Code testing method, device and medium based on directed gray box fuzz testing technology
By using directional gray box fuzzing technology in fuzzing test, combined with the analysis of control flow and data flow, the problem that existing fuzzing test technology cannot effectively reach the target point, achieving more efficient testing and more comprehensive coverage.
Patent Information
- Application Number
- CN202410387237.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-04-01
- Publication Date
- 2025-06-06
- Estimated Expiration
- 2044-04-01
AI Technical Summary
Existing fuzz testing techniques cannot effectively target the target point, resulting in waste of resources and performance losses.
By obtaining the source code to be tested, determining the target points, and filtering key points through static analysis of control flow and data flow. Then, determine the distance between the seed execution path and the base block and the target point, allocate energy and cyclic variations to generate a test case.
Improves testing efficiency, reduces performance losses, can more effectively detect software defects, and improves test coverage.
Smart Images

Figure CN118227494B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of software security technology, and in particular to a code testing method, device and medium based on directed grey box fuzz testing technology. Background Art
[0002] With the popularization of computers and smart devices, the impact of software on people's lives is becoming increasingly obvious. To ensure the security of software, software must undergo security testing before release to find existing functional errors and security vulnerabilities. Fuzz testing is a software testing technology for finding software vulnerabilities. Its idea is to provide a large number of test inputs to the program under test and observe the abnormal behavior of the program. In order to solve the problem that fuzz testing cannot be directed, a directed greybox fuzzing technology (Directed Greybox Fuzzing, DGF) is proposed on the basis of fuzz testing technology. It uses most of the time budget to reach and test the target site without wasting resources to emphasize irrelevant program components. Therefore, DGF can reach and test the target location faster than general fuzz testing technology. This feature makes DGF perform well in certain usage scenarios such as patch testing, crash reproduction, and static analysis report verification.
[0003] However, most existing fuzz testing technologies are based on the seed distance calculation method of AFLGO, which has major flaws: the generated seed distance cannot well express the ability of the current seed to reach the target point, nor can it effectively exclude irrelevant inputs, thus wasting a lot of energy to explore irrelevant code. In addition, most existing fuzz testing technologies use full coverage instrumentation to obtain seed coverage feedback to calculate the seed distance. Full coverage instrumentation uses a large number of instrumentation statements, which will cause a large performance loss during the test process. Summary of the invention
[0004] In order to solve the above problems, this application proposes a code testing method based on directed gray box fuzz testing technology, including:
[0005] Obtaining source code to be tested, determining target points corresponding to the source code, and compiling the source code. During the compilation process, filtering key points in the source code;
[0006] Determine a seed execution path corresponding to the key point, and determine the distance between a basic block in the seed execution path and the target point by using a preset distance calculator;
[0007] For each seed execution path, the basic block with the smallest corresponding distance is used as the seed distance, and according to the seed distance, energy is allocated to the seed corresponding to the seed distance;
[0008] For the seed after energy allocation, the seed is cyclically mutated, and the source code is tested based on the mutated seed to obtain a corresponding abnormal feedback report.
[0009] In one implementation of the present application, after obtaining the source code to be tested, the method further includes:
[0010] Based on a preset CG / CFG extractor, the control flow in the source code is extracted, and the source code is statically analyzed to obtain the data flow corresponding to the source code.
[0011] In an implementation of the present application, after determining the distance between the basic block in the seed execution path and the target point, the method further includes:
[0012] The key points in the data flow and the control flow are plugged by a preset plugger to obtain corresponding plugging points.
[0013] In an implementation of the present application, for the seed after energy allocation, before cyclically mutating the seed, the method further includes:
[0014] determining whether the seed reaches the insertion point or the target point;
[0015] If so, the seed is added to the seed queue as an interesting seed, so as to generate corresponding mutant seeds by cyclically mutating the seeds in the seed queue, and the mutant seeds are used as test input to test the source code.
[0016] In one implementation of the present application, determining the distance between the basic block in the seed execution path and the target point by a preset distance calculator specifically includes:
[0017] Determining, according to the control flow, whether a current basic block currently executed in the seed execution path is located at the target point;
[0018] If yes, assign 1 to the current basic block;
[0019] If not, determine whether the current basic block has a successor basic block, and if the successor basic block exists, calculate the reachability corresponding to the current basic block according to the successor basic block;
[0020] The inverse of the reachability is taken as the distance between the current basic block and the target point.
[0021] In an implementation of the present application, before calculating the reachability corresponding to the current basic block according to the successor basic block, the method further includes:
[0022] Determine, according to the data flow, the variable type associated with the subsequent basic block; wherein the variable type includes key variables and auxiliary variables;
[0023] According to the variable type, a corresponding weight is assigned to the successor basic block, and the weight corresponding to the successor basic block associated with the key variable is greater than the weight corresponding to the successor basic block associated with the auxiliary variable.
[0024] In an implementation of the present application, calculating the reachability corresponding to the current basic block according to the successor basic block specifically includes:
[0025] Determine all successor basic blocks of the current basic block;
[0026] For each successor basic block, determine whether the successor basic block is located at the target point, and if so, use the successor basic block as a target successor basic block, and set the reachability value corresponding to the target successor basic block to 1;
[0027] Taking the target successor basic block as a starting point, traversing forward all successor basic blocks between the current basic block and the target successor basic block, and determining reachability values corresponding to all successor basic blocks respectively;
[0028] The reachability values corresponding to all the successor basic blocks are multiplied by their corresponding weights, and the product obtained by the multiplication is added to the reachability value corresponding to the target successor basic block to obtain the reachability value corresponding to the current basic block.
[0029] In one implementation of the present application, respectively determining the reachability values corresponding to all the subsequent basic blocks specifically includes:
[0030] For any successor basic block among all the successor basic blocks, the product of the reachability value corresponding to the designated successor basic block located after the any successor basic block and its corresponding weight is added to the reachability value corresponding to the target successor basic block to obtain the reachability value corresponding to the any successor basic block.
[0031] The embodiment of the present application provides a code testing device based on a directed gray box fuzz testing technology, the device comprising:
[0032] at least one processor;
[0033] and, a memory communicatively coupled to the at least one processor;
[0034] Among them, the memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute a code testing method based on directed gray box fuzz testing technology as described in any of the above items.
[0035] The embodiment of the present application provides a non-volatile computer storage medium storing computer executable instructions, wherein the computer executable instructions are configured as follows:
[0036] A code testing method based on directed grey-box fuzz testing technology as described in any of the above items.
[0037] The code testing method based on the directed gray-box fuzz testing technology proposed in this application can bring the following beneficial effects:
[0038] By determining the seed execution path and seed distance corresponding to the key points, it can help testers prioritize the basic blocks closest to the target point, improve test efficiency, and reduce performance loss without the need to fully test the source code. Through seed mutation technology and energy allocation, seeds can be quickly generated and tested for key points in the source code, thereby more effectively discovering software defects. At the same time, loop mutation seeds can help expand test cases, increase test coverage, and explore more boundary conditions, thereby improving software quality. Combining control flow and data flow to generate seeds, and calculating the distance between the seeds and the target point, the current problem of inaccurate judgment of seed superiority is solved. BRIEF DESCRIPTION OF THE DRAWINGS
[0039] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:
[0040] Figure 1 A flowchart of a code testing method based on a directed grey box fuzz testing technique provided in an embodiment of the present application;
[0041] Figure 2 A flowchart of another code testing method based on directed grey box fuzz testing technology provided in an embodiment of the present application;
[0042] Figure 3 A schematic diagram of the structure of a code testing device based on directed grey-box fuzz testing technology provided in an embodiment of the present application. DETAILED DESCRIPTION
[0043] In order to make the purpose, technical solution and advantages of the present application clearer, the technical solution of the present application will be clearly and completely described below in combination with the specific embodiments of the present application and the corresponding drawings. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present application.
[0044] The technical solutions provided by various embodiments of the present application are described in detail below in conjunction with the accompanying drawings.
[0045] like Figure 1 As shown, the code testing method based on the directed gray box fuzz testing technology provided in the embodiment of the present application includes:
[0046] S101: Acquire source code to be tested, determine target points corresponding to the source code, and compile the source code. During the compilation process, filter and obtain key points in the source code.
[0047] DGF is a method for dynamic fuzz testing of specific code locations in a test program. Directed gray-box fuzz testing adds some indicators to guide the input to mutate toward specific code locations in the test program on the basis of gray-box fuzz testing. Most of the current directed gray-box fuzz testing tools rely on control flow to generate basic block distances to determine whether to allocate more energy to seed inputs to generate mutations, while ignoring the impact of data flow. The seed distance generated by relying on control flow cannot provide good feedback on the ability of the seed to reach the target point, and may even mislead the fuzz tester to push the mutation to a position that deviates from the target point. Based on this, the embodiment of the present application judges the ability of the seed to reach the target point based on the information of control flow and data flow, and implements directed gray-box fuzz testing technology based on selective plugging, which solves the problem of performance loss in the full coverage plugging process.
[0048] In order to solve the problem of inaccurate DGF orientation, the embodiment of the present application combines control flow and data flow to more accurately locate the seed direction. Control flow can help analyze the execution path of the source code, discover potential errors or loopholes, and provide a better understanding of the execution logic of the program for the test tool, thereby better guiding the generation and execution of test cases. The data flow model describes the data flow between variables and the dependencies of data changes. Therefore, after obtaining the source code to be tested, it is necessary to extract the control flow in the source code based on the preset CG / CFG extractor, and perform static analysis on the source code to obtain the data flow corresponding to the source code.
[0049] Before testing the source code, you first need to identify the target point corresponding to the source code. In software testing, the target point is usually a specific target of the test, such as statement coverage, branch coverage, etc. After selecting the target point, in order to reduce the performance loss caused by a large number of plug-in statements in full coverage plug-in, the source code needs to be compiled, and during the compilation process, the key points in the source code are filtered through slicing technology and pruning technology. Key points refer to locations and nodes that can have a significant impact on program behavior. They can be basic blocks, conditional statements, function calls, loops, etc. During the test process, the coverage and execution of key points are monitored, and feedback information on key points can be collected during the test process, helping testers find problems faster. At the same time, it also reduces the time and resources required to fully test the entire program and reduces the performance loss during the test process.
[0050] Specifically, when compiling the program to be tested, slicing technology can analyze the control flow and data flow of the program according to the target point, identify the code fragments related to the target, and generate slices, that is, the program subset containing the target point. Pruning technology can further filter out key code paths and nodes to better focus test resources and energy on key points.
[0051] S102: Determine a seed execution path corresponding to the key point, and determine the distance between the basic block in the seed execution path and the target point through a preset distance calculator.
[0052] After determining the key points, the seed execution path is generated through static analysis or dynamic testing. The seed execution path covers the execution path of the key points, which can be implemented using test generation tools or manually designed test cases. The seed is the starting point of the seed execution path. During the test execution process, the seed needs to be gradually positioned to the target point. In this process, the distance between the basic block in the seed execution path and the target point needs to be calculated according to the preset distance calculator. According to the distance calculation results, the seed mutation can be adjusted in real time. In this way, the test input can be continuously changed, the test strategy can be adjusted, and more effective test cases can be designed, which can effectively improve the coverage and test quality.
[0053] In one embodiment, the distance between a basic block and a target point can be evaluated by reachability. Reachability refers to whether a basic block in a program can be executed. According to the control flow, it can be determined whether the current basic block currently executed in the seed execution path is located at the target point. If the current basic block has reached the target point, it means that the current test target has been completed. At this time, the current basic block is assigned a value of 1. If the current basic block has not yet reached the target point, it is necessary to recursively calculate the reachability of the current basic block through the reachability of its corresponding successor basic block. The distance of each basic block is the reciprocal of its reachability. This ensures that the basic block with the greatest possibility of reaching the target point has a shorter corresponding distance. Therefore, after calculating the reachability of the current basic block, the reciprocal of the reachability is used as the distance between the current basic block and the target point.
[0054] During the test process, in order to more accurately evaluate the code coverage and program execution path, help testers focus on the basic blocks that have a greater impact on the source code, and improve test efficiency and quality, before calculating the reachability corresponding to the current basic block, different weights need to be assigned to the successor basic blocks of each basic block, so that the execution path and influencing factors of the program can be more comprehensively considered when calculating the reachability of the basic block. When assigning weights, the variable type associated with the successor basic block needs to be determined based on the data flow. Among them, the variable type includes key variables and auxiliary variables. Then, according to the variable type, the corresponding weight is assigned to the successor basic block, and the weight corresponding to the successor basic block associated with the key variable is greater than the weight corresponding to the successor basic block associated with the auxiliary variable.
[0055] The reachability of the current basic block is calculated recursively, which can be specifically performed through the following steps: first, determine all the successor basic blocks of the current basic block, and then for each successor basic block selected above, determine whether the successor basic block is located at the target point. If so, the successor basic block can be used as the focus of the seed execution path, and the successor basic block can be used as the target successor basic block, and then its corresponding reachability value is set to 1. Since the reachability corresponding to each basic block is obtained based on all its successor basic blocks, it is necessary to take the target successor basic block as the starting point, traverse all the successor basic blocks between the current basic block and the target successor basic block, and determine the reachability values corresponding to all the successor basic blocks respectively. The reachability calculation logic is the same as that of the current basic block. The reachability value of each successor basic block that has not reached the target point is calculated by all its successor basic blocks. When calculating the reachability value, the weight assigned to each successor basic block must also be considered. That is to say, for any successor basic block among all the successor basic blocks, the product of the reachability value corresponding to the specified successor basic block located after any successor basic block and its corresponding weight is added to the reachability value corresponding to the target successor basic block. In this way, the reachability value corresponding to any successor basic block is obtained.
[0056] After that, after determining the reachability value corresponding to each successor basic block, multiply the reachability values corresponding to all successor basic blocks by their corresponding weights, and add the multiplied product with the reachability value corresponding to the target successor basic block to obtain the reachability value corresponding to the current basic block. Taking the inverse of the reachability value, we get the distance between the current basic block and the target point.
[0057] S103: For each seed execution path, the basic block with the smallest corresponding distance is used as the seed distance, and energy is allocated to the seed corresponding to the seed distance according to the seed distance.
[0058] In order to better reflect the current test progress, for each seed execution path, the basic block with the smallest corresponding distance is used as the seed distance. Seed distance can help testers evaluate the degree of correlation between seed test cases and target points, so as to select the most representative and influential seeds for testing. Therefore, based on the above degree of correlation, seeds with more effective test effects can be selected for testing, thereby improving the efficiency and coverage of test cases and better discovering potential problems. This process can be carried out through the strategy of allocating energy to seeds. By allocating relatively high energy to seeds with shorter seed distances, the seed execution path where the seed is located can be executed first in the subsequent test process, making it more likely to reach the target point in advance, thereby improving test efficiency.
[0059] S104: For the seeds after energy allocation, the seeds are cyclically mutated, and the source code is tested based on the mutated seeds to obtain a corresponding abnormality feedback report.
[0060] After allocating energy to the seed, in order to generate as many test cases as possible to find potential defects in the source code, the seed needs to be mutated cyclically to continuously generate new test inputs, thereby triggering different execution logic in the source code. In this way, testing the source code based on the mutated seed can more comprehensively evaluate the source code and improve the test coverage.
[0061] Before the seed mutates, in order to expand the test coverage, it is necessary to determine whether the seed reaches the insertion point or the target point. Among them, the insertion point is obtained by inserting the key points in the data flow and control flow through the preset inserter before the source code is fuzz tested. The final insertion point can be uploaded to the fuzzer in the form of an insertion binary file, so that the fuzzer can expand the test scope more comprehensively based on the insertion point during the fuzz test. When the seed reaches the insertion point or the target point, the seed needs to be added to the seed queue as a seed of interest. In this way, by cyclically mutating the seeds in the above seed queue, the corresponding mutant seeds can be generated. Using the mutant seeds as test input to test the source code can generate more diverse test cases and improve test efficiency.
[0062] During the fuzz testing process, testers will collect program execution status, exceptions, and feedback information. Exception feedback reports include information such as program crashes, error output, and abnormal behavior, which are used to analyze and locate program problems. By receiving and analyzing exception feedback reports in a timely manner, testers can quickly discover potential vulnerabilities and improve testing strategies.
[0063] Figure 2 A flowchart of another code testing method based on directional gray box fuzz testing technology provided in an embodiment of the present application. Figure 2 As shown, after obtaining the source code to be tested, the control flow corresponding to the source code must first be extracted through the CG / CFG extractor, and at the same time, the data flow corresponding to the source code must also be obtained. After clarifying the target point corresponding to the source code, the distance between the basic block and the target point is calculated through a preset distance calculator to filter out the seed distance according to the obtained distance file. After the seed distance is obtained through screening and energy is allocated to the seed distance, the source code needs to be fuzz tested through a fuzzer. During the fuzz testing process, the initial seed is mutated, and the potential defects in the source code are continuously mined according to the mutated seed to improve the test efficiency. Among them, the inserter can insert the key points in the control flow and data flow, so that when performing fuzz testing, the performance loss can be effectively reduced, and the insert point can participate in the seed mutation as a seed to achieve effective expansion of the test case.
[0064] The above are embodiments of the method proposed in this application. Based on the same idea, some embodiments of this application also provide devices and non-volatile computer storage media corresponding to the above methods.
[0065] Figure 3 A schematic diagram of the structure of a code testing device based on a directional gray box fuzz testing technology provided in an embodiment of the present application. Figure 3 As shown, including:
[0066] at least one processor; and,
[0067] at least one processor is communicatively connected to a memory; wherein,
[0068] The memory stores instructions executable by at least one processor, the instructions being executed by at least one processor to enable the at least one processor to:
[0069] Obtain the source code to be tested, determine the target point corresponding to the source code, and compile the source code. During the compilation process, filter out the key points in the source code;
[0070] Determine a seed execution path corresponding to the key point, and determine the distance between the basic block in the seed execution path and the target point through a preset distance calculator;
[0071] For each seed execution path, the basic block with the smallest corresponding distance is taken as the seed distance, and energy is allocated to the seed corresponding to the seed distance according to the seed distance;
[0072] For the seeds after energy allocation, the seeds are cyclically mutated, and the source code is tested based on the mutated seeds to obtain the corresponding abnormal feedback report.
[0073] The embodiment of the present application provides a non-volatile computer storage medium storing computer executable instructions, wherein the computer executable instructions are configured as follows:
[0074] Obtain the source code to be tested, determine the target point corresponding to the source code, and compile the source code. During the compilation process, filter out the key points in the source code;
[0075] Determine a seed execution path corresponding to the key point, and determine the distance between the basic block in the seed execution path and the target point through a preset distance calculator;
[0076] For each seed execution path, the basic block with the smallest corresponding distance is taken as the seed distance, and energy is allocated to the seed corresponding to the seed distance according to the seed distance;
[0077] For the seeds after energy allocation, the seeds are cyclically mutated, and the source code is tested based on the mutated seeds to obtain the corresponding abnormal feedback report.
[0078] Each embodiment in this application is described in a progressive manner, and the same or similar parts between the embodiments can be referred to each other, and each embodiment focuses on the differences from other embodiments. In particular, for the device and medium embodiments, since they are basically similar to the method embodiments, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiments.
[0079] The devices and media provided in the embodiments of the present application correspond one-to-one to the methods. Therefore, the devices and media also have similar beneficial technical effects as the corresponding methods. Since the beneficial technical effects of the methods have been described in detail above, the beneficial technical effects of the devices and media will not be repeated here.
[0080] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application may adopt the form of a computer program product implemented in one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that include computer-usable program code.
[0081] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0082] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.
[0083] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.
[0084] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.
[0085] The memory may include non-permanent storage in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. The memory is an example of a computer-readable medium.
[0086] Computer readable media include permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. Information can be computer readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic tape magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer readable media does not include temporary computer readable media (transitory media), such as modulated data signals and carrier waves.
[0087] It should also be noted that the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, commodity or device. In the absence of more restrictions, the elements defined by the sentence "comprises a ..." do not exclude the existence of other identical elements in the process, method, commodity or device including the elements.
[0088] The above is only an embodiment of the present application and is not intended to limit the present application. For those skilled in the art, the present application may have various changes and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application should be included in the scope of the claims of the present application.
Claims
1. A code testing method based on directed gray box fuzz testing technology, characterized in that: The method comprises: Obtaining source code to be tested, determining target points corresponding to the source code, and compiling the source code. During the compilation process, filtering key points in the source code; Determine a seed execution path corresponding to the key point, and determine the distance between a basic block in the seed execution path and the target point by using a preset distance calculator; For each seed execution path, the basic block with the smallest corresponding distance is used as the seed distance, and according to the seed distance, energy is allocated to the seed corresponding to the seed distance; For the seed after energy allocation, the seed is cyclically mutated, and the source code is tested based on the mutated seed to obtain a corresponding abnormal feedback report.
2. According to claim 1, a code testing method based on directed gray box fuzz testing technology is characterized in that: After obtaining the source code to be tested, the method further includes: Based on a preset CG / CFG extractor, the control flow in the source code is extracted, and the source code is statically analyzed to obtain the data flow corresponding to the source code.
3. According to claim 2, a code testing method based on directed gray box fuzz testing technology is characterized in that: After determining the distance between the basic block in the seed execution path and the target point, the method further includes: The key points in the data flow and the control flow are plugged by a preset plugger to obtain corresponding plugging points.
4. According to claim 3, a code testing method based on directed gray box fuzz testing technology is characterized in that: For the seed after energy distribution, before cyclically mutating the seed, the method further includes: determining whether the seed reaches the insertion point or the target point; If so, the seed is added to the seed queue as an interesting seed, so as to generate corresponding mutant seeds by cyclically mutating the seeds in the seed queue, and the mutant seeds are used as test input to test the source code.
5. According to claim 2, a code testing method based on directed gray box fuzz testing technology is characterized in that: Determining the distance between the basic block in the seed execution path and the target point by using a preset distance calculator specifically includes: Determining, according to the control flow, whether a current basic block currently executed in the seed execution path is located at the target point; If yes, assign 1 to the current basic block; If not, determine whether the current basic block has a successor basic block, and if the successor basic block exists, calculate the reachability corresponding to the current basic block according to the successor basic block; The inverse of the reachability is taken as the distance between the current basic block and the target point.
6. A code testing method based on directed gray box fuzz testing technology according to claim 5, characterized in that: Before calculating the reachability corresponding to the current basic block according to the successor basic block, the method further includes: Determine, according to the data flow, the variable type associated with the subsequent basic block; wherein the variable type includes key variables and auxiliary variables; According to the variable type, a corresponding weight is assigned to the successor basic block, and the weight corresponding to the successor basic block associated with the key variable is greater than the weight corresponding to the successor basic block associated with the auxiliary variable.
7. A code testing method based on directed gray box fuzz testing technology according to claim 6, characterized in that: Calculating the reachability corresponding to the current basic block according to the successor basic block, specifically including: Determine all successor basic blocks of the current basic block; For each successor basic block, determine whether the successor basic block is located at the target point, and if so, use the successor basic block as a target successor basic block, and set the reachability value corresponding to the target successor basic block to 1; Taking the target successor basic block as a starting point, traversing forward all successor basic blocks between the current basic block and the target successor basic block, and determining reachability values corresponding to all successor basic blocks respectively; The reachability values corresponding to all the successor basic blocks are multiplied by their corresponding weights, and the product obtained by the multiplication is added to the reachability value corresponding to the target successor basic block to obtain the reachability value corresponding to the current basic block.
8. A code testing method based on directed grey box fuzz testing technology according to claim 7, characterized in that: Determining the reachability values corresponding to all the subsequent basic blocks respectively, specifically including: For any successor basic block among all the successor basic blocks, the product of the reachability value corresponding to the designated successor basic block located after the any successor basic block and its corresponding weight is added to the reachability value corresponding to the target successor basic block to obtain the reachability value corresponding to the any successor basic block.
9. A code testing device based on directed gray box fuzz testing technology, characterized in that: The device comprises: at least one processor; and, a memory communicatively coupled to the at least one processor; Wherein, the memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute a code testing method based on directed gray box fuzz testing technology as described in any one of claims 1-8.
10. A non-volatile computer storage medium storing computer executable instructions, characterized in that: The computer executable instructions are configured to: A code testing method based on directed grey-box fuzz testing technology as described in any one of claims 1 to 8.
Citation Information
Patent Citations
Parallel fuzzy test method and system based on target point task division
CN114328213A
Guiding type grey box fuzzy testing method and device based on dominating point coverage
CN114661578A