A security detection method and system for power Internet of Things devices
Through segmented tests and historical test results analysis, the fuzz test duration of power IoT devices is accurately regulated, and the problem of unreasonable repeated tests and test durations in existing fuzz tests is solved, and efficient and accurate safety detection is achieved.
Patent Information
- Application Number
- CN202211391196.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-11-08
- Publication Date
- 2025-06-27
- Estimated Expiration
- 2042-11-08
AI Technical Summary
Existing fuzz testing can easily lead to repeated tests during the testing process, waste time and unreasonable test duration, which may affect the normal use of the tested target or the vulnerability cannot be discovered.
Through segmented testing, the test data of power IoT devices are obtained, the configuration files are processed in segments and parsed, the fragility of each test segment is calculated based on historical test results and preset test targets, and the test duration of each target test segment is accurately controlled to avoid repeated tests.
It effectively avoids repeated tests, reduces the amount of calculation during the test process, shortens the test time, ensures the normal use of the test objects, and significantly improves the detection effect.
Smart Images

Figure CN115618347B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure belongs to the technical field of fuzz testing, and particularly relates to a security detection method and system for power Internet of Things devices. Background Art
[0002] The statements in this part merely provide background technical information related to the present disclosure and do not necessarily constitute prior art.
[0003] With the development of modern economy and information technology, the industrial control information system not only means facing security threats beyond traditional control functions, but also means that the industrial control system will face various ransomware viruses, hidden Trojan viruses, and various hacker intrusions.
[0004] Fuzzy security testing technology is a kind of security testing application technology. By fuzzily constructing abnormal input data in software, it can cause abnormal situations such as system crashes in the constructed software, and based on this, accurately locate security hidden problems existing in the software. The technology of using fuzz testing for vulnerability analysis has the characteristic of traversing all inputs because fuzz testing itself has the possibility of traversing various fuzzed variant data. Therefore, compared with other methods for security vulnerability mining, the efficiency of fuzz testing in discovering security hidden problems and technical vulnerabilities is significantly improved, and it can disclose many blind spots that cannot be reached by traditional means, and has received extensive attention and welcome in the fields of information security and vulnerability analysis.
[0005] However, in the existing fuzz testing during the testing process, since the test tasks are all set manually, it may cause fuzz testing to be performed again on the same test completion or a target with almost zero vulnerability rate. Repeated testing not only wastes time but also increases the workload of testers. In addition, the existing tests rarely consider the test duration. If the test duration is too long, it may affect the normal use of the target under test. If the test duration is too short, it may not be able to discover vulnerabilities. Summary of the Invention
[0006] To solve the above problems, the present disclosure proposes a security detection method and system for power Internet of Things devices, which consider historical test situations and test duration, and effectively improve the detection effect by accurately regulating the test duration of each target test segment through segmented testing.
[0007] According to some embodiments, the first solution of the present disclosure provides a security detection method for power Internet of Things devices, adopting the following technical solution:
[0008] A security detection method for power Internet of Things devices, comprising:
[0009] Obtain test data of the power Internet of Things device;
[0010] Segment the obtained test data to obtain test segments and the configuration files corresponding to the test segments;
[0011] Based on the test segments, determine the target test segment, parse the configuration file of the target test segment, and obtain the target fuzz testing run object file containing the test duration;
[0012] Adjust the user fuzz testing engine, perform fuzz testing on the target fuzz testing run object file, and generate a test result when the test duration is reached to complete the security detection of the power Internet of Things device.
[0013] As a further technical limitation, the test data includes a task name, identification information of the test segment to be tested, the task information creator, the creation time, and the configuration file; the configuration file includes test cases, the number of tests, and the connection entry for running the test task; the identification information includes a main number and a sub-number, the main number is used to indicate the serial number of the test target where the test segment is located, and the sub-number is used to indicate the serial number of the target test segment in the test target.
[0014] As a further technical limitation, in the process of determining the target test segment based on the test segments, retrieve the historical test results from the historical test database; determine the target test segment from the test segments according to the historical test results.
[0015] Further, the method for retrieving the historical test results from the historical test database includes:
[0016] Obtain the identification information corresponding to the test segment, and the identification information includes a main number and a sub-number;
[0017] Determine the first target storage range from the historical test database according to the main number;
[0018] Determine the first target storage location from the first target storage range according to the sub-number;
[0019] Call the historical test results stored at the first target storage location.
[0020] Further, the method for screening out the target test segment from the test segments according to the historical test results includes:
[0021] Obtain the historical test times, the vulnerability rate corresponding to the historical test, the preset test times, and the preset vulnerability rate corresponding to the preset test;
[0022] Calculate the vulnerability degree of the test segment according to the historical test times, the vulnerability rate corresponding to the historical test, the preset test times, and the preset vulnerability rate corresponding to the preset test;
[0023] Screen out the target test segment from the test segments according to the vulnerability level.
[0024] Further, the process of parsing the configuration file of the target test segment is as follows:
[0025] Determine the second target storage range from the algorithm parsing library according to the main number;
[0026] Determine the second target storage location from the second target storage range according to the sub-number;
[0027] Call the parsing algorithm stored at the second target storage location, and use the parsing algorithm to parse the configuration file of the target test segment to obtain the configuration file.
[0028] As a further technical limitation, the target fuzz testing run object file including the test duration includes:
[0029] Obtain configuration information, where the configuration information includes the length of the code to be tested in the target test segment;
[0030] Calculate the test duration of each target test segment according to the length, vulnerability level and preset test duration. The preset test duration includes a first preset test duration and a second preset test duration, and the first preset test duration is greater than the second preset test duration;
[0031] Generate a target fuzz testing run object file including the test duration.
[0032] According to some embodiments, the second solution of the present disclosure provides a security detection system for power Internet of Things devices, adopting the following technical solution:
[0033] A security detection system for power Internet of Things devices includes:
[0034] An acquisition module, which is configured to acquire test data of power Internet of Things devices;
[0035] A segmentation module, which is configured to segment the acquired test data to obtain test segments and the configuration files corresponding to the test segments;
[0036] An analysis module, which is configured to determine a target test segment based on the test segments, and analyze the configuration file of the target test segment to obtain a target fuzz testing run object file including the test duration;
[0037] A detection module, which is configured to adjust the user fuzz testing engine, perform fuzz testing on the target fuzz testing run object file, and generate a test result when the test duration is reached, thereby completing the security detection of the power Internet of Things device.
[0038] According to some embodiments, the third solution of the present disclosure provides a computer-readable storage medium, adopting the following technical solution:
[0039] A computer-readable storage medium, on which a program is stored, and when the program is executed by a processor, it implements the steps in the security detection method of the power Internet of Things device as described in the first aspect of the present disclosure.
[0040] According to some embodiments, the fourth solution of the present disclosure provides an electronic device, adopting the following technical solution:
[0041] An electronic device includes a memory, a processor, and a program stored on the memory and executable on the processor. When the processor executes the program, it implements the steps in the security detection method of the power Internet of Things device as described in the first aspect of the present disclosure.
[0042] Compared with the prior art, the beneficial effects of the present disclosure are as follows:
[0043] The present disclosure obtains the vulnerability levels of each test segment through historical test results and preset test targets, and screens out the target test segments from the test segments input by the user according to the vulnerability levels, avoiding repeated tests, reducing the calculation amount during the test, and shortening the test time. At the same time, considering the vulnerability level, length, and preset test duration of the test segments, it realizes the precise control of the test duration of each target test segment, shortens the test duration while ensuring the normal use of the test object, and significantly improves the detection effect. BRIEF DESCRIPTION OF THE DRAWINGS
[0044] The accompanying drawings forming a part of this disclosure are used to provide a further understanding of the disclosure. The illustrative embodiments and descriptions thereof of the disclosure are used to explain the disclosure and do not constitute an improper limitation of the disclosure.
[0045] Figure 1 is a flowchart of the security detection method of the power Internet of Things device in Embodiment 1 of the present disclosure;
[0046] Figure 2 is a block diagram of the structure of the security detection system of the power Internet of Things device in Embodiment 2 of the present disclosure. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0047] The following further describes the present disclosure in conjunction with the accompanying drawings and embodiments.
[0048] It should be noted that the following detailed descriptions are all illustrative and are intended to provide further descriptions of the present disclosure. Unless otherwise specified, all technical and scientific terms used herein have the same meaning as commonly understood by those of ordinary skill in the technical field to which the present disclosure belongs.
[0049] It should be noted that the terms used herein are only for describing specific embodiments and are not intended to limit the exemplary embodiments according to the present disclosure. As used herein, unless the context clearly indicates otherwise, the singular forms are also intended to include the plural forms. In addition, it should be understood that when the terms "comprising" and / or "including" are used in this specification, they indicate the presence of features, steps, operations, devices, components, and / or combinations thereof.
[0050] In the present disclosure, terms such as "upper", "lower", "left", "right", "front", "rear", "vertical", "horizontal", "side", "bottom", etc. indicate the orientation or positional relationship based on the orientation or positional relationship shown in the drawings. They are only relational terms determined for the convenience of describing the structural relationship of each component or element of the present disclosure and do not specifically refer to any component or element in the present disclosure and should not be construed as a limitation to the present disclosure.
[0051] In the present disclosure, terms such as "fixed connection", "connected", "connected to" should be understood in a broad sense, indicating that it can be a fixed connection, an integral connection or a detachable connection; it can be directly connected or indirectly connected through an intermediate medium. For those skilled in relevant scientific research or technology in this field, the specific meanings of the above terms in this disclosure can be determined according to specific circumstances and should not be construed as a limitation to the present disclosure.
[0052] Without conflict, the embodiments in the present disclosure and the features in the embodiments can be combined with each other.
[0053] Embodiment 1
[0054] Embodiment 1 of the present disclosure introduces a security detection method for power Internet of Things devices.
[0055] As Figure 1 shown, a security detection method for power Internet of Things devices includes:
[0056] Obtain test data of the power Internet of Things device;
[0057] Perform segmented processing on the obtained test data to obtain test segments and the configuration files corresponding to the test segments;
[0058] Determine the target test segment based on the test segments, parse the configuration file of the target test segment to obtain the target fuzz testing run object file including the test duration;
[0059] Adjust the user fuzz testing engine, perform fuzz testing on the target fuzz testing run object file, and generate a test result when the test duration is reached to complete the security detection of the power Internet of Things device.
[0060] As one or more embodiments, the test file may include a task name, identification information of the test segment to be tested, the task information creator, the creation time, and a configuration file, and the configuration file includes information such as test cases and the number of tests. Of course, operations such as adding, deleting, querying, and modifying the data in the test file can be performed as needed. In addition, the configuration file may further contain a connection entry for running the test task; the configuration files are all encrypted and compressed files, and the data in the configuration file needs to be parsed subsequently to be read.
[0061] The identification information includes a main number and a sub-number. The main number is used to indicate the serial number of the test target where the test segment is located, and the sub-number is used to indicate the serial number of the target test segment in the test target.
[0062] The test segment can be a device, or a certain file in a device, or a certain segment of a certain file in a certain device. The test target can be a device cluster, or a device, or a certain file of a certain device.
[0063] In this embodiment, the method for determining the target test segment from the test segments includes:
[0064] Retrieving the historical test results from the historical test database;
[0065] Determining the target test segment from the test segments according to the historical test results.
[0066] The historical test of the test segment can directly affect the parameters of its re-test. Therefore, in the embodiments of the present invention, the historical test results and the preset test target are used to evaluate the test segment. When it meets the requirements for re-test, it is determined as the target test segment and screened out from multiple test segments, thus avoiding multiple useless repeated tests and shortening the test duration.
[0067] In this embodiment, the method for retrieving the historical test results from the historical test database includes:
[0068] Obtaining the identification information corresponding to the test segment, where the identification information includes a main number and a sub-number. The main number is used to indicate the serial number of the test target where the test segment is located, and the sub-number is used to indicate the serial number of the target test segment in the test target;
[0069] Determining a first target storage range from the historical test database according to the main number;
[0070] Determining a first target storage location from the first target storage range according to the sub-number;
[0071] Invoking the historical test results stored at the first target storage location.
[0072] In the embodiment of the present invention, the historical test data of each test segment is stored in the historical test, and is distributed and stored according to the main number and sub-number of each test target, which is convenient for subsequent query, call or modification.
[0073] In this embodiment, the method for screening out the target test segment from the test segments according to the historical test results includes:
[0074] Obtain the historical test times, the vulnerability rate corresponding to the historical test, the preset test times, and the preset vulnerability rate corresponding to the preset test;
[0075] Calculate the vulnerability degree of the test segment according to the historical test times, the vulnerability rate corresponding to the historical test, the preset test times, and the preset vulnerability rate corresponding to the preset test;
[0076] Screen out the target test segment from the test segments according to the vulnerability degree.
[0077] Since the test times of each test segment and the number of vulnerabilities obtained in each test are different, it can be known that the vulnerability degree of each test segment is different, that is, the probability of discovering vulnerabilities is different. If a test segment is tested multiple times and its vulnerability rate in each test is high, it means it is more vulnerable. On the contrary, if a test segment has few test times but its vulnerability rate is very low, it may be that the test segment has been tested with the same test cases many times, rather than having a high vulnerability degree.
[0078] The formula for calculating the vulnerability degree constructed in this embodiment is:
[0079]
[0080] In the formula, Fra i represents the vulnerability degree of the test segment with the i-th sub-number, F i represents the test times of the test segment with the i-th sub-number, f i represents the preset test times of the test segment with the i-th sub-number, R i represents the vulnerability rate of the test segment with the i-th sub-number, r i represents the preset vulnerability rate of the test segment with the i-th sub-number.
[0081] In this embodiment, the method for parsing the configuration file of the target test segment through the preset parsing algorithm includes:
[0082] Determine the second target storage range from the algorithm parsing library according to the main number;
[0083] Determine the second target storage location from the second target storage range according to the sub-number;
[0084] Call the parsing algorithm stored in the second target storage location, and use the parsing algorithm to parse the configuration file of the target test segment to obtain configuration information.
[0085] In the embodiment of the present invention, the parsing data of each test segment is stored in the algorithm parsing library and is distributedly stored according to the main number and sub-number of each test target, which is convenient for subsequent query, call or modification.
[0086] In this embodiment, the method for generating the target fuzz testing run object file includes:
[0087] Obtain configuration information, where the configuration information includes the length of the code to be tested in the target test segment;
[0088] Determine the test duration of each target test segment according to the length, vulnerability level and preset test duration. The preset test duration includes a first preset test duration and a second preset test duration, and the first preset test duration is greater than the second preset test duration;
[0089] Generate a target fuzz testing run object file including the test duration.
[0090] Specifically, the higher the vulnerability level, the longer the required test time, and the longer the length (which can also be the file size) of the target test segment, the longer the required test time. Based on the above, the calculation formula for the test duration of each target test segment constructed in the embodiment of the present invention is:
[0091]
[0092] where t i represents the test duration of the target test segment with the i-th sub-number, T1 represents the first preset test duration, T2 represents the second preset test duration, L i represents the length of the target test segment with the i-th sub-number, Len represents the total length of all target test segments, and n represents the number of target test segments.
[0093] The embodiment of the present invention provides two preset durations, namely the first preset duration and the second preset duration. The first preset duration is the basic duration of each fuzz testing. The gain duration of each fuzz testing is determined according to the vulnerability level of each target test segment, and the proportion of each target test segment in the total duration of each fuzz testing is determined according to the length of each target test segment. Then, the test duration corresponding to each target test segment is calculated, and testing according to this duration can ensure the smooth progress of the test.
[0094] Specifically, the target fuzz testing run object file includes information such as the target test segment, the target port called by the test, the target fuzz testing algorithm called by the fuzz testing, and the test duration.
[0095] Specifically, corresponding test cases are generated according to the fuzz testing algorithm, and the test port is called to send the test cases generated by the target fuzz testing algorithm in an attack manner to the target test segment to complete the fuzz testing. If all the test cases within the test duration have been fully tested, the test cases are repeated for testing and test results are generated. If not all the test cases within the test duration have been completed, the test results are directly generated.
[0096] In this embodiment, the vulnerability levels of each test segment are obtained through historical test results and preset test targets. The target test segment is selected from the test segments input by the user according to the vulnerability level, avoiding repeated testing, reducing the computational workload during the testing process, and shortening the testing time. At the same time, considering the vulnerability level, length of the test segment, and preset test duration, precise regulation of the test duration for each target test segment is achieved, ensuring the normal use of the test object while shortening the test duration, and significantly improving the detection effect.
[0097] Embodiment Two
[0098] Embodiment Two of the present disclosure introduces a security detection system for power Internet of Things devices.
[0099] As Figure 2 shown, a security detection system for power Internet of Things devices includes:
[0100] An acquisition module, configured to acquire test data of the power Internet of Things device;
[0101] A segmentation module, configured to segment the acquired test data to obtain test segments and configuration files corresponding to the test segments;
[0102] An analysis module, configured to determine a target test segment based on the test segment, analyze the configuration file of the target test segment, and obtain a target fuzz testing running object file including the test duration;
[0103] A detection module, configured to adjust the user fuzz testing engine, perform fuzz testing on the target fuzz testing running object file, and generate test results when the test duration is reached, completing the security detection of the power Internet of Things device.
[0104] The detailed steps are the same as those of the security detection method for power Internet of Things devices provided in Embodiment One, and will not be elaborated here.
[0105] Embodiment Three
[0106] Embodiment Three of the present disclosure provides a computer-readable storage medium.
[0107] A computer-readable storage medium stores a program thereon, and when the program is executed by a processor, the steps in the security detection method of the power Internet of Things device as described in Embodiment 1 of the present disclosure are implemented.
[0108] The detailed steps are the same as those of the security detection method of the power Internet of Things device provided in Embodiment 1, and will not be elaborated here.
[0109] Embodiment 4
[0110] Embodiment 4 of the present disclosure provides an electronic device.
[0111] An electronic device includes a memory, a processor, and a program stored on the memory and executable on the processor. When the processor executes the program, the steps in the security detection method of the power Internet of Things device as described in Embodiment 1 of the present disclosure are implemented.
[0112] The detailed steps are the same as those of the security detection method of the power Internet of Things device provided in Embodiment 1, and will not be elaborated here.
[0113] The above are only the preferred embodiments of the present disclosure and are not used to limit the present disclosure. For those skilled in the art, the present disclosure can have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present disclosure shall be included in the protection scope of the present disclosure.
[0114] Although the specific implementation manners of the present disclosure have been described above in conjunction with the accompanying drawings, it is not a limitation on the protection scope of the present disclosure. Those skilled in the art should understand that, based on the technical solutions of the present disclosure, various modifications or deformations that can be made without creative efforts by those skilled in the art are still within the protection scope of the present disclosure.
Claims
1. A security detection method for power Internet of Things devices, characterized in that Including: Obtain the test data of the power Internet of Things device; Perform segmented processing on the obtained test data to obtain test segments and the configuration files corresponding to the test segments; Based on the test segments, determine the target test segment, parse the configuration file of the target test segment to obtain a target fuzz testing run object file including the test duration; Adjust the user fuzz testing engine, perform fuzz testing on the target fuzz testing run object file, and generate a test result when the test duration is reached, completing the security detection of the power Internet of Things device; In the process of determining the target test segment based on the test segments, retrieve the historical test results from the historical test database; Determine the target test segment from the test segments according to the historical test results; The method for screening the target test segment from the test segments according to the historical test results includes: Obtain the historical test times, the vulnerability rate corresponding to the historical test, the preset test times, and the preset vulnerability rate corresponding to the preset test; Calculate the vulnerability degree of the test segment according to the historical test times, the vulnerability rate corresponding to the historical test, the preset test times, and the preset vulnerability rate corresponding to the preset test; Screen the target test segment from the test segments according to the vulnerability degree; The target fuzz testing run object file including the test duration includes: Obtain configuration information, where the configuration information includes the length of the code to be tested in the target test segment; Calculate the test duration of each target test segment according to the length, vulnerability degree, and preset test duration, where the preset test duration includes a first preset test duration and a second preset test duration, and the first preset test duration is greater than the second preset test duration; Generate a target fuzz testing run object file including the test duration.
2. The security detection method of an electric power Internet of Things device as described in claim 1, characterized in that, The test data includes the task name, the identification information of the test segment to be tested, the task information creator, the creation time, and the configuration file; the configuration file includes test cases, the number of tests, and the connection entry for running the test task; the identification information includes the main number and the sub-number, the main number is used to indicate the serial number of the test target where the test segment is located, and the sub-number is used to indicate the serial number of the target test segment in the test target.
3. The security detection method for an electric power Internet of Things device as described in claim 1, wherein The method for retrieving the historical test results from the historical test database includes: Obtain the identification information corresponding to the test segment, where the identification information includes the main number and the sub-number; Determine the first target storage range from the historical test database according to the main number; Determine the first target storage location from the first target storage range according to the sub-number; Call the historical test results stored at the first target storage location.
4. The security detection method for an electric power Internet of Things device as described in claim 3, characterized in that, The process of parsing the configuration file of the target test segment is: Determine the second target storage range from the algorithm parsing library according to the main number; Determine the second target storage location from the second target storage range according to the sub-number; Call the parsing algorithm stored at the second target storage location, and use the parsing algorithm to parse the configuration file of the target test segment to obtain the configuration file.
5. A security detection system for power Internet of Things devices, characterized in that, Including: An acquisition module configured to acquire the test data of the power Internet of Things device; A segmentation module, which is configured to segment the acquired test data to obtain test segments and configuration files corresponding to the test segments; A parsing module, which is configured to determine a target test segment based on the test segment, parse the configuration file of the target test segment, and obtain a target fuzz testing run object file including a test duration; A detection module, which is configured to adjust the user fuzz testing engine, perform fuzz testing on the target fuzz testing run object file, and generate a test result when the test duration is reached, completing the security detection of the power Internet of Things device; In the process of determining the target test segment based on the test segment, the historical test results are retrieved from the historical test database; The target test segment is determined from the test segments according to the historical test results; The method for screening the target test segment from the test segments according to the historical test results includes: Obtaining the historical test times, the vulnerability rate corresponding to the historical test, the preset test times, and the preset vulnerability rate corresponding to the preset test; Calculating the vulnerability degree of the test segment according to the historical test times, the vulnerability rate corresponding to the historical test, the preset test times, and the preset vulnerability rate corresponding to the preset test; Screening the target test segment from the test segments according to the vulnerability degree; The target fuzz testing run object file including the test duration includes: Obtaining configuration information, where the configuration information includes the length of the code to be tested in the target test segment; Calculating the test duration of each target test segment according to the length, the vulnerability degree, and the preset test duration, where the preset test duration includes a first preset test duration and a second preset test duration, and the first preset test duration is greater than the second preset test duration; Generating a target fuzz testing run object file including the test duration.
6. A computer-readable storage medium having a program stored thereon, characterized in that, When the program is executed by a processor, it implements the steps in the security detection method of the power Internet of Things device described in any one of claims 1-4.
7. An electronic device, comprising a memory, a processor, and a program stored on the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the steps in the security detection method of the power Internet of Things device described in any one of claims 1-4.
Citation Information
Patent Citations
Risk testing method and device and storage medium
CN113626830A
Generating synthetic test cases for network fuzz testing
US20220269591A1