A JAVA fuzz testing method based on program analysis
Through program analysis and AST analysis technology, effective JAVA fuzz testing cases are generated, which solves the problem of low code coverage in the existing technology and significantly improves the efficiency and effectiveness of fuzz testing.
Patent Information
- Application Number
- CN202411365453.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-29
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2044-09-29
AI Technical Summary
When the existing JAVA fuzz testing method is tested at the system level, the code's running coverage is low and it is difficult to improve in a short time.
Through program analysis, the test case data of interface parameters and interface call order is obtained, and AST parsing and reverse derivation technology is used to parse the syntax tree and call link relationship of binary file packages to generate effective test cases.
Significantly increase the business logic that is difficult to explore in fuzzy testing, improve the coverage of the objects being tested, and find more defects that have not been overdue.
Smart Images

Figure CN119271556B_ABST
Abstract
Description
Technical Field
[0001] The embodiment of the present invention relates to the field of network information security technology, and in particular to a JAVA fuzzy testing method based on program analysis. Background Art
[0002] The existing fuzz testing methods for JAVA have low running coverage of most codes during system-level testing, and cannot be improved through fuzz testing in a short period of time. There is a problem that the test coverage of the target under test is low when there is sufficient testing time.
[0003] The invention patent with the publication number CN118427830A and the name "Java deserialization vulnerability mining method, device and medium based on fuzzy testing" discloses a Java deserialization vulnerability mining method based on fuzzy testing, which includes: using the bidirectional tracking taint analysis technology, taking the Java deserialization entry function and the dangerous function as the starting point to search, find the potential vulnerability call chain, and obtain the function information in the corresponding execution path; based on the function weight allocation strategy of the TrustRank algorithm, determine the corresponding function type, and calculate the TrustRank weight coefficient corresponding to each function type, so as to sort the functions in the order of the TrustRank weight coefficient from high to low; the function types include dangerous functions, path functions, suspicious functions and branch functions; based on the function call information and the corresponding TrustRank weight coefficient, and through the gray box fuzzy test, the vulnerability call chain is fuzzy tested to determine the validity of the vulnerability call chain, and complete the mining of Java deserialization vulnerabilities. However, this method is relatively complicated and the testing efficiency is not high.
[0004] Therefore, it is necessary to provide a JAVA fuzz testing method based on program analysis to solve the above problems. Summary of the invention
[0005] The present invention provides a JAVA fuzzy testing method based on program analysis. The test case data of interface parameters and interface calling sequence that can be obtained through program analysis can greatly increase the business logic that is difficult to explore through fuzzy testing, thereby increasing the coverage of the object under test. Based on the improvement of coverage, the number of paths explored by fuzzy testing increases, which can promote the discovery of more non-overdue defects.
[0006] The embodiment of the present invention provides a JAVA fuzz testing method based on program analysis, comprising:
[0007] Get the binary file package of the program under test;
[0008] Performing AST parsing on the binary file package;
[0009] Parsing nodes at each level of the syntax tree of the binary file package to obtain all conditional branches under all classes and all methods;
[0010] By reverse deduction of the node calls at each layer, the call link relationship of each branch judgment parameter of the binary file package is parsed;
[0011] Determine whether the call link relationship is a single interface call or a cross-interface call.
[0012] Preferably, when the call link relationship is a single interface call, a magic number is parsed for the single interface to determine whether the magic number is a constant or a configuration file field;
[0013] When the magic number is a constant field, mapping the constant to an interface variable;
[0014] When the magic number is a configuration file field, the corresponding variable is mapped to the configuration file field.
[0015] Preferably, it also includes:
[0016] Generate test data for a single interface and change the calling method of the specified configuration file field.
[0017] Preferably, it also includes:
[0018] When the call link relationship is a cross-interface call, parsing the interface relationship;
[0019] Decompiling the binary file package to obtain program source code using the binary decompilation method;
[0020] Parse the JAVA code files and various XML resource package files contained in the source code.
[0021] Preferably, determining whether there is an SQL operation in the source code;
[0022] When there is an SQL operation in the source code, the method and field of the SQL operation are mapped to the interface through parsing, and the parsed relationship between the cache operation and the interface is stored in the interface relationship analysis pool;
[0023] When there is no SQL operation in the source code, it is determined whether there is a cache operation in the source code.
[0024] Preferably, the determining whether there is a cache operation in the source code includes:
[0025] When there is a cache operation in the source code, the mode and field of the cache operation are mapped to the interface through parsing, and the parsed relationship between the cache operation and the interface is stored in the interface relationship analysis pool;
[0026] When there is no cache operation in the source code, it is determined whether there is a file operation in the source code.
[0027] Preferably, the determining whether there is a file operation in the source code includes:
[0028] When there is a file operation in the source code, the mode and field of the file operation are mapped to the interface through parsing, and the relationship between the parsed file operation and the interface is stored in the interface relationship analysis pool;
[0029] When there is no file operation in the source code, it is determined whether there is a message operation in the source code.
[0030] Preferably, the determining whether there is a message operation in the source code includes:
[0031] When there is a message operation in the source code, the mode and field of the message operation are mapped to the interface through parsing, and the relationship between the parsed message operation and the interface is stored in the interface relationship analysis pool;
[0032] When there is no message operation in the source code, the interface relationship data stored in the interface relationship analysis pool is dynamically run and explored.
[0033] Preferably, it also includes dynamically running and exploring the interface relationship data stored in the interface relationship analysis pool;
[0034] Use the path exploration algorithm to perform breadth-first exploration and generation of all combinations of interface call relationships;
[0035] The generated interface call relationship, interface test data and configuration steps are run and tested and the run coverage is collected.
[0036] Preferably, the method further comprises the following steps:
[0037] If the interface call relationship, interface test data, and configuration steps generate a new path, it is a valid test case;
[0038] If no new path is generated, the algorithm continues to generate new test cases for testing until the interface relationship analysis pool is explored;
[0039] Output all valid test cases.
[0040] Compared with the prior art, the technical solution of the embodiment of the present invention has the following beneficial effects:
[0041] A JAVA fuzzy testing method based on program analysis provided by an embodiment of the present invention includes: obtaining a binary file package of a program under test; performing AST parsing on the binary file package; parsing nodes at each layer of a syntax tree of the binary file package to obtain all conditional branches under all classes and all methods; parsing the call link relationship of parameters of each branch of the binary file package through reverse deduction of the calls of the nodes at each layer; judging whether the call link relationship is a single interface call or a cross-interface call. The test case data of interface parameters and interface call sequence that can be obtained through program analysis can greatly increase the business logic that is difficult to explore with fuzzy testing, thereby increasing the coverage of the object under test. Based on the improvement of coverage, the number of paths explored by fuzzy testing increases, which can prompt more non-overdue defects to be discovered. BRIEF DESCRIPTION OF THE DRAWINGS
[0042] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following is a brief introduction to the drawings required for use in the embodiments or the prior art descriptions. Obviously, the drawings described below are some embodiments of the present invention, not all embodiments. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative labor.
[0043] Figure 1 A flowchart of a JAVA fuzzy testing method based on program analysis provided by an embodiment of the present invention;
[0044] Figure 2 A flowchart of a JAVA fuzzy testing method based on program analysis provided by another embodiment of the present invention;
[0045] Figure 3 A flowchart of a JAVA fuzzy testing method based on program analysis is provided for yet another embodiment of the present invention. DETAILED DESCRIPTION
[0046] In order to make the purpose, technical solution and advantages of the embodiments of the present invention clearer, the technical solution in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0047] The technical solution of the present invention is described in detail with specific embodiments below. The following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described in detail in some embodiments.
[0048] Based on the problems existing in the prior art, an embodiment of the present invention provides a JAVA fuzz testing method based on program analysis. The test case data of interface parameters and interface call sequence that can be obtained through program analysis can greatly increase the business logic that is difficult to explore through fuzz testing, thereby increasing the coverage of the object under test. Based on the improvement of coverage, the number of paths explored by fuzz testing increases, which can prompt more non-overdue defects to be discovered.
[0049] Figure 1 A flowchart of a JAVA fuzzy testing method based on program analysis is provided for one embodiment of the present invention. Figure 1 , provides a JAVA fuzz testing method based on program analysis, including:
[0050] Step S101: Obtain the binary file package of the program under test;
[0051] Step S102: performing AST (Abstract Syntax Tree) parsing on the binary file package;
[0052] Step S103: parsing nodes at each level of the syntax tree of the binary file package to obtain all conditional branches under all classes and all methods;
[0053] Step S104: parsing the call link relationship of each branch judgment parameter of the binary file package through reverse deduction of the node calls of each layer;
[0054] Step S105: Determine whether the call link relationship is a single interface call or a cross-interface call.
[0055] Specifically, in step S102, the AST syntax tree, i.e., the abstract syntax tree, is a tree-shaped data structure used to represent the syntax structure of the source code. Before the code is compiled or interpreted, it needs to go through two stages: lexical analysis and grammatical analysis. Lexical analysis decomposes the source code into lexical units (Tokens), such as keywords, identifiers, operators, etc. Syntactic analysis organizes these lexical units into a syntax tree according to grammatical rules. This tree is the AST syntax tree.
[0056] In step S104, branch judgment includes statements such as if, Block, Catch, continue, do, forEach, return, try, synchronized, throw, while, and yield.
[0057] Figure 2 A flowchart of a JAVA fuzzy testing method based on program analysis is provided for another embodiment of the present invention. Figure 2, provides a JAVA fuzz testing method based on program analysis, including:
[0058] Step S201: Obtain the binary file package of the program under test;
[0059] Step S202: performing AST parsing on the binary file package;
[0060] Step S203: parsing nodes at each level of the syntax tree of the binary file package to obtain all conditional branches under all classes and all methods;
[0061] Step S204: parsing the call link relationship of each branch judgment parameter of the binary file package through reverse deduction of the node calls of each layer;
[0062] Step S205: determining whether the call link relationship is a single interface call or a cross-interface call;
[0063] Step S206: when the call link relationship is a single interface call, performing magic number analysis on the single interface to determine whether the magic number is a constant or a configuration file field;
[0064] Step S207: When the magic number is a constant field, map the constant to an interface variable;
[0065] Step S208: When the magic number is a configuration file field, mapping the corresponding variable to the configuration file field.
[0066] Specifically, for example, there is a judgment condition if A=1, 1 is the magic number, A is the corresponding variable, and the variable A can be mapped to a field in the configuration file through parsing.
[0067] Figure 3 A flowchart of a JAVA fuzzy testing method based on program analysis is provided for another embodiment of the present invention. Figure 3 , provides a JAVA fuzz testing method based on program analysis, including:
[0068] Step S301: Obtain the binary file package of the program under test;
[0069] Step S302: performing AST parsing on the binary file package;
[0070] Step S303: parsing nodes at each level of the syntax tree of the binary file package to obtain all conditional branches under all classes and all methods;
[0071] Step S304: parsing the call link relationship of each branch judgment parameter of the binary file package through reverse deduction of the node calls of each layer;
[0072] Step S305: determining whether the call link relationship is a single interface call or a cross-interface call;
[0073] Step S306: when the call link relationship is a single interface call, performing magic number analysis on the single interface to determine whether the magic number is a constant or a configuration file field;
[0074] Step S307: When the magic number is a constant field, map the constant to an interface variable;
[0075] Step S308: When the magic number is a configuration file field, mapping the corresponding variable to the configuration file field;
[0076] Step S309: Generate test data for a single interface and change the calling method of the specified configuration file field.
[0077] Step S310: When the call link relationship is a cross-interface call, the interface relationship is parsed;
[0078] Step S311: Decompile the binary file package to obtain program source code using a binary decompilation method;
[0079] Step S312: Parse the JAVA code files and various XML resource package files contained in the source code. Specifically, in step S309, for example, there is a judgment condition if A=1, 1 is a magic number, A is a corresponding variable, and if through parsing, A can correspond to a field B in the configuration file. Then when generating this single interface test, it is necessary to add a call step to rewrite the configuration file field B, so as to test different situations of the judgment condition A=1 in the program code by changing the value of field B.
[0080] In a specific implementation, it is determined whether there is an SQL operation in the source code;
[0081] When there is a SQL (Structured Query Language) operation in the source code, the method and field of the SQL operation are mapped to the interface through parsing, and the parsed relationship between the cache operation and the interface is stored in the interface relationship analysis pool;
[0082] When there is no SQL operation in the source code, it is determined whether there is a cache operation in the source code.
[0083] In a specific implementation, determining whether there is a cache operation in the source code includes:
[0084] When there is a cache operation in the source code, the mode and field of the cache operation are mapped to the interface through parsing, and the parsed relationship between the cache operation and the interface is stored in the interface relationship analysis pool;
[0085] When there is no cache operation in the source code, it is determined whether there is a file operation in the source code.
[0086] In a specific implementation, the determining whether there is a file operation in the source code includes:
[0087] When there is a file operation in the source code, the mode and field of the file operation are mapped to the interface through parsing, and the relationship between the parsed file operation and the interface is stored in the interface relationship analysis pool;
[0088] When there is no file operation in the source code, it is determined whether there is a message operation in the source code.
[0089] In a specific implementation, the determining whether there is a message operation in the source code includes:
[0090] When there is a message operation in the source code, the mode and field of the message operation are mapped to the interface through parsing, and the relationship between the parsed message operation and the interface is stored in the interface relationship analysis pool;
[0091] When there is no message operation in the source code, the interface relationship data stored in the interface relationship analysis pool is dynamically run and explored.
[0092] In a specific implementation, it also includes dynamically running and exploring the interface relationship data stored in the interface relationship analysis pool;
[0093] Use the path exploration algorithm to perform breadth-first exploration and generation of all combinations of interface call relationships;
[0094] The generated interface call relationship, interface test data and configuration steps are run and tested and the run coverage is collected.
[0095] In the specific implementation, the following steps are also included:
[0096] If the interface call relationship, interface test data, and configuration steps generate a new path, it is a valid test case;
[0097] If no new path is generated, the algorithm continues to generate new test cases for testing until the interface relationship analysis pool is explored;
[0098] Output all valid test cases.
[0099] Finally, the fuzz testing of the above method is verified through auxiliary effects.
[0100] The unassisted fuzz testing coverage is as follows:
[0101] Row coverage: 51.28%; Row hits: 60 / 117.
[0102] Branch coverage: 18.75%; Branch hit count: 9 / 48.
[0103] After using the above method to assist fuzz testing with program analysis, the coverage is as follows:
[0104] Row coverage: 72.65%; Row hits: 85 / 117; Improvement over no assistance: 42%.
[0105] Branch coverage: 43.75%; Branch hits: 21 / 48; Improvement over unassisted: 133%.
[0106] In summary, an embodiment of the present invention provides a JAVA fuzzy testing method based on program analysis, including: obtaining a binary file package of a program under test; performing AST parsing on the binary file package; parsing nodes at each layer of the syntax tree of the binary file package to obtain all conditional branches under all classes and all methods; parsing the call link relationship of parameters of each branch of the binary file package through reverse deduction of the calls of the nodes at each layer; judging whether the call link relationship is a single interface call or a cross-interface call. The test case data of interface parameters and interface call sequence that can be obtained through program analysis can greatly increase the business logic that is difficult to explore with fuzzy testing, thereby increasing the coverage of the object under test. Based on the improvement of coverage, the number of paths explored by fuzzy testing increases, which can prompt more non-overdue defects to be discovered.
[0107] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or replace some or all of the technical features therein with equivalents. However, these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present invention.
Claims
1. A JAVA fuzz testing method based on program analysis, characterized in that: include: Get the binary file package of the program under test; Performing AST parsing on the binary file package; Parsing nodes at each level of the syntax tree of the binary file package to obtain all conditional branches under all classes and all methods; By reverse deduction of the node calls at each layer, the call link relationship of each branch judgment parameter of the binary file package is parsed; Determining whether the call link relationship is a single-interface call or a cross-interface call; When the call link relationship is a single interface call, performing magic number parsing on the single interface to determine whether the magic number is a constant or a configuration file field; When the magic number is a constant field, mapping the constant to an interface variable; When the magic number is a configuration file field, mapping the corresponding variable to the configuration file field; Generate test data for a single interface and change the calling method of the specified configuration file field; When the call link relationship is a cross-interface call, parsing the interface relationship; Decompiling the binary file package to obtain program source code using the binary decompilation method; Parsing the JAVA code files and various XML resource package files contained in the source code; Determine whether there is an SQL operation in the source code; When there is an SQL operation in the source code, the method and field of the SQL operation are mapped to the interface through parsing, and the parsed relationship between the cache operation and the interface is stored in the interface relationship analysis pool; When there is no SQL operation in the source code, determining whether there is a cache operation in the source code; The determining whether there is a cache operation in the source code includes: When there is a cache operation in the source code, the mode and field of the cache operation are mapped to the interface through parsing, and the parsed relationship between the cache operation and the interface is stored in the interface relationship analysis pool; When there is no cache operation in the source code, it is determined whether there is a file operation in the source code.
2. The JAVA fuzz testing method based on program analysis according to claim 1 is characterized in that: The determining whether there is a file operation in the source code includes: When there is a file operation in the source code, the mode and field of the file operation are mapped to the interface through parsing, and the relationship between the parsed file operation and the interface is stored in the interface relationship analysis pool; When there is no file operation in the source code, it is determined whether there is a message operation in the source code.
3. The JAVA fuzz testing method based on program analysis according to claim 2 is characterized in that: The determining whether there is a message operation in the source code includes: When there is a message operation in the source code, the mode and field of the message operation are mapped to the interface through parsing, and the relationship between the parsed message operation and the interface is stored in the interface relationship analysis pool; When there is no message operation in the source code, the interface relationship data stored in the interface relationship analysis pool is dynamically run and explored.
4. The JAVA fuzz testing method based on program analysis according to any one of claims 1 to 3, characterized in that: It also includes dynamically running and exploring the interface relationship data stored in the interface relationship analysis pool; Use the path exploration algorithm to perform breadth-first exploration and generation of all combinations of interface call relationships; The generated interface call relationship, interface test data and configuration steps are run and tested and the run coverage is collected.
5. The JAVA fuzz testing method based on program analysis according to claim 4 is characterized in that: The following steps are also included: If the interface call relationship, interface test data, and configuration steps generate a new path, it is a valid test case; If no new path is generated, the algorithm continues to generate new test cases for testing until the interface relationship analysis pool is explored; Output all valid test cases.
Citation Information
Patent Citations
Java deserialization vulnerability mining method and device based on fuzz testing and medium
CN118427830A
Calling link generation method based on Java static code analysis
CN118312250A
Method and system for detecting security risk of software supply chain
CN118551381A