Stateful protocol fuzz testing method and system based on response information

By combining response information and coverage information, the state definition and seed variation process of the state protocol fuzz testing tool are modified, and the state and seed variation energy are segmented, the problem of fuzziness in the existing technology is solved, and higher code coverage and vulnerability discovery efficiency are achieved.

CN119645883BActive Publication Date: 2025-05-06HANGZHOU DIANZI UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510174601.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-18
Publication Date
2025-05-06
Estimated Expiration
2045-02-18

AI Technical Summary

Technical Problem

The existing state protocol fuzz testing tool causes inefficient fuzzing and makes it difficult to find deep paths and vulnerabilities when the state definition is inaccurate.

Method used

By combining response information and coverage information, the state definition and seed variation processes in the fuzzy process are modified, and the variation energy of the state and seeds are subdivided to improve coverage and fuzzy testing efficiency.

Benefits of technology

The code coverage of stateful protocol fuzz testing has been significantly improved, more vulnerabilities have been found, and the efficiency of fuzz testing has been greatly improved, solving the shortcomings of traditional fuzzers in state division and seed mutation positions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119645883B_ABST
    Figure CN119645883B_ABST
Patent Text Reader

Abstract

The present invention relates to a stateful protocol fuzz testing method and system based on response information, and the method comprises the following steps: S1: preprocessing stage S2: fuzz testing stage; S3: state selection stage; S4: seed scheduling stage. The system comprises a test preparation module, a fuzz testing module, a state selection module, and a seed scheduling module. The present invention captures the allocation and use of enumeration type variables therein by statically analyzing the source code of the protocol entity program to be tested. The present invention analyzes the response result information of the program to be tested, extracts the response header field, further subdivides the state on the basis of the state represented by the response code, effectively distinguishes the states represented by multiple same state codes in the same seed, uses the response header field information and coverage information of the target state to adjust the seed value and mutation position, significantly improves the code coverage of the stateful protocol fuzz testing, discovers more vulnerabilities, and greatly improves the efficiency of the fuzz testing.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of fuzzy testing, and in particular relates to a stateful protocol fuzzy testing method and system based on response information. Background Art

[0002] As the most popular automated software vulnerability mining technology, fuzz testing has been widely used in academia and industry. It has the advantages of high automation, low energy consumption, and high computing resource utilization. However, when fuzzing stateful protocols, the traditional protocol fuzzer does not accurately describe the state information of the program under test, which may lead to low fuzzing efficiency and difficulty in discovering deep paths and vulnerabilities.

[0003] There are two main types of stateful protocol fuzz testing tools today: generation-based and mutation-based. Generation-based fuzz testing requires manual specification of the message template and state machine of the protocol being tested. The fuzzer uses each message template for testing based on the state machine. Mutation-based fuzz testing does not require manual provision of message templates and state machines. It uses real traffic as the initial seed and automatically builds the state machine according to its own state definition principle during the test. During fuzzing, the fuzzer selects the state to be fuzzified from the state machine according to the state selection algorithm, selects the seed that can reach the state based on the selected state, retains the prefix message sequence that reaches the target state in the seed, and mutates the subsequent message sequence to generate test cases.

[0004] The existing fuzz testing tools based on stateful protocol implementation mainly include the following frameworks and papers:

[0005] 1. SNPSFuzzer: A Fast Greybox Fuzzer for Stateful Network Protocolsusing Snapshots provides a strategy for adjusting the prefix message sequence, saving the longest message sequence snapshot that can trigger the target state of the program under test during fuzzing. SNPSFuzzer is based on the state definition of AFLNET, uses the return code of the program under test as the state, and maintains a snapshot of the program under test for each state internally. During fuzzing, the fuzzer uses the snapshot to allow the program under test to reach the target state. During the fuzzer test, when the message sequence received by the program under test when triggering state a is longer than the message sequence received by the program snapshot of state a maintained internally, the current program under test snapshot is saved so that the maintained program snapshot receives the longest message sequence when reaching the target state. This method uses the return code to represent the state, and only the longest message sequence is retained for each state. However, when fuzzing the target state, this method will cause the message sequence to reach the target state to become single, and lack the exploration of reaching the target state from other paths, which will lead to the overall inefficiency of fuzz testing.

[0006] 2. State Selection Algorithms and Their Impact on The Performance of Stateful Network Protocol Fuzzing Based on AFLNET, AFLNET-Legion was proposed, which improved the state definition and state selection algorithm of AFLNET. AFLNET-Legion believes that the granularity of using return codes to divide states in AFLNET is too large, which cannot accurately describe the state of the program under test, resulting in low efficiency of the fuzzer. Therefore, AFLNET-Legion constructs the triggered return codes into a tree structure based on the return codes, and regards the return codes of all different paths as a state for fuzz testing. This method uses the triggered return code sequence to represent the state. In thousands of fuzz tests, many different return code sequences may be generated. This method will identify hundreds of states, making it complicated to maintain state information and difficult to evaluate the value of the state.

[0007] In summary, in the fuzz testing system for stateful protocols, due to unreasonable definition of states, the fuzzer cannot accurately describe the server state, resulting in a lack of exploration on rare paths of the program under test during the fuzzing process, making it difficult to reach deep program branches, which in turn affects the overall efficiency of the fuzz testing. Summary of the invention

[0008] The technical problem to be solved by the present invention is to provide a stateful protocol fuzz testing method and system based on response information, solve the problem of inaccurate state definition of a stateful protocol fuzzer based on mutation, combine response information and coverage information, modify the state definition and seed mutation processes in the fuzzification process, subdivide the mutation energy of the state and seed on the basis of AFLNET, and improve the coverage and fuzz testing efficiency.

[0009] The present invention provides a stateful protocol fuzzy testing method based on response information, comprising the following steps:

[0010] S1: Preprocessing stage: compile and instrument the program under test, prepare the program under test and the initial seed file, and build the fuzzer initial state, seed, and coverage information;

[0011] S2: Fuzz testing phase: Generate a prefix message that reaches the target state, mark the mutation position of the seed, evaluate the mutation energy and number of mutations of the seed, mutate the seed to generate test cases and send them to the program under test, analyze the response information, and obtain the state pool and the seed queue of the target state;

[0012] S3: State selection phase: traverse the states in the state pool, calculate the state value of each state, and select the state with the highest value for fuzz testing;

[0013] S4: Seed scheduling phase; calculate the seed value and select seeds from the seed queue of the target state for fuzz testing.

[0014] Preferably, the step S1 specifically includes the following steps:

[0015] S1.1: Use the stub compilation tool to perform stub compilation on the program under test and generate the corresponding binary executable file;

[0016] S1.2: Prepare the initial seed file. The fuzzer reads the initial seed file and creates a seed, allocates shared memory for the coverage bitmap, and records the program branch coverage information when the program under test is executed.

[0017] S1.3: The fuzzer uses a subprocess to run the generated binary executable file and interacts with the subprocess through a pipe to perform fuzz testing using the initial seed to build the initial state, seed, and coverage information.

[0018] Preferably, the step S2 specifically includes the following steps:

[0019] S2.1: Traverse the message sequence of the seed, mark the message that triggers the target state as the mutation point, generate the prefix message sequence that reaches the target state, and take the message that triggers the next state after the mutation point as the mutation position;

[0020] SS2.2: Calculate the mutation energy of seeds , use AFLNET's own mutation frequency allocation method to calculate the number of seed mutations, obtain the number of program branches covered by the current seed and the average coverage ratio of the branches, obtain the mutation round of the current seed, obtain the number of target state sub-states contained in the current seed, and obtain the execution time of the seed, so as to calculate the seed mutation energy , the calculation formula is as follows:

[0021] ,

[0022] in, Indicates the number of program branches covered by the current seed and the ratio of the average covered branches, Indicates the mutation round of the current seed. Indicates the number of target state sub-states contained in the current seed. Indicates the execution time of the seed;

[0023] S2.3: Difference ratio of branches covered by mutation points in different sub-states , assign mutation times to different mutation points, covering branch difference ratio The calculation formula is as follows:

[0024] ,

[0025] in, Indicates The coverage branch difference ratio of sub-states, Indicates The number of program branches covered by each sub-state individually, Indicates The number of new coverage branches covered by each substate, The value ranges from 1 to , indicating that the current seed contains Sub-state;

[0026] S2.4: Mutate the seed to generate test cases; Use the mutation strategy provided by AFLNET to mutate the seed to generate test cases, including bit flipping, bit addition and subtraction, and bit replacement;

[0027] S2.5: Send the test case to the program under test; start the program under test, send the test case to the program under test, receive the response message and analyze the coverage, and when a new program branch is covered, save the new program branch index number and test case;

[0028] S2.6: Build seed state information; save the current test case as a seed, analyze the response message of the test case, extract the status code and response header field in the response message, and form a state pool. Use the status code to represent the state, compare the status code and the response header field, and when the status code is different, it is a different state. When the status code is the same but the response header field is different, it is a different sub-state under the same state. Add the response header field to the field hash structure of the trigger state, which records the response header field and the number of fuzzy times of the response header field.

[0029] S2.7: Record sub-state coverage information; start the program under test, send the current test case, record the coverage bitmap triggered by each message sending, and calculate the number of program branches that are individually covered in different sub-states under the same state , the calculation formula is as follows:

[0030] ,

[0031] in, Indicates The coverage bitmap of the sub-state Place value, Indicates The coverage bitmap of the sub-state Place value, The value ranges from 1 to , Indicates the number of sub-states of the current state;

[0032] Calculate the number of new program branches covered by each substate , the calculation formula is as follows:

[0033] ,

[0034] in, Indicates The number of new program branches covered by each substate, The new program branch covered by index number k in step S2.5;

[0035] S2.8: Traverse the state queue triggered by the seed and add the seed to the seed queue of the triggered state.

[0036] Preferably, the step S3 specifically includes the following steps:

[0037] S3.1: traverse all states, and adjust the state value based on the original state value of AFLNET using the fuzzy count of the response header field of the state;

[0038] Traverse the states in the state pool, obtain the number of test cases generated by the current state and the number of times they are selected, as well as the number of seeds generated to cover new paths, obtain the field hash structure of the current state, and use the fuzzy times of the response header field in the structure to calculate the state value , the calculation formula is as follows:

[0039] ,

[0040] in, Indicates the number of seeds that cover the new path when blurring the current state. Indicates the number of fuzzy response header fields included in the current state. Indicates the number of test cases generated when fuzzifying the current state. Indicates the number of times the current state is selected;

[0041] S3.2: Select the state with the largest value for fuzz testing and modify the fuzzification times of the state.

[0042] Preferably, step S4 specifically includes the following steps:

[0043] S4.1: Calculate the seed value, traverse the seeds in the target state seed queue, calculate the number of covered branches of the seeds when the target state is triggered, the fuzzy response header field when the target state is triggered, and the fuzzy times and execution time of the seeds to calculate the seed value , the calculation formula is as follows:

[0044] ,

[0045] in, Indicates the number of program branches covered by the seed when the target state is triggered. Response header field indicating the triggering target status The number of blurs, Indicates the number of fuzzy times of the seed, Indicates the execution time of the seed;

[0046] S4.2: Select the seed with the largest value to enter the fuzzy mutation, and modify the fuzzy times of the response header field of the seed and the target state in the seed.

[0047] A system of the aforementioned stateful protocol fuzz testing method based on response information, comprising a test preparation module, a fuzz testing module, a state selection module, and a seed scheduling module;

[0048] Test preparation module: provides initial seeds, uses the instrumentation compilation tool to compile and instrument the target protocol entity to generate a binary executable program, allocates shared memory for the coverage bitmap to record the program branch coverage information of the program under test, uses a subprocess to run the program under test, and sends the initial seeds to the program under test to build the initial state, seeds, and coverage information;

[0049] Fuzz testing module: Analyze the message sequence of the seed, construct the prefix message sequence that reaches the target state, calculate the seed mutation energy, assign mutation times to the seed according to the mutation energy, assign mutation times to each prefix message sequence according to the coverage bitmap difference of the target prefix sequence that meets the conditions, apply the random mutation strategy of AFLNET to mutate the seed to generate test cases, send the test cases to the program under test, record the coverage bitmap, save the test cases that cover the new program branches as seeds, analyze the response results of the seed, retest the seed, record the coverage branch information of each sub-state, add the seed to the seed queue of the trigger state, and complete the test of the test case;

[0050] State selection module: traverses the state pool, calculates the state value according to the number of fuzzy times of the state, the number of program branches found, and the fuzzy information of the response header field contained in the state, and selects the state with the highest value for fuzzification;

[0051] Seed scheduling module: According to the selected target state, the seed with the highest seed value is selected from the seed queue of the target state for fuzzification.

[0052] The present invention has the following technical effects:

[0053] 1. By analyzing the response result information of the program under test, extracting the response header field, and further subdividing the state based on the state represented by the response code, the state represented by multiple identical status codes in the same seed is effectively distinguished. The response header field information and coverage information of the target state are used to adjust the seed value and mutation position, which significantly improves the code coverage of stateful protocol fuzz testing, discovers more vulnerabilities, and greatly improves the efficiency of fuzz testing.

[0054] 2. It effectively solves the problems of unreasonable state division and single seed mutation position of traditional stateful protocol fuzzers; guides fuzz testing by response information and coverage information, and conducts more tests on locations that are easier to cover new paths, thereby improving coverage branches to discover more vulnerabilities and improving the efficiency of fuzz testing. BRIEF DESCRIPTION OF THE DRAWINGS

[0055] Figure 1 The present invention is a flow chart of a stateful protocol fuzzy testing method based on response information.

[0056] Figure 2 The present invention is a stateful protocol fuzzy testing method based on response information, taking the RTSP protocol as an example, and using the response header information to distinguish sub-states.

[0057] Figure 3 A schematic diagram of calculating the number of mutations in the stateful protocol fuzzy testing method based on response information of the present invention.

[0058] Figure 4 This is a seed scheduling flow chart of the stateful protocol fuzzy testing method based on response information of the present invention. DETAILED DESCRIPTION

[0059] In order to make the objectives, technical solutions and advantages of the present invention more clear, the present invention is described in detail below with reference to the accompanying drawings.

[0060] like Figure 1 As shown, the stateful protocol fuzz testing method based on response information includes the following steps:

[0061] S1: Preprocessing stage: compile and instrument the program under test, prepare the program under test and the initial seed file, and build the fuzzer initial state, seed, and coverage information;

[0062] S1.1: Use the instrumentation compilation tool to perform instrumentation compilation on the program under test and generate the corresponding binary executable file; use LLVM 5 and afl-clang-fast, afl-clang-fast++ to compile and instrument the program under test, perform static analysis on the program under test, insert a randomly generated code block number cur_loc into the code basic block of the program under test, and when the current code block is called, the inserted instrumentation code uses the XOR value of the previous code block number prev_loc and cur_loc as the index to modify the bit of the index subscript of the coverage bitmap in the specified shared memory, add 1 to it, and assign cur_loc>>1 to prev_loc, thereby completing the coverage program branch marking.

[0063] S1.2: Prepare the initial seed file. The fuzzer reads the initial seed file and creates a seed. It allocates shared memory for the coverage bitmap and records the program branch coverage information when the program under test is executed. The initial seed file prepared by AFLNET is copied to the seed file of the program under test. The fuzzer is started. The shared memory is applied for and the shared memory id is assigned to the specified shared memory environment variable. The child process is used to run forkserver. The child process loads the target program and waits for the main process to execute the target program. The main process sends the execution information to forkserver through the specified pipe. The child process forks itself to run the process of the program under test and passes the process ID of the program under test to the main process through the pipe. The main process sends the initial seed to the program under test through the process ID and port number.

[0064] S1.3: The fuzzer uses a subprocess to run the generated binary executable file and interacts with the subprocess through a pipe to perform fuzz testing using the initial seed to build the initial state, seed, and coverage information.

[0065] S2: Fuzz testing phase; Generate prefix messages that reach the target state, mark the mutation position of the seed, evaluate the mutation energy and number of mutations of the seed, mutate the seed to generate test cases and send them to the program under test, analyze the response information, obtain the state pool and the seed queue of the target state; traverse the seeds, determine the prefix message sequence and mutation position and number of mutations, mutate the message sequence, send the generated test cases to the program under test, analyze the response information and coverage information, retain the test cases that cover the new program branches, and add the seeds to the seed queue of the triggered state.

[0066] S2.1: Traverse the message sequence of the seed, mark the message that triggers the target state as the mutation point, generate the prefix message sequence that reaches the target state, and use the message that triggers the next state after the mutation point as the mutation position; analyze the state triggered by the current message sequence, and when the message sequence triggers the target state, record the current message sequence position p, and obtain all prefix message sequences M1_message that can reach the target state.

[0067] M1_message={region[0], region[1],…,region[i]}, i=0,1,2,..,p,

[0068] Where region is the message sequence array of the current seed.

[0069] Traverse the message sequence after p, and take the first message sequence that triggers the state after p as the mutated message sequence M2_message.

[0070] S2.2: Calculate the mutation energy of the seed , get the mutation round of the current seed, the mutation round of the current seed is equal to the mutation round of the seed that generated the seed + 1; get the message at position p in step S2.1, and count the number of target state sub-states contained in the current seed by comparing the response header fields of the messages at each position; get the execution time of the current seed, and calculate the number of sub-states of the target state contained in the current seed according to the seed mutation energy Use AFLNET's own mutation frequency allocation method to calculate the number of seed mutations and seed mutation energy The calculation formula is as follows:

[0071] ,

[0072] in, Indicates the number of program branches covered by the current seed and the ratio of the average covered branches, Indicates the mutation round of the current seed. Indicates the number of target state sub-states contained in the current seed. Indicates the execution time of the seed;

[0073] When the coverage branch of the seed is larger than the average coverage branch, the more program branches the seed passes through, the larger the mutation round, the fewer fuzzy times the program branches covered by the seed may be, and when there are more sub-states, the current seed is more likely to be in different states, so the number of seed fuzzifications should be appropriately increased. When the seed execution time is longer, the fuzzy time is higher, so the number of fuzzifications should be appropriately reduced.

[0074] S2.3: Difference ratio of branches covered by mutation points in different sub-states , assign mutation times to different mutation points, covering branch difference ratio The calculation formula is as follows:

[0075] ,

[0076] in, Indicates The coverage branch difference ratio of sub-states, Indicates The number of program branches covered by each sub-state individually, Indicates The number of new coverage branches covered by each substate, The value ranges from 1 to , indicating that the current seed contains Sub-state;

[0077] After allocating the number of mutations of the seed, if the seed has multiple mutation positions, such as Figure 3 As shown, the number of mutations is allocated according to the coverage of branches by the sub-states of these mutation positions, the number of mutations for each mutation position is allocated according to the branches covered by the current sub-state alone and the proportion of new program branches covered, the program branches covered by all sub-states alone and the new program branches covered are standardized, and the sub-states with a higher proportion get more mutations.

[0078] S2.4: mutate the seed to generate test cases; use AFLNET's own mutation strategy to mutate the seed to generate test cases, including bit flipping, bit addition and subtraction, and bit replacement; in the message at the mutation position, randomly apply AFLNET's own mutation strategy to mutate the seed to generate a mutated message sequence M2_massage, and concatenate the prefix message sequences M1_message and M2_message, as well as the message sequence M3_message after the mutation position into the test case kl_message.

[0079] S2.5: Send the test case to the program under test; start the program under test, send the test case to the program under test, receive the response message and analyze the coverage. When a new program branch is covered, save the new program branch index number and the test case; establish a connection with the program under test, send kl_message to the program under test, and receive the message result returned by the program under test, detect the program coverage and the vulnerabilities of the program under test, and save the new program branch index and kl_message if a new branch is covered.

[0080] S2.6: Build seed state information; save the current test case as a seed, analyze the response message of the test case, extract the status code and response header field in the response message, form a state pool, use the status code to represent the state, compare the status code and the response header field, when the status code is different, it is a different state, when the status code is the same but the response header field is different, it is a different sub-state under the same state, and add the response header field to the hash structure of the trigger state;

[0081] Analyze the response message and read the characters in the response message. Taking the RTSP protocol as an example, the response code is usually in the first line immediately following the RTSP version number. The line after the response code is the response header information, and the response header information is usually <field name: field value>. Extract the response code and response header field name according to the protocol format.

[0082] Compare the return code (state) of each message with the response header field (field), such as Figure 2 As shown, the field name of one report is cseq,date,transport,****,session, and the field name of the other report is cseq,range,session,****, and the return code (state) is 200.

[0083] When the response codes are the same, compare the response field names of each message. If different field names appear, the message is likely to have caused the program under test to modify the corresponding field, and the program under test is likely to have entered a new state. For example, the Session field generally represents the establishment of a connection with the server, such as Figure 2 As shown, when the response codes are the same, if the response field names are different, they are divided into different sub-states of the current seed, and the field names are recorded in the state structure represented by the current response code.

[0084] S2.7: Record sub-state coverage information; start the program under test, send the current test case, record the coverage bitmap triggered by each message sending, and calculate the number of program branches that are individually covered in different sub-states under the same state , the calculation formula is as follows:

[0085] ,

[0086] in, Indicates The coverage bitmap of the sub-state Place value, Indicates The coverage bitmap of the sub-state Place value, The value ranges from 1 to , Indicates the number of sub-states of the current state;

[0087] Calculate the number of new program branches covered by each substate , the calculation formula is as follows:

[0088] ,

[0089] in, Indicates The number of new program branches covered by each substate, The new program branch covered by index number k in step S2.5;

[0090] The more program branches a substate covers individually, the rarer the path triggered by the substate in the current seed. In this case, more mutation opportunities should be obtained during mutation, and the number of new program branches triggered by the current seed should be recorded. , if more new program branches are covered, the sub-state should be given more mutation opportunities to explore the program branch.

[0091] S2.8: Traverse the state queue triggered by the seed and add the seed to the seed queue of the triggered state. Each state maintains a seed queue seeds, which contains seeds that can reach the current state. Traverse the state queue triggered by the seed and add the seed to the seed queue of the triggered state.

[0092] S3: State selection phase: traverse the states in the state pool, calculate the state value of each state, and select the state with the highest value for fuzz testing;

[0093] S3.1: traverse all states, obtain the field hash structure of the state, and use the fuzzy times of the response header field to adjust the original state value of AFLNET;

[0094] Traverse the states in the state pool, obtain the number of test cases generated by the current state and the number of times they are selected, as well as the number of seeds generated to cover new paths, and calculate the state value in combination with the fuzzy information of the response header field contained in the current state , the calculation formula is as follows:

[0095] ,

[0096] in, is the number of seeds generated to cover the new path when blurring the current state, is the number of fuzzy counts of the response header fields included in the current state, is the number of test cases generated when fuzzifying the current state, is the number of times the current state has been selected.

[0097] when The larger it is, the easier it is for the current state to trigger a new path. The larger the value, the more test cases are generated in the current state, which will reduce the state value. It indicates the ambiguity of the current state when triggering the response header field. The larger the value, the less ambiguous the current state is when the program under test sets the specified field. It indicates the number of times the state is selected. When the number of selections increases, the state value will be appropriately reduced. This formula comprehensively evaluates the state value from the benefits and fuzziness of the state.

[0098] S3.2: Select the state with the highest value for fuzz testing and modify the fuzzy times of the state. , Modify the fuzzy times when the test case covers a new program branch During fuzz testing, the number of mutations is allocated and then modified to trigger the response header field of the target state. The number of blurs Modify after selecting a seed.

[0099] S4: Seed scheduling phase; calculate the seed value and select seeds from the seed queue of the target state for fuzz testing.

[0100] S4.1: Calculate the seed value, e.g. Figure 4 As shown, the seeds in the target state seed queue are traversed, the number of covered branches of the seeds when the target state is triggered is calculated, the situation of response header field fuzziness when the target state is triggered, and the number of fuzzy times and execution time of the seeds are calculated to calculate the seed value , the calculation formula is as follows:

[0101] ,

[0102] in, Indicates the number of program branches covered by the seed when the target state is triggered. Response header field indicating the triggering target status The number of blurs, Indicates the number of fuzzy times of the seed, Indicates the execution time of the seed; Represents the number of program branches covered when the seed triggers the target state, by accumulating It is calculated that this represents the ability of the target state to cover the program branch in the current seed, It means the ambiguity of the response header fields contained in the target state. The larger the value, the less ambiguous the current state is when responding to these fields. It indicates the execution time of the current seed, which is the cost of seed execution. When the cost is higher, the seed value is appropriately reduced.

[0103] S4.2: Select the seed with the largest value to enter the fuzzy mutation, and modify the fuzzy times of the response header field of the seed and the target state in the seed. Select the seed with the largest value to enter the fuzzy mutation, and modify the fuzzy times of the seed , and the fuzzy information of the response header field contained when the seed triggers the target state, that is, the response header field that triggers the target state The number of blurs .

[0104] For this embodiment, an experimental verification was conducted on the RTSP protocol. The control group selected the most advanced fuzzer AFLNET. Each group of tests lasted 12 hours, and the experimental data was recorded every two hours. In order to reduce the impact of randomness in the fuzzy test, all experiments were repeated three times, and the average value of the results was taken. The test results are shown in Tables 1 and 2 below:

[0105] Table 1

[0106]

[0107] Table 2

[0108]

[0109] As can be seen from Table 1 above, the number of paths found by this embodiment on the RTSP protocol is much larger than the most advanced fuzzer AFLNET within 12 hours, and the number of paths found by this embodiment is 151 more than the number of paths found by the most advanced fuzzer AFLNET at 12 hours; As can be seen from Table 2 above, the number of vulnerabilities found by this embodiment on the RTSP protocol is much larger than the most advanced fuzzer AFLNET within 12 hours, and the number of vulnerabilities found by this embodiment is 19 more than the number of vulnerabilities found by the most advanced fuzzer AFLNET at 12 hours; After using the method described in the present invention, compared with the traditional stateful protocol fuzzy testing method, the two key indicators of the number of paths and the number of vulnerabilities have been improved. Therefore, the method described in the present invention can effectively improve the efficiency of the stateful protocol fuzzy testing system in detecting vulnerabilities.

[0110] The embodiments described above are only descriptions of the preferred modes of the present invention, and are not intended to limit the scope of the present invention. Without departing from the design spirit of the present invention, various modifications and improvements made to the technical solutions of the present invention by ordinary technicians in this field should all fall within the protection scope determined by the claims of the present invention.

Claims

1. A stateful protocol fuzz testing method based on response information, characterized in that: The steps include: S1: Preprocessing stage: compile and instrument the program under test, prepare the program under test and the initial seed file, and build the fuzzer initial state, seed, and coverage information; S2: fuzz testing phase; Generate a prefix message that reaches the target state, mark the mutation position of the seed, evaluate the mutation energy and number of mutations of the seed, mutate the seed to generate test cases and send them to the program under test, analyze the response information, and obtain the state pool and the seed queue of the target state; S3: State selection phase: traverse the states in the state pool, calculate the state value of each state, and select the state with the highest value for fuzz testing; S4: seed scheduling stage; Calculate the seed value and select the seed from the target state's seed queue for fuzz testing; The step S1 specifically includes the following steps: S1.1: Use the stub compilation tool to perform stub compilation on the program under test and generate the corresponding binary executable file; S1.2: Prepare the initial seed file. The fuzzer reads the initial seed file and creates a seed, allocates shared memory for the coverage bitmap, and records the program branch coverage information when the program under test is executed. S1.3: The fuzzer uses a subprocess to run the generated binary executable file and interacts with the subprocess through a pipeline, uses the initial seed for fuzz testing, and builds the initial state, seed, and coverage information; The step S2 specifically includes the following steps: S2.1: Traverse the message sequence of the seed, mark the message that triggers the target state as the mutation point, generate the prefix message sequence that reaches the target state, and take the message that triggers the next state after the mutation point as the mutation position; S2.2: Calculate the mutation energy of the seed , use AFLNET's own mutation frequency allocation method to calculate the number of seed mutations, obtain the number of program branches covered by the current seed and the average coverage ratio of the branches, obtain the mutation round of the current seed, obtain the number of target state sub-states contained in the current seed, and obtain the execution time of the seed, so as to calculate the seed mutation energy , the calculation formula is as follows: , in, Indicates the number of program branches covered by the current seed and the ratio of the average covered branches, Indicates the mutation round of the current seed. Indicates the number of target state sub-states contained in the current seed. Indicates the execution time of the seed; S2.3: Difference ratio of branches covered by mutation points in different sub-states , assign mutation times to different mutation points, covering branch difference ratio The calculation formula is as follows: , in, Indicates The coverage branch difference ratio of sub-states, Indicates The number of program branches covered by each sub-state individually, Indicates The number of new coverage branches covered by each substate, The value ranges from 1 to , indicating that the current seed contains Sub-state; S2.4: Mutate the seed to generate test cases; Use the mutation strategy provided by AFLNET to mutate the seed to generate test cases, including bit flipping, bit addition and subtraction, and bit replacement; S2.5: Send the test case to the program under test; start the program under test, send the test case to the program under test, receive the response message and analyze the coverage, and when a new program branch is covered, save the new program branch index number and test case; S2.6: Build seed state information; save the current test case as a seed, analyze the response message of the test case, extract the status code and response header field in the response message, form a state pool, use the status code to represent the state, compare the status code and the response header field, when the status code is different, it is a different state, when the status code is the same but the response header field is different, it is a different sub-state under the same state, and add the response header field to the hash structure of the trigger state; S2.7: Record sub-state coverage information; start the program under test, send the current test case, record the coverage bitmap triggered by each message sending, and calculate the number of program branches that are individually covered in different sub-states under the same state , the calculation formula is as follows: , in, Indicates The coverage bitmap of the sub-state Place value, Indicates The coverage bitmap of the sub-state Place value, The value ranges from 1 to , Indicates the number of sub-states of the current state; Calculate the number of new program branches covered by each substate , the calculation formula is as follows: , in, Indicates The number of new program branches covered by each substate, The new program branch covered by index number k in step S2.5; S2.8: traverse the state queue triggered by the seed and add the seed to the seed queue of the triggered state; The step S3 specifically includes the following steps: S3.1: traverse all states, and adjust the state value based on the original state value of AFLNET using the fuzzy count of the response header field of the state; Traverse the states in the state pool, obtain the number of test cases generated by the current state and the number of times they are selected, as well as the number of seeds generated to cover new paths, and calculate the state value in combination with the fuzzy information of the response header field contained in the current state , the calculation formula is as follows: , in, Indicates the number of seeds that cover the new path when blurring the current state. Indicates the number of fuzzy response header fields included in the current state. Indicates the number of test cases generated when fuzzifying the current state. Indicates the number of times the current state is selected; S3.2: Select the state with the maximum value for fuzz testing, and modify the fuzzy times of the state; The step S4 specifically includes the following steps: S4.1: Calculate the seed value, traverse the seeds in the target state seed queue, calculate the number of covered branches of the seeds when the target state is triggered, the fuzzy response header field when the target state is triggered, and the fuzzy times and execution time of the seeds to calculate the seed value , the calculation formula is as follows: , in, Indicates the number of program branches covered by the seed when the target state is triggered. Response header field indicating the triggering target status The number of blurs, Indicates the number of fuzzy times of the seed, Indicates the execution time of the seed; S4.2: Select the seed with the largest value to enter the fuzzy mutation, and modify the fuzzy times of the response header field of the seed and the target state in the seed.

2. A system for the stateful protocol fuzz testing method based on response information according to claim 1, characterized in that: It includes test preparation module, fuzzy test module, state selection module and seed scheduling module; Test preparation module: provides initial seeds, uses the instrumentation compilation tool to compile and instrument the program under test to generate a binary executable program, allocates shared memory for the coverage bitmap to record the program branch coverage information of the program under test, uses a subprocess to run the program under test, and sends the initial seeds to the program under test to build the initial state, seeds, and coverage information; Fuzz testing module: Analyze the message sequence of the seed, construct the prefix message sequence that reaches the target state, calculate the seed mutation energy, assign mutation times to the seed according to the mutation energy, assign mutation times to each prefix message sequence according to the coverage bitmap difference of the target prefix sequence that meets the conditions, apply the random mutation strategy of AFLNET to mutate the seed to generate test cases, send the test cases to the program under test, record the coverage bitmap, save the test cases that cover the new program branches as seeds, analyze the response results of the seed, retest the seed, record the coverage branch information of each sub-state, add the seed to the seed queue of the trigger state, and complete the test of the test case; State selection module: traverses the state pool, calculates the state value according to the number of fuzzy times of the state, the number of program branches found, and the fuzzy information of the response header field contained in the state, and selects the state with the highest value for fuzzification; Seed scheduling module: According to the selected target state, the seed with the highest seed value is selected from the seed queue of the target state for fuzzification.

Citation Information

Patent Citations

  • Fuzzy testing method and device for stateful network protocol and storage medium

    CN113326181A

  • Fuzzy test method and system, electronic equipment and medium

    CN113934621A