A Fuzz Testing Method and System Based on Associated Information of Web Services in Embedded Devices
By combining static analysis and dynamic execution methods, the related information of embedded device Web service and construct test cases are extracted, and the problem of low fuzzy testing of embedded device Web service is solved, precise monitoring of data interaction and implicit call paths is realized, and vulnerability mining efficiency is improved.
Patent Information
- Application Number
- CN202310082373.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-01-17
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2043-01-17
AI Technical Summary
The prior art is difficult to efficiently analyze data interaction and implicit calls of embedded device web services, resulting in low vulnerability mining efficiency on embedded device web services and unable to meet current information security needs.
The method of combining static analysis and dynamic execution is adopted to extract the related information of the embedded device Web service, including data flow keywords and sensitive function call paths, and test cases are constructed through the embedded device Web service front-end management interface, and the dynamic program instrumentation method is used to monitor data interaction and implicit calls to achieve accurate monitoring.
It improves the fuzz testing efficiency of embedded device web services, breaks through complex interactions and implicit call constraints, realizes accurate identification and monitoring of sensitive function call paths, and solves the incompatibility of traditional fuzz testing methods on embedded devices.
Smart Images

Figure CN116010279B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular, to a fuzz testing method and system based on associated information of Web services of embedded devices. Background Art
[0002] In recent years, the security of Internet of Things (IoT) devices has attracted increasing attention. Among all IoT devices, wireless routers and network cameras are attacked more frequently than other embedded devices. The key reason is that these embedded devices containing Web servers expose Web services with exploitable vulnerabilities. The existing methods cannot efficiently analyze Web services in embedded systems to detect vulnerabilities because there are complex data interactions and implicit data flows between the front-end management interfaces (interfaces) and back-end binary components of Web services of embedded devices.
[0003] After years of research on software vulnerability mining technology, many technical means such as static analysis, symbolic execution, and fuzz testing have been proposed for vulnerability mining. Generally speaking, these vulnerability mining technical means can be roughly divided into two categories: dynamic solutions and static solutions. Among them, dynamic solutions provide program states at runtime, but these states can only cover a small part of all possible program states, which leads to a large number of false negatives; static solutions do not involve the specific code execution process, which leads to many false positives.
[0004] In dynamic solutions, fuzz testing is the most widely used vulnerability mining technology at present. Its advantages such as high degree of automation, low system consumption, low false positive rate, and independence from the source code of the target program have aroused people's enthusiasm for fuzz testing research. Many researchers have applied fuzz testing technology to vulnerability mining. Through several years of research, fuzz testing technology has been developed to a certain extent. In the testing of traditional desktop platforms, fuzz testing has good performance. However, this technology still has certain inadaptability in testing Web services of embedded devices.
[0005] The traditional fuzz testing method for Web services of embedded devices has been difficult to meet the requirements of protecting the privacy and information security of end-users of embedded devices under the current situation. Therefore, it is particularly important to discover these vulnerabilities before they are exploited by malicious attackers. Proposing an efficient fuzz testing method for Web services of embedded devices is a feasible solution to address the above challenges. Summary of the Invention
[0006] The present invention proposes a fuzz testing method and system based on the associated information of embedded device Web services. It mainly targets the Web services of embedded devices, guides fuzz testing through the associated information of embedded device Web services obtained by pre-analysis, accurately locates and analyzes the data interaction between the front and back ends of embedded device Web services, and solves the problem of low vulnerability mining efficiency when traditional fuzz testing methods are applied to embedded device Web services.
[0007] To achieve the above object, the present invention adopts the following technical solutions:
[0008] On the one hand, the present invention proposes a fuzz testing method based on the associated information of embedded device Web services, which utilizes the idea of combining static analysis and dynamic execution. The associated information of embedded device Web services obtained in the static analysis stage is applied to the dynamic fuzz testing of embedded device Web services, avoiding blind and meaningless test analysis, and thus realizing the improvement of vulnerability mining efficiency when testing on embedded device Web services. The method specifically includes:
[0009] Extract the associated information of embedded device Web services, where the associated information of embedded device Web services includes data flow keywords and sensitive function call paths;
[0010] Test the embedded device Web services by constructing test cases through the front-end management interface of the embedded device Web services and using the data flow keywords, and at the same time monitor the identified sensitive function call paths. The accurate monitoring of complex data interaction and implicit calls in the embedded device Web services is realized through the dynamic program instrumentation method, avoiding ineffective tests and thus improving the fuzz testing efficiency of the embedded device Web services.
[0011] Further, the data flow keywords are obtained in the following manner:
[0012] Take the firmware decompression package squashfs extracted by Binwalk as the input, and divide the firmware decompression package squashfs into a front-end file set and a back-end file set by means of file classification;
[0013] Extract the front-end keyword set of all front-end files in the front-end file set by means of regular matching and abstract syntax tree methods;
[0014] Traverse and extract the back-end keywords of each back-end binary component in the back-end file set, and record the intersection of the back-end files and back-end keywords with the front-end keyword set as the data flow keywords and store them in a mapping structure;
[0015] Sort the mapping structure by the method of sorting according to the number of keywords in the match to obtain the final mapping structure.
[0016] Further, after obtaining the data stream keywords, it further includes:
[0017] According to the role played by the data stream keywords in data interaction, they are further subdivided into parameter - type keywords for the actual content information of the payload and API - type keywords for identifying processing functions.
[0018] Further, the sensitive function call path is obtained in the following manner:
[0019] Generate a decompiled object of the interactive binary component;
[0020] Traversingly analyze each keyword in the parameter - type data stream keywords corresponding to the interactive binary component in the reference function set of the decompiled object of the interactive binary component;
[0021] For any reference function set, traverse the complete function call chain of each reference function therein, and filter out the function call chains containing sensitive functions and store them together with the parameter - type data stream keywords in a mapping structure.
[0022] Further, test cases are constructed in the following manner:
[0023] Capture the data packets in the normal interaction of the embedded device Web service as the original test cases and perform primitive disassembling. After mutating the data stream keywords therein, recombine them to generate the test cases to be sent.
[0024] Further, a dynamic program instrumentation method is implemented using a remote debugging architecture based on "gdb + gdbserver":
[0025] Set the semaphore to be monitored and the debugging rules in the interactive binary component as the preset conditions. When the interactive binary component meets the preset conditions during operation, trigger the debugging of gdb, and automatically monitor its running status to provide fuzz testing feedback;
[0026] When the process of the interactive binary component crashes, the remote debugging environment gdb cannot continue to obtain real - time running information, and the target device system generates a core dump file. The fuzz testing engine uploads the core dump file back through the API of gdb via a socket for debugging and detecting the crash site.
[0027] On the other hand, the present invention proposes a fuzz testing system based on the associated information of the embedded device Web service, including:
[0028] An associated information extraction module, configured to extract the associated information of the embedded device Web service, where the associated information of the embedded device Web service includes data stream keywords and sensitive function call paths;
[0029] The fuzz testing module is used to test the embedded device web service through the front - end management interface of the embedded device web service and construct test cases using data flow keywords, while monitoring the identified sensitive function call paths, and achieving precise monitoring of complex data interactions and implicit calls in the embedded device web service through dynamic program instrumentation methods, avoiding ineffective tests and thus improving the fuzz testing efficiency of the embedded device web service.
[0030] Further, the data flow keywords are obtained in the following way:
[0031] Taking the firmware unpacked package squashfs extracted by Binwalk as the input, and dividing the firmware unpacked package squashfs into a front - end file set and a back - end file set through a file classification method;
[0032] Extracting the front - end keyword set of all front - end files in the front - end file set by regular matching and abstract syntax tree methods;
[0033] Traversing to extract the back - end keywords of each back - end binary component in the back - end file set, and recording the intersection of the back - end files, back - end keywords and the front - end keyword set as the data flow keywords and storing them in a mapping structure;
[0034] Sorting the mapping structure by the method of sorting according to the number of keywords in the match to obtain the final mapping structure.
[0035] Further, the associated information extraction module is also used for:
[0036] Continuing to subdivide according to the role played by the data flow keywords in data interaction into parameter - type keywords for the actual content information of the payload and API - type keywords for identifying processing functions.
[0037] Further, the sensitive function call paths are obtained in the following way:
[0038] Generating a decompiled object of the interactive binary component;
[0039] Traversing and analyzing each keyword in the parameter - type data flow keywords corresponding to the interactive binary component in the reference function set of the decompiled object of the interactive binary component;
[0040] For any reference function set, traversing the complete function call chain of each reference function in it, and screening out the function call chains containing sensitive functions and storing them in the mapping structure together with the parameter - type data flow keywords.
[0041] Further, the test cases are constructed in the following way:
[0042] Capture the data packets in the normal interaction of the embedded device web service as the original test cases, perform primitive disassembling, mutate the data flow keywords therein, and recombine them to generate the test cases to be sent.
[0043] Furthermore, implement a dynamic program instrumentation method based on the remote debugging architecture of "gdb + gdbserver":
[0044] Set the semaphore to be monitored and the debugging rules in the interactive binary component as the preset conditions. When the interactive binary component meets the preset conditions during operation, trigger the debugging of gdb, automatically monitor its running status, and provide fuzz testing feedback;
[0045] When the process of the interactive binary component crashes, the remote debugging environment gdb cannot continue to obtain real-time running information, and the target device system generates a core dump file. The fuzz testing engine uses the API of gdb to upload the core dump file via a socket for debugging and detecting the crash site.
[0046] Compared with the prior art, the beneficial effects of the present invention are:
[0047] Traditional fuzz testing methods do not consider the complete process of data interaction in embedded device web services from an overall perspective, and cannot accurately locate and monitor the complex interaction processes and implicit calls therein. There are certain incompatibilities when applied to the testing of actual embedded device web services. In addition, the diverse processor architectures of embedded devices also hinder the traditional fuzz testing methods from being tested on embedded device web services to a certain extent. However, the present invention guides fuzz testing through the associated information of embedded device web services obtained by pre-static analysis, breaks through the complex information interaction constraints in embedded device web services, and realizes the accurate identification of sensitive function call paths; on the basis of accurately identifying sensitive function call paths, uses a cross-architecture monitoring mechanism to accurately monitor sensitive paths in the web services of embedded devices, and solves the incompatibility when the fuzz testing method is applied to the embedded platform. In addition, the present invention uses a test case construction method based on primitive splitting, only introducing a small amount of necessary test payloads into the original interaction information, which can ensure the effectiveness of the test cases while not being rejected in large quantities by the web service objects of the embedded devices to be tested.
[0048] Starting from the information interaction process in the Web service of embedded devices, and based on static analysis and dynamic testing, the present invention proposes a fuzz testing method and system for the Web service of embedded devices, effectively solving the problem that traditional fuzz testing methods are difficult to effectively test the Web service of embedded devices. Moreover, the present invention is applied to the actual testing of the Web service of embedded devices, and the testing effect is significantly improved, and it has good adaptability to the Web service of embedded devices. Description of the Drawings
[0049] Figure 1 It is the basic flowchart of a fuzz testing method for the Web service of embedded devices based on associated information according to an embodiment of the present invention;
[0050] Figure 2 It is an example diagram of decompilation according to an embodiment of the present invention;
[0051] Figure 3 It is a schematic diagram of the architecture of the fuzz testing engine constructed according to an embodiment of the present invention;
[0052] Figure 4 It is an example diagram of the test case generation process according to an embodiment of the present invention;
[0053] Figure 5 It is a schematic diagram of the sensitive function instrumentation process according to an embodiment of the present invention;
[0054] Figure 6 It is a schematic diagram of the architecture of a fuzz testing system for the Web service of embedded devices based on associated information according to an embodiment of the present invention. Detailed Embodiments
[0055] The following further explains the present invention in conjunction with the drawings and specific embodiments:
[0056] As Figure 1 shown, a fuzz testing method for the Web service of embedded devices based on associated information includes:
[0057] Extracting the associated information of the Web service of the embedded device, where the associated information of the Web service of the embedded device includes data flow keywords and sensitive function call paths;
[0058] Testing the Web service of the embedded device by constructing test cases through the front-end management interface of the Web service of the embedded device and using the data flow keywords, and at the same time monitoring the identified sensitive function call paths, and realizing precise monitoring of complex data interactions and implicit calls in the Web service of the embedded device through the dynamic program instrumentation method, avoiding invalid testing and thus improving the fuzz testing efficiency of the Web service of the embedded device.
[0059] The following is a specific elaboration:
[0060] 1. The present invention uses the associated information of the embedded device Web service to guide fuzz testing. Therefore, first, it is necessary to extract the associated information of the embedded device Web service, which mainly consists of two parts: 1) data flow keywords, which are the keywords for data interaction between the front-end management interface and the back-end binary components carried in the embedded device Web service; 2) sensitive function call paths, which are the function call paths where the data flow keywords are referenced in the back-end binary components of the embedded device Web service and may have security vulnerabilities.
[0061] 1.1 Regarding the data flow keywords, the present invention obtains them by regular matching and abstract syntax trees based on the categories of the front-end resource files of the embedded device Web service (mainly three categories: Html, Xml, and Js), and continues to divide them into parameter class keywords that carry the actual content information of the payload (such as Figure 2 the "deviceName" field in Figure 2 ) and API class keywords used to identify processing functions (such as
[0062] the "goform / setUsbUnload" field in
[0063] ). The process description of the specific data flow keyword extraction algorithm is as follows:
[0064] ① First, the algorithm takes the firmware decompression package squashfs extracted by Binwalk as the input, and divides the firmware decompression package squashfs into a front-end file set front_files and a back-end file set back_files through the file_classify method for file classification;
[0065] ④Finally, the algorithm sorts the mapping structure bin_keywords_map through the sort_by_match_num method that sorts according to the number of keywords in the match, and obtains the final bin_keywords_map.
[0066] bin_keywords_map is a mapping of serial numbers sorted in descending order to interactive binary components (backend binary components responsible for front-end and back-end interaction) and the corresponding data flow keywords, expressed as bin_keywords_map := index → bin, keywds, where index represents the serial number, bin represents the interactive binary component, and keywds represents the data flow keywords corresponding to the interactive binary component. Among them, any group of keywd in keywds can be represented by parameter class keyword para and API class keyword api as: keywd = [api, para], that is, keywds can be represented by several groups of [api, para].
[0067] 1.2 Regarding the sensitive function call path, the present invention extracts it with a sensitive function call path generation algorithm. This algorithm takes the interactive binary component bin and its corresponding parameter class data flow keyword para_keywds as inputs. The specific process description of the sensitive function call path generation algorithm is as follows:
[0068] ①First, the algorithm generates a decompiled object current_Program of the interactive binary component bin through the read_bin method;
[0069] ②Then, the algorithm traverses and analyzes each para_keywd in the parameter class data flow keyword para_keywds corresponding to bin in the reference function set callers of the decompiled object current_Program of bin through the get_refFunc method;
[0070] ③For any reference function set callers, the algorithm traverses the complete function call chain caller_chain of each caller in it through the check_callPcode method, and filters out the caller_chain containing the sensitive functions in Table 1 and para_keywd through the check_focusFun method and stores them in the mapping structure keywd_paths together.
[0071] The algorithm finally obtains the mapping of parameter class data flow keywords to sensitive function call paths in the current binary program: para_keywd_paths:=para_keywd→path. At the same time, from the relationship between parameter class keywords and API class keywords in 1.1, it can be seen that para_keywd_paths:=[api,para]→path.
[0072] It is worth noting that the implementation of related functions in the sensitive function call path generation algorithm calls the API of the open source disassembly tool Ghidra. For example, the function check_callPcode is used to obtain the complete function call chain caller_chain of the keyword keywd. Its functional implementation depends on the Ghidra P-Code API provided by Ghidra. Ghidra P-Code is a register transfer language designed by Ghidra specifically for reverse engineering. It can model CPUs of different architectures, convert various CPU assembly codes into a unified intermediate language P-Code, and provide an API. In addition, the function check_focusFun is responsible for determining whether caller_chain is a path that may lead to security vulnerabilities. The sensitive function check basis of check_focusFun is shown in Table 1.
[0073] Table 1 Sensitive function table
[0074]
[0075] 2. After obtaining the above embedded device Web service association information, it is necessary to apply the association information to the fuzzy test of the embedded device Web. Therefore, the present invention constructs a fuzzy test engine (such as Figure 3 As shown in the figure, the fuzz test is implemented by using the associated information. 1) The data flow keywords [api_keywd, para_keywd] guide + fuzz testing to generate higher quality test cases; 2) The sensitive function call path path is realized through the dynamic program instrumentation (binary code dynamic instrumentation) technology to form feedback on the efficient abnormal monitoring mechanism of the backend Web service binary component of the embedded device, thereby guiding the fuzz test.
[0076] 2.1 Regarding the test case generation part, the present invention adopts a mutation method based on primitive (here specifically refers to the inseparable protocol field in the network protocol) disassembly. Specifically, the present invention captures the data packets in the normal interaction of the embedded device Web service as the original test case and performs primitive disassembly, mutates the key primitives (data flow keywords) therein, and then reassembles them to generate the test case to be sent. The detailed generation process is as follows: Figure 4 shown.
[0077] 2.2 Embedded devices have a rich and diverse architecture system. When performing program instrumentation on the firmware of embedded devices, cross-architecture debugging is the first challenge to face. During the implementation process, the present invention realizes an efficient exception monitoring mechanism for the Web service binary components of embedded devices through the sensitive function instrumentation method. The realization of this method depends on the dynamic binary code instrumentation technology to Figure 3 dynamically instrument the call path path of sensitive functions in
[0078] Specifically, the realization of the sensitive function instrumentation method is based on the remote debugging architecture of "gdb + gdbserver". Gdb (in the present invention, the version gdb-multiarch that supports debugging multiple hardware architectures is actually used) is a powerful tool that supports debugging application programs in the Linux system. Gdb has strong cross-architecture capabilities and can meet the debugging requirements of target programs with different architectures; Gdb can meet the personalized debugging needs of developers, and it provides rich and convenient Python APIs for external scripts to call. In addition, the debugging command "follow-fork-mode" of gdb has good support for multi-process debugging, avoiding missing the business logic processing program that is the focus of attention during debugging. Therefore, the "gdb + gdbserver" remote debugging architecture well supports the implementation requirements of the sensitive function instrumentation method.
[0079] When using gdb to debug a program, gdb can monitor and capture various signals generated during the program's operation and suspend the program according to the set debugging rules to obtain the current program state context information, such as memory information, register information, stack and heap structures, and function call chains. As Figure 5 shown, the fuzz testing engine uses this feature of gdb to set the signal quantity and debugging rules to be monitored in the interactive binary component as preconditions. When the interactive binary component meets the preconditions during operation, it triggers the debugging of gdb and automatically monitors its running status to provide fuzz testing feedback. In addition, when the process of the interactive binary component crashes, the remote debugging environment gdb cannot continue to obtain real-time running information, and the target device system will generate a core dump file. The fuzz testing engine uses the API of gdb to transfer the core dump file back through the socket for debugging and detecting the crash site. The backtrace of the crash site helps to analyze complex crashes to finally confirm vulnerabilities.
[0080] Based on the above embodiments, as Figure 6 shown, the present invention also proposes a fuzz testing system based on the associated information of the Web service of the embedded device, including:
[0081] An associated information extraction module, which is used to extract the associated information of the embedded device Web service, and the associated information of the embedded device Web service includes data flow keywords and sensitive function call paths;
[0082] A fuzz testing module, which is used to test the embedded device Web service by constructing test cases through the front-end management interface of the embedded device Web service and using the data flow keywords, and at the same time monitor the identified sensitive function call paths, and achieve precise monitoring of complex data interactions and implicit calls in the embedded device Web service through the dynamic program instrumentation method, avoid invalid tests, and thus improve the fuzz testing efficiency of the embedded device Web service.
[0083] Further, the data flow keywords are obtained in the following manner:
[0084] Taking the firmware decompression package squashfs extracted by Binwalk as the input, and dividing the firmware decompression package squashfs into a front-end file set and a back-end file set by means of file classification;
[0085] Extracting the front-end keyword set of all front-end files in the front-end file set by means of regular matching and abstract syntax tree methods;
[0086] Traversing and extracting the back-end keywords of each back-end binary component in the back-end file set, and recording the intersection of the back-end file and the back-end keyword with the front-end keyword set as the data flow keywords and storing them in the mapping structure;
[0087] Sorting the mapping structure by the method of sorting according to the number of keywords in the matching to obtain the final mapping structure.
[0088] Further, the associated information extraction module is also used for:
[0089] Continuing to subdivide according to the role played by the data flow keywords in data interaction into parameter class keywords for the actual content information of the payload and API class keywords for identifying processing functions.
[0090] Further, the sensitive function call path is obtained in the following manner:
[0091] Generating a decompiled object of the interactive binary component;
[0092] Traversing and analyzing each keyword in the parameter class data flow keywords corresponding to the generated interactive binary component in the reference function set of the decompiled object of the interactive binary component;
[0093] For any reference function set, traversing the complete function call chain of each reference function in it, and screening out the function call chains containing sensitive functions and storing them in the mapping structure together with the parameter class data flow keywords.
[0094] Furthermore, test cases are constructed in the following manner:
[0095] Capture the data packets in the normal interaction of the embedded device web service as the original test cases and perform primitive disassembly. After mutating the data flow keywords therein, recombine them to generate the test cases to be sent.
[0096] Furthermore, implement the dynamic program instrumentation method based on the remote debugging architecture of "gdb + gdbserver":
[0097] Set the semaphore to be monitored and the debugging rules in the interactive binary component as the preset conditions. When the interactive binary component meets the preset conditions during operation, trigger the debugging of gdb, and automatically monitor its running status to provide fuzz testing feedback;
[0098] When the process of the interactive binary component crashes, the remote debugging environment gdb cannot continue to obtain real-time running information, and the target device system generates a core dump file. The fuzz testing engine uses the API of gdb to upload the core dump file via a socket for debugging and detecting the crash site.
[0099] In summary, based on the traditional fuzz testing method for embedded device web services, the present invention uses the associated information of the embedded device web service to guide the fuzz testing process, improving the overall efficiency of fuzz testing on embedded device web services.
[0100] The above are only the preferred embodiments of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present invention, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of the present invention.
Claims
1. A fuzz testing method based on associated information of Web services in embedded devices, characterized in that Including: Extract the associated information of the embedded device Web service, where the associated information of the embedded device Web service includes data flow keywords and sensitive function call paths; Test the embedded device Web service through the front-end management interface of the embedded device Web service and construct test cases using the data flow keywords. At the same time, monitor the identified sensitive function call paths, and achieve precise monitoring of data interaction and implicit calls in the embedded device Web service through the dynamic program instrumentation method to avoid ineffective testing; Obtain the data flow keywords in the following manner: Take the firmware decompression package squashfs extracted by Binwalk as the input, and divide the firmware decompression package squashfs into a front-end file set and a back-end file set by classifying files; Extract the front-end keyword set of all front-end files in the front-end file set using regular matching and abstract syntax tree methods; Traverse and extract the back-end keywords of each back-end binary component in the back-end file set, and record the intersection of the back-end files, back-end keywords, and the front-end keyword set as the data flow keywords and store them in the mapping structure; Sort the mapping structure by the method of sorting according to the number of keywords in the match to obtain the final mapping structure; Obtain the sensitive function call paths in the following manner: Generate the decompiled object of the interactive binary component; Analyze each keyword in the parameter class data flow keywords corresponding to the generated interactive binary component in the reference function set of the decompiled object of the interactive binary component; For any reference function set, traverse each complete function call chain in it, and filter out the function call chains containing sensitive functions and store them in the mapping structure together with the parameter class data flow keywords; Implement the dynamic program instrumentation method using the remote debugging architecture based on "gdb + gdbserver": Set the semaphore and debugging rules to be monitored in the interactive binary component as preconditions. When the interactive binary component meets the preconditions during operation, trigger the debugging of gdb, and automatically monitor its running status to provide fuzz testing feedback; When the process of the interactive binary component crashes, the remote debugging environment gdb cannot continue to obtain real-time running information, and the target device system generates a core dump file. The fuzz testing engine uses the API of gdb to upload the core dump file through the socket for debugging and detecting the crash site.
2. The fuzz testing method based on the associated information of the Web service of the embedded device according to claim 1, characterized in that After obtaining the data flow keywords, it also includes: Continue to subdivide according to the role played by the data flow keywords in data interaction into parameter class keywords for the actual content information of the payload and API class keywords for identifying processing functions.
3. A fuzz testing method based on associated information of Web services of an embedded device according to claim 1, characterized in that, Construct test cases in the following manner: Capture the data packets in the normal interaction of the embedded device Web service as the original test cases and perform primitive decomposition. After mutating the data flow keywords in them, recombine them to generate the test cases to be sent.
4. A fuzz testing system based on associated information of Web services of an embedded device, characterized in that, Including: An associated information extraction module for extracting the associated information of the embedded device Web service, where the associated information of the embedded device Web service includes data flow keywords and sensitive function call paths; The fuzz testing module is used to test the embedded device Web service through the front-end management interface of the embedded device Web service and construct test cases using data flow keywords, while monitoring the identified sensitive function call paths, and achieving precise monitoring of data interaction and implicit calls in the embedded device Web service through dynamic program instrumentation methods, avoiding ineffective tests; Obtain data flow keywords in the following manner: Use the firmware unpacked package squashfs extracted by Binwalk as input, and divide the firmware unpacked package squashfs into a front-end file set and a back-end file set by classifying files; Extract the front-end keyword set of all front-end files in the front-end file set using regular matching and abstract syntax tree methods; Traverse and extract the back-end keywords of each back-end binary component in the back-end file set, and record the intersection of the back-end file, back-end keyword, and front-end keyword set as the data flow keyword and store it in the mapping structure; Sort the mapping structure by the method of sorting according to the number of keywords in the match to obtain the final mapping structure; Obtain sensitive function call paths in the following manner: Generate the decompiled object of the interactive binary component; Traverse and analyze each keyword in the parameter class data flow keyword corresponding to the generated interactive binary component in the reference function set of the decompiled object of the interactive binary component; For any reference function set, traverse the complete function call chain of each reference function in it, and filter out the function call chain containing sensitive functions and store it in the mapping structure together with the parameter class data flow keyword; Implement the dynamic program instrumentation method based on the remote debugging architecture of "gdb + gdbserver": Set the semaphore to be monitored and debugging rules in the interactive binary component as the preset condition. When the interactive binary component meets the preset condition during operation, trigger the debugging of gdb, and automatically monitor its running status to provide fuzz testing feedback; When the process of the interactive binary component crashes, the remote debugging environment gdb cannot continue to obtain real-time running information, and the target device system generates a core dump file. The fuzz testing engine uses the API of gdb to upload the core dump file through the socket for debugging and detecting the crash site.
5. The fuzz testing system based on the associated information of the Web service of the embedded device according to claim 4, wherein The associated information extraction module is also used for: Continue to be subdivided into parameter class keywords for the actual content information of the payload and API class keywords for identifying processing functions according to the role played by the data flow keywords in data interaction.
6. The fuzz testing system based on the Web service associated information of the embedded device according to claim 4, wherein Construct test cases in the following manner: Capture the data packets in the normal interaction of the embedded device Web service as the original test case and perform primitive decomposition, mutate the data flow keywords in it, and then recombine them to generate the test case to be sent.
Citation Information
Patent Citations
Fuzzy test method for firmware of industrial control equipment
CN111830928A
Fuzzy testing method and device oriented to Windows program graphical interface bypassing
CN114416520A