Protocol fuzzy testing method and system based on multi-dimensional feedback information

Through the multi-dimensional feedback information processing method, the selection of mutation fields is optimized, and the problem of single feedback information and random selection of mutation fields in the existing technology is solved, which significantly improves the efficiency and effectiveness of protocol fuzz testing, and ensures more efficient vulnerability detection.

CN119561879BActive Publication Date: 2025-05-06HANGZHOU DIANZI UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510088640.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-01-21
Publication Date
2025-05-06
Estimated Expiration
2045-01-21

AI Technical Summary

Technical Problem

In the existing protocol fuzz testing technology, the single feedback information dimension and the selection of mutation fields is too random, resulting in limited testing efficiency and effectiveness, and the lack of precise focus on the key fields that cause the crash.

Method used

Using the multi-dimensional feedback information processing method, by selecting the field variation stage and the variable field cost probability calculation stage, the Alias ​​Method algorithm and Z-Score standardization technology are used to generate more targeted test cases to improve coverage branches and test efficiency.

Benefits of technology

Significantly improves the code space coverage of protocol fuzzing, reveals more potential vulnerabilities, improves testing efficiency and detection quality, and ensures that tests are focused on the paths that are most likely to cause crashes under limited resources.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119561879B_ABST
    Figure CN119561879B_ABST
Patent Text Reader

Abstract

The present invention relates to a protocol fuzz testing method and system based on multi-dimensional feedback information, the method comprising pre-processing a target protocol entity program to prepare for testing; performing fuzz testing; during the fuzz testing process, including selecting a field mutation phase and a mutation field cost probability calculation phase to perform multi-dimensional feedback information processing; obtaining test result information and performing result information feedback; the system comprises three modules: a test preparation module, a fuzz testing module, and a result information feedback module. The present invention significantly improves the code space coverage of the protocol fuzz testing by selecting a field mutation phase and a mutation field cost probability calculation phase to perform multi-dimensional feedback information processing, reveals more potential vulnerabilities, greatly improves the test efficiency, and focuses the test on the path that is most likely to cause a crash under limited resources, thereby improving the detection quality and speed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The invention belongs to the technical field of protocol fuzzy testing, and in particular relates to a protocol fuzzy testing method and system based on multi-dimensional feedback information. Background Art

[0002] Network Protocol Fuzzing is an important security assessment technology, which is mainly used to discover hidden defects and potential risks in network protocol implementation. Its basic principle is to send specially designed or random data packets to the target system to induce abnormal behavior, thereby identifying the weaknesses of the software when processing unexpected input. This testing strategy pays special attention to common problems in network protocol implementation, such as buffer overflow, data parsing errors, and authentication mechanism failures, with the goal of accurately identifying security risks.

[0003] In recent years, the protocol fuzz testing technology based on syntax generation has developed rapidly, and a new method combining syntax generation and coverage orientation has emerged, which has greatly improved the ability and depth of detecting protocol vulnerabilities. This method uses coverage branch feedback as a key criterion, combines syntax-driven generation with dynamic analysis technology, and realizes intelligent test case construction. The core idea is that the generated test cases not only conform to the protocol syntax, but also can explore the program execution path in a targeted manner, increasing the chance of discovering potential defects. Therefore, this method not only improves the test efficiency, but also can achieve code coverage more accurately, helping to reveal more hidden and deep security risks.

[0004] The current work related to grammar generation and coverage-guided protocol fuzz testing includes the following:

[0005] 1. Z-Fuzzer is an improved version of Boofuzz, adding a coverage feedback mechanism. It uses test cases that trigger new code paths, while maintaining these coverage conditions, mutating other parts to explore code areas more deeply.

[0006] 2. PAVFuzz automatically learns the relationship between two mutated fields in adjacent state models during testing to guide testing. When a field needs to be mutated, PAVFuzz queries the relationship table, finds the mutated field of the previous state model with the largest relationship value, and mutates it together with the current mutated field. This process is designed to guide fuzz testing towards maximizing coverage.

[0007] In summary, although the protocol fuzz testing technology based on syntax generation and coverage feedback has achieved certain results, there are still problems such as the single dimension of feedback information and the random selection of mutation fields. The actual situation shows that the crash of the protocol program is not caused by arbitrary changes in all fields. In the limited testing time, failure to accurately focus on the key fields that cause the crash will limit the effectiveness and efficiency of fuzz testing. Therefore, identifying and prioritizing fields that have a significant impact on the crash is the key to improving the effectiveness of the mutation strategy. Summary of the invention

[0008] The technical problem to be solved by the present invention is to provide a protocol fuzzy testing method and system based on multi-dimensional feedback information, introduce the concept of multi-dimensional dynamic feedback, and improve coverage branches and testing efficiency.

[0009] The present invention provides a protocol fuzzy testing method based on multi-dimensional feedback information, comprising the following steps:

[0010] S1: Preprocess the target protocol entity program to prepare for testing;

[0011] S2: Perform fuzz testing; the fuzz testing process includes the field mutation selection phase and the mutation field cost probability calculation phase to perform multi-dimensional feedback information processing;

[0012] S3: Obtain test result information and provide result information feedback.

[0013] Preferably, the specific steps of step S1 include:

[0014] S1.1: Use the stub compilation tool to perform stub compilation on the target protocol entity program to generate the corresponding binary executable file;

[0015] S1.2: Combined with the official protocol specification of the target protocol entity program, use the state model definition function provided by the Boofuzz ​​fuzz testing framework to define the state model set of the protocol , and its calculation formula is:

[0016] ={ ,..., ,..., }, i=1,…,n,

[0017] Where n is the total number of state models;

[0018] S1.3: Run the binary executable file generated in step S1.1, and open a shared memory ShareMem of 64KB to count the coverage branch information of the target protocol entity program in real time.

[0019] Preferably, the specific steps of selecting the field variation stage in step S2 include:

[0020] S2.1: State model selection; from the state model set Select a state model in order , and initialize the state model The calculation formula of the variation value is:

[0021] =SM,

[0022] Among them, SM is the fixed number of mutations, and its value is obtained in the state model during the field selection phase. The number of new test cases generated under

[0023] S2.2: Select field variation; extract state model A collection of mutation fields consisting of multiple mutation fields , and its calculation formula is:

[0024] ={ ,..., ,..., }, i=1,…,n, j=1,…,m,

[0025] Among them, n is the total number of state models, m is the state model The number of variant fields included in ;

[0026] Under the guidance of the cost probability table, the Alias ​​Method algorithm is used to select the variant field set according to the probability. Select a variant field in Mutate to generate a test case with the jth mutation field of the i-th state model mutated ;

[0027] S2.3: Test cases Inject into the target protocol entity program, count the coverage branch information of the opened shared memory ShareMem, and the status information returned by the target protocol entity program.

[0028] Preferably, when the test case generated in step S2.2 When the target protocol entity program crashes, the exception log is recorded and the test case is saved , used for vulnerability analysis after the test is completed.

[0029] Preferably, in the variant field cost probability calculation phase of step S2, the state model is calculated The cost values ​​of each variant field in the state model The probability of being selected is expressed quantitatively.

[0030] Preferably, the specific steps of the variant field cost probability calculation phase in step S2 include:

[0031] S2.4: Collect feedback information and standardize it; count the coverage branch information of the shared memory ShareMem opened in step S1.3 and the status information returned by the target protocol entity program; in each test case After execution, collect feedback information returned by the target protocol entity program, and then standardize the collected feedback information using Z-Score;

[0032] S2.5: Calculate the cost value and probability value; calculate the variation field using the data standardized by Z-Score The cost value of this cost is calculated; after the current value is calculated, the cost value is standardized; then, the standardized value is probability mapped using the probability selection algorithm Softmax function;

[0033] S2.6: Cost probability table update; when test case If the new cost value is greater than the original value in the cost probability table, the table is updated.

[0034] Preferably, in step S2.4, the feedback information collected is a , , A data structure in the form of a triple. Represented as a test case The number of covered branches; Represented as a test case The return status code is Represented as a mutating field The total number of exception return codes;

[0035] The collected feedback information is then standardized using the Z-Score to generate a Design a historical information table, each variant field has a corresponding data row, variant field The data rows are represented as: , , ],

[0036] in, Represented as a mutating field The unique id in the current state model, starting from 0 and increasing as a whole. The value is the mutating field The maximum number of covered branches, whose initial value is 0; The value is the mutating field The total number of exception return codes. The initial value is 0.

[0037] Preferably, in step S2.5, the variation field is obtained by calculation The cost value is calculated as follows: ,

[0038] in, Represented as a mutating field Cost value; Represented as a test case The data after normalization of the number of covered branches; Represented as a test case The return status code is the standardized data. Represented as a mutating field The total number of abnormal return codes is standardized Represented as three adjustable parameters,

[0039] After calculating the cost value, the cost value is standardized. The calculation formula is as follows:

[0040]

[0041] in, Represented as a mutating field The standardized cost value of Expressed as mean; Expressed as standard deviation;

[0042] The standardized values ​​are mapped to probability, and the calculation formula is as follows:

[0043]

[0044] in, Represented as a mutating field The selection probability of ; the value of k ranges from 1 to m.

[0045] Preferably, the step S3 presents the collected coverage branch data and other information in real time and visually in the user interface, and intuitively feeds back the test progress of the current fuzz test.

[0046] A protocol fuzzy testing system based on multi-dimensional feedback information, comprising:

[0047] Test preparation module; provide test data input and pre-process the test data input; use the stub compilation tool to perform stub compilation on the target protocol entity program to generate the corresponding binary executable file; refer to the official protocol specification of the target protocol entity program, write the test template, and form a state model set ; Real-time statistics of coverage branch information of the target protocol entity program;

[0048] Fuzz testing module; from the state model collection Select the state model in turn , and then execute the field selection phase and the field cost probability calculation phase; use the Alias ​​Method algorithm to select the mutated field according to the cost probability table Perform mutations and generate test cases , the test case Inject into the target protocol entity program, collect feedback information and standardize the feedback information, and then perform cost and probability calculation and cost probability table update steps;

[0049] Result information feedback module; for test cases The results after being input into the target protocol entity program are analyzed, and the collected coverage branch data information is visualized in real time in the user interface, providing intuitive feedback on the test progress of the current fuzz test.

[0050] The present invention has the following technical effects:

[0051] 1. By selecting the field mutation stage and the mutation field cost probability calculation stage for multi-dimensional feedback information processing, the code space coverage of the protocol fuzz test is significantly improved, more potential vulnerabilities are revealed, and the test efficiency is greatly improved. Under limited resources, the test is focused on the path that is most likely to cause a crash, thereby improving the detection quality and speed.

[0052] 2. Effectively solve the problems of single feedback information and overly random selection of mutation fields in traditional fuzz testing technology; guide fuzz testing through multi-dimensional feedback information, generate more test cases for important mutation fields, thereby improving coverage branches to discover more crashes and enhancing the accuracy of fuzz testing. BRIEF DESCRIPTION OF THE DRAWINGS

[0053] Figure 1 It is a flow chart of the protocol fuzzy testing method based on multi-dimensional feedback information of the present invention;

[0054] Figure 2 A schematic diagram of a state model set defined in the protocol fuzzy testing method based on multi-dimensional feedback information of the present invention, taking the RTSP protocol as an example;

[0055] Figure 3The protocol fuzzy testing method based on multi-dimensional feedback information of the present invention takes the options state model in the RTSP protocol as an example, and defines the cost probability representation intent;

[0056] Figure 4 The protocol fuzzy testing method based on multi-dimensional feedback information of the present invention takes the options state model in the RTSP protocol as an example and defines the historical information representation intent. DETAILED DESCRIPTION

[0057] In order to make the objectives, technical solutions and advantages of the present invention more clear, the present invention is described in detail below with reference to the accompanying drawings.

[0058] like Figure 1 As shown, the protocol fuzz testing method based on multi-dimensional feedback information includes the following steps:

[0059] S1: Preprocess the target protocol entity program to prepare for testing;

[0060] S2: Perform fuzz testing; the fuzz testing process includes the field mutation selection phase and the mutation field cost probability calculation phase to perform multi-dimensional feedback information processing;

[0061] S3: Obtain test result information and provide result information feedback.

[0062] The specific steps of step S1 include:

[0063] S1.1: Use the stub compilation tool to perform stub compilation on the target protocol entity program to generate the corresponding binary executable file; Use the gcc and g++ compilation tools that come with AFL-Net to perform stub compilation on the target protocol entity program to generate the corresponding binary executable file. Its essence is to mark each static program block of the program under test. In the subsequent execution of a test case, the entire execution path of the test case can be determined according to different marks;

[0064] S1.2: Combined with the official protocol specification of the target protocol entity program, use the state model definition function provided by the Boofuzz ​​fuzz testing framework to define the state model set of the protocol ={ }, i = 1, ..., n, where n represents the total number of target protocol state models, and the defined state model set Used as a protocol specification template for generating new test cases;

[0065] like Figure 2 As shown, using the RTSP protocol, the defined state model set ={options, describe1,describe2, setup, play, pause, teardown, get_parameter, set_parameter1, set_parameter2};

[0066] S1.3: Run the binary executable file generated by step S1.1, and open a shared memory ShareMem of 64KB (the size of ShareMem is an empirical value, 64K bytes can represent 65536 branches, which is larger than the number of branches of most target protocol entity programs and can meet the branch coverage statistics requirements of most target protocol entity programs) to count the coverage branch information of the target protocol entity program in real time.

[0067] The specific steps of selecting the field variation stage in step S2 include:

[0068] S2.1: State model selection; from the state model set Select a state model in order , and initialize the state model The calculation formula of the variation value is:

[0069] =SM,

[0070] Among them, SM is the fixed number of mutations, and its value is obtained in the state model during the field selection phase. The number of new test cases generated, the SM value is 2000;

[0071] S2.2: Select field variation; extract state model A collection of mutation fields consisting of multiple mutation fields , and its calculation formula is:

[0072] ={ ,..., ,..., }, i=1,…,n, j=1,…,m,

[0073] Among them, n is the total number of state models, m is the state model The number of variant fields included in ;

[0074] Under the guidance of the cost probability table, the Alias ​​Method algorithm is used to select the variant field set according to the probability. Select a variant field in Mutate to generate a mutated test case for the j-th mutated field of the i-th state model ;

[0075] The Alias Method algorithm is a method for generating random samples that follow a specified probability distribution, especially suitable for discrete probability distributions. Its main idea is to construct a data structure through preprocessing so that the time complexity of generating samples is at the constant level;

[0076] The sampling process of the original probability event using the Alias Method algorithm is as follows:

[0077] 1) S is a list. Let S[i] be the probability P[i] of each event multiplied by the number of events N. P is the probability list of the mutated fields of a certain state model and N is the number of mutated fields under this state model;

[0078] 2) Initialize two lists: Prob and Alias, both of length N; create two queues: small and large;

[0079] 3) Traverse the list S. If S[i] < 1, add i to small. If S[i] >= 1, add i to large;

[0080] 4) When both queues small and large are not empty, remove an element m from small and an element g from large. Let Prob[m]=S[m], Alias[m]=g, S[g] = S[g]+S[m]-1. If S[g]<1, add g to small, otherwise add it to large;

[0081] 5) If one of small and large is not empty, for each element i, Prob[i]=1, Alias[i]=-1, indicating that this position always selects itself;

[0082] 6) Generate a random number i, i = 0, …, N - 1, to determine which column to use. Generate a uniformly distributed random number u between 0 and 1. If u < Prob[i], then select event i, otherwise select Alias[i].

[0083] After obtaining the subscript of the mutated field through the above algorithm, select the mutated field according to the subscript to generate a mutated test case ; Each state model has its own cost probability table, which is a two-dimensional array structure with m rows and 3 columns, such as Figure 3As shown, m is the state model The number of variant fields contained in , each variant field has a corresponding data row, variant field Data behavior: , , ], Represented as a mutating field The unique id in the current state model, starting from 0 and increasing. The initial value of is 0. The initial value is ;

[0084] In the following period of time, the mutation work for the state model is carried out under the guidance of the cost probability table until the mutation value (SM) of the state model is 0;

[0085] S2.3: Test cases Inject into the target protocol entity program, count the coverage branch information of the opened shared memory ShareMem, and the status information returned by the target protocol entity program.

[0086] When the test case generated in step S2.2 When the target protocol entity program crashes, the exception log is recorded and the test case is saved , used for vulnerability analysis after the test is completed.

[0087] The algorithm flow for selecting field mutation is:

[0088] 1) First, initialize the state model The mutation value SM.

[0089] 2) From the state model Select all the mutated fields and store them in the mutated field list Fields[].

[0090] 3) In the state model If the number of remaining mutations is greater than zero, perform the following steps:

[0091] 3.1) Use the Alias ​​Method algorithm to select a mutation field subscript from the cost probability table. This step calculates the probability weight of each field and selects a mutation field subscript by sampling, and then selects the mutation field .

[0092] 3.2) For the selected variant field Perform mutation operation.

[0093] 3.3) Generate a variable containing the mutated fields Test cases .

[0094] 3.4) Generate test cases Inject the target protocol entity program and obtain feedback information.

[0095] 3.5) The feedback information is passed to the mutation field cost probability calculation stage for further calculation.

[0096] 4) Repeat the above steps until the required number of mutations is reached.

[0097] In the variant field cost probability calculation phase of step S2, the state model is calculated The cost values ​​of each variant field in the state model The probability of being selected is expressed quantitatively.

[0098] The specific steps of the variant field cost probability calculation phase in step S2 include:

[0099] S2.4: Collect feedback information and standardize it; count the coverage branch information of the shared memory ShareMem opened in step S1.3 and the status information returned by the target protocol entity program; in each test case After execution, collect the feedback information returned by the protocol entity program, and then standardize the collected feedback information using Z-Score;

[0100] The feedback information collected is a , , A data structure in the form of a triple. Represented as a test case The number of covered branches; Represented as a test case The return status code of the status code is quantified as follows: "2XX" represents a normal return, with a value of 0.1; abnormal return codes, "4XX", "5XX", etc., have a value of 0.9; Represented as a mutating field The total number of exception return codes;

[0101] The collected feedback information is then standardized using the Z-Score to generate a Design a historical information table, such as Figure 4 As shown, each variant field has a corresponding data row. The data rows are represented as: , , ],

[0102] in, Represented as a mutating field The unique id in the current state model, starting from 0 and increasing as a whole. The value is the mutating field The maximum number of covered branches, whose initial value is 0; The value is the mutating field The total number of exception return codes. The initial value is 0.

[0103] The use of Z-Score normalization for data processing aims to balance the contribution of each feature parameter in the cost function; this can eliminate the dimensional differences between features and prevent individual features from dominating the calculation due to excessive numerical ranges, which will excessively affect the results. Without normalization, the weights of the first and third indicators will far exceed the second one, which may lead to unexpected optimization results. The normalization step effectively compresses the feature values ​​so that they participate in the cost function calculation with equal weight, ensuring that each part contributes reasonably to the total cost, thereby improving the robustness and accuracy of the model.

[0104] S2.5: Calculate the cost value and probability value; calculate the variation field using the data standardized by Z-Score The cost value of this cost is calculated; after the current value is calculated, the cost value is standardized; then, the standardized value is probability mapped using the probability selection algorithm Softmax function;

[0105] Calculate the variation field The cost value is calculated as follows: ,

[0106] in, Represented as a mutating field Cost value; Represented as a test case The data after normalization of the number of covered branches; Represented as a test case The return status code is the standardized data. Represented as a mutating field The total number of abnormal return codes is standardized It is represented by three adjustable parameters, which are 0.455, 0.255, and 0.290 respectively in this embodiment.

[0107] After calculating the cost value, the cost value is standardized. The calculation formula is as follows:

[0108]

[0109] in, Represented as a mutating field The standardized cost value of Expressed as mean; Expressed as standard deviation;

[0110] The standardized values ​​are mapped to probabilities, and the Softmax function is used at this time; the Softmax function is a commonly used probability selection algorithm that can map a set of weights to a probability distribution. Larger weights correspond to larger probabilities, but smaller weights still have a certain probability of being selected. The calculation formula is as follows:

[0111]

[0112] in, Represented as a mutating field The selection probability of ; the value of k ranges from 1 to m.

[0113] S2.6: Cost probability table update; when the test case If the new cost value is greater than the original value in the cost probability table, the table is updated.

[0114] The calculation process of the probability of mutation field cost is as follows:

[0115] 1) First, initialize the list cost_probability[] of cost values ​​and selection probability values ​​of the mutable fields in the current state model.

[0116] 2) Get test cases After execution is completed and the mutated fields are standardized Covered branch information .

[0117] 3) Get test cases After execution is completed and the mutated fields are standardized The resulting status code information .

[0118] 4) Get test cases After execution is completed and the mutated fields are standardized Information about the number of occurrences of the abnormal status code caused .

[0119] 5) Calculate the mutation field by covering branch information, status code information and abnormal status code information Cost value .

[0120] 6) Standardize the calculated cost value to obtain the standardized cost value .

[0121] 7) Map the standardized cost value to the variant field The probability of being selected .

[0122] 8) If the newly calculated cost value (and its corresponding probability value) is higher than the previous old cost value, update the cost and probability information of the field.

[0123] The step S3 presents the collected coverage branch data information in real time in the user interface, and intuitively feedbacks the test progress of the current fuzz test. At the same time, the number of times the target protocol entity program crashes is tracked and displayed in real time to ensure timely identification of system stability risks. In addition, the system automatically records and saves each test case that causes the target protocol entity program to crash. , in order to provide key basis for subsequent crash reproduction and in-depth analysis.

[0124] For this embodiment, experimental verification was carried out on the RTSP protocol and the MQTT protocol. The control group selected the most advanced fuzzer Boofuzz, and each group of experiments lasted for 24 hours. In order to reduce the impact of randomness in the fuzz test, all experiments were repeated three times and the results were averaged.

[0125] The experimental results are shown in the following table:

[0126] Target Protocol Target protocol implementation Number of branches covered by Boofuzz This embodiment covers the number of branches Improvements of this embodiment over Boofuzz RTSP Live555 3023 3128 3.5% MQTT mosquitto 1994 2039 2.3%

[0127] It can be seen from the above table that in the RTSP protocol, the number of branches covered by this embodiment is 105 more than that covered by Boofuzz, a relative increase of 3.5%; in the MQTT protocol, the number of branches covered by this embodiment is 45 more than that covered by Boofuzz, a relative increase of 2.3%; this embodiment has a significant improvement in the number of covered branches.

[0128] Any of the methods or steps described above may be stored as computer instructions or programs in various types of computer memories, and the computer instructions or programs may be recognized by various types of computer processors to implement any of the methods or steps described above.

[0129] The embodiments described above are only descriptions of the preferred modes of the present invention, and are not intended to limit the scope of the present invention. Without departing from the design spirit of the present invention, various modifications and improvements made to the technical solutions of the present invention by ordinary technicians in this field should all fall within the protection scope determined by the claims of the present invention.

Claims

1. A protocol fuzzy testing method based on multi-dimensional feedback information, characterized in that: The steps include: S1: Preprocess the target protocol entity program to prepare for testing; S2: Perform fuzz testing; The fuzz testing process includes the field mutation selection phase and the mutation field cost probability calculation phase to process multi-dimensional feedback information; S3: Obtain test result information and provide result information feedback; The specific steps of step S1 include: S1.1: Use the stub compilation tool to perform stub compilation on the target protocol entity program to generate the corresponding binary executable file; S1.2: Combined with the official protocol specification of the target protocol entity program, use the state model definition function provided by the Boofuzz ​​fuzz testing framework to define the state model set of the protocol , and its calculation formula is: ={ ,..., ,..., }, i=1,…,n, Where n is the total number of state models; S1.3: Run the binary executable file generated in step S1.1, and open a shared memory ShareMem of 64KB to count the coverage branch information of the target protocol entity program in real time; The specific steps of selecting the field variation stage in step S2 include: S2.1: State model selection; from the state model set Select a state model in order , and initialize the state model The calculation formula of the variation value is: =SM, Among them, SM is the fixed number of mutations, and its value is obtained in the state model during the field selection phase. The number of new test cases generated under S2.2: Select field variation; extract state model A collection of mutation fields consisting of multiple mutation fields , and its calculation formula is: ={ ,..., ,..., }, i=1,…,n ,j=1,…,m , Among them, n is the total number of state models, m is the state model The number of variant fields included in ; Under the guidance of the cost probability table, the Alias ​​Method algorithm is used to select the variant field set according to the probability. Select a variant field in Mutate to generate a test case with the jth mutation field of the i-th state model mutated ; S2.3: Test cases Inject into the target protocol entity program, count the coverage branch information of the opened shared memory ShareMem, and the status information returned by the target protocol entity program; When the test case generated in step S2.2 When the target protocol entity program crashes, the exception log is recorded and the test case is saved , used for vulnerability analysis after the test; In the variant field cost probability calculation phase of step S2, the state model is calculated The cost values ​​of each variant field in the state model The probability of being selected and quantitatively expressed; The specific steps of the variant field cost probability calculation phase in step S2 include: S2.4: Collect feedback information and standardize it; count the coverage branch information of the shared memory ShareMem opened in step S1.3 and the status information returned by the target protocol entity program; After execution, collect feedback information returned by the target protocol entity program, and then standardize the collected feedback information using Z-Score; S2.5: Calculate the cost value and probability value; calculate the variation field using the data standardized by Z-Score The cost value of this cost is calculated; after the current value is calculated, the cost value is standardized; then, the standardized value is probability mapped using the probability selection algorithm Softmax function; S2.6: Cost probability table update; when test case If the new cost value is greater than the original value in the cost probability table, update the table; In step S2.4, the feedback information collected is a , , A data structure in the form of a triple. Represented as a test case The number of covered branches; Represented as a test case The return status code is Represented as a mutating field The total number of exception return codes; The collected feedback information is then standardized using the Z-Score to generate a Design a historical information table, each variant field has a corresponding data row, variant field The data rows are represented as: , , ], in, Represented as a mutating field The unique id in the current state model, starting from 0 and increasing as a whole. The value is the mutating field The maximum number of covered branches, whose initial value is 0; The value is the mutating field The total number of abnormal return codes, the initial value is 0; In step S2.5, the variation field is obtained by calculation. The cost value is calculated as: , in, Represented as a mutating field The cost value of Represented as a test case The data after normalization of the number of covered branches; Represented as a test case The return status code is the standardized data. Represented as a mutating field The total number of abnormal return codes is standardized Represented as three adjustable parameters, After calculating the cost value, the cost value is standardized. The calculation formula is as follows: , in, Represented as a mutating field The standardized cost value of Expressed as mean; Expressed as standard deviation; The standardized values ​​are mapped to probability, and the calculation formula is as follows: , in, Represented as a mutating field The selection probability of ; the value of k ranges from 1 to m.

2. The protocol fuzzy testing method based on multi-dimensional feedback information according to claim 1 is characterized in that: The step S3 presents the collected coverage branch data information in real time and visually in the user interface, providing intuitive feedback on the test progress of the current fuzz test.

3. A system for the protocol fuzzy testing method based on multi-dimensional feedback information according to claim 1, characterized in that: include: Test preparation module; Providing test data input and pre-processing the test data input; Use the stub compilation tool to perform stub compilation on the target protocol entity program to generate the corresponding binary executable file; refer to the official protocol specification of the target protocol entity program, write a test template, and form a state model set ; Real-time statistics of coverage branch information of the target protocol entity program; Fuzz testing module; from the state model collection Select the state model in turn , and then execute the field selection phase and the field cost probability calculation phase; use the Alias ​​Method algorithm to select the mutated field according to the cost probability table Perform mutations and generate test cases , the test case Inject into the target protocol entity program, collect feedback information and standardize the feedback information, and then perform cost and probability calculation and cost probability table update steps; Result information feedback module; for test cases The results after being input into the target protocol entity program are analyzed, and the collected coverage branch data information is visualized in real time in the user interface, providing intuitive feedback on the test progress of the current fuzz test.

Citation Information

Patent Citations

  • Protocol fuzz testing method and system based on grammar generation and coverage rate guidance

    CN115982025A

  • Modbus TCP (Transmission Control Protocol) fuzzy test method based on QRNN (Quantitative Recurrent Neural Network)

    CN116094972A