A method and device for determining a test seed
By analyzing and filtering test seeds covering new nodes and optimizing test inputs based on their fitness, the simple problem of testing seed selection strategies in the prior art is solved, and the efficiency and accuracy of fuzz testing are improved.
Patent Information
- Application Number
- CN202210666920.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-06-13
- Publication Date
- 2025-06-27
- Estimated Expiration
- 2042-06-13
AI Technical Summary
The prior art has relatively simple strategies when screening test seeds, and fails to effectively consider the impact of different fitness degrees of selected seeds on fuzz testing, resulting in a decrease in fuzz testing efficiency.
By analyzing whether each test seed in each round of fuzzing tests covers a new node in the function call flow graph, retaining the test seed covering the new node, and determining the seed fitness based on its calls and the called data in the function call flow graph, optimizing the test input.
By giving higher weights to test seeds that are more capable of covering more branches, the efficiency and accuracy of fuzzing is improved and the quality of test seed pools is improved.
Smart Images

Figure CN115017048B_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present application relate to the field of financial technology (Fintech), and in particular, to a method and device for determining test seeds. Background Art
[0002] With the development of computer technology, more and more technologies (such as big data, cloud computing, or blockchain) are applied in the financial field, and the traditional financial industry is gradually transforming into financial technology. For example, for the massive amounts of data existing in the financial field, such massive amounts of data can be stored through blockchain. When using blockchain to store data, smart contracts will be used. Essentially, a smart contract is a set of codes and data stored at a specific address on the Ethereum blockchain. Therefore, in order to ensure the quality of data storage, the smart contract needs to be tested before it is officially put into use. Currently, the method for testing smart contracts is grey-box fuzz testing. Grey-box fuzz testing adopts lightweight program analysis technology and guides the testing process by collecting some key code information. Among them, grey-box fuzz testing first generates random test cases for the program under test and runs the test cases to determine whether it covers a new uncovered program path, and then screens out high-quality test cases through a certain screening strategy, performs crossover and mutation operations on them to generate new test cases, and conducts the next round of test iteration. Currently, in the process of screening test cases, the strategy for selecting test seeds is relatively simple, mainly retaining all seeds that cover new branches based on the distance selection method defined by the control flow graph. Obviously, this solution does not consider the influence of the different fitness of the selected seeds on the inputs generated by fuzz testing, thus affecting the quality of the fuzz testing seed pool and reducing the fuzz testing efficiency. Summary of the Invention
[0003] The present application provides a method and device for determining test seeds to screen out high-quality test seeds, thereby improving the efficiency of fuzz testing.
[0004] In a first aspect, an embodiment of the present application provides a method for determining test seeds, the method comprising: for the i-th round of test seeds of a target smart contract, performing the (i + 1)-th round of fuzz testing based on the i-th round of test seeds, and obtaining function call records of each test seed in the i-th round of test seeds during the (i + 1)-th round of fuzz testing; for any one of the test seeds in the i-th round of test seeds, according to the function call record of the test seed during the (i + 1)-th round of fuzz testing, if it is determined that the test seed covers a new node in the function call flow graph during the (i + 1)-th round of fuzz testing, then retain the test seed as a candidate test seed; wherein, the function call flow graph is constructed with each function in the target smart contract as a node, and a connection line is drawn between two functions with a call relationship as a call edge, and any call edge is marked with the number of function calls; for any candidate test seed in the i-th round of test seeds, determine the seed fitness of the candidate test seed according to the number of call times and the number of times being called of the new node corresponding to the candidate test seed in the function call flow graph; according to the seed fitness corresponding to each candidate test seed respectively, determine the (i + 1)-th round of test seeds for performing the (i + 2)-th round of fuzz testing from the i-th round of test seeds, and return to execute the step of performing the (i + 1)-th round of fuzz testing based on the i-th round of test seeds of the target smart contract until the preset time of the fuzz testing is satisfied.
[0005] In the above solution, when selecting test seeds for the next round of testing during each round of fuzz testing, by analyzing whether each seed used for fuzz testing in the current fuzz testing process covers a new node in the function call flow graph, if it covers, then retain the test seed. For the retained test seed, by analyzing the call and being-called data of the new node corresponding to the test seed in the function call flow graph, for this method of determining the seed fitness of the test seed based on the call and being-called data, by assigning a higher weight to the test seed that is more capable of covering more branches, differentiating the seed quality in terms of fitness dimension, optimizing the input of the test, the process of fuzz testing is accelerated and the test efficiency is increased.
[0006] In a possible implementation method, the first round of test seeds of the target smart contract is obtained in the following manner, including: compiling the target smart contract to obtain the application binary interface (ABI) file of the target smart contract; obtaining the first round of test seeds of the target smart contract according to the data types of different parameters in the ABI file.
[0007] In the above solution, it specifically describes how to obtain the test seeds for the first round of fuzz testing of the smart contract. When obtaining the test seeds for the first round of fuzz testing of the smart contract, the first round of fuzz testing of the smart contract can be performed based on the test seeds of the first round, so as to obtain the test seeds for the second round of fuzz testing of the smart contract according to the fuzz testing results of the first round.
[0008] In a possible implementation method, obtaining the test seeds for the first round of the target smart contract according to the data types of different parameters in the ABI file includes: for any parameter in the ABI file, if the data type of the parameter is an integer or a decimal type, determining a value between the maximum value and the minimum value of the data type as the test seed for the first round of the parameter through a random function; if the parameter is a boolean type, randomly determining a value between 0 and 1 as the test seed for the first round of the parameter; if the parameter is a string type, randomly selecting a value from the constant strings in the bytecode as the test seed for the first round of the parameter; if the parameter is an array type, generating the test seed for the first round of the parameter according to the original data types of the elements in the array; if the parameter is a structure type, generating the test seed for the first round of the parameter according to the original data types in the structure.
[0009] In the above solution, it specifically describes how to determine the corresponding test seeds for parameters of different data types. Through this method, the test seeds for the first round of fuzz testing of the smart contract can be generated quickly.
[0010] In a possible implementation method, the function call flow graph is constructed in the following way, including: compiling the target smart contract to obtain the WASM bytecode file of the target smart contract; determining the function set of the target smart contract and the instruction set of any function in the function set according to the WASM bytecode file; determining the function call flow graph according to the function set and each instruction set.
[0011] In the above solution, it specifically describes how to generate the function call flow graph corresponding to the smart contract. After each round of fuzz testing is completed, the seed fitness of the test seeds for the current round of fuzz testing can be calculated based on the generated function call flow graph. Since the function call flow graph involves the data of the calls and being called of each function, the accuracy of the seed fitness of the test seeds calculated based on this method is higher. Therefore, when using test seeds with high accuracy for fuzz testing, the efficiency of fuzz testing can be improved.
[0012] In a possible implementation method, determining the function set of the target smart contract and the instruction set of any function in the function set according to the WASM bytecode file includes: converting the WASM bytecode file into a wat text and setting an initial function set; the initial function set is empty; traversing each instruction in the wat text; for the currently traversed instruction, if it is determined that the instruction indicates a function, adding the function indicated by the instruction to the end of the initial function set; if it is determined that the instruction does not indicate a function, adding the instruction to the end of the instruction set of the currently indicated function; determining the function call flow graph according to the function set and each instruction set includes: for any function in the function set, traversing each instruction in the instruction set of the function; if it is determined that the currently traversed instruction is a call instruction, recording the called function after the call instruction and adding a directed connection from the function to the called function; if it is determined that the directed connection already exists, updating the call count of the call edge indicated by the directed connection; if it is determined that the currently traversed instruction is a return instruction, jumping to the next function in the function set and returning to execute the step of traversing each instruction in the instruction set of the function, so as to obtain the function call flow graph.
[0013] In the above solution, it specifically describes how to generate a function call flow graph corresponding to a smart contract, presenting the call and called relationships of each function in the smart contract in a graphical style, and at the same time marking the call count. The larger the call count, the higher the fitness of the test seed corresponding to the function. Therefore, by assigning higher weights to the test seeds that are more capable of covering more branches, differentiating the seed quality in terms of fitness dimension, optimizing the test input, the process of fuzz testing is accelerated and the test efficiency is increased.
[0014] In a possible implementation method, determining the seed fitness of the candidate test seed according to the call count and the called count of the new node corresponding to the candidate test seed in the function call flow graph includes: obtaining the adjacency matrix of the function call flow graph; determining the seed fitness of the candidate test seed according to the call count, the called count of the new node corresponding to the candidate test seed in the function call flow graph, and the adjacency matrix.
[0015] In the above solution, it specifically describes how to determine the seed fitness of candidate test seeds. During the process of determining the seed fitness of candidate test seeds, since the adjacency matrix of the function call graph is applied and the call times and the number of times being called of the new node corresponding to the candidate test seed in the function call graph are used, the accuracy of calculating the seed fitness of the candidate test seeds can be greatly improved. Thus, by assigning higher weights to the test seeds that are more capable of covering more branches, differentiating the seed quality in terms of fitness dimension, and optimizing the test input, the process of fuzz testing can be accelerated and the test efficiency can be increased.
[0016] In a possible implementation method, determining the seed fitness of the candidate test seeds according to the call times and the number of times being called of the new node corresponding to the candidate test seed in the function call graph and the adjacency matrix includes: determining an initial seed fitness k; where k = αS + βT, α and β are the preset weights of S and T respectively, S represents the sum of the call times of each incoming call edge reaching the new node determined based on the function call graph, and T represents the sum of the call times of each outgoing call edge starting from the new node determined based on the function call graph; determining the seed fitness of the candidate test seeds according to the initial seed fitness k and the adjacency matrix.
[0017] In the above solution, it specifically describes how to determine the seed fitness of candidate test seeds. Since during the process of calculating the seed fitness of candidate test seeds, the call times and the number of times being called of the function corresponding to the candidate test seed in the function call graph are used, and by assigning higher weights to the test seeds that are more capable of covering more branches, differentiating the seed quality in terms of fitness dimension, and optimizing the test input, the process of fuzz testing can be accelerated and the test efficiency can be increased.
[0018] In a possible implementation method, determining the (i + 1)-th round of test seeds for the (i + 2)-th round of fuzz testing from the i-th round of test seeds according to the seed fitness corresponding to each candidate test seed includes: determining each first candidate test seed and each second candidate test seed from each candidate test seed; where the seed fitness of any first candidate test seed is greater than the seed fitness of any second candidate test seed; updating each first candidate test seed in a first set manner to generate each first updated test seed, and updating each second candidate test seed in a second set manner to generate each second updated test seed; using each first updated test seed and each second updated test seed as the (i + 1)-th round of test seeds for the (i + 2)-th round of fuzz testing.
[0019] In the above solution, for the results of each round of fuzz testing, the seed fitness of the candidate test seeds for each round of fuzz testing is calculated, and different update methods are used for the candidate test seeds with different seed fitnesses to update the test seeds. The updated candidate test seeds (i.e., updated test seeds) are used as the test seeds for the next round of fuzz testing. This solution for fuzz testing based on updated test seeds helps improve the efficiency and accuracy of fuzz testing.
[0020] In a second aspect, an embodiment of the present application provides an apparatus for determining test seeds. The apparatus includes: a function call record acquisition unit, configured to perform the (i + 1)-th round of fuzz testing based on the i-th round of test seeds for a target smart contract, and acquire the function call records of each test seed in the i-th round of test seeds during the (i + 1)-th round of fuzz testing; a candidate test seed determination unit, configured to, for any one test seed in the i-th round of test seeds, if it is determined that the test seed covers a new node in the function call flow graph during the (i + 1)-th round of fuzz testing according to the function call record of the test seed during the (i + 1)-th round of fuzz testing, retain the test seed as a candidate test seed; wherein the function call flow graph is constructed with each function in the target smart contract as a node, and a connection line is drawn between two functions with a call relationship as a call edge, and any call edge is marked with the number of function calls; a seed fitness determination unit, configured to, for any candidate test seed in the i-th round of test seeds, determine the seed fitness of the candidate test seed according to the number of call times and the number of times being called of the new node corresponding to the candidate test seed in the function call flow graph; a test seed determination unit, configured to determine the (i + 1)-th round of test seeds for performing the (i + 2)-th round of fuzz testing from the i-th round of test seeds according to the seed fitness corresponding to each candidate test seed, and return to execute the step of performing the (i + 1)-th round of fuzz testing based on the i-th round of test seeds for the target smart contract until the preset time of the fuzz testing is satisfied.
[0021] In a third aspect, an embodiment of the present application provides a computing device, including:
[0022] a memory, configured to store program instructions;
[0023] a processor, configured to call the program instructions stored in the memory and execute any implementation method in the first aspect according to the obtained program.
[0024] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, where the computer-readable storage medium stores computer-executable instructions, and the computer-executable instructions are used to cause a computer to execute any implementation method in the first aspect. Description of the Drawings
[0025] To more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0026] Figure 1 It is a schematic diagram of a method for determining a test seed provided by an embodiment of the present application;
[0027] Figure 2 It is a schematic diagram of a function call flow graph provided by an embodiment of the present application;
[0028] Figure 3 It is a schematic diagram of a device for determining a test seed provided by an embodiment of the present application;
[0029] Figure 4 It is a schematic diagram of a computing device provided by an embodiment of the present application. Detailed implementation manners
[0030] In order to make the purpose, technical solutions and advantages of the present application clearer, the following will further describe the present application in detail with reference to the drawings. Obviously, the described embodiments are only some embodiments of the present application, rather than all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present application.
[0031] The selection strategy of the test seeds currently applied to fuzz testing is too simple, resulting in the selected test seeds affecting the quality of the fuzz testing seed pool and reducing the efficiency of fuzz testing.
[0032] To address the above technical problems, the present application provides a method for determining a test seed. This method is executed by a device for determining a test seed. The test seeds determined based on the method for determining a test seed proposed in the present application can improve the quality of the fuzz testing seed pool and thus improve the efficiency of fuzz testing. As Figure 1 shown, it is a schematic diagram of a method for determining a test seed provided by an embodiment of the present application. The method includes the following steps:
[0033] Step 101, for the i-th round of test seeds of the target smart contract, perform the (i + 1)-th round of fuzz testing based on the i-th round of test seeds, and obtain the function call records of each test seed in the i-th round of test seeds during the (i + 1)-th round of fuzz testing.
[0034] In this step, optionally, the target smart contract is any Liquid smart contract. The Liquid smart contract is a brand-new smart contract language based on the Rust language independently developed by the blockchain team of WeBank, and is used for the development of smart contracts on the FISCO-BCOS chain.
[0035] WASM, short for WebAssembly, is a brand-new portable, small-sized, fast-loading, and Web-compatible bytecode format. Using WASM in smart contracts can reduce the resource occupancy of the blockchain, make the smart contracts run faster and more stably, and make the network transmission of information more efficient.
[0036] Optionally, the Liquid smart contract of this application adopts the WASM (WebAssembly) bytecode format. Currently, both EOSIO and FISCO-BCOS support converting the smart contracts on the chain into the WASM bytecode format. The Liquid smart contract language independently proposed by FISCO-BCOS can be compiled and converted into the WASM bytecode and the corresponding ABI file for deployment on the chain.
[0037] In this step, for any test seed in the i-th round of test seeds of the target smart contract, by using this test seed to perform the (i + 1)-th round of fuzz testing on the target smart contract, during the fuzz testing process, optionally, the function call record of this test seed during the (i + 1)-th round of fuzz testing is obtained through the WASM virtual machine instrumentation technology.
[0038] Step 102, for any test seed in the i-th round of test seeds, according to the function call record of the test seed during the (i + 1)-th round of fuzz testing, if it is determined that the test seed covers a new node in the function call flow graph during the (i + 1)-th round of fuzz testing, then retain the test seed as a candidate test seed.
[0039] Among them, the function call flow graph is constructed with each function in the target smart contract as a node, and a node connection is made between two functions with a call relationship as a call edge. Any call edge is marked with the function call count.
[0040] In this step, based on the function call record of the i-th round of test seeds obtained in Step 101 during the (i + 1)-th round of fuzz testing, relying on this function call record, the pre-generated function call flow graph can be searched to determine whether the test seed covers a new node in the function call flow graph. If a certain test seed covers a new node in the function call flow graph, then this test seed can be used as a candidate test seed.
[0041] Step 103: For any candidate test seed among the test seeds in the i-th round, determine the seed fitness of the candidate test seed according to the call count and the called count of the new node corresponding to the candidate test seed in the function call flow graph.
[0042] In this step, based on the candidate test seeds obtained in Step 102, the call count and the called count of the new node corresponding to each candidate test seed in the function call flow graph are obtained respectively, and the seed fitness of the candidate test seed is determined based on the obtained call count and called count.
[0043] In the above manner, by assigning higher weights to the test seeds that are more capable of covering more branches, the seed quality is differentiated in terms of fitness dimension, thereby quantifying the importance of each candidate test seed shown in the fuzz testing process. Selecting high-quality test seeds as the seeds for the new round of fuzz testing based on the quantified candidate test seeds can accelerate the process of fuzz testing and improve the testing efficiency.
[0044] Step 104: Determine the (i + 1)-th round of test seeds for the (i + 2)-th round of fuzz testing from the test seeds in the i-th round according to the seed fitness corresponding to each candidate test seed, and return to execute the step of the i-th round of test seeds for the target smart contract and perform the (i + 1)-th round of fuzz testing based on the i-th round of test seeds until the preset time of the fuzz testing is satisfied.
[0045] In this step, based on the seed fitness of each candidate test seed obtained in Step 103, test seeds for the new round of fuzz testing can be selected according to the various seed fitnesses; after selecting the test seeds for the new round of fuzz testing, the process of the new round of fuzz testing can be started using the selected test seeds. The specific steps can refer to Steps 101 - 104 until the preset time set for this fuzz testing is reached, and the fuzz testing is ended.
[0046] In the above solution, when selecting the test seeds for the next round of testing in each round of fuzz testing, by analyzing whether each test seed for fuzz testing in the current fuzz testing process covers the new nodes in the function call flow graph, if it covers, the test seed is retained. For the retained test seed, by analyzing the call and called data of the new node corresponding to the test seed in the function call flow graph, for this method of determining the seed fitness of the test seed based on the call and called data, by assigning higher weights to the test seeds that are more capable of covering more branches, the seed quality is differentiated in terms of fitness dimension, optimizing the test input, accelerating the process of fuzz testing, and improving the testing efficiency.
[0047] The above steps will be described in detail below with examples.
[0048] In some embodiments of the present application, the first-round test seeds of the target smart contract are obtained in the following manner, including: compiling the target smart contract to obtain the application binary interface (ABI) file of the target smart contract; and obtaining the first-round test seeds of the target smart contract according to the data types of different parameters in the ABI file.
[0049] In some embodiments of the present application, obtaining the first-round test seeds of the target smart contract according to the data types of different parameters in the ABI file includes: for any parameter in the ABI file, if the data type of the parameter is an integer or decimal type, determining a value between the maximum and minimum values of the data type as the first-round test seed of the parameter through a random function; if the parameter is a boolean type, randomly determining a value between 0 and 1 as the first-round test seed of the parameter; if the parameter is a string type, randomly selecting a value from the constant strings in the bytecode as the first-round test seed of the parameter; if the parameter is an array type, generating the first-round test seed of the parameter according to the original data types of the elements in the array; and if the parameter is a structure type, generating the first-round test seed of the parameter according to the original data types in the structure.
[0050] For example, for a Liquid smart contract to be tested, for the sake of description, the Liquid smart contract to be tested is designated as smart contract T. First, by compiling the smart contract, the ABI file of the smart contract will be obtained.
[0051] Next, for the obtained ABI file, initial test seeds for fuzz testing the smart contract will be generated according to the data types of different function parameters in the ABI file. These initial test seeds are also the test seeds for the first round of fuzz testing. The specific methods are as follows:
[0052] First, read the data type of each parameter in the ABI file in JSON format.
[0053] Then, for the parameter data type (Type) of each parameter, execute the following rules (1)-(5):
[0054] (1) If Type is an integer or decimal type, select a value between the maximum and minimum values of the data type as the initial value of the parameter using a random function.
[0055] (2) If Type is a boolean type, randomly select a value between 0 and 1 as the initial value.
[0056] (3) If Type is of String type, randomly select a value from the constant string in the bytecode as the initial value.
[0057] (4) If Type is of array type, generate the initial value of the parameter according to the original data type of the elements in the data, using the methods in (1)-(3).
[0058] (5) If Type is of struct type, generate the initial value of the parameter according to the original data type in the struct, using the methods in (1)-(3).
[0059] In some embodiments of the present application, the function call flow graph is constructed in the following manner, including: compiling the target smart contract to obtain the WASM bytecode file of the target smart contract; determining the function set of the target smart contract and the instruction set of any function in the function set according to the WASM bytecode file; and determining the function call flow graph according to the function set and each instruction set.
[0060] In some embodiments of the present application, determining the function set of the target smart contract and the instruction set of any function in the function set according to the WASM bytecode file includes: converting the WASM bytecode file into wat text and setting the function set in the initial state; the function set in the initial state is empty; traversing each instruction in the wat text; for the currently traversed instruction, if it is determined that the instruction indicates a function, add the function indicated by the instruction to the end of the function set in the initial state; if it is determined that the instruction does not indicate a function, add the instruction to the end of the instruction set of the instruction that currently indicates the function; determining the function call flow graph according to the function set and each instruction set includes: for any function in the function set, traversing each instruction in the instruction set of the function; if it is determined that the currently traversed instruction is a call instruction, record the called function after the call instruction and add a directed connection from the function to the called function; if it is determined that the directed connection already exists, update the call count of the call edge indicated by the directed connection; if it is determined that the currently traversed instruction is a return instruction, jump to the next function in the function set and return to execute the step of traversing each instruction in the instruction set of the function, so as to obtain the function call flow graph.
[0061] Continuing with the previous example, for the smart contract T, by compiling the smart contract, the WASM bytecode will be obtained; according to the obtained WASM bytecode, the call relationship between functions in the smart contract T will be constructed, the instructions and the number that can reflect the call relationship will be recorded, and a graph will be drawn, and the drawn graph is the function call flow graph. The specific method is as follows:
[0062] 1. Initialize the graph data structure G, which consists of a set of function nodes F in the WASM bytecode and a set of directed call edges E between functions. Each function node f in the set of function nodes F is composed of the WASM opcode instruction set S and the node name name. Each directed edge e in E consists of a source node, a target node, and the call count num of this edge.
[0063] 2. Read the WASM bytecode file and use the official WASM tool wasm2wati to convert the binary WASM bytecode into a more readable wat text.
[0064] 3. Scan the obtained wat text. For each instruction instr scanned, make a judgment in the following way:
[0065] If the instruction is func, create a new function node N in the function call flow graph and add it to the end of the set of nodes F, with the node name being the function name name.
[0066] If the instruction is not func, that is, the instruction is a general instruction, add the instruction instr to the instruction set S of the node N at the end of the set of nodes.
[0067] 4. For the obtained set of function nodes F containing the instruction set, make a judgment for each node N in the set F in the following way:
[0068] (1). Scan the instruction set S in node N. For each instruction instr in the instruction set S, make a judgment in the following way:
[0069] (a). If instr is a call instruction, record the function name parameter name after the call instruction and add a directed connection from node N to the node with the name name; this directed connection is a call edge. For the call edge, make the following analysis:
[0070] If the call edge already exists, directly update the call count num of this edge in the edge set E to num + 1.
[0071] If the call edge does not exist, add the directed edge and set the call count num to 1.
[0072] (b). If instr is not a call instruction, continue scanning the next instruction and jump to (a).
[0073] (c). If instr is a return instruction, it means that the scanning of the instruction set S of this node is completed. Jump to the next node and execute (a).
[0074] After scanning all nodes \(N\) in \(F\), the function call flow graph \(G\) is obtained. The function call flow graph \(G\) contains all function node sets \(F\) and directed call edge sets \(E\).
[0075] In an implementation of the above step 103, determining the seed fitness of the candidate test seed according to the call times and the called times of the new node corresponding to the candidate test seed in the function call flow graph includes: obtaining the adjacency matrix of the function call flow graph; determining the seed fitness of the candidate test seed according to the call times, the called times of the new node corresponding to the candidate test seed in the function call flow graph, and the adjacency matrix.
[0076] For example, following the above example, for the smart contract \(A\), during the process of fuzz testing the smart contract using the initial test seed, the WASM virtual machine can be used for instrumentation processing. By placing the initial test seed in the instrumented WASM virtual machine for execution, the log output desired during the fuzz testing process can be obtained. For example, information during the execution of the opcode related to branch coverage analysis can be recorded. For example, log outputs are added to the virtual machine implementation related to the return instruction and the call instruction, so that the functions covered by the initial test seed during the fuzz testing process can be obtained.
[0077] For the functions covered by the initial test seed during the fuzz testing process, by comparing the covered functions with the pre-generated function call flow graph, it can be determined whether the covered functions cover new nodes in the function call flow graph. If it is determined that the functions cover new nodes in the function call flow graph, the initial test seed can be used as a candidate test seed. Otherwise, the initial test seed is directly discarded.
[0078] For each candidate test seed among the obtained multiple candidate test seeds, calculate the fitness \(k = \alpha S+\beta T\) of the candidate test seed.
[0079] Define \(W\) as the weighted adjacency matrix of all edges in the function call flow graph \(G\), where \(W\) ij represents the directed edge from function node \(i\) to function node \(j\), and its value is 0 (representing the non-existence of the directed edge) or \(num\) (representing the existence of the directed edge, and \(num\) is the number of calls included in this edge). \(S\) is the sum of \(num\) of all edges reaching the function \(x\) corresponding to the candidate test seed, and \(T\) is the sum of \(num\) of all next directed edges starting from the function corresponding to the candidate test seed. \(\alpha\) and \(\beta\) are the weights of \(S\) and \(T\) respectively. As an example, in this application, \(\alpha\) and \(\beta\) are set to 0.6 and 0.4 respectively.
[0080] Seeds with high fitness mean a higher chance of covering the next function node, which is more conducive to the conduct of fuzz testing. During the execution of fuzz testing, the fitness k corresponding to the new fuzz testing input seeds will be calculated according to this algorithm.
[0081] In one implementation of the above step 104, determining the (i + 1)-th round of test seeds for the (i + 2)-th round of fuzz testing from the i-th round of test seeds according to the seed fitness corresponding to each candidate test seed includes: determining each first candidate test seed and each second candidate test seed from each candidate test seed; wherein, the seed fitness of any first candidate test seed is greater than the seed fitness of any second candidate test seed; updating each first candidate test seed in a first set manner to generate each first updated test seed, and updating each second candidate test seed in a second set manner to generate each second updated test seed; using each first updated test seed and each second updated test seed as the (i + 1)-th round of test seeds for the (i + 2)-th round of fuzz testing.
[0082] For example, following the previous example, assume that after fuzz testing the smart contract using the initial test seeds, a total of 10 candidate test seeds are obtained, named candidate test seed 1, candidate test seed 2... candidate test seed 9, and candidate test seed 10 respectively. Each of these 10 candidate test seeds corresponds to a new node in the function call flow graph G. After calculating according to the above method for calculating the seed fitness, assume that after sorting these 10 candidate test seeds in descending order of seed fitness, the sorting result is candidate test seed 1, candidate test seed 2,... candidate test seed 9, candidate test seed 10.
[0083] Specifically, before using candidate test seed 1, candidate test seed 2,... candidate test seed 9, and candidate test seed 10 as the test seeds for the second round of fuzz testing in this application, an update operation for the test seeds will also be performed on these 10 candidate test seeds, so as to perform the second round of fuzz testing based on the updated test seeds obtained from the seed update operation, which can improve the efficiency of fuzz testing. Optionally, the ways of the seed update operation include crossover operation and mutation operation. Specifically, the first set manner in this application is the crossover operation manner, and the second set manner is the mutation operation manner.
[0084] The operations of crossover and mutation are as follows:
[0085] For several candidate test seeds with higher fitness rankings, perform crossover operations pairwise:
[0086] a), For candidate test seeds 1 and 2 with higher fitness ranking, decompose a certain index position i of the bit array vector of each seed into two segments, vector[0 - i] and vector[i + 1, n], where n is the length of the array;
[0087] b), Cross the second segments of the two seeds to obtain two new seeds, which are respectively denoted as updated test seed 1’ and updated test seed 2’.
[0088] For several candidate test seeds with lower fitness ranking, perform mutation operations one by one:
[0089] For example, for candidate test seed 10 with lower fitness ranking, flip a randomly selected position or byte, add or replace the selected random byte, and replace a value at a random position with a constant, so as to obtain the corresponding updated test seed 10’.
[0090] According to the same method, the updated test seeds 1’, 2’, …, 9’, 10’ after the cross and mutation operations on candidate test seeds 1, 2, …, 9, 10 can be used as the input for the second round of fuzz testing to perform the second round of fuzz testing.
[0091] Next, a specific example is used to illustrate the use of the method for determining test seeds.
[0092] For example, compile a smart contract (such as the Liquid smart contract) that supports compilation into WASM bytecode to generate an ABI file and a WASM bytecode file.
[0093] Among them, the content of the ABI file is as follows:
[0094]
[0095]
[0096] The content of the WASM bytecode is as follows:
[0097] 0x0061736d0100000001500d60027…
[0098] Initialize the seed pool according to the ABI file: For the function named test in the ABI, which has a parameter named number of type uint32 and a return value of type bool. Since the maximum and minimum values of the uint32 type are 4294967295 and 0 respectively, and the value range of bool is 0 and 1, assume the input seeds in the randomly initialized seed pool are 0x21902100 (in hexadecimal representation) and 0, corresponding to the uint32 and bool types respectively.
[0099] Construct the function call flow graph G according to the WASM bytecode file, as follows:
[0100] In the initial state, according to the hierarchical relationship, the data structure of the function call flow graph G contains a set of function nodes F and a set of edges E. Each node f in the set of function nodes F consists of an opcode instruction set S and a function node name name. The set of edges E consists of a source node e1, a target node e2, and the call count num of this edge. These data structures are initialized as empty sets.
[0101] Then, convert the bytecode into the wat text format, as follows:
[0102]
[0103]
[0104] For the wat text format of the above example, the set of function nodes F adds nodes N1 and N2. The instruction set S of N1 contains all the instructions within the func$f7, and the same applies to N2. The node name name of N1 is 7, and the node name name of N2 is 8.
[0105] Next, add call edges. Taking the above figure as an example, scan the set of nodes F. When scanning the instructions in node N1, it is found that the func$f7 contains the statement call$f8. Then, it is found that the name of the target node is 8, and the name of the source node is itself. That is, add an edge e to the set of edges E. The name of the source node of this edge is 7, and the name of the target node is 8. Since the existence of this call edge has not been searched before, the call count num of this call edge is set to 1.
[0106] As Figure 2As shown, it is a schematic diagram of a function call flow graph provided in an embodiment of the present application, wherein each circle represents a function node, and the function name is marked in the circle, wherein the directed arrow is a call edge, and for a call edge, the number on the call edge represents the number of calls to the target function contained in the source node function. If the call edge is not marked with a number, the default number of function calls is 1, otherwise, it indicates that the number of function calls is the number marked on the call edge, for example, $func11 contains 5 calls to $func19.
[0107] Fitness calculation: For a test seed that covers a new function node, its fitness k needs to be calculated based on the obtained function call flow graph G. For example, for the candidate test seed s1 that covers $func19 in the figure above, the value of S is 5, that is, the number of calls num on the call edge starting from $func11 is 5, and the value of T is 6, that is, the number of calls to other function nodes included in the directed edge starting from $func19 is 6. The calculated k value is 5.4. The fitness calculation method for other seeds is the same.
[0108] Crossover and mutation process: First, sort each candidate test seed according to the fitness level, and perform crossover operations on the candidate test seeds with higher fitness that are ranked higher. For example, for the two selected seeds s1 (0x21902100) and s2 (0x10231442), truncation and crossover are performed at the second byte, that is, the 16-bit position, and the new seed s3 is (0x21901442) and s4 is (0x10232100). For the candidate test seeds with lower fitness that are ranked lower, random bit flipping is performed (a certain bit changes from 0 to 1), for example, s5 (0x00001100) is bit flipped at the lowest bit to obtain s6 (0x00001101), and these new seeds are put into the seed pool.
[0109] Based on the same concept, the present application embodiment provides a device for determining a test seed, such as Figure 3 , which is a schematic diagram of a test seed determination device provided in an embodiment of the present application, the device includes a function call record acquisition unit 301, a candidate test seed determination unit 302, a seed fitness determination unit 303 and a test seed determination unit 304;
[0110] A function call record acquisition unit 301 is used to perform an i+1th round of fuzzy testing based on the i-th round of test seeds for the target smart contract, and obtain function call records of each test seed in the i-th round of test seeds in the i+1th round of fuzzy testing;
[0111] A candidate test seed determination unit 302, configured to, for any test seed in the i-th round of test seeds, according to the function call record of the test seed in the (i + 1)-th round of fuzz testing, if it is determined that the test seed covers a new node in the function call flow graph in the (i + 1)-th round of fuzz testing, retain the test seed as a candidate test seed; wherein, the function call flow graph is constructed by using each function in the target smart contract as a node, and connecting nodes of two functions with a call relationship as a call edge, and any call edge is marked with the number of function calls;
[0112] A seed fitness determination unit 303, configured to, for any candidate test seed in the i-th round of test seeds, determine the seed fitness of the candidate test seed according to the number of call times and the number of times being called of the new node corresponding to the candidate test seed in the function call flow graph;
[0113] A test seed determination unit 304, configured to determine the (i + 1)-th round of test seeds for the (i + 2)-th round of fuzz testing from the i-th round of test seeds according to the seed fitness corresponding to each candidate test seed respectively, and return to execute the step of performing the (i + 1)-th round of fuzz testing based on the i-th round of test seeds for the target smart contract until the preset time of the fuzz testing is satisfied.
[0114] Further, for this device, it further includes an initial test seed determination unit 305; the initial test seed determination unit 305 is configured to: compile the target smart contract to obtain the application binary interface ABI file of the target smart contract; obtain the first round of test seeds of the target smart contract according to the data types of different parameters in the ABI file.
[0115] Further, for this device, the initial test seed determination unit 305 is specifically configured to: for any parameter in the ABI file, if the data type of the parameter is an integer or a decimal type, determine a value between the maximum value and the minimum value of the data type as the first round of test seed of the parameter through a random function; if the parameter is a boolean type, randomly determine a value between 0 and 1 as the first round of test seed of the parameter; if the parameter is a string type, randomly select a value from the constant strings in the bytecode as the first round of test seed of the parameter; if the parameter is an array type, generate the first round of test seeds of the parameter according to the original data types of the elements in the array; if the parameter is a structure type, generate the first round of test seeds of the parameter according to the original data types in the structure.
[0116] Further, for the device, it further includes a function call flow graph construction unit 306; the function call flow graph construction unit 306 is configured to: compile the target smart contract to obtain the WASM bytecode file of the target smart contract; determine the function set of the target smart contract and the instruction set of any function in the function set according to the WASM bytecode file; and determine the function call flow graph according to the function set and each instruction set.
[0117] Further, for the device, the function call flow graph construction unit 306 is specifically configured to: convert the WASM bytecode file into a wat text and set an initial function set; the initial function set is empty; traverse each instruction in the wat text; for the currently traversed instruction, if it is determined that the instruction indicates a function, add the function indicated by the instruction to the end of the initial function set; if it is determined that the instruction does not indicate a function, add the instruction to the end of the instruction set of the instruction that currently indicates a function; for any function in the function set, traverse each instruction in the instruction set of the function; if it is determined that the currently traversed instruction is a call instruction, record the called function after the call instruction and add a directed connection from the function to the called function; if it is determined that the directed connection already exists, update the call count of the call edge indicated by the directed connection; if it is determined that the currently traversed instruction is a return instruction, jump to the next function in the function set and return to execute the step of traversing each instruction in the instruction set of the function, so as to obtain the function call flow graph.
[0118] Further, for the device, the seed fitness determination unit 303 is specifically configured to: obtain the adjacency matrix of the function call flow graph; determine the seed fitness of the candidate test seed according to the call count, the called count of the new node corresponding to the candidate test seed in the function call flow graph, and the adjacency matrix.
[0119] Further, for the device, the seed fitness determination unit 303 is specifically configured to: determine an initial seed fitness k; where k = αS + βT, α and β are the preset weights of S and T respectively, S represents the sum of the call counts of each incoming call edge reaching the new node determined based on the function call flow graph, and T represents the sum of the call counts of each outgoing call edge starting from the new node determined based on the function call flow graph; determine the seed fitness of the candidate test seed according to the initial seed fitness k and the adjacency matrix.
[0120] Further, for the device, the test seed determination unit 304 is specifically configured to:
[0121] Determine each first candidate test seed and each second candidate test seed from each candidate test seed; wherein, the seed fitness of any first candidate test seed is greater than the seed fitness of any second candidate test seed; update each first candidate test seed in a first set manner to generate each first updated test seed, and update each second candidate test seed in a second set manner to generate each second updated test seed; use each first updated test seed and each second updated test seed as the (i + 1)-th round of test seeds for the (i + 2)-th round of fuzz testing.
[0122] An embodiment of this application also provides a computing device, which may specifically be a desktop computer, a portable computer, a smart phone, a tablet computer, a personal digital assistant (PDA), etc. The computing device may include a central processing unit (CPU), a memory, input / output devices, etc. The input devices may include a keyboard, a mouse, a touch screen, etc. The output devices may include display devices, such as a liquid crystal display (LCD), a cathode ray tube (CRT), etc.
[0123] The memory may include a read-only memory (ROM) and a random access memory (RAM), and provide program instructions and data stored in the memory to the processor. In the embodiment of this application, the memory may be used to store the program instructions of the method for determining test seeds;
[0124] The processor is used to call the program instructions stored in the memory and execute the method for determining test seeds according to the obtained program.
[0125] As Figure 4 shown, it is a schematic diagram of a computing device provided by an embodiment of this application. The computing device includes:
[0126] A processor 401, a memory 402, a transceiver 403, and a bus interface 404; wherein, the processor 401, the memory 402, and the transceiver 403 are connected through a bus 405;
[0127] The processor 401 is used to read the program in the memory 402 and execute the above method for determining test seeds;
[0128] The processor 401 may be a central processing unit (CPU), a network processor (NP), or a combination of a CPU and an NP. It may also be a hardware chip. The above-mentioned hardware chip may be an application-specific integrated circuit (ASIC), a programmable logic device (PLD), or a combination thereof. The above-mentioned PLD may be a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof.
[0129] The memory 402 is used to store one or more executable programs and can store the data used by the processor 401 when performing operations.
[0130] Specifically, the program may include program code, and the program code includes computer operation instructions. The memory 402 may include a volatile memory, such as a random-access memory (RAM); the memory 402 may also include a non-volatile memory, such as a flash memory, a hard disk drive (HDD), or a solid-state drive (SSD); the memory 402 may also include a combination of the above types of memories.
[0131] The memory 402 stores the following elements, executable modules, or data structures, or subsets thereof, or extended sets thereof:
[0132] Operation instructions: including various operation instructions for implementing various operations.
[0133] Operating system: including various system programs for implementing various basic services and processing hardware-based tasks.
[0134] The bus 405 can be a Peripheral Component Interconnect (PCI) bus, an Extended Industry Standard Architecture (EISA) bus, or the like. The bus can be divided into an address bus, a data bus, a control bus, etc. For the sake of convenience of representation, Figure 4 only a thick line is used to represent it in Figure 4 , but it does not mean that there is only one bus or one type of bus.
[0135] The bus interface 404 can be a wired communication access port, a wireless bus interface, or a combination thereof. Among them, the wired bus interface can be, for example, an Ethernet interface. The Ethernet interface can be an optical interface, an electrical interface, or a combination thereof. The wireless bus interface can be a WLAN interface.
[0136] The embodiment of the present application also provides a computer-readable storage medium, and the computer-readable storage medium stores computer-executable instructions for causing a computer to execute the method for determining a test seed.
[0137] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a computer program product, or a combination thereof. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memories, CD-ROMs, optical memories, etc.) containing computer-usable program codes.
[0138] The present application is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or block in the flowchart and / or block diagram, and the combination of processes and / or blocks in the flowchart and / or block diagram, can be realized by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate a device for realizing the functions specified in Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.
[0139] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured product including an instruction device, and the instruction device realizes the functions in the process Figure 1one process or multiple processes and / or blocks Figure 1 the functions specified in one block or multiple blocks.
[0140] These computer program instructions can also be loaded onto a computer or other programmable data processing device, so that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in Figure 1 one process or multiple processes and / or blocks Figure 1 the functions specified in one block or multiple blocks.
[0141] Although the preferred embodiments of the present application have been described, those skilled in the art can make additional changes and modifications to these embodiments once they learn the basic creative concepts. Therefore, the appended claims are intended to be construed to include the preferred embodiments as well as all changes and modifications falling within the scope of the present application.
[0142] Obviously, those skilled in the art can make various changes and modifications to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalent technologies, the present application is also intended to include these modifications and variations.
Claims
1. A method for determining test seeds, characterized in that, Including: For the i-th round of test seeds of the target smart contract, perform the (i + 1)-th round of fuzz testing based on the i-th round of test seeds, and obtain the function call records of each test seed in the i-th round of test seeds during the (i + 1)-th round of fuzz testing; For any one of the test seeds in the i-th round of test seeds, according to the function call record of the test seed during the (i + 1)-th round of fuzz testing, if it is determined that the test seed covers a new node in the function call flow graph during the (i + 1)-th round of fuzz testing, then retain the test seed as a candidate test seed; wherein, the function call flow graph is constructed with each function in the target smart contract as a node, and a node connection is made between two functions with a call relationship as a call edge, and any call edge is marked with the function call count; For any one of the candidate test seeds in the i-th round of test seeds, determine the seed fitness of the candidate test seed according to the call count and the called count of the new node corresponding to the candidate test seed in the function call flow graph; According to the seed fitness corresponding to each candidate test seed respectively, determine the (i + 1)-th round of test seeds for the (i + 2)-th round of fuzz testing from the i-th round of test seeds, and return to execute the step of performing the (i + 1)-th round of fuzz testing based on the i-th round of test seeds of the target smart contract until the preset time of the fuzz testing is satisfied.
2. The method according to claim 1, characterized in that, i=1; Obtain the first round of test seeds of the target smart contract through the following method, including: Compile the target smart contract to obtain the application binary interface (ABI) file of the target smart contract; According to the data types of different parameters in the ABI file, obtain the first round of test seeds of the target smart contract.
3. The method according to claim 2, wherein The obtaining the first round of test seeds of the target smart contract according to the data types of different parameters in the ABI file includes: For any one of the parameters in the ABI file, if the data type of the parameter is an integer or a decimal type, determine a value between the maximum value and the minimum value of the data type through a random function as the first round of test seed of the parameter; If the parameter is a boolean type, randomly determine a value from 0 and 1 as the first round of test seed of the parameter; If the parameter is a string type, randomly select a value from the constant strings in the bytecode as the first round of test seed of the parameter; If the parameter is an array type, generate the first round of test seeds of the parameter according to the original data types of the elements in the array; If the parameter is a structure type, generate the first round of test seeds of the parameter according to the original data types in the structure.
4. The method according to claim 1, wherein The function call flow graph is constructed through the following method, including: Compile the target smart contract to obtain the WASM bytecode file of the target smart contract; According to the WASM bytecode file, determine the function set of the target smart contract and the instruction set of any one function in the function set; Determine the function call flow graph according to the function set and each instruction set.
5. The method according to claim 4, wherein the determining the function set of the target smart contract and the instruction set of any function in the function set according to the WASM bytecode file includes: Convert the WASM bytecode file into a wat text and set a function set in an initial state; the function set in the initial state is empty; Traverse each instruction in the wat text; For the currently traversed instruction, if it is determined that the instruction indicates a function, add the function indicated by the instruction to the end of the function set in the initial state; If it is determined that the instruction does not indicate a function, add the instruction to the end of the instruction set of the instruction currently indicating the function; The determining the function call flow graph according to the function set and each instruction set includes: For any function in the function set, traverse each instruction in the instruction set of the function; if it is determined that the currently traversed instruction is a call instruction, record the called function after the call instruction and add a directed connection from the function to the called function; if it is determined that the directed connection already exists, update the call count of the call edge indicated by the directed connection; If it is determined that the currently traversed instruction is a return instruction, jump to the next function in the function set and return to execute the step of traversing each instruction in the instruction set of the function, so as to obtain the function call flow graph.
6. The method according to claim 1, wherein the determining the seed fitness of the candidate test seed according to the call count and the called count of the new node corresponding to the candidate test seed in the function call flow graph includes: Obtain the adjacency matrix of the function call flow graph; Determine the seed fitness of the candidate test seed according to the call count, the called count of the new node corresponding to the candidate test seed in the function call flow graph, and the adjacency matrix.
7. The method according to claim 6, wherein the determining the seed fitness of the candidate test seed according to the call count, the called count of the new node corresponding to the candidate test seed in the function call flow graph, and the adjacency matrix includes: Determine an initial seed fitness k; where k = αS + βT, α and β are preset weights of S and T respectively, S represents the sum of the call counts of each incoming call edge reaching the new node determined based on the function call flow graph, and T represents the sum of the call counts of each outgoing call edge starting from the new node determined based on the function call flow graph; Determine the seed fitness of the candidate test seed according to the initial seed fitness k and the adjacency matrix.
8. The method according to claim 1, wherein the determining the (i + 1)-th round of test seeds for the (i + 2)-th round of fuzz testing from the i-th round of test seeds according to the seed fitness corresponding to each candidate test seed includes: Determine each first candidate test seed and each second candidate test seed from each candidate test seed; wherein, the seed fitness of any first candidate test seed is greater than the seed fitness of any second candidate test seed; Update each first candidate test seed in a first set manner to generate each first updated test seed, and update each second candidate test seed in a second set manner to generate each second updated test seed; Use each first updated test seed and each second updated test seed as the (i + 1)-th round test seeds for the (i + 2)-th round of fuzz testing.
9. A determining device for test seeds, characterized in that, Comprising: A function call record acquisition unit, configured to perform the (i + 1)-th round of fuzz testing based on the i-th round test seeds for the target smart contract, and acquire the function call records of each test seed in the i-th round test seeds during the (i + 1)-th round of fuzz testing; A candidate test seed determination unit, configured to, for any one test seed in the i-th round test seeds, according to the function call record of the test seed during the (i + 1)-th round of fuzz testing, if it is determined that the test seed covers a new node in the function call flow graph during the (i + 1)-th round of fuzz testing, retain the test seed as a candidate test seed; wherein, the function call flow graph is constructed with each function in the target smart contract as a node, and a node connection is made between two functions with a call relationship as a call edge, and any call edge is marked with the function call times; A seed fitness determination unit, configured to, for any one candidate test seed in the i-th round test seeds, determine the seed fitness of the candidate test seed according to the call times and the called times of the new node corresponding to the candidate test seed in the function call flow graph; A test seed determination unit, configured to determine the (i + 1)-th round test seeds for the (i + 2)-th round of fuzz testing from the i-th round test seeds according to the seed fitness corresponding to each candidate test seed, and return to execute the step of performing the (i + 1)-th round of fuzz testing based on the i-th round test seeds for the target smart contract, until the preset time of the fuzz testing is satisfied.
10. A computer device, characterized in that, Comprising: A memory, configured to store a computer program; A processor, configured to call the computer program stored in the memory and execute the method according to any one of claims 1 - 8 according to the obtained program.
11. A computer-readable storage medium, characterized in that, The storage medium stores computer-executable instructions, and the computer-executable instructions are used to cause a computer to execute the method according to any one of claims 1 - 8.
Citation Information
Patent Citations
Naming and blockchain record of the internet of things (IoT)
CN110024422A
Method and system for improving coverage of fuzzy test
CN112328505A