A State-Based Fuzz Testing Method for Industrial Control Protocols

By constructing the state variable matrix and state model of the industrial control protocol program, combined with the state selection algorithm, the problem of inaccurate inference of the protocol state machine in the existing technology is solved, and the efficiency and accuracy of fuzz testing are improved.

CN118427821BActive Publication Date: 2025-06-03ZHEJIANG UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410435510.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-04-11
Publication Date
2025-06-03
Estimated Expiration
2044-04-11

AI Technical Summary

Technical Problem

The existing gray box protocol fuzz testing tool is not accurate enough in protocol state machine inference, resulting in long execution time and low testing efficiency.

Method used

By constructing the state variable matrix of industrial control protocol programs, an unsupervised clustering method is used to establish a state model, a protocol program state machine is constructed, and a state selection algorithm is formulated to realize the guidance of the execution status of the protocol program.

Benefits of technology

The efficiency of fuzz testing is improved, and the test time is shortened through accurate state recognition and state transition information, and the accuracy of test results is improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118427821B_ABST
    Figure CN118427821B_ABST
Patent Text Reader

Abstract

The present invention discloses a state-based fuzz testing method for industrial control protocols. The present invention performs static analysis on the source code of the industrial control protocol program to extract state variables; realizes state variable tracking through instrumentation; executes the initial fuzz testing loop, collects the state variable value data corresponding to the test cases generated by each mutation, completes the construction of the state variable matrix, and establishes a state model corresponding to the state variable matrix to construct an initial protocol program state machine; executes the fuzz testing loop again, selects a state and makes the program enter the selected state; generates a new test case and executes it, adds the new test case that generates a new state or a new state transition to the seed pool, and updates the state model and the protocol program state machine to perform a new round of loop to re-select test cases for mutation. The present invention can detect the state information of the industrial control protocol program, and perform state-guided fuzz testing on the protocol program based on the state information, and has a good effect on stateful industrial control protocols.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of industrial control protocol fuzz testing, and particularly to a state-based industrial control protocol fuzz testing method. Background Art

[0002] Fuzz testing is a common vulnerability mining technology. By inputting a large number of random or semi-random test cases to the object under test and monitoring the execution status to detect anomalies, it explores the possible vulnerabilities of the object under test. The grey-box protocol fuzz testing technology is an application of fuzz testing technology in the field of protocols.

[0003] Existing grey-box protocol fuzz testing tools have some deficiencies, including inaccurate protocol state machine inference, etc., resulting in long fuzz testing execution time and low testing efficiency. Therefore, targeted research needs to be carried out. Summary of the Invention

[0004] The purpose of the present invention is to propose a state-based industrial control protocol fuzz testing method in view of the deficiencies of existing grey-box protocol fuzz testing tools.

[0005] The purpose of the present invention is achieved through the following technical solutions: A state-based industrial control protocol fuzz testing method, the method includes the following steps:

[0006] Step 1: Construct an initial test case to form an initial seed pool;

[0007] Step 2: Use the program static analysis method to analyze the source code of the industrial control protocol program, and formulate heuristic rules to extract the state variables in the program;

[0008] Step 3: Adopt the program instrumentation technology to implement instrumentation for coverage, and at the same time insert instrumentation points at the state variable positions of the program to achieve tracking of state variables;

[0009] Step 4: Execute the initial fuzz testing loop. When the state variable instrumentation points are triggered during program operation, a set of state variable value data corresponding to the test case generated by each mutation is collected to complete the construction of the state variable matrix;

[0010] Step 5: Use an unsupervised clustering method to establish a state model corresponding to the state variable matrix. Each group of data represents a state, the same states are clustered into one category, at least one test case is retained in each category and is labeled with the same value, different states are labeled with different values, establish a state training set, and construct an initial protocol program state machine, including a state list and state transition information;

[0011] Step 6: Execute the fuzz testing loop again, use the state selection algorithm to select states, and send the test cases retained by the selected states to the running program to make the program enter the selected state;

[0012] Step 7: Select a test case from the seed pool and mutate it to generate several new test cases, which are sent to the running program. Consider the new test cases that produce new states or new state transitions as interesting, add them to the seed pool, and update the state model and the protocol program state machine with the new states or new state transitions to perform a new round of loop to re-select test cases for mutation, and finally output the fuzz testing results.

[0013] Further, in the step 2, the program static analysis method adopted is to analyze the call relationship graph and construct an abstract syntax tree.

[0014] Further, the step 2 is specifically as follows: Analyze the working logic of the industrial control protocol program source code, formulate a set of heuristic rules to identify variables related to the protocol state, denoted as state variables; traverse the constructed abstract syntax tree according to the formulated heuristic rules to find the state variables and their positions.

[0015] Further, in the step 2, the heuristic rules are as follows: ① State variables may be in branch statements; ② State variables may be in loop statements; ③ State variables may have value changes during the interaction process when the program runs.

[0016] Further, in the step 4, assuming that n state variables are extracted and m test cases are input, the m groups of state variable values corresponding to the m collected test cases are represented in the form of a state variable matrix as:

[0017]

[0018] where, x mn represents the value of the nth state variable in the mth group.

[0019] Further, in the step 5, an unsupervised clustering method is adopted to represent each group of data with a state parameter y i where i = 1, 2,..., m, and the obtained state model is represented as:

[0020]

[0021] Further, in the step 6, the state selection algorithm is specifically as follows: Initially, select states in sequence; then collect the degree of coverage increase corresponding to each state and normalize it to [0, 1] as the score of each state. The higher the score of the state with more coverage increase, the higher the score. In subsequent fuzz testing, the size of the state score corresponds to the probability of the state being selected.

[0022] Further, in step 7, generating a new state means adding the state variable value corresponding to the new test case to the state variable matrix as the data in the (m + 1)-th row, and then performing unsupervised clustering again. If its category belongs to the existing categories, it is discarded. If its category is a new category, that is, a new value appears in the state parameter, it indicates that a new state is generated; generating a new state transition means that a new situation appears in the conversion of the state parameter value.

[0023] Further, during the fuzz testing loop, the state model and the protocol program state machine are continuously updated through state information feedback, and the state scores in the state selection algorithm are continuously updated through coverage feedback.

[0024] The present invention also provides a state-based industrial control protocol fuzz testing device, including a memory and one or more processors. An executable code is stored in the memory. When the processor executes the executable code, it is used to implement the above-mentioned state-based industrial control protocol fuzz testing method.

[0025] The present invention also provides a computer-readable storage medium, on which a program is stored. When the program is executed by a processor, it implements the above-mentioned state-based industrial control protocol fuzz testing method.

[0026] Compared with the prior art, the present invention has the following advantages:

[0027] 1. By extracting the state variables in the industrial control protocol program, constructing a protocol program state machine, and proposing a new method for identifying the states of industrial control protocols.

[0028] 2. Formulating a state selection algorithm and performing fuzz testing with state-guided execution of the protocol program based on the state information of the protocol program, thereby improving the efficiency of fuzz testing.

[0029] 3. The present invention has generality and universality for industrial control protocols for which source code can be obtained. BRIEF DESCRIPTION OF THE DRAWINGS

[0030] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required in the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0031] Figure 1 It is the overall working flowchart of the method of the present invention;

[0032] Figure 2 It is a partial code example of the Modbus protocol program. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0033] To make the above objects, features, and advantages of the present invention more apparent and understandable, the following provides a detailed description of the specific embodiments of the present invention in conjunction with the accompanying drawings.

[0034] In the following description, many specific details are set forth in order to fully understand the present invention. However, the present invention may also be implemented in other ways different from those described herein. Those skilled in the art can make similar generalizations without departing from the connotation of the present invention. Therefore, the present invention is not limited by the specific embodiments disclosed below.

[0035] As Figure 1 shown, an embodiment of the present invention provides a state-based industrial control protocol fuzz testing method. This method can be implemented based on the AFLNET tool but is not limited thereto. The specific steps of this method are as follows:

[0036] Step 1: Construct an initial test case to form an initial seed pool.

[0037] Step 2: Obtain the source code of the industrial control protocol program and perform static program analysis to obtain an abstract syntax tree.

[0038] Formulate heuristic rules to extract state variables in the program that can reflect the state. Specifically:

[0039] Analyze the working logic of the source code of the industrial control protocol program, formulate a set of heuristic rules to identify variables related to the protocol state, denoted as state variables; traverse the constructed abstract syntax tree according to the formulated heuristic rules to find the state variables and their positions;

[0040] The heuristic rules in this embodiment are: ① State variables may be in branch statements; ② State variables may be in loop statements; ③ State variables may have value changes during the interaction process when the program runs.

[0041] Give an example of a state variable. As Figure 2 shown, it is a partial code example of the Modbus protocol program. It can be seen that the variable function is in a branch statement, and it is defined as one of the state variables of this protocol program.

[0042] Step 3: Adopt program instrumentation technology to achieve coverage instrumentation, and at the same time insert instrumentation points at the positions of the state variables of the program to achieve the tracking of state variables.

[0043] Step 4: Execute the initial fuzz testing loop. When the state variable instrumentation points are triggered during the program execution, a set of state variable value data corresponding to each mutant-generated test case is collected to complete the construction of the state variable matrix; assuming that n state variables are extracted and m test cases are input, the m sets of state variable values corresponding to the m test cases collected are represented in the form of a state variable matrix as:

[0044]

[0045] where x mn represents the value of the nth state variable in the mth group.

[0046] Step 5: Use an unsupervised clustering method to establish a state model corresponding to the state variable matrix. Each group of data represents a state. The same states are clustered into one category, and at least one test case is retained for each category and labeled with the same value, while different states are labeled with different values to establish a state training set, and construct an initial protocol program state machine, including a state list and state transition information; specifically:

[0047] Use an unsupervised clustering method to represent each group of data with a state parameter y i where i = 1, 2,..., m, and the obtained state model is expressed as:

[0048]

[0049] Step 6: Execute the fuzz testing loop again. Use the state selection algorithm to select states, and send the test cases retained by the selected states to the running program to make the program enter the selected states;

[0050] In this embodiment, the state selection algorithm is implemented as follows but is not limited to this: Initially, select states in sequence; then collect the degree of coverage increase corresponding to each state and normalize it to [0, 1] as the score of each state. The state with a greater increase in coverage has a higher score, and in subsequent fuzz testing, the size of the state score corresponds to the probability of the state being selected.

[0051] Step 7: Select a test case from the seed pool and mutate it to generate several new test cases and send them to the running program. Consider the new test cases that generate new states or new state transitions as interesting, add them to the seed pool, and update the state model and the protocol program state machine using the new states or new state transitions to perform a new round of loop to re-select test cases for mutation, and finally output the fuzz testing result;

[0052] Specifically, generating a new state means adding the state variable values corresponding to the new test case to the state variable matrix as the data in the (m + 1)th row, and re-performing unsupervised clustering. If its category belongs to an existing category, it is discarded. If its category is a new category, that is, a new value appears in the state parameter, it indicates that a new state is generated; generating a new state transition means that a new situation appears in the conversion of the state parameter value.

[0053] During the fuzz testing loop process, the state model and the protocol program state machine are continuously updated through state information feedback, and the state scores in the state selection algorithm are continuously updated through coverage feedback.

[0054] In this embodiment, test monitoring is implemented through the AFLNET tool, and information such as code coverage is achieved through the instrumentation step. The timing for stopping the test can refer to: (1) the color of the "cycles done" field in the output window turns green; (2) the code coverage of the protocol program does not change for a long time; (3) the code coverage of the protocol program reaches 99%. The format of the final output fuzz testing results is the same as that of AFLNET.

[0055] An embodiment of the present invention further provides a state-based industrial control protocol fuzz testing device, including a memory and one or more processors. An executable code is stored in the memory. When the processor executes the executable code, the above-mentioned state-based industrial control protocol fuzz testing method is implemented.

[0056] An embodiment of the present invention further provides a computer-readable storage medium, on which a program is stored. When the program is executed by a processor, the above-mentioned state-based industrial control protocol fuzz testing method is implemented.

[0057] The above are only the preferred embodiments of one or more embodiments of this specification, and are not intended to limit one or more embodiments of this specification. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of one or more embodiments of this specification shall be included within the scope of protection of one or more embodiments of this specification.

Claims

1. A state-based industrial control protocol fuzzy testing method, characterized in that: include: Step 1: Construct initial test cases to form an initial seed pool; Step 2: Use the program static analysis method to analyze the source code of the industrial control protocol program and formulate heuristic rules to extract the state variables in the program; Step 3: Use program instrumentation technology to achieve instrumentation coverage, and insert stubs at the program's state variable sites to track state variables; Step 4: Execute the initial fuzz testing cycle. When the program is running, the state variable stub is triggered, so as to collect a set of state variable value data corresponding to each test case generated by mutation, and complete the construction of the state variable matrix; Step 5: Use unsupervised clustering method to establish the state model corresponding to the state variable matrix. Each group of data represents a state. The same state is clustered into one category. Each category retains at least one test case and is labeled with the same value. Different states are labeled with different values. Establish a state training set and construct the initial protocol program state machine, which includes a state list and state transition information. Step 6: Execute the fuzz testing cycle again, select the state using the state selection algorithm, send the selected state-retained test case to the running program, and make the program enter the selected state; Step 7: Select a test case from the seed pool and mutate it to generate several new test cases and send them to the running program. New test cases that generate new states or new state transitions are considered interesting and added to the seed pool. The state model and the protocol program state machine are updated using the new states or new state transitions to perform a new cycle and reselect test cases for mutation, and finally output the fuzz testing results.

2. The state-based industrial control protocol fuzzy testing method according to claim 1 is characterized in that: In step 2, the program static analysis method adopted is to analyze the call relationship graph and construct an abstract syntax tree.

3. The state-based industrial control protocol fuzzy testing method according to claim 2 is characterized in that: The step 2 is specifically as follows: analyzing the working logic of the industrial control protocol program source code, formulating a set of heuristic rules to identify variables related to the protocol state, recorded as state variables; traversing the constructed abstract syntax tree according to the formulated heuristic rules to find out the state variables and their locations.

4. The state-based industrial control protocol fuzzy testing method according to claim 1 is characterized in that: In step 2, the heuristic rule is: ① the state variable may be in a branch statement; ② The state variable may be in a loop statement; ③ The state variable may change its value during the interactive process when the program is running.

5. The state-based industrial control protocol fuzzy testing method according to claim 1 is characterized in that: In step 4, assuming that n state variables are extracted and m test cases are input, the m groups of state variable values ​​corresponding to the m test cases collected are expressed in the form of a state variable matrix as follows: Among them, x mn Represents the value of the nth state variable in the mth group.

6. The state-based industrial control protocol fuzzy testing method according to claim 5 is characterized in that: In step 5, an unsupervised clustering method is used to cluster each group of data with a state parameter y i To represent, where i = 1, 2, ..., m, the state model is expressed as:

7. The state-based industrial control protocol fuzzy testing method according to claim 1 is characterized in that: In step 6, the state selection algorithm is specifically as follows: initially, the states are selected in order; then the coverage increase corresponding to each state is collected and normalized to [0, 1] as the score of each state. The higher the coverage increase, the higher the state score. In subsequent fuzzy tests, the state score corresponds to the probability of the state being selected.

8. The state-based industrial control protocol fuzzy testing method according to claim 5 is characterized in that: In step 7, generating a new state refers to adding the state variable value corresponding to the new test case to the state variable matrix as the m+1th row of data, and re-performing unsupervised clustering. If its category belongs to an existing category, it is discarded. If its category is a newly added category, that is, a new value appears in the state parameter, indicating that a new state is generated; generating a new state transition refers to a new situation in the transition of the state parameter value.

9. The state-based industrial control protocol fuzzy testing method according to claim 8 is characterized in that: During the fuzz testing cycle, the state model and protocol program state machine are continuously updated through state information feedback, and the state score in the state selection algorithm is continuously updated through coverage feedback.

10. A state-based industrial control protocol fuzzy testing device, comprising a memory and one or more processors, wherein the memory stores executable code, characterized in that: When the processor executes the executable code, it is used to implement the state-based industrial control protocol fuzz testing method as described in any one of claims 1-9.

Citation Information

Patent Citations

  • Fuzzy mining method for input verification vulnerabilities of industrial control terminal equipment

    CN113901475A

  • Industrial control equipment black box fuzzy test method based on protocol reversal

    CN116991743A