An unknown protocol fuzz testing method and device thereof
By generating a protocol state transition diagram and using reinforcement learning algorithm for fuzz testing, the efficiency and accuracy of unknown protocol testing are solved, and efficient detection of unknown protocol vulnerability is achieved.
Patent Information
- Application Number
- CN202111450649.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-01
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2041-12-01
AI Technical Summary
The prior art is difficult to effectively test unknown protocols, which makes it difficult to detect protocol vulnerabilities in network communication systems and is inefficient in fuzzy testing.
By obtaining traffic packets and protocol entities of unknown protocols, extracting keywords, generating protocol status transition diagrams, and using reinforcement learning algorithms to perform fuzz testing, the fuzz testing of unknown protocols is automated.
It improves the accuracy and efficiency of unknown protocol testing, is suitable for a variety of network communication systems, and reduces dependence on source code.
Smart Images

Figure CN114116500B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of network communication protocol testing. Specifically, it relates to a method and device for fuzz testing of unknown protocols. Background Art
[0002] In innovative networks such as industrial control, military communication, and financial information, a large number of unknown protocols (private or semi-private) are widely adopted. Conducting strict testing on communication protocols and their implementations is an important means to ensure the security of network systems. Most of the existing testing means and methods can only be applied to known protocols, and the widespread adoption of unknown protocols poses challenges to the testing of unknown protocols. Protocol vulnerability mining is an important means to ensure network communication security, mainly including reverse analysis and fuzz testing.
[0003] Among them, the repeated interaction of auxiliary messages such as the preamble and regression sequence in the fuzz testing method reduces the testing efficiency during the testing process. Moreover, since test cases corresponding to the message types are input according to the protocol state in which the protocol entity is located, it is impossible to discover protocol defects caused by abnormal input orders of messages, resulting in many systems being unusable. Summary of the Invention
[0004] The purpose of the embodiments of this application is to provide a method and device for fuzz testing of unknown protocols, which have high testing accuracy, do not have excessive requirements for source code, can be used in various network communication systems, and have high applicability.
[0005] In a first aspect, the embodiments of this application provide a method for fuzz testing of unknown protocols, and the method includes:
[0006] Obtain traffic messages of an unknown protocol and a protocol entity corresponding to the unknown protocol;
[0007] Obtain keywords in the traffic messages;
[0008] Obtain multiple protocol states and their corresponding multiple state messages according to the keywords;
[0009] Obtain a protocol state transition diagram according to the multiple protocol states;
[0010] Perform fuzz testing on the protocol entity according to the protocol state transition diagram to obtain a test result.
[0011] In the above implementation process, by generating a complete protocol state transition diagram and then parsing the protocol state transition diagram of the unknown protocol through fuzz testing, automated fuzz testing of multiple protocol states is realized, and efficient fuzz testing of the unknown protocol is completed.
[0012] Further, the step of obtaining the keywords in the traffic messages includes:
[0013] Perform multiple sequence alignment processes on the traffic packet to obtain the immutable domain of the unknown protocol as a keyword.
[0014] In the above implementation process, by dividing keywords in the traffic packet of the unknown protocol, each protocol state and its corresponding state packet can be reserved in advance.
[0015] Further, the step of obtaining multiple protocol states and their corresponding multiple state packets according to the keyword includes:
[0016] Generate a feature vector according to the keyword;
[0017] Perform clustering processing on the feature vector to obtain the multiple protocol states and their corresponding multiple state packets.
[0018] In the above implementation process, obtaining keywords from traffic packets and clustering the keywords to obtain protocol states greatly improves the automation degree of obtaining protocol states.
[0019] Further, the step of obtaining a protocol state transition diagram according to the multiple protocol states includes:
[0020] Obtain the message time sequence relationship in the unknown protocol;
[0021] Perform comparison processing on the multiple protocol states according to the time sequence relationship to obtain multiple transition directions of the multiple protocol states;
[0022] Generate the protocol state transition diagram according to the multiple transition directions.
[0023] In the above implementation process, obtain a protocol state transition diagram through multiple transition directions, and the protocol state transition diagram can reflect multiple protocol states and the transition directions of protocol states.
[0024] Further, the step of performing fuzz testing on the protocol entity according to the protocol state transition diagram to obtain a test result includes:
[0025] Obtain test cases according to the keyword and the state packet;
[0026] Obtain a first action according to the protocol state transition diagram;
[0027] Perform state transition on the protocol entity according to the first action, and send the test case to the protocol entity so that the protocol entity returns a first response packet;
[0028] Obtain a reward score according to the first response packet, and obtain a second action according to the reward score;
[0029] Perform a state transition on the protocol entity according to the second action, and send the test case to the protocol entity so that the protocol entity returns a second response message;
[0030] Obtain a discrimination criterion. If the second response message meets the discrimination criterion, output the second response message as the test result; if the second response message does not meet the discrimination criterion, obtain a new reward score according to the second response message.
[0031] In the above implementation process, analyzing the first action through the reward function to obtain a reward score can help the protocol entity obtain a second action that more conforms to the discrimination criterion, so as to obtain a second response message.
[0032] Further, the step of obtaining the first action according to the protocol state transition diagram includes:
[0033] Obtain the auxiliary message in the traffic message;
[0034] Input the Q-value table into the auxiliary message to obtain an action set;
[0035] Input the Q-value table into the protocol state transition diagram to obtain a state set;
[0036] Select an action from the action set according to the state set as the first action.
[0037] In the above implementation process, by setting the reward function and the Q-value table, it is possible to realize the automatic selection of the response message with the highest reward score, complete the transfer guidance of the protocol state and the fuzz testing process for each protocol state.
[0038] Further, the step of obtaining a reward score according to the first response message includes:
[0039] Obtain the protocol entity state according to the first response message returned by the protocol entity;
[0040] Obtain a reward score according to the reward function and the protocol entity state;
[0041] In the above implementation process, the reward function can help the protocol entity determine whether the test case meets the requirements, so as to select a response message with a higher reward score.
[0042] Further, the step of determining the protocol entity state according to the first response message returned by the protocol entity includes:
[0043] Perform a comparison process on the first response message and the auxiliary message to obtain the protocol entity state.
[0044] Further, the step of obtaining multiple protocol states and their corresponding multiple status messages according to the keyword further includes:
[0045] Combining the bidirectional transferable protocol states among the multiple protocol states and eliminating the redundant multiple protocol states.
[0046] In the above implementation process, eliminating the redundant protocol states can make the obtained multiple protocol states more accurate and ensure that the subsequent test results are more precise.
[0047] In a second aspect, an embodiment of the present application further provides an unknown protocol fuzz testing device, and the device includes:
[0048] An acquisition module, configured to acquire traffic messages of an unknown protocol and a protocol entity corresponding to the unknown protocol;
[0049] A processing module, configured to obtain keywords in the traffic messages;
[0050] An analysis module, configured to obtain multiple protocol states and their corresponding multiple status messages according to the keyword;
[0051] A state transition graph obtaining module, configured to obtain a protocol state transition graph according to the multiple protocol states;
[0052] A fuzz testing module, configured to perform fuzz testing on the protocol entity according to the protocol state transition graph to obtain a test result.
[0053] In the above implementation process, by generating a complete protocol state transition graph and then parsing the protocol state transition graph of the unknown protocol through fuzz testing, automatic fuzz testing of multiple protocol states is realized, and fuzz testing of the unknown protocol is efficiently completed.
[0054] In a third aspect, an electronic device provided by an embodiment of the present application includes: a memory, a processor, and a computer program stored in the memory and executable on the processor, and when the processor executes the computer program, the steps of the method according to any one of the first aspects are implemented.
[0055] In a fourth aspect, a computer-readable storage medium provided by an embodiment of the present application has instructions stored thereon, and when the instructions run on a computer, the computer is caused to execute the method according to any one of the first aspects.
[0056] In a fifth aspect, a computer program product provided by an embodiment of the present application, when running on a computer, causes the computer to execute the method according to any one of the first aspects.
[0057] Other features and advantages of the present disclosure will be set forth in the following description, or may be learned by inference or without doubt from the description, or may be learned by implementing the above technologies of the present disclosure.
[0058] And it can be implemented according to the content of the description. The following will be described in detail with reference to the preferred embodiments of the present application and the accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0059] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings required to be used in the embodiments of the present application. It should be understood that the following drawings only show some embodiments of the present application, and therefore should not be regarded as limiting the scope. For those of ordinary skill in the art, other related drawings can be obtained based on these drawings without creative efforts.
[0060] Figure 1 It is a schematic flow chart of an unknown protocol fuzz testing method provided by an embodiment of the present application;
[0061] Figure 2 It is a schematic structural composition diagram of an unknown protocol fuzz testing device provided by an embodiment of the present application;
[0062] Figure 3 It is a schematic structural composition diagram of an electronic device provided by an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0063] The following will describe the technical solutions in the embodiments of the present application with reference to the accompanying drawings in the embodiments of the present application.
[0064] It should be noted that similar reference numerals and letters denote similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings. At the same time, in the description of the present application, the terms "first", "second", etc. are only used for distinguishing descriptions and cannot be understood as indicating or implying relative importance.
[0065] The following will further describe in detail the specific embodiments of the present application with reference to the accompanying drawings and embodiments. The following embodiments are used to illustrate the present application but are not used to limit the scope of the present application.
[0066] Embodiment 1
[0067] Figure 1 It is a schematic flow chart of an unknown protocol fuzz testing method provided by an embodiment of the present application. As Figure 1 shown, the method includes:
[0068] S1, obtaining traffic packets of an unknown protocol and a protocol entity corresponding to the unknown protocol;
[0069] S2. Obtain the keywords in the traffic packet.
[0070] S3. Obtain multiple protocol states and their corresponding multiple status packets according to the keywords.
[0071] S4. Obtain the protocol state transition graph according to the multiple protocol states.
[0072] S5. Perform fuzz testing on the protocol entity according to the protocol state transition graph to obtain the test result.
[0073] Taking this embodiment as an example, through methods such as the inference of protocol states, a complete protocol state transition graph is generated, and then through fuzz testing, the protocol state transition graph of the unknown protocol obtained by reverse engineering is analyzed, so as to automatically perform fuzz testing on multiple protocol states and efficiently complete the fuzz testing of the unknown protocol.
[0074] In S1, obtain the traffic packet of the unknown protocol and the protocol entity corresponding to the unknown protocol.
[0075] Taking this embodiment as an example, a protocol is the abbreviation of a network protocol, which is a set of agreements that both communicating computers must jointly comply with. An unknown protocol means that the key information of the protocol cannot be obtained, and fuzz testing needs to be performed on the unknown protocol. A protocol entity is a physical protocol, that is, not an abstract protocol.
[0076] In S2, obtain the keywords in the traffic packet, including:
[0077] Perform multiple sequence alignment processes on the traffic packet to obtain the immutable domain of the unknown protocol as the keyword.
[0078] Exemplarily, a sequence alignment algorithm can be used to process the traffic packet, and the immutable domain is identified through multiple pairwise sequence alignments, thereby inferring the keyword. By dividing the keyword in the traffic packet of the unknown protocol, each protocol state and its corresponding status packet can be reserved in advance.
[0079] In S3, obtain multiple protocol states and their corresponding multiple status packets according to the keywords, including:
[0080] Generate a feature vector according to the keywords;
[0081] Perform clustering processing on the feature vector to obtain multiple protocol states and their corresponding multiple status packets.
[0082] Further, obtaining multiple protocol states and their corresponding multiple status packets according to the keywords further includes:
[0083] Merge the bidirectionally transferable protocol states in the multiple protocol states to eliminate the redundant multiple protocol states.
[0084] Taking this embodiment as an example, feature vectors are generated according to keywords. Based on the characteristic of the common keyword feature vectors among state messages in different states, state messages with common keyword feature vectors are merged, multiple protocol states are clustered, and the protocol messages corresponding to each protocol state are recorded.
[0085] By means of the method of clustering messages according to keywords, the format extraction of unknown protocols is realized. The protocol states are inferred based on the timing relationship in traffic messages. At the same time, by using the method of merging protocol states that can be transferred bidirectionally, an automated interrogation process is realized, greatly improving the automation degree of protocol state inference.
[0086] Record each protocol state S t and the protocol message M corresponding to this state t,1 、M t,2 、…、M t,n ,Regularly send state messages (M t,1 、M t,2 、…、M t,n ) and receive feedback to realize an automated interrogation process.
[0087] In this process, the protocol states that can be transferred bidirectionally are merged. For example, if S1→S2 is true and S2→S1 is true, such protocol states are protocol states that can be transferred bidirectionally. Thus, some redundant protocol states generated in the clustering process are eliminated. Repeat the action of merging the protocol states that can be transferred bidirectionally until no two of the inferred protocol states can be transferred bidirectionally.
[0088] Taking this embodiment as an example, eliminating redundant protocol states can make the obtained multiple protocol states more accurate and ensure that the subsequent test results are more precise.
[0089] In S4, a protocol state transition graph is obtained according to multiple protocol states, including:
[0090] Obtain the message timing relationship in the unknown protocol;
[0091] Compare and process multiple protocol states according to the timing relationship to obtain multiple transfer directions of multiple protocol states;
[0092] Generate a protocol state transition graph according to multiple transfer directions.
[0093] Taking this embodiment as an example, compare the multiple protocol states inferred according to the message timing relationship to clarify the multiple transfer directions of multiple protocol states. For example: if S1→S2 is true and S2→S1 is false, then the state transfer direction between protocol state S1 and protocol state S2 is S1→S2.
[0094] The transition of the protocol state is caused by auxiliary messages. In this process, it is necessary to save the auxiliary messages that cause the protocol state transition. Finally, a protocol state transition diagram is obtained through multiple transition directions. The protocol state transition diagram can reflect multiple protocol states and the transition directions of the protocol states.
[0095] In S5, fuzz testing is performed on the protocol entity according to the protocol state transition diagram to obtain test results, including:
[0096] Obtain test cases according to keywords and status messages;
[0097] Obtain the first action according to the protocol state transition diagram;
[0098] Perform a state transition on the protocol entity according to the first action, and send the test case to the protocol entity so that the protocol entity returns a first response message.
[0099] Obtain a reward score according to the first response message, and obtain a second action according to the reward score;
[0100] Perform a state transition on the protocol entity according to the second action, and send the test case to the protocol entity so that the protocol entity returns a second response message;
[0101] Obtain a discrimination criterion. If the second response message meets the discrimination criterion, output the second response message as the test result; if the second response message does not meet the discrimination criterion, obtain a new reward score according to the second response message.
[0102] Furthermore, the steps to obtain the first action according to the protocol state transition diagram include:
[0103] Obtain the auxiliary message in the traffic message;
[0104] Input the Q-value table into the auxiliary message to obtain an action set;
[0105] Input the Q-value table into the protocol state transition diagram to obtain a state set;
[0106] Select an action from the action set according to the state set as the first action.
[0107] The Q-value table is a method in the reinforcement learning algorithm. Q is Q(s, a), which is the expected return that can be obtained by taking action a in the state s at a certain moment. The environment will give corresponding rewards according to the action, and the algorithm will construct a Q-value table of states and actions to store the Q-values, and then select the action that can obtain the maximum return according to the Q-values.
[0108] Taking this embodiment as an example, by setting the reward function and the Q-value table, it is possible to automatically select the response message with the highest reward score, complete the transfer guidance of the protocol state, and the fuzz testing process for each protocol state.
[0109] Further, the steps for obtaining the reward score according to the first response message include:
[0110] Obtaining the protocol entity state according to the first response message returned by the protocol entity;
[0111] Obtaining the reward score according to the reward function and the protocol entity state;
[0112] The reward function is:
[0113]
[0114] where S t is the protocol entity state, A t is the action corresponding to the protocol entity state, a, b, and c are three different scores, and each score corresponds to a different protocol entity state.
[0115] Taking this embodiment as an example, the reward function can help the protocol entity determine whether the test case meets the requirements, so as to select the response message with a higher reward score.
[0116] Further, determining the protocol entity state according to the first response message returned by the protocol entity includes:
[0117] Comparing and processing the first response message and the auxiliary message to obtain the protocol entity state.
[0118] Taking this embodiment as an example, by making a judgment on the first action through the reward function to obtain the reward score, it can help the protocol entity obtain a second action that better meets the discrimination criteria, so as to obtain the second response message.
[0119] Exemplarily, the embodiment of the present application uses a reinforcement learning algorithm to build a model to implement fuzz testing of unknown protocols. The reward score is accumulated in each round of the algorithm iteration process. When the training ends, the algorithm iteration is completed, and the reward score will also be accumulated to obtain a final value, and the test case with the highest corresponding reward score is obtained. Using the above-trained model, it is possible to complete the transfer guidance of the protocol state and the fuzz testing process for each state, and efficiently mine vulnerabilities in the protocol.
[0120] Taking this embodiment as an example, through methods such as inferring the protocol state, a complete protocol state transition diagram is generated. Then, through fuzz testing, the protocol state transition diagram of the reverse-engineered unknown protocol is parsed to automatically perform fuzz testing on multiple protocol states. The testing accuracy rate is high, there are no excessive requirements for the source code, and it can be used in various network communication systems, with high applicability.
[0121] Embodiment 2
[0122] To execute the method corresponding to the above Embodiment 1 to achieve the corresponding functions and technical effects, the following provides a fuzz testing device for an unknown protocol, as Figure 2 shown. The device includes:
[0123] An acquisition module 1, configured to acquire traffic packets of the unknown protocol and a protocol entity corresponding to the unknown protocol;
[0124] A processing module 2, configured to acquire keywords in the traffic packets;
[0125] An analysis module 3, configured to acquire multiple protocol states and their corresponding multiple state packets according to the keywords;
[0126] A state transition diagram obtaining module 4, configured to obtain a protocol state transition diagram according to the multiple protocol states;
[0127] A fuzz testing module 5, configured to perform fuzz testing on the protocol entity according to the protocol state transition diagram to obtain a test result.
[0128] Further, the processing module 2 is further configured to:
[0129] Perform multiple sequence alignment processes on the traffic packets to obtain the immutable domain of the unknown protocol as the keyword.
[0130] Further, the analysis module 3 is further configured to:
[0131] Generate a feature vector according to the keyword;
[0132] Perform clustering processing on the feature vector to obtain multiple protocol states and their corresponding multiple state packets;
[0133] Merge the bidirectionally transferable protocol states in the multiple protocol states to eliminate the redundant multiple protocol states.
[0134] Further, the state transition diagram obtaining module 4 is further configured to:
[0135] Obtain the message timing relationship in the unknown protocol;
[0136] Perform comparison processing on the multiple protocol states according to the timing relationship to obtain multiple transfer directions of the multiple protocol states;
[0137] Generate a protocol state transition diagram according to multiple transfer directions.
[0138] Furthermore, the fuzz testing module 5 is further configured to:
[0139] Obtain test cases according to keywords and status messages;
[0140] Obtain a first action according to the protocol state transition diagram;
[0141] Perform state transition on the protocol entity according to the first action, and send the test case to the protocol entity so that the protocol entity returns a first response message;
[0142] Obtain a reward score according to the first response message, and obtain a second action according to the reward score;
[0143] Perform state transition on the protocol entity according to the second action, and send the test case to the protocol entity so that the protocol entity returns a second response message;
[0144] Obtain a discrimination criterion. If the second response message meets the discrimination criterion, output the second response message. If the second response message does not meet the discrimination criterion, obtain a new reward score according to the second response message;
[0145] Judge the state of the protocol entity according to the first response message returned by the protocol entity;
[0146] Obtain a reward score according to the reward function and the state of the protocol entity;
[0147] Compare and process the first response message and the auxiliary message to obtain the state of the protocol entity.
[0148] The above-mentioned unknown protocol fuzz testing device can implement the method of the first embodiment. The optional items in the first embodiment are also applicable to this embodiment, and will not be elaborated here.
[0149] The remaining content of the embodiments of the present application can refer to the content of the first embodiment, and will not be elaborated in this embodiment.
[0150] Embodiment Three
[0151] The embodiment of the present application provides an electronic device, including a memory and a processor. The memory is used to store a computer program, and the processor runs the computer program to enable the electronic device to execute the method for constructing the question and answer model in the first embodiment.
[0152] Optionally, the above-mentioned electronic device may be a server.
[0153] Please refer to Figure 3 , Figure 3Schematic diagram of the structural composition of the electronic device provided by the embodiment of the present application. The electronic device may include a processor 31, a communication interface 32, a memory 33, and at least one communication bus 34. Among them, the communication bus 34 is used to realize the direct connection and communication of these components. Among them, the communication interface 32 of the device in the embodiment of the present application is used to communicate signaling or data with other node devices. The processor 31 may be an integrated circuit chip with signal processing capabilities.
[0154] The above-mentioned processor 31 may be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it may also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components. It can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor may be a microprocessor or the processor 31 may also be any conventional processor, etc.
[0155] The memory 33 may be, but is not limited to, a random access memory (RAM), a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), etc. The memory 33 stores computer-readable instructions. When the computer-readable instructions are executed by the processor 31, the device can execute the above Figure 1 Each step involved in the method embodiment.
[0156] Optionally, the electronic device may further include a storage controller and an input / output unit. The memory 33, the storage controller, the processor 31, the peripheral interface, and the input / output unit are directly or indirectly electrically connected to each other to realize data transmission or interaction. For example, these components may be electrically connected to each other through one or more communication buses 34. The processor 31 is used to execute the executable module stored in the memory 33, such as the software function module or computer program included in the device.
[0157] The input / output unit is used to enable the user to create tasks and create an optional start period or a preset execution time for the tasks, so as to realize the interaction between the user and the server. The input / output unit can be, but is not limited to, a mouse, a keyboard, etc.
[0158] It can be understood that Figure 3 The structure shown is only schematic, and the electronic device may also include more or fewer components than those shown Figure 3 in it, or have a different configuration from that shown Figure 3 in it. Figure 3 Each component shown in it can be implemented by hardware, software, or a combination thereof.
[0159] In addition, an embodiment of the present application also provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, the method for constructing the question-and-answer model in Embodiment 1 is implemented.
[0160] An embodiment of the present application also provides a computer program product. When the computer program product runs on a computer, the computer is enabled to execute the method described in the method embodiment.
[0161] In several embodiments provided by the present application, it should be understood that the disclosed apparatus and method can also be implemented in other ways. The apparatus embodiments described above are merely illustrative. For example, the flowcharts and block diagrams in the accompanying drawings show the possible architectures, functions, and operations of the apparatus, method, and computer program product according to multiple embodiments of the present application. In this regard, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code, and the module, program segment, or part of code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order from that marked in the accompanying drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, and the combination of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or actions, or can be implemented by a combination of dedicated hardware and computer instructions.
[0162] In addition, in each embodiment of the present application, the various functional modules may be integrated together to form an independent part, or each module may exist alone, or two or more modules may be integrated to form an independent part.
[0163] When the above-mentioned functions are implemented in the form of software function modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of this application. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, ROM, RAM, magnetic disks, or optical discs that can store program codes.
[0164] The above are only the embodiments of this application and are not used to limit the protection scope of this application. For those skilled in the art, this application can have various changes and modifications. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of this application shall be included in the protection scope of this application. It should be noted that similar reference numerals and letters in the following drawings represent similar items. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings.
[0165] The above is only the specific implementation manner of this application, but the protection scope of this application is not limited thereto. Any person skilled in the art can easily think of changes or replacements within the technical scope disclosed by this application and should be covered by the protection scope of this application. Therefore, the protection scope of this application should be subject to the protection scope of the claims.
[0166] It should be noted that in this article, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or also includes elements inherent to such process, method, article or device. Without further limitations, an element defined by the statement "including a..." does not exclude the existence of additional identical elements in the process, method, article or device including the said element.
Claims
1. An unknown protocol fuzz testing method, characterized in that, The method includes: Obtaining traffic packets of an unknown protocol and a protocol entity corresponding to the unknown protocol; Obtaining keywords in the traffic packets; Obtaining multiple protocol states and their corresponding multiple status packets according to the keywords; Obtaining a protocol state transition diagram according to the multiple protocol states; Performing fuzz testing on the protocol entity according to the protocol state transition diagram to obtain a test result; The step of performing fuzz testing on the protocol entity according to the protocol state transition diagram to obtain a test result includes: Obtaining test cases according to the keywords and the status packets; Obtaining a first action according to the protocol state transition diagram; Performing state transition on the protocol entity according to the first action, and sending the test cases to the protocol entity so that the protocol entity returns a first response packet; Obtaining a reward score according to the first response packet, and obtaining a second action according to the reward score; Performing state transition on the protocol entity according to the second action, and sending the test cases to the protocol entity so that the protocol entity returns a second response packet; Obtaining a discrimination criterion. If the second response packet meets the discrimination criterion, output the second response packet as the test result; if the second response packet does not meet the discrimination criterion, obtain a new reward score according to the second response packet.
2. The unknown protocol fuzz testing method according to claim 1, wherein, The step of obtaining keywords in the traffic packets includes: Performing multiple sequence alignment processes on the traffic packets to obtain an immutable domain of the unknown protocol as the keyword.
3. The unknown protocol fuzz testing method according to claim 1, wherein The step of obtaining multiple protocol states and their corresponding multiple status packets according to the keywords includes: Generating a feature vector according to the keywords; Performing clustering processing on the feature vector to obtain the multiple protocol states and their corresponding multiple status packets.
4. The unknown protocol fuzz testing method according to claim 1, wherein The step of obtaining a protocol state transition diagram according to the multiple protocol states includes: Obtaining the message time sequence relationship in the unknown protocol; Performing comparison processing on the multiple protocol states according to the time sequence relationship to obtain multiple transfer directions of the multiple protocol states; Generating the protocol state transition diagram according to the multiple transfer directions.
5. The unknown protocol fuzz testing method according to claim 1, characterized in that The step of obtaining a first action according to the protocol state transition diagram includes: Obtaining auxiliary packets in the traffic packets; Inputting a Q-value table into the auxiliary packets to obtain an action set; Inputting the Q-value table into the protocol state transition diagram to obtain a state set; Selecting an action in the action set according to the state set as the first action.
6. The unknown protocol fuzz testing method according to claim 1, wherein The step of obtaining a reward score according to the first response packet includes: Obtaining a protocol entity state according to the first response packet returned by the protocol entity; Obtaining the reward score according to a reward function and the protocol entity state.
7. The unknown protocol fuzz testing method according to claim 6, wherein The step of judging the protocol entity state according to the first response packet returned by the protocol entity includes: Performing comparison processing on the first response packet and the auxiliary packets to obtain the protocol entity state.
8. The unknown protocol fuzz testing method according to claim 1, characterized in that, The step of obtaining multiple protocol states and their corresponding multiple status packets according to the keywords further includes: Merge the two-way transferable protocol states among the multiple protocol states to eliminate the redundant multiple protocol states.
9. An unknown protocol fuzz testing device, characterized in that The device includes: An acquisition module, configured to acquire traffic packets of an unknown protocol and a protocol entity corresponding to the unknown protocol; A processing module, configured to acquire keywords in the traffic packets; A parsing module, configured to acquire multiple protocol states and their corresponding multiple status packets according to the keywords; A state transition diagram obtaining module, configured to obtain a protocol state transition diagram according to the multiple protocol states; A fuzz testing module, configured to perform fuzz testing on the protocol entity according to the protocol state transition diagram to obtain a test result; The fuzz testing module is further configured to: Obtain a test case according to the keywords and the status packets; Obtain a first action according to the protocol state transition diagram; Perform state transition on the protocol entity according to the first action, and send the test case to the protocol entity, so that the protocol entity returns a first response packet; Obtain a reward score according to the first response packet, and obtain a second action according to the reward score; Perform state transition on the protocol entity according to the second action, and send the test case to the protocol entity, so that the protocol entity returns a second response packet; Obtain a discrimination criterion. If the second response packet meets the discrimination criterion, output the second response packet as the test result; if the second response packet does not meet the discrimination criterion, obtain a new reward score according to the second response packet.
Citation Information
Patent Citations
Unknown protocol fuzzy test automation method based on reverse technology
CN113206834A