基于状态驱动的Linux内核漏洞可用性搜索方法及系统

By constructing a three-layer feedback mechanism and state variable instrumentation, the problem of fuzzing methods being unable to focus on vulnerabilities in the Linux kernel is solved, achieving comprehensive vulnerability exploration and reducing false positives.

CN116451236BActive Publication Date: 2026-07-17Chinese People's Liberation Army Cyberspace Force Information Engineering University

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Chinese People's Liberation Army Cyberspace Force Information Engineering University
Filing Date
2023-03-30
Publication Date
2026-07-17

AI Technical Summary

Technical Problem

Existing fuzzing methods struggle to focus their efforts on Linux kernel vulnerabilities, failing to fully explore their exploitability and leading to misjudgments and insufficient vulnerability discovery.

Method used

By extracting key objects and state variables from kernel vulnerability data, a three-layer feedback mechanism is constructed, consisting of coverage feedback, kernel key object feedback, and kernel state feedback. Using state variables as input, fuzzing instrumentation is performed to guide fuzzing to search for vulnerability-related code segments and explore different paths and states.

Benefits of technology

It effectively improves the efficiency and ability of fuzz testing in discovering different erroneous behaviors of vulnerabilities, ensuring that energy is concentrated near the current vulnerability, comprehensively exploring the exploitability of the vulnerability, and reducing false positives.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116451236B_ABST
    Figure CN116451236B_ABST
Patent Text Reader

Abstract

本发明涉及网络安全技术领域,特别涉及一种基于状态驱动的Linux内核漏洞可用性搜索方法及系统,通过提取内核漏洞数据中漏洞相关的关键对象,其中,内核漏洞数据包含:内核错误报告及相应的内核源码;对关键对象的成员变量进行分析来获取漏洞相关的状态变量,并以状态变量作为输入进行模糊测试插桩;构建包含覆盖率反馈、内核关键对象反馈和内核状态反馈的三层反馈机制,以在内核关键对象反馈约束下引导模糊测试搜索当前漏洞相关代码段、在覆盖率反馈和内核状态反馈约束下引导模糊测试探索不同路径和内核状态。本发明从当前漏洞相关的状态变量入手,以模糊测试为基础,有效解决传统的模糊测试难以聚焦单个的漏洞可利用性、无法全面挖掘漏洞错误行为的问题。
Need to check novelty before this filing date? Find Prior Art