed state value of the test case in the first-phase subroutine, and can determine the target symbolic path constraint expression recorded in the second-phase subroutine as the seed state value of the test case in the second-phase subroutine.
[0113] Specifically, during the process of performing hybrid symbolic execution, the present invention can correspondingly record the execution time of each input-related statement in the program under test, as well as the symbolic path constraint expression formed when the input-related statement is executed. After that, after dividing the phase subroutines, the present invention can determine the phase subroutine to which each input-related statement belongs, determine the symbolic path constraint expression corresponding to the input-related statement with the earliest execution time in the phase subroutine, and determine it as the target symbolic path constraint expression, that is, determine it as the seed state value of the test case in the phase subroutine.
[0114] It can be understood that the present invention can input the seed state value as the initial state value of the test case into the program under test to carry out symbolic execution testing. At this time, symbolic execution does not need to perform complex path exploration, that is, it can reach the corresponding input-related statement in a short time, explore other branch paths of non-seed paths, and carry out symbolic execution testing in the case of realizing phase crossing, which can effectively improve code coverage.
[0115] S105. According to the symbolic execution strategy, input at least one seed state value into the program under test to carry out symbolic execution testing.
[0116] Among them, the symbolic execution strategy can include the execution order of carrying out symbolic execution testing for different phase subroutines.
[0117] Specifically, the present invention can perform symbolic execution tests on the corresponding stage subroutines in sequence according to the execution order of each stage subroutine included in the symbolic execution strategy. For example, for the first-stage subroutine, the second-stage subroutine, and the third-stage subroutine, if in the symbolic execution strategy, the execution order of the first-stage subroutine is 1, the execution order of the second-stage subroutine is 2, and the execution order of the third-stage subroutine is 3, then when the present invention performs symbolic execution tests on the program under test according to the symbolic execution strategy, it can first perform symbolic execution tests on the first-stage subroutine, then perform symbolic execution tests on the second-stage subroutine, and finally perform symbolic execution tests on the third-stage subroutine.
[0118] It can be understood that the present invention can perform symbolic execution tests on one stage subroutine by only using the seed state value corresponding to one stage subroutine, or can perform symbolic execution tests on each stage subroutine by using the seed state values corresponding to different stage subroutines respectively.
[0119] Specifically, the present invention can sequentially input the seed state values corresponding to each stage subroutine into the program under test according to the symbolic execution strategy to perform symbolic execution tests (that is, sequentially use the seed state values corresponding to each stage subroutine as the initial state values of the test cases and input them into the program under test to perform symbolic execution tests). For example, when the execution orders of the first-stage subroutine and the second-stage subroutine in the program under test are 1 and 2 respectively, the present invention can first input the seed state value corresponding to the first-stage subroutine into the program under test to perform symbolic execution tests, and then input the seed state value corresponding to the second-stage subroutine into the program under test to perform symbolic execution tests.
[0120] Optionally, the symbolic execution test can include static symbolic execution test and dynamic symbolic execution test.
[0121] Optionally, the seed state value can only include a symbolic path constraint expression. In this case, the present invention can input the seed state value as the initial state value of the test case into the program under test to perform a static symbolic execution test on the program under test.
[0122] Optionally, the seed state value can also include a target specific value corresponding to the symbolic path constraint expression. It can be understood that the target specific value can be the specific value used for hybrid symbolic execution of the program under test; of course, the present invention can also solve the symbolic path constraint expression in the seed state value through a constraint solver to obtain the specific value corresponding to the symbolic path constraint expression.
[0123] It should be noted that when the seed state value includes a symbolic path constraint expression and a specific value, the present invention can input the seed state value as the initial state value of the test case into the program to be tested, and perform dynamic symbolic execution testing on the program to be tested.
[0124] Among them, in most cases, the path constraint conditions of the stage subroutines at the front position in the program to be tested are simpler than those of the stage subroutines at the back position. Therefore, when formulating the symbolic execution strategy, the present invention can consider the position order of the stage subroutines in the seed path.
[0125] Optionally, step S105 can be specifically:
[0126] According to the position order of each stage subroutine in the program to be tested, the corresponding seed state value is sequentially input into the program to be tested to carry out symbolic execution testing.
[0127] Specifically, the present invention can first perform symbolic execution testing on the stage subroutines at the front position in the program to be tested, and then perform symbolic execution testing on the stage subroutines at the back position, which is beneficial to improving the testing efficiency of symbolic execution testing.
[0128] It should be noted that when the present invention performs symbolic execution testing on a certain stage subroutine, it does not need to end this symbolic execution testing after covering all the code. The present invention can end this symbolic execution testing when the code coverage rate does not increase within a certain period of time, which is beneficial to avoiding the unnecessary consumption of testing resources; of course, the present invention can also set a preset testing duration, and end this symbolic execution testing when the testing duration of the symbolic execution testing exceeds the preset testing duration, which is beneficial to controlling the consumption of testing resources.
[0129] Among them, the preset testing duration can be formulated by technicians according to the actual situation, and the present invention does not limit this. Specifically, the present invention can increase the preset testing duration to increase the testing duration of the symbolic execution testing on the stage subroutine, that is, increase the path exploration duration, and try to increase the code coverage rate during symbolic execution testing, and increase the probability of increasing the code coverage rate.
[0130] Specifically, the present invention can set a preset overall testing duration for the symbolic execution testing on the target subroutine of the program to be tested on the seed path. When the sum of the testing durations for each stage subroutine exceeds the preset overall testing duration, the present invention can end this symbolic execution testing on the target subroutine, which is beneficial to controlling the consumption of overall testing resources. Among them, if the sum of the testing durations for each stage subroutine does not exceed the preset overall testing duration, the present invention can continue to perform symbolic execution testing on the basis of the path exploration of the previous stage subroutines.
[0131] It should also be noted that when the present invention inputs the seed state value as the initial state value of the test case into the program to be tested and conducts symbolic execution testing for the corresponding stage subroutine, the symbolic execution can be made without complex path exploration. It can avoid getting stuck in a certain stage subroutine due to executing loop or recursive instructions, etc. It can reach the statement related to the input corresponding to the seed state value in a certain stage subroutine in a short time, and can continue to conduct symbolic execution testing from this statement. At this time, the present invention can make the symbolic execution explore other branch paths that do not belong to the seed path, execute the code corresponding to other branch paths in the program to be tested, and explore more or deeper paths in the program to be tested within a limited time, thereby improving the code coverage rate of the program to be tested and improving the program detection efficiency and detection quality.
[0132] The program detection method proposed in this embodiment can input the seed file into the program to be tested for hybrid symbolic execution to determine the seed path in the program to be tested. The seed file includes test cases. During the process of inputting the seed file into the program to be tested for hybrid symbolic execution, the time series data of the basic block execution information is determined, and the time series data is clustered to divide the target subroutine into at least one stage subroutine. The target subroutine is composed of the basic blocks of the program to be tested on the seed path. The seed state value of the test case in at least one stage subroutine is recorded, and according to the symbolic execution strategy, at least one seed state value is input into the program to be tested to conduct symbolic execution testing. The present invention can input the seed state value as the initial state value of the test case into the program to be tested and conduct symbolic execution testing for the corresponding stage subroutine, which can make the symbolic execution without complex path exploration, that is, it can reach the statement related to the input corresponding to the seed state value in a certain stage subroutine in a short time, and can continue to conduct symbolic execution testing from this statement, avoiding getting stuck in a certain stage subroutine due to executing loop or recursive instructions, etc. It enables the symbolic execution to explore other branch paths that do not belong to the seed path for a longer time within a limited time, execute the code corresponding to other branch paths in the program to be tested, and explore more or deeper paths in the program to be tested within a limited time, improving the code coverage rate of the program to be tested and improving the program detection efficiency and detection quality.
[0133] Based on Figure 1 the steps shown, another program detection method is proposed in this embodiment, as Figure 2 shown. In this method, step S102 can specifically include the following steps:
[0134] S201. During the process of inputting the seed file into the program to be tested for hybrid symbolic execution, respectively determine the basic block vectors corresponding to multiple consecutive time periods with equal durations. The basic block vector includes the execution marking data of each path basic block within the corresponding time period, and the code coverage rate at the end of the corresponding time period. The path basic block is the basic block of the program to be tested on the seed path, and the execution marking data is used to mark whether the path basic block is executed within the corresponding time period.
[0135] It should be noted that in Figure 2 the method shown, the basic block execution information may include the execution marking data of each path basic block within the corresponding time period and the code coverage rate of the hybrid symbolic execution at the end of the corresponding time period.
[0136] Among them, the basic block vector corresponding to each time period can include the execution marking data of each path basic block on the seed path within the corresponding time period, and the code coverage rate of the hybrid symbolic execution at the end of the corresponding time period. For example, if the program to be tested includes five path basic blocks, namely the first path basic block, the second path basic block, the third path basic block, the fourth and fifth path basic blocks, on the seed path, and the execution marking data of these five path basic blocks in the first time period are 1, 1, 0, 0, and 0 respectively (0 can indicate that the path basic block is not executed, and 1 can indicate that the path basic block is executed), then the basic block vector corresponding to the first time period can be expressed as [2 / 5, 1, 1, 0, 0, 0], where 2 / 5 is the code coverage rate at the end of the first time period.
[0137] Among them, the present invention can periodically count the basic block execution information of the hybrid symbolic execution within the corresponding time period during the process of performing hybrid symbolic execution on the target subroutine using the test case, that is, it can respectively count the execution marking data of each path basic block within the corresponding time period and the code coverage rate of the hybrid symbolic execution at the end of the corresponding time period, so as to respectively determine the basic block vectors corresponding to multiple consecutive time periods with equal durations. For example, the present invention can count the execution marking data of each path basic block within the first time period and the code coverage rate of the hybrid symbolic execution at the end of the first time period, and determine the execution marking data of each path basic block and the code coverage rate within the first time period as the basic block vector corresponding to the first time period; then count the execution marking data of each path basic block within the second time period that is equal in duration and consecutive with the first time period, and the code coverage rate of the hybrid symbolic execution at the end of the second time period, and determine the execution marking data of each path basic block and the code coverage rate within the second time period as the basic block vector corresponding to the second time period.
[0138] S202. Determine the determined basic block vectors as time series data.
[0139] It should be noted that each basic block vector can be used as an element data in the time series data. The present invention can arrange the basic block vectors in chronological order to obtain the time series data.
[0140] It can be understood that in the above target subroutine, a code block containing loop execution instructions (i.e., a loop code segment) is very likely to be the code in the subroutine of the same stage. When executing the target subroutine, code blocks that exhibit the same or similar execution behaviors within consecutive time periods are very likely to be a loop code segment. Therefore, the present invention can determine the code blocks that exhibit the same or similar execution behaviors within consecutive time periods as the code blocks within the subroutine of the same stage. And in non-consecutive time periods, even if the same or similar execution behaviors occur, the present invention can consider that their execution behaviors do not belong to the execution behaviors within the subroutine of the same stage, and can consider the codes corresponding to the same or similar execution behaviors occurring in non-consecutive time periods as non-the same loop code segment, that is, the codes in non-the same stage subroutines.
[0141] It should be noted that when executing a loop code segment within the subroutine of the same stage in the target subroutine, the change rate of its code coverage rate within consecutive time periods can be small or unchanged. Therefore, the present invention can further determine whether the same or similar execution behaviors occur within consecutive time periods according to the size change of the code coverage rate within consecutive time periods, so as to determine whether the codes that exhibit the same or similar execution behaviors are the codes within the subroutine of the same stage.
[0142] Among them, if the present invention does not further determine whether the same or similar execution behaviors occur within consecutive time periods according to the code coverage rate, it may mis-determine the codes that exhibit the same or similar execution behaviors in non-consecutive time periods as the codes in the subroutine of the same stage, resulting in an incorrect division of the stage subroutines.
[0143] Specifically, the present invention can add the code coverage rate to the basic block vector, so that when subsequent clustering is performed using the time series data and the target subroutine is divided into stage subroutines, the basic block vectors that are adjacent in time and have the same or similar basic block execution information can be divided into the same cluster, improving the accuracy of the stage division of the target subroutine.
[0144] The program detection method proposed in this embodiment can respectively determine the basic block vectors corresponding to multiple time periods, and use the determined basic block vectors as time series data, improving the accuracy of the stage division of the target subroutine to improve the detection efficiency of the program to be tested.
[0145] Based on Figure 2 the steps shown, this embodiment proposes another program detection method, as Figure 3As shown, in this method, step S201 may specifically include the following steps:
[0146] S301. During the process of inputting the seed file into the program to be tested for hybrid symbolic execution, record the execution mark data of each path basic block respectively within a plurality of consecutive time periods with equal duration.
[0147] Specifically, the present invention can record the execution mark data of each path basic block on the target subroutine respectively within a plurality of consecutive time periods with equal duration. For example, within the first time period, record the execution mark data of each path basic block on the target subroutine, and within the second time period that is consecutive and has the same duration as the first time period, record the execution mark data of each path basic block on the target subroutine.
[0148] S302. Perform normalization processing on the execution mark data within each time period respectively to obtain the corresponding data after normalization processing.
[0149] Among them, the present invention can perform normalization processing on the execution mark data of each path basic block respectively within each time period.
[0150] Specifically, when performing normalization processing, the present invention can divide the execution mark data of each path basic block by the sum value of the execution mark data within the corresponding time period, and the data after division is the data after normalization processing. For example, within the first time period, if the execution mark data of each path basic block is 1, 1, 0, 0, and 0 respectively, the sum value of the execution mark data within the first time period is 2. The present invention can divide the execution mark data of each path basic block by 2 respectively to obtain 1 / 2, 1 / 2, 0, 0, and 0, and 1 / 2, 1 / 2, 0, 0, and 0 are the data after normalization processing.
[0151] S303. Calculate the code coverage rate at the end of each time period respectively.
[0152] Specifically, the present invention can obtain the code coverage rate corresponding to each time period respectively at the end of each time period. For example, the present invention can determine the code coverage rate corresponding to the first time period at the end of the first time period; the present invention can determine the code coverage rate corresponding to the second time period at the end of the second time period.
[0153] S304. Determine the data after normalization processing of each time period and the corresponding code coverage rate as a basic block vector respectively.
[0154] Specifically, for the normalized data and the corresponding code coverage in any time period, the present invention can determine each data in the normalized data in this time period and the corresponding code coverage as elements in a basic block vector to obtain a corresponding basic block vector. For example, for the first time period, if the normalized data is 0, 0, 1 / 2, 1 / 2, and 0, and the code coverage at the end of the first time period is 2 / 5, the present invention can use 0, 0, 1 / 2, 1 / 2, 0, and 2 / 5 as elements in a basic block vector to obtain the corresponding first basic block vector [2 / 5, 0, 0, 1 / 2, 1 / 2, 0].
[0155] It should be noted that the present invention does not limit the positions of the normalized data and the code coverage in the basic block vector. For example, the present invention can set the code coverage before the normalized data, such as the above first basic block vector; for another example, the present invention can also set the code coverage after the normalized data.
[0156] To better introduce the process of obtaining the basic block vector, the present invention proposes and combines the following Example 2 to illustrate the process of obtaining the basic block vector.
[0157] Example 2: As Figure 4 shown, this embodiment proposes a schematic diagram of the execution flow of each path basic block in a target subroutine. Among them, the target subroutine can include a total of 11 path basic blocks, namely path basic block 1, path basic block 2, path basic block 2... path basic block 10, and path basic block 11. There are input-related statements in path basic blocks 3 and 8. When executing the target subroutine, path basic blocks 3, 4, and 5 can be looped 3 times, and path basic blocks 7, 8, 9, and 10 can be looped 2 times. In the process of performing hybrid symbolic execution on the target subroutine, the present invention can use a graphical recording method to record and count the basic block execution information in multiple consecutive time periods with equal durations. Among them, if the duration of each time period is the duration required to execute 3 path basic blocks, the schematic diagram of the execution mark of the path basic block as shown in Figure 5 can be obtained.
[0158] In Figure 5In this invention, vertical bars are used to represent the execution status of each path basic block within a time period, and small rectangles are used within the vertical bars to mark whether the path basic block is executed within the corresponding time period. Specifically, within the first time period, path basic block 1, path basic block 2, and path basic block 3 are each executed once. Therefore, in this invention, small rectangles can be marked at the corresponding positions of path basic block 1, path basic block 2, and path basic block 3 in the first vertical bar. Specifically, within the second time period, path basic block 4, path basic block 5, and path basic block 3 are each executed once. Therefore, in this invention, small rectangles can be marked at the corresponding positions of path basic block 4, path basic block 5, and path basic block 3 in the second vertical bar. And so on, this invention can mark the execution status of each path basic block in seven vertical bars.
[0159] Among them, this invention can respectively obtain a corresponding vector for each vertical bar, and the execution marking data of each path basic block can be used as the elements at the corresponding positions in the basic block vector.
[0160] As Figure 6 shown, taking the sixth vertical bar as an example, this invention can obtain a corresponding vector for the sixth vertical bar. In this vector, its first element is the execution marking data of path basic block 1, the second element is the execution marking data of path basic block 2,..., and the eleventh element is the execution marking data of path basic block 11. And in the sixth vertical bar, three path basic blocks, namely path basic block 10, path basic block 7, and path basic block 8, are executed. At this time, when the execution marking data is 1 or 0 (0 can indicate that the path basic block is not executed, and 1 can indicate that the path basic block is executed), the vector corresponding to the sixth vertical bar can be [0, 0, 0, 0, 0, 0, 1, 1, 0, 1, 0].
[0161] After obtaining the vectors corresponding to each vertical bar, this invention can respectively perform normalization processing on the elements in each vector, that is, the execution marking data, to obtain the normalized data for the corresponding time period. After that, this invention can obtain the code coverage rate for the corresponding time period, and determine the corresponding basic block vector based on the normalized data for the corresponding time period and the code coverage rate. Taking Figure 6Taking the vector corresponding to the sixth vertical strip shown as an example, the present invention can normalize the elements in the vector [0, 0, 0, 0, 0, 0, 1, 1, 0, 1, 0] to obtain the normalized data corresponding to the sixth period, that is, [0, 0, 0, 0, 0, 0, 1 / 3, 1 / 3, 0, 1 / 3, 0]. Then, the code coverage rate of the corresponding period can be obtained, that is, the code coverage rate at the end of the sixth period is 10 / 11 (at the end of the sixth period, path basic blocks 1 to 10 have been executed, and path basic block 11 has not been executed). According to the normalized data corresponding to the sixth period and the code coverage rate of the corresponding period, the basic block vector corresponding to the sixth period is determined, that is, [0, 0, 0, 0, 0, 0, 1 / 3, 1 / 3, 0, 1 / 3, 0, 10 / 11]. As Figure 7 shown, the present invention can obtain seven basic block vectors corresponding to each vertical strip.
[0162] The program detection method proposed in this embodiment can record and statistically analyze the execution mark data and the corresponding code coverage rate of path basic blocks in multiple periods respectively, obtain the corresponding basic block vectors, improve the accuracy of stage division of the target subroutine, and thus improve the detection efficiency of the program to be tested.
[0163] Based on Figure 3 the steps shown, another program detection method is proposed in this embodiment. In this method, step S103 may specifically include:
[0164] S401. Cluster each basic block vector;
[0165] Specifically, the present invention can cluster each basic block vector after obtaining multiple basic block vectors corresponding to multiple periods respectively.
[0166] S402. Determine the first mark data among the execution mark data of each basic block vector within the same cluster. The first mark data is the execution mark data used to mark that the path basic block is executed;
[0167] Specifically, the present invention can identify the first mark data used to mark that the path basic block is executed among the basic block vectors belonging to the same cluster.
[0168] S403. Determine the path basic blocks corresponding to each first mark data within the same cluster as a stage subroutine.
[0169] Specifically, the present invention can first determine the executed path basic blocks corresponding to the first data within the same cluster, and then determine the determined path basic blocks as the path basic blocks in the same stage subroutine, that is, determine the path basic blocks executed during the period corresponding to the basic block vector of the same cluster as the path basic blocks in the same stage subroutine to determine at least one stage subroutine.
[0170] It should be noted that for each basic block vector within a cluster, the present invention can correspondingly determine a stage subroutine. If multiple clusters can be obtained after clustering, the present invention can correspondingly divide the target subroutine into multiple stage subroutines.
[0171] To better illustrate the process of dividing the stage subroutines, the present invention can be described in conjunction with Figure 7 the basic block vectors obtained in the above-mentioned Example 2 as shown. Specifically, the present invention can cluster Figure 7 the basic block vectors shown. After that, the basic block vectors can be clustered into three clusters. The first cluster can include the basic block vectors corresponding to the first time period, the second cluster can include the basic block vectors corresponding to the second, third, and fourth time periods respectively, and the third cluster can include the basic block vectors corresponding to the fifth, sixth, and seventh time periods respectively. Specifically, the present invention can determine the first marker data from the execution marker data of the basic block vectors in the first cluster, that is, determine three 1 / 3s. Then, the path basic blocks corresponding to these three 1 / 3s, namely path basic block 1, path basic block 2, and path basic block 3, are determined as the path basic blocks of the same stage subroutine, so as to determine a stage subroutine A in the target subroutine. By analogy, the present invention can determine another stage subroutine B in the target subroutine according to the second cluster, and determine another stage subroutine C in the target subroutine according to the third cluster, that is, the target subroutine can be divided into three stage subroutines. It can be understood that hybrid symbolic execution can execute the code on stage subroutine A within the first time period, execute the code on stage subroutine B within the second, third, and fourth time periods, and execute the code on stage subroutine C within the fifth, sixth, and seventh time periods, as Figure 8 shown.
[0172] The program detection method proposed in this embodiment can determine the path basic blocks that are executed within the same cluster as the same stage subroutine in the target subroutine, improve the accuracy of stage division for the target subroutine, and thus improve the detection efficiency of the program to be tested.
[0173] Corresponding to the method shown in Figure 1 as shown in Figure 9 this embodiment proposes a first program detection device, which can include: a first determination unit 101, a second determination unit 102, a division unit 103, a first recording unit 104, and a test unit 105, where:
[0174] The first determination unit 101 is configured to perform: input a seed file into the program to be tested for hybrid symbolic execution to determine the seed path in the program to be tested, and the seed file includes test cases;
[0175] Among them, the seed file can be a file used to input the program to be tested to start the hybrid symbolic execution of the program to be tested. The seed file may include test cases for performing hybrid symbolic execution on the program to be tested. The test cases may include specific values and symbolic values.
[0176] Among them, the hybrid symbolic execution may include concrete execution and symbolic execution. Specifically, in the process of using test cases to perform hybrid symbolic execution on the program to be tested, the present invention can use specific values to perform concrete execution on the program to be tested and use symbolic values to perform symbolic execution on the program to be tested.
[0177] Among them, the program to be tested can be a computer program that needs to be detected. The program to be tested can be a computer program with a complete structure or a computer program with an incomplete structure. Among them, the computer program with an incomplete structure can be composed of partial codes in the computer program with a complete structure.
[0178] Specifically, the program to be tested may include subroutines on one path or multiple paths. Each subroutine on each path can be composed of basic blocks of the program to be tested on the corresponding path.
[0179] Among them, the seed path can be a certain path in the program to be tested. The seed path can correspond to the test cases in the seed file. The present invention can use the test cases to perform hybrid symbolic execution on the target subroutine of the program to be tested on the seed path. Specifically, in the process of using test cases to perform hybrid symbolic execution on the program to be tested, the present invention can identify and record the basic blocks where execution occurs, and determine the seed path corresponding to the test cases according to the basic blocks where execution occurs.
[0180] Specifically, the present invention can perform one hybrid symbolic execution on the target subroutine of the program to be tested on the seed path. During the hybrid symbolic execution process, record the relevant information about the execution of the basic blocks on the seed path at different time periods, that is, the basic block execution information, and can divide the target subroutine into stages according to the recorded basic block execution information in multiple time periods. Then, perform symbolic execution tests for each stage of the target subroutine respectively to achieve stage crossing of the program, explore deeper paths in the program to be tested, improve the code coverage rate of the program to be tested, and improve the program detection efficiency and detection quality.
[0181] Specifically, in the process of performing hybrid symbolic execution on the program to be tested, for each statement or instruction of the program to be tested on the seed path, the present invention can first perform concrete execution on it, and then immediately perform symbolic execution on it.
[0182] The second determination unit 102 is configured to perform: during the process of inputting the seed file into the program to be tested for hybrid symbolic execution, determining time series data of basic block execution information;
[0183] Wherein, the time series data may be composed of multiple element data arranged in the order of occurrence time, and each element data may include the basic block execution information of the hybrid symbolic execution within a corresponding time period with a preset value of duration.
[0184] Wherein, the present invention can record the basic block execution information of the hybrid symbolic execution in each time period during the process of performing hybrid symbolic execution on the program to be tested.
[0185] Wherein, the basic block execution information can reflect the execution behavior of the hybrid symbolic execution on each path basic block on the seed path during the corresponding time period. Optionally, the basic block execution information may include: the code coverage rate at the end of the corresponding time period of the hybrid symbolic execution, and execution mark data for marking the execution situation of each path basic block during the corresponding time period.
[0186] Optionally, the execution mark data may include 1 and 0. 1 may be used to mark that a certain path basic block is executed, and 0 may be used to mark that a certain path basic block is not executed. It should be noted that the present invention does not limit the specific numerical value or specific type of the execution mark data.
[0187] Wherein, the code coverage rate may be the ratio of the number of path basic blocks that have been executed by the hybrid symbolic execution on the seed path to the total number of path basic blocks on the seed path.
[0188] It should be noted that the composition information in the element data may be arranged in the element data in the corresponding order.
[0189] Specifically, the present invention can, when inputting the test case into the program to be tested for hybrid symbolic execution, statistically calculate the basic block execution information of the hybrid symbolic execution on the seed path according to the cycle duration, so as to obtain element data corresponding to each time period with equal and continuous durations, thereby obtaining time series data.
[0190] Wherein, the cycle duration can be formulated by those skilled in the art according to the actual situation, and the present invention does not limit this. For example, the present invention can determine the cycle duration by using the time required to execute 1000 instructions.
[0191] The partitioning unit 103 is configured to perform: clustering the time series data to partition the target subroutine into at least one stage subroutine, where the target subroutine is composed of the basic blocks of the program to be tested on the seed path;
[0192] Among them, the target subroutine can be the subroutine of the program to be tested on the seed path.
[0193] Among them, the phase subroutine can be a code block of a certain phase in the target subroutine, that is, a code block with the same or similar execution behaviors. It can be understood that the phase subroutine can also be a subroutine in the target subroutine.
[0194] Specifically, after obtaining the time series data, the present invention can cluster the element data in the time series data to divide the element data that are in continuous time periods and have the same or similar basic block execution information into the same cluster, that is, divide the element data with the same or similar overall execution behaviors shown in the continuous time periods into the same cluster.
[0195] Specifically, the present invention can use a clustering algorithm for the above clustering process, such as the K-means algorithm.
[0196] Specifically, the present invention can divide the path basic blocks where execution occurs into code blocks of the same phase, that is, the same phase subroutines, within the element data of the same cluster.
[0197] The first recording unit 104 is configured to perform: recording the seed state values of the test case in at least one phase subroutine;
[0198] Among them, the seed state value can include the symbolic path constraint expression formed when the test case passes through the input-related statements in the phase subroutine.
[0199] Among them, the input-related statements can be statements that can generate path branches in the program, such as conditional judgment, error checking, or loop instructions, that is, path branch statements.
[0200] Specifically, the present invention can record the symbolic path constraint expression formed when the test case passes through the input-related statements during the process of performing hybrid symbolic execution on the target subroutine using the test case.
[0201] Optionally, the first recording unit 104 may include: an eighth determination unit, a second recording unit, and a ninth determination unit, where:
[0202] The eighth determination unit is configured to perform: determining path branch statements in at least one phase subroutine;
[0203] The second recording unit is configured to perform: respectively recording the target symbolic path constraint expressions formed when each path branch statement is first executed;
[0204] The ninth determination unit is configured to perform: respectively determining each target symbolic path constraint expression as the seed state value of the test case in the corresponding phase subroutine.
[0205] Among them, the path branch statement can be a statement related to the above input.
[0206] Specifically, the present invention can record the target symbolic path constraint expression formed when symbolic execution finishes executing the path branch statement for the first time after determining the path branch statement in the determination stage subroutine.
[0207] Specifically, the present invention can determine the recorded target symbolic path constraint expression as the seed state value of the test case in the corresponding stage subroutine.
[0208] Specifically, during the process of performing hybrid symbolic execution, the present invention can correspondingly record the execution time of each input-related statement in the program to be tested, as well as the symbolic path constraint expression formed when the input-related statement is executed. After that, after dividing the stage subroutines, the present invention can determine the stage subroutine to which each input-related statement belongs, determine the symbolic path constraint expression corresponding to the input-related statement with the earliest execution time in the stage subroutine, and determine it as the target symbolic path constraint expression, that is, determine it as the seed state value of the test case in the stage subroutine.
[0209] It can be understood that the present invention can input the seed state value as the initial state value of the test case into the program to be tested to carry out symbolic execution testing. At this time, symbolic execution does not need to perform complex path exploration, that is, it can reach the corresponding input-related statement in a short time, explore other branch paths of non-seed paths, and perform symbolic execution testing in the case of realizing stage crossing, which can effectively improve code coverage.
[0210] The test unit 105 is configured to execute: according to the symbolic execution strategy, input at least one seed state value into the program to be tested to carry out symbolic execution testing.
[0211] Among them, the symbolic execution strategy can include the execution order of performing symbolic execution testing for different stage subroutines.
[0212] Specifically, the present invention can perform symbolic execution testing for the corresponding stage subroutines in turn according to the execution order of each stage subroutine included in the symbolic execution strategy.
[0213] Specifically, the present invention can input the seed state values corresponding to each stage subroutine into the program to be tested in turn according to the symbolic execution strategy to carry out symbolic execution testing.
[0214] Among them, in most cases, the path constraint conditions of the stage subroutines in the front position in the program to be tested are simpler than those of the stage subroutines in the back position. Therefore, when formulating the symbolic execution strategy, the present invention can consider the position order of the stage subroutines in the seed path.
[0215] Optionally, the test unit 105 is configured to perform: in the order of the positions of the respective stage subroutines in the program to be tested, sequentially input the corresponding seed state values into the program to be tested to perform symbolic execution testing.
[0216] In the order of the positions of the respective stage subroutines in the program to be tested, sequentially input the corresponding seed state values into the program to be tested to perform symbolic execution testing.
[0217] Specifically, the present invention can first perform symbolic execution testing on the stage subroutines in the front positions in the program to be tested, and then perform symbolic execution testing on the stage subroutines in the rear positions, which is beneficial to improving the testing efficiency of symbolic execution testing.
[0218] The program detection device proposed in this embodiment can, by inputting the seed state value as the initial state value of the test case into the program to be tested, perform symbolic execution testing on the corresponding stage subroutines, so that symbolic execution does not need to perform complex path exploration, that is, it can reach the statement related to the input corresponding to the seed state value in a certain stage subroutine in a short time, and can continue to perform symbolic execution testing from this statement, avoiding being trapped in a certain stage subroutine due to executing loop or recursive instructions, etc., enabling symbolic execution to explore other branch paths that do not belong to the seed path for a longer time within a limited time, execute the code corresponding to other branch paths in the program to be tested, explore more or deeper paths in the program to be tested within a limited time, improve the code coverage rate of the program to be tested, and improve the program detection efficiency and detection quality.
[0219] Based on Figure 9 the shown structural schematic diagram, this embodiment proposes a second program detection device. In this device, the second determination unit 102 may include: a third determination unit and a fourth determination unit, where:
[0220] The third determination unit is configured to perform: during the process of inputting the seed file into the program to be tested for hybrid symbolic execution, respectively determine the basic block vectors corresponding to a plurality of consecutive time periods with equal durations, where the basic block vector includes the execution marking data of each path basic block within the corresponding time period and the code coverage rate at the end of the corresponding time period, the path basic block is the basic block of the program to be tested on the seed path, and the execution marking data is used to mark whether the path basic block is executed within the corresponding time period;
[0221] The fourth determination unit is configured to perform: determine the determined basic block vectors as time series data.
[0222] Among them, the basic block execution information may include the execution marker data of each path basic block in the corresponding time period and the code coverage rate at the end of the corresponding time period of hybrid symbolic execution.
[0223] Among them, the basic block vector corresponding to each time period may include the execution marker data of each path basic block on the seed path in the corresponding time period and the code coverage rate at the end of the corresponding time period of hybrid symbolic execution.
[0224] Among them, the present invention can periodically count the basic block execution information of hybrid symbolic execution in the corresponding time period during the process of performing hybrid symbolic execution on the target subroutine using test cases.
[0225] It should be noted that each basic block vector can be used as an element data in the time series data. The present invention can arrange the basic block vectors in chronological order to obtain the time series data.
[0226] Specifically, the present invention can add the code coverage rate to the basic block vector, so that when subsequent clustering is performed using the time series data to divide the target subroutine into stage subroutines, the basic block vectors in adjacent time periods with the same or similar basic block execution information can be divided into the same cluster, improving the accuracy of stage division of the target subroutine.
[0227] The program detection device proposed in this embodiment can respectively determine the basic block vectors corresponding to multiple time periods and use the determined basic block vectors as time series data to improve the accuracy of stage division of the target subroutine, thereby improving the detection efficiency of the program to be tested.
[0228] Based on the above-mentioned second program detection device, this embodiment proposes a third program detection device. In the third program detection device, the third determination unit may include: a second recording unit, a processing unit, an obtaining unit, a calculation unit, and a fifth determination unit, where:
[0229] The second recording unit is configured to execute: during the process of inputting the seed file into the program to be tested for hybrid symbolic execution, record the execution marker data of each path basic block in multiple consecutive time periods with equal duration;
[0230] The processing unit is configured to execute: perform normalization processing on the execution marker data in each time period respectively;
[0231] The obtaining unit is configured to execute: obtain the data after normalization processing in each time period;
[0232] The calculation unit is configured to execute: calculate the code coverage rate at the end of each time period respectively;
[0233] The fifth determination unit is configured to perform: respectively determine the normalized data of each time period and the corresponding code coverage as a basic block vector.
[0234] Specifically, the present invention can record the execution mark data of each path basic block on the target subroutine in multiple consecutive time periods with equal duration.
[0235] Among them, the present invention can perform normalization processing on the execution mark data of each path basic block in each time period.
[0236] Specifically, when performing normalization processing, the present invention can divide the execution mark data of each path basic block by the sum value of the execution mark data in the corresponding time period, and the divided data is the normalized data.
[0237] Specifically, the present invention can obtain the code coverage corresponding to each time period at the end of each time period.
[0238] Specifically, for the normalized data and the corresponding code coverage in any time period, the present invention can determine each data in the normalized data of the time period and the corresponding code coverage as elements in a basic block vector to obtain a corresponding basic block vector.
[0239] It should be noted that the present invention does not limit the positions of the normalized data and the code coverage in the basic block vector.
[0240] The program detection device proposed in this embodiment can record and statistically analyze the execution mark data and the corresponding code coverage of the path basic block in multiple time periods, obtain the corresponding basic block vector, improve the accuracy of stage division of the target subroutine, and thus improve the detection efficiency of the program to be tested.
[0241] Based on the third program detection device, this embodiment proposes a fourth program detection device. In the fourth program detection device, the division unit 103 may include: a clustering unit, a sixth determination unit, and a seventh determination unit, where:
[0242] The clustering unit is configured to perform: clustering each basic block vector;
[0243] The sixth determination unit is configured to perform: determine the first mark data in the execution mark data of each basic block vector within the same cluster, and the first mark data is the execution mark data used to mark that the path basic block is executed;
[0244] The seventh determination unit is configured to perform: determine the path basic blocks corresponding to each first mark data within the same cluster as a stage subroutine.
[0245] Specifically, after obtaining multiple basic block vectors corresponding to multiple time periods respectively, the present invention can cluster each basic block vector.
[0246] Specifically, the present invention can identify first marking data for marking the execution of path basic blocks among the basic block vectors within the same cluster.
[0247] Specifically, the present invention can first determine each executed path basic block corresponding to the first data within the same cluster, and then determine the determined path basic blocks as the path basic blocks in the same-stage subroutine, that is, determine the path basic blocks executed during the time period corresponding to the basic block vectors of the same cluster as the path basic blocks of the same-stage subroutine, so as to determine at least one stage subroutine.
[0248] It should be noted that the present invention can correspondingly determine a stage subroutine for each basic block vector belonging to a cluster. If multiple clusters can be obtained after clustering, the present invention can correspondingly divide the target subroutine into multiple stage subroutines.
[0249] The program detection device proposed in this embodiment can determine the path basic blocks executed within the same cluster as the path basic blocks of the same stage in the target subroutine, improve the accuracy of stage division for the target subroutine, and thus improve the detection efficiency of the program to be tested.
[0250] It should also be noted that the term "including", "comprising" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed, or further includes elements inherent to such process, method, commodity or device. Without further limitation, the element defined by the statement "including one..." does not exclude the existence of another identical element in the process, method, commodity or device including the element.
[0251] The above are only embodiments of the present application and are not used to limit the present application. For those skilled in the art, various changes and modifications can be made to the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included within the scope of the claims of the present application.
Claims
1. A program detection method, characterized in that, Comprising: Inputting a seed file into a program to be tested for hybrid symbolic execution to determine a seed path in the program to be tested, wherein the seed file includes test cases; During the process of inputting the seed file into the program to be tested for hybrid symbolic execution, determining time series data of basic block execution information; Clustering the time series data to divide a target subroutine into at least one stage subroutine, where the target subroutine is composed of basic blocks of the program to be tested on the seed path; Recording the seed state values of the test cases in at least one of the stage subroutines; According to a symbolic execution strategy, inputting at least one of the seed state values into the program to be tested to conduct symbolic execution testing.
2. The method according to claim 1, characterized in that, The determining of the time series data of basic block execution information includes: Respectively determining basic block vectors corresponding to a plurality of consecutive time periods with equal durations, wherein the basic block vector includes execution marking data of each path basic block within the corresponding time period and the code coverage rate at the end of the corresponding time period, the path basic block being the basic block of the program to be tested on the seed path, and the execution marking data being used to mark whether the path basic block is executed within the corresponding time period; Determining each of the determined basic block vectors as the time series data.
3. The method according to claim 2, characterized in that, The respectively determining of the basic block vectors corresponding to a plurality of consecutive time periods with equal durations includes: Respectively recording the execution marking data of each of the path basic blocks within a plurality of consecutive time periods with equal durations; Respectively performing normalization processing on the execution marking data within each of the time periods to obtain the normalized data of each of the time periods; Respectively calculating the code coverage rate at the end of each of the time periods; Respectively determining the normalized data of each of the time periods and the corresponding code coverage rate as a basic block vector.
4. The method according to claim 2 or 3, characterized in that, The clustering of the time series data to divide the target subroutine into at least one stage subroutine includes: Clustering each of the basic block vectors; Among the execution marking data of each of the basic block vectors within the same cluster, determining first marking data, where the first marking data is the execution marking data used to mark that the path basic block is executed; Determining the path basic blocks corresponding to each of the first marking data within the same cluster as one of the stage subroutines.
5. The method according to claim 1, characterized in that, The recording of the seed state values of the test cases in at least one of the stage subroutines includes: In at least one of the stage subroutines, determining path branch statements; Respectively recording the target symbolic path constraint expressions formed when each of the path branch statements is first executed; Respectively determining each of the target symbolic path constraint expressions as the seed state value of the test case in the corresponding stage subroutine.
6. The method according to claim 1, characterized in that, The inputting of at least one of the seed state values into the program to be tested to conduct symbolic execution testing according to a symbolic execution strategy includes: According to the position order of each of the stage subroutines in the program to be tested, sequentially inputting the corresponding seed state values into the program to be tested to conduct symbolic execution testing.
7. A program detection device, characterized in that, Comprising: The first determination unit, the second determination unit, the division unit, the first recording unit, and the testing unit, where: The first determination unit is configured to perform: input the seed file into the program to be tested for hybrid symbolic execution to determine the seed path in the program to be tested, and the seed file includes test cases; The second determination unit is configured to perform: during the process of inputting the seed file into the program to be tested for hybrid symbolic execution, determine the time series data of the basic block execution information; The division unit is configured to perform: cluster the time series data to divide the target subroutine into at least one stage subroutine, and the target subroutine is composed of the basic blocks of the program to be tested on the seed path; The first recording unit is configured to perform: record the seed state values of the test cases in at least one of the stage subroutines; The testing unit is configured to perform: according to the symbolic execution strategy, input at least one of the seed state values into the program to be tested to carry out symbolic execution testing.
8. The device according to claim 7, characterized in that, The second determination unit includes: a third determination unit and a fourth determination unit, where: The third determination unit is configured to perform: during the process of inputting the seed file into the program to be tested for hybrid symbolic execution, respectively determine the basic block vectors corresponding to a plurality of consecutive time periods with equal durations, where the basic block vector includes the execution marking data of each path basic block within the corresponding time period and the code coverage rate at the end of the corresponding time period, the path basic block is the basic block of the program to be tested on the seed path, and the execution marking data is used to mark whether the path basic block is executed within the corresponding time period; The fourth determination unit is configured to perform: determine the determined basic block vectors as the time series data.
9. The device according to claim 8, characterized in that, The third determination unit includes: a second recording unit, a processing unit, an obtaining unit, a calculating unit, and a fifth determination unit, where: The second recording unit is configured to perform: during the process of inputting the seed file into the program to be tested for hybrid symbolic execution, respectively record the execution marking data of each path basic block within a plurality of consecutive time periods with equal durations; The processing unit is configured to perform: respectively perform normalization processing on the execution marking data within each time period; The obtaining unit is configured to perform: obtain the data after normalization processing of each time period; The calculating unit is configured to perform: respectively calculate the code coverage rate at the end of each time period; The fifth determination unit is configured to perform: respectively determine the data after normalization processing of each time period and the corresponding code coverage rate as a basic block vector.
10. The device according to claim 8 or 9, characterized in that, The division unit includes: a clustering unit, a sixth determination unit, and a seventh determination unit, where: The clustering unit is configured to perform: cluster each of the basic block vectors; The sixth determination unit is configured to perform: in the execution mark data of each basic block vector within the same cluster, determine first mark data, where the first mark data is execution mark data used to mark that a path basic block is executed; The seventh determination unit is configured to perform: determine the path basic blocks corresponding to the respective first mark data within the same cluster as one of the stage subroutines.
Citation Information
Patent Citations
Dynamic symbol execution path searching method for finding vulnerabilities
CN104008053A
Software fuzzy test method
CN110196815A