A DCS controller static trusted verification function automated testing method and system

By performing automated testing of the DCS controller in an actual production environment, the problem that existing offline testing methods cannot fully simulate the actual working environment and consume large testing resources is solved, efficient and accurate testing is achieved, and the reliability and security of the system are improved.

CN119690055BActive Publication Date: 2025-05-06XIAN THERMAL POWER RES INST CO LTD +2
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510197242.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-21
Publication Date
2025-05-06
Estimated Expiration
2045-02-21

AI Technical Summary

Technical Problem

The existing offline testing methods cannot fully simulate the actual working environment, resulting in problems that may occur during the online operation of the DCS controller. The test requires a lot of time and resources, which affects the online time, and it is impossible to test the online DCS controller.

Method used

An automated test method for the DCS controller's static trusted verification function is proposed. By loading test programs and configuration files in the actual production environment, the static trusted verification function of the DCS controller is tested online, including starting, stopping, reading, writing, deleting, renaming and modifying properties, and generating a test report in HTML format.

Benefits of technology

It improves the accuracy and reliability of the test, reduces the test time and resource consumption, avoids the impact on the online time of the DCS controller, and can test the online DCS controller to detect and solve problems early, and improves the reliability and security of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119690055B_ABST
    Figure CN119690055B_ABST
Patent Text Reader

Abstract

The present invention discloses a method and system for automatically testing the static trusted verification function of a DCS controller, which belongs to the field of computer security. The method includes: loading a test program and a configuration file into a DCS controller; starting or stopping the static trusted verification function of the DCS controller through the test program, and verifying whether it is started or stopped normally; performing a first editing operation on a file or a specific file indicated in the configuration file through the test program, and testing whether the protection of the file by the static trusted verification function is normal; performing a second editing operation on a directory or file with protection problems through the test program, and obtaining context test results; and outputting a test report based on the context test results through the test program. The method can test an online DCS controller, avoiding the situation where problems still occur during online operation after offline testing.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The invention belongs to the field of computer security and relates to an automatic testing method and system for a static trusted verification function of a DCS controller. Background Art

[0002] In technical fields such as computer science and technology, software engineering, and network security, trusted verification functions are important mechanisms for ensuring the security of systems and applications. Trusted verification functions are often used to verify user identity, data integrity, and the legitimacy and security of applications. In industrial control systems, DCS (Distributed Control System) controllers are key devices that monitor and control production processes. In order to ensure the security and reliability of DCS controllers, static trusted verification functions need to be tested to ensure that they can work properly in different environments and conditions.

[0003] The static trusted verification function on the trusted DCS controller allows trusted files to be read, executed, prohibited from modification, prohibited from deletion, prohibited from renaming, prohibited from modifying attributes, etc.; untrusted files cannot be read, executed, modified, deleted, renamed, or have their attributes modified. This function can effectively prevent files in the operating system from being tampered with, deleted, renamed, and executed, protecting the integrity of the operating system files.

[0004] In the existing technology, the offline testing method is usually adopted, that is, the static trusted verification function of the DCS controller is tested before it goes online. This testing method requires a series of tests on the DCS controller in a specific test environment to simulate the actual working environment. After the test is completed, the DCS controller will be installed in the actual production environment and put into operation.

[0005] However, there are some problems with existing offline testing methods. First, offline testing cannot fully simulate the actual working environment. Therefore, even if the test passes, problems may still occur in the online operation of the DCS controller. Secondly, offline testing takes a lot of time and resources because it is necessary to build a special test environment, design and execute test cases, and evaluate and analyze test results. In addition, offline testing may also affect the online time of the DCS controller, because after the test is completed, the DCS controller needs to be installed and configured, as well as the final functional verification. Therefore, the existing offline testing methods have certain limitations in practical applications. Summary of the invention

[0006] In order to solve the above problems, the present invention proposes an automated testing method and system for the static trusted verification function of a DCS controller. The method can test the DCS controller that has been put online, avoiding the situation where problems still occur during online operation after offline testing. During testing, only a test program and a configuration file need to be uploaded to the DCS controller. First, configure the directory and file name to be tested in the configuration file. After the test program runs, read the configuration file to perform the test, read, write, execute, delete, rename, modify attributes, etc. on the file, and then write the operation results into an html file to verify whether the trusted function is successfully configured and functions normally.

[0007] To achieve the above purpose, the present invention adopts the following technical means:

[0008] The first aspect of the present invention is to provide a DCS controller static trust verification function automatic testing method, comprising:

[0009] Load the test program and configuration file into the DCS controller in the actual production environment;

[0010] Starting or stopping the static trusted verification function of the DCS controller through the test program, and verifying whether the static trusted verification function is started or stopped normally; wherein, during the verification process, the test program monitors the running state of the static trusted verification function to ensure that the static trusted verification function can be started and stopped normally;

[0011] Performing a first editing operation on the file indicated in the configuration file through the test program, and testing whether the protection of the file indicated in the configuration file by the static trusted verification function is normal; and / or, performing a first editing operation on a specific file of the DCS controller through the test program, and testing whether the protection of the specific file of the static trusted verification function is normal, wherein the first editing operation includes at least one of batch reading, writing, deleting, renaming, and modifying attributes;

[0012] Performing a second editing operation on the directory or file where the protection of the static trusted verification function has problems through the test program, and obtaining a context test result of the second editing operation, wherein the second editing operation includes at least one of reading, writing, deleting, renaming, and modifying attributes, and the context test result includes a test result and context information of the protection function of the static trusted verification function;

[0013] A test report is outputted through the test program based on the context test result summary.

[0014] As a further improvement of the present invention, the test program and configuration file are loaded into the / dev / shm directory of the DCS controller; the files indicated in the configuration file include the files in the tested directory indicated in the configuration file, and the tested files indicated in the configuration file;

[0015] The method further comprises:

[0016] The configuration file is modified by the test program, and the tested directory and the tested file are determined according to the modified configuration file.

[0017] As a further improvement of the present invention, the test report is in HTML format.

[0018] As a further improvement of the present invention, performing a first editing operation on the file indicated in the configuration file by the test program includes:

[0019] Performing a first editing operation on the file indicated in the configuration file by the test program;

[0020] In the process of executing the first editing operation, using the static trusted verification function to perform static trusted verification on the file indicated in the configuration file;

[0021] Check whether the static trusted verification function prevents the first editing operation from being performed on the protected file, and record the operation result of the first editing operation.

[0022] As a further improvement of the present invention, the second editing operation of the directory or file having protection problems of the static trusted verification function through the test program includes:

[0023] Reading the parent directory of the directory or file where the protection of the static trusted verification function has problems through the test program;

[0024] Add the upper-level directory to the configuration file, use the upper-level directory as a new test target, and perform a static trusted verification function test;

[0025] A directory that records the static trusted verification functional tests that have been performed;

[0026] The test report is determined based on the test results of the files in the directory where the static trusted verification function test has been executed and the context information of the test process, and the test report includes: problem location process, analysis results, problem confirmation status and related logs, screenshots or video evidence.

[0027] As a further improvement of the present invention, the second editing operation on the file includes at least one of the following:

[0028] Read file attributes, including file size, user group, and permissions;

[0029] Read the file contents;

[0030] Random write;

[0031] Append write;

[0032] Delete files;

[0033] Rename the file;

[0034] Modify properties;

[0035] The second editing operation on the directory includes at least one of the following:

[0036] Read directory properties;

[0037] Create a new file in the directory;

[0038] Delete a directory;

[0039] Rename the directory;

[0040] Modify properties;

[0041] In the process of performing the second editing operation on the directory or file, the monitoring tool provided by the operating system is used to record the system status and the behavior of the test program as a problem locating process log.

[0042] As a further improvement of the present invention, the obtaining of the context test result of the second editing operation, and the outputting of a test report based on the context test result by the test program, include:

[0043] Obtaining a log related to the static trusted verification function during the process of performing the second editing operation on the directory or file;

[0044] Analyze and process the logs related to the static trusted verification function to find error messages, abnormal behaviors or inconsistent log entries;

[0045] In combination with system monitoring data, analyzing the behavior pattern and system resource usage of the static trusted verification function when an abnormality occurs in the protection function of the file or directory;

[0046] Constructing a context environment when the protection function is abnormal based on the log entry, the behavior pattern and system resource usage when the protection function is abnormal, and the test result of the protection function of the static trusted verification function;

[0047] Based on the context analysis result of the context environment, confirm whether the abnormality of the protection function is caused by the static trusted verification function, and determine the specific manifestation and impact scope of the abnormality of the protection function;

[0048] The problem locating process, analysis results, problem confirmation status, and related logs, screenshots, or video evidence of the abnormal protection function are organized into a test report.

[0049] The second aspect of the present invention is to provide a DCS controller static trusted verification function automatic test system, comprising:

[0050] Loading module, used to load test programs and configuration files into the DCS controller in the actual production environment;

[0051] A verification module, used to start or stop the static trusted verification function of the DCS controller through the test program, and verify whether the static trusted verification function is started or stopped normally; wherein, during the verification process, the test program monitors the running state of the static trusted verification function to ensure that the static trusted verification function can be started and stopped normally;

[0052] A test module, used to perform a first editing operation on the file indicated in the configuration file through the test program, and test whether the protection of the file indicated in the configuration file by the static trusted verification function is normal; and / or, perform a first editing operation on a specific file of the DCS controller through the test program, and test whether the protection of the specific file of the static trusted verification function is normal, wherein the first editing operation includes at least one of batch reading, writing, deleting, renaming, and modifying attributes;

[0053] an acquisition module, used to perform a second editing operation on the directory or file where the protection of the static trusted verification function has problems through the test program, and obtain a context test result of the second editing operation, wherein the second editing operation includes at least one of reading, writing, deleting, renaming, and modifying attributes, and the context test result includes a test result and context information of the protection function of the static trusted verification function;

[0054] A summary module is used to summarize and output a test report based on the context test results through the test program.

[0055] The third aspect of the present invention is to provide an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements an automated testing method for the static trusted verification function of the DCS controller when executing the computer program of the first aspect.

[0056] A fourth aspect of the present invention is to provide a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the automated testing method for the static trusted verification function of the DCS controller described in the first aspect is implemented.

[0057] Compared with the prior art, the present invention has the following beneficial effects:

[0058] The present invention proposes an automated testing method for the static trusted verification function of a DCS controller, which avoids the shortcomings of offline testing in the prior art. By testing in an actual production environment, the working environment of the DCS controller can be simulated more accurately, thereby improving the accuracy and reliability of the test. At the same time, since the test is conducted in an online environment, there is no need to spend a lot of time and resources on the construction of a special test environment and the design and execution of test cases, and the impact of offline testing on the online time of the DCS controller is also avoided. The DCS controller that has been put online can be tested, which has obvious advantages over offline testing in the prior art. Because in an actual production environment, the DCS controller has been connected to the production process, and its working state and working environment may be different from those during offline testing. By testing in an actual environment, problems can be discovered and solved earlier, thereby improving the reliability and safety of the system. BRIEF DESCRIPTION OF THE DRAWINGS

[0059] Figure 1 A flow chart of an automated testing method for static trusted verification function of a DCS controller provided by the present invention;

[0060] Figure 2 Schematic diagram of an automated testing method for a static trusted verification function of a DCS controller in an embodiment;

[0061] Figure 3 The present invention provides an automatic testing system for static trusted verification function of a DCS controller. DETAILED DESCRIPTION

[0062] In order to enable those skilled in the art to better understand the scheme of the present invention, the technical scheme in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of the present invention.

[0063] It should be noted that the terms "first", "second", etc. in the specification and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the numbers used in this way can be interchanged where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein.

[0064] In addition, the terms "comprises," "comprising," and "having," and any variations thereof, are intended to cover non-exclusive inclusions. For example, a process, method, system, product, or apparatus that includes a series of steps or elements is not necessarily limited to those steps or elements explicitly listed, but may include other steps or elements not explicitly listed or inherent to such process, method, product, or apparatus.

[0065] The first object of the present invention is to provide a DCS controller static trust verification function automated testing method, such as Figure 1 As shown, the following steps are included:

[0066] S1, load the test program and configuration file into the DCS controller in the actual production environment.

[0067] For example: Load the test program and configuration file into the / dev / shm directory of the DCS controller.

[0068] S2, starting or stopping the static trusted verification function of the DCS controller through the test program, and verifying whether the static trusted verification function is started or stopped normally; wherein, during the verification process, the test program monitors the running status of the static trusted verification function to ensure that the static trusted verification function can be started and stopped normally.

[0069] S3, performing a first editing operation on the file indicated in the configuration file through the test program, and testing whether the protection of the file indicated in the configuration file by the static trusted verification function is normal; and / or, performing a first editing operation on a specific file of the DCS controller through the test program, and testing whether the protection of the specific file of the static trusted verification function is normal, wherein the first editing operation includes at least one of batch reading, writing, deleting, renaming, and modifying attributes.

[0070] S4, performing a second editing operation on the directory or file where the protection of the static trusted verification function has problems through the test program, and obtaining a context test result of the second editing operation, wherein the second editing operation includes at least one of reading, writing, deleting, renaming, and modifying attributes, and the context test result includes the test result and context information of the protection function of the static trusted verification function.

[0071] S5, outputting a test report based on the context test results summary through the test program.

[0072] The present invention mainly adopts the following technical means and the principle analysis is as follows:

[0073] The present invention proposes an automated testing method for the static trusted verification function of a DCS controller. This method can test the static trusted verification function of a DCS controller when it is online, thus avoiding the situation where problems still occur during online operation after offline testing.

[0074] In the present invention, the directories and files to be detected can be configured through a conf configuration file, so that the directories and files to be detected can be flexibly selected, thereby improving the efficiency and flexibility of the test.

[0075] In the present invention, the / dev / shm directory can be used to store test programs and configuration files. Since the / dev / shm directory is a temporary file system, no static files will remain on the machine being tested, thereby avoiding the risk of possible impact on the system.

[0076] In the present invention, the test program can automatically generate test reports in HTML format, and these test reports can be easily converted into files in PDF and other formats, which facilitates the storage and analysis of the test reports.

[0077] In some implementations, the specific file may be any file in the DCS controller, may be a file indicated in the configuration file, or may be other files other than the files indicated in the processing configuration file.

[0078] In some implementations, the file indicated in the configuration file may be a file in a directory indicated in the configuration file, or a file directly indicated in the configuration file.

[0079] The test program in the present invention will perform batch reading, writing, deletion, renaming, modifying attributes and other operations on the files specified in the configuration file, as well as batch reading, writing, deletion, renaming, modifying attributes and other operations on specific files. This can comprehensively verify whether the static trusted verification function works normally, and whether its protection of other directories and files is normal.

[0080] The test program in the present invention can perform operations such as reading, writing, deleting, renaming, modifying attributes, etc. on the directory and files with problems, obtain context test results, and confirm where the problem lies, so that the problem can be quickly located and solved.

[0081] The present invention mainly solves the following technical problems: 1. It solves the problem that the existing offline testing method cannot fully simulate the actual working environment. Since the offline test is carried out in a specific test environment and cannot fully simulate the actual working environment, even if the test passes, the DCS controller may still have problems during online operation. 2. It solves the problem that the existing offline testing method requires a lot of time and resources. Offline testing requires the construction of a special test environment, the design and execution of test cases, and the evaluation and analysis of test reports, all of which require a lot of time and resources. 3. It solves the problem that the existing offline testing method may affect the online time of the DCS controller. After the test is completed, the DCS controller needs to be installed and configured, as well as the final functional verification, all of which will affect the online time of the DCS controller. 4. It solves the problem that the existing offline testing method cannot test the DCS controller that has been online.

[0082] The core principle of the automated testing method for the static trusted verification function of the trusted DCS controller proposed in this embodiment is to comprehensively and meticulously verify whether the static trusted verification function of the DCS controller works normally through systematic steps and automated testing procedures. This testing method aims to improve the efficiency, flexibility and accuracy of the test and ensure the safety and reliability of the DCS controller. The following is a detailed analysis of the principle of this method:

[0083] File upload and configuration:

[0084] First, the test program and configuration files are limited to a reasonable size (no more than 10MB) and uploaded to the / dev / shm directory of the DCS controller. This is to reduce the processing burden of the DCS controller and ensure that the test process does not have too much impact on the production environment.

[0085] In some implementations, the files indicated in the configuration file include files in a tested directory indicated in the configuration file, and the tested files indicated in the configuration file;

[0086] The method further comprises:

[0087] The configuration file is modified by the test program, and the tested directory and the tested file are determined according to the modified configuration file.

[0088] In this implementation, the directories and files to be tested are specified by modifying the configuration file. This step enhances the flexibility and pertinence of the test and allows the tester to flexibly configure the test scope according to actual needs.

[0089] The test procedure first verifies the normal start and stop of the static trusted verification function. This is a basic step to verify the functional integrity and ensure that the basic functions of the static trusted verification function can be correctly implemented on the DCS controller.

[0090] The test program performs batch reading, writing, deleting, renaming, and modifying attributes of files in the configuration directory to simulate various situations that may be encountered in the actual operating environment. Through these operations, the response and effect of the static trusted verification function in processing these operations can be fully evaluated.

[0091] In particular, the test program also performs batch operations on specific files to test the ability of the static trusted verification function to protect other directories and files. This step is to verify the boundaries and scope of the static trusted verification function to ensure that it does not cause unnecessary impact on other normal operations.

[0092] For problems that occur during the test process, the test program will further perform detailed read, write, delete, rename and other operations on the problematic directories and files to obtain more specific context test results, thereby helping testers to accurately locate the problem.

[0093] The test program summarizes the context test results and outputs them into an HTML file for subsequent storage and analysis. The HTML file format makes the context test results more intuitive and easy to understand, making it easier for system administrators to analyze the results and make optimization adjustments.

[0094] Through the implementation of the automated testing method, problems in the static trusted verification function of the DCS controller can be discovered and solved in a timely manner, thereby improving the overall performance and stability of the system. At the same time, this testing method also provides valuable reference and basis for subsequent system optimization and upgrades.

[0095] In summary, the automated testing method proposed in this embodiment comprehensively and meticulously verifies the static trusted verification function of the DCS controller through systematic steps and automated testing procedures, effectively improves the efficiency, flexibility and accuracy of the test, and provides a strong guarantee for the safety and reliability of the DCS controller.

[0096] As an optional implementation manner, the performing a second editing operation on the directory or file with protection problems of the static trusted verification function through the test program includes:

[0097] Reading the parent directory of the directory or file where the protection of the static trusted verification function has problems through the test program;

[0098] Add the parent directory to the configuration file, take the parent directory as a new test target, and perform a static trusted verification function test; for example, the current directory is dir2, and the directory structure is dir1 / dir2, dir1 / file3.txt, dir1 / file4.txt, the test program traverses the files and directories in the parent directory, i.e., dir1: file3.txt, file4.txt, and then executes the first editing operation, and monitors whether the static trusted verification function protects the files in the parent directory. For example, if the first editing operation is to delete the files in the parent directory, and the configuration file indicates that the files in the parent directory are prohibited from being deleted, then it is necessary to monitor whether the static trusted verification function successfully blocks the first editing operation;

[0099] A directory that records the static trusted verification functional tests that have been performed;

[0100] The test report is determined based on the test results of the files in the directory where the static trusted verification function test has been executed and the context information of the test process, and the test report includes: the problem location process, analysis results, problem confirmation status and related logs, screenshots or video evidence. Typical test results include: file name: / dir1 / file3.txt, operation time: 2024-12-19:10:30:01, operation action: modify, operation result: reject; such test results are summarized in the test report, and the number of operation results of "reject" is counted.

[0101] Specific embodiments are given below. Figure 2 As shown, the steps of the present invention are described in detail:

[0102] Embodiment 1:

[0103] This embodiment provides a DCS controller static trust verification function automated testing method, the specific steps are as follows:

[0104] Step 1: The system administrator uploads the test program and configuration file to the / dev / shm directory of the DCS controller. The size of the test program and configuration file should not exceed 10MB to ensure that it does not cause excessive burden on the DCS controller.

[0105] Step 2: Modify the configuration file on the DCS controller to determine the directories and files to be tested. The directories and files to be tested can be configured through the configuration file, so that the directories and files to be tested can be flexibly selected, which improves the efficiency and flexibility of the test.

[0106] Step 3: The test program starts and stops the static trusted verification function to verify whether the function starts and stops normally. During the verification process, the test program monitors the running status of the static trusted verification function to ensure that it can start and stop normally.

[0107] Step 4: The test program performs batch reading, writing, deleting, renaming, and modifying attributes of the files in the configuration file to test whether the static trusted verification function works properly. During the operation, the test program will record the results of each operation for subsequent analysis.

[0108] Step 5: The test program performs batch read, write, delete, rename, and modify attribute operations on specific files, such as files in the parent directory of the problematic file, to test whether the static trusted verification function protects other directories and files normally. During the operation, the test program will record the results of each operation for subsequent analysis.

[0109] Step 6: The test program reads, writes, deletes, renames, and other operations on the problematic directories and files to obtain context test results and confirm the problem. During the operation, the test program will record the results of each operation for subsequent analysis.

[0110] Step 7: The test program summarizes the context test results and outputs them to an HTML file as a test report. The size of the generated HTML file does not exceed 100KB to facilitate subsequent storage and analysis.

[0111] Step 8: The system administrator downloads the test report and analyzes the results. The system administrator can view the test report by browsing the HTML file and make corresponding adjustments and optimizations based on the test report.

[0112] The above are the specific steps of this embodiment. Through these steps, the static trusted verification function of the online environment can be effectively verified, reducing the occurrence of problems caused by different environments, and effectively avoiding the situation where a problem cannot be completely fixed after repeated modifications.

[0113] As a preferred solution, in order to test the static trusted verification function performance when the program performs batch reading, writing, deleting, renaming, modifying attributes, etc. on files in the configuration file, the following detailed test plan can be designed. This step can ensure the systematic, comprehensive and repeatable nature of the test process.

[0114] Identify a dedicated test directory that contains a certain number of test files to simulate the real environment. Prepare necessary test tools, such as scripts, command line tools, etc., to automate test operations. Set up a logging system or text file to record the results of each operation and any exceptions or error prompts.

[0115] Ensure that the test program has been properly installed and configured with static trust verification. Understand in depth how the static trust verification function in the test program works, especially its behavior during file operations.

[0116] As an optional implementation manner, performing a first editing operation on the file indicated in the configuration file by the test program includes:

[0117] Performing a first editing operation on the file indicated in the configuration file by the test program;

[0118] In the process of executing the first editing operation, using the static trusted verification function to perform static trusted verification on the file indicated in the configuration file;

[0119] Check whether the static trusted verification function prevents the first editing operation from being performed on the protected file, and record the operation result of the first editing operation.

[0120] For example, perform the following edits on the files indicated in the configuration file and verify them:

[0121] Batch read files: Test whether the program can correctly read all files in the configuration directory and record the information of success or failure of reading;

[0122] Batch write files: Create or modify multiple files in the configuration directory and check whether the static trusted verification function blocks unauthorized or non-compliant write operations;

[0123] Batch file deletion: Attempt to delete multiple files in the configuration directory, record which files are successfully deleted and which files are blocked due to static trust verification;

[0124] Batch rename files: Test the behavior of the program when renaming files to ensure that the renaming operation does not violate the integrity of static trusted verification;

[0125] Modify file attributes: Test the program's behavior when modifying file attributes (such as modifying the file group and permissions), and check whether the static trusted verification function prevents unauthorized write operations.

[0126] Design specific test cases to cover all the above scenarios. Each test case should include:

[0127] Clearly describe the operation to be performed, such as "batch read all .txt files in a directory". Define the expected results that the operation should achieve based on the test purpose. Record the actual results observed after the operation. Record any exceptions or error prompts.

[0128] As an optional implementation manner, the second editing operation on the file includes at least one of the following:

[0129] Read file attributes, including file size, user group, and permissions;

[0130] Read the file contents;

[0131] Random write;

[0132] Append write;

[0133] Delete files;

[0134] Rename the file;

[0135] Modify properties;

[0136] The second editing operation on the directory includes at least one of the following:

[0137] Read directory properties;

[0138] Create a new file in the directory;

[0139] Delete a directory;

[0140] Rename the directory;

[0141] Modify properties;

[0142] In the process of performing the second editing operation on the directory or file, the monitoring tool provided by the operating system is used to record the system status and the behavior of the test program as a problem locating process log.

[0143] Execution of the test specifically includes: Using automated scripts to execute test cases to reduce human errors and improve test efficiency. The script should be able to simulate user operations, perform file operations such as read, write, delete, rename, etc., and capture and record the results.

[0144] Monitor the test process in real time to ensure that all operations are performed as expected. Record the results of each operation, including success or failure information, as well as any exceptions or error prompts.

[0145] Analyze test records to evaluate the performance of static trust verification functions in file operations. Determine if there are any unexpected behaviors or potential vulnerabilities.

[0146] For any problems or anomalies found, write a detailed problem report, including problem description, reproduction steps, scope of impact, etc. Submit the problem report to the development team so that they can fix and optimize it.

[0147] Write a test report outlining the test process, results analysis, problem reporting, and improvement measures. Submit the test summary report to relevant stakeholders so that they can understand the test situation and make appropriate decisions.

[0148] Among them, the embodiment of the present invention also integrates the test of the static trusted verification function into the CI / CD (Continuous Integration, CI; Continuous Deployment, CD, continuous integration / continuous deployment) process to achieve automated testing and continuous monitoring, ensuring that problems can be discovered and repaired in time after each code change, and ensuring that the static trusted verification function of the DCS controller can be tested and verified in time and effectively after each code change, thereby improving the security and stability of the system.

[0149] As an optional implementation manner, the obtaining of the context test result of the second editing operation, and outputting a test report based on the context test result by the test program, includes:

[0150] Obtaining a log related to the static trusted verification function during the process of performing the second editing operation on the directory or file;

[0151] Analyze and process the logs related to the static trusted verification function to find error messages, abnormal behaviors or inconsistent log entries;

[0152] In combination with system monitoring data, analyzing the behavior pattern and system resource usage of the static trusted verification function when an abnormality occurs in the protection function of the file or directory;

[0153] Constructing a context environment when the protection function is abnormal based on the log entry, the behavior pattern and system resource usage when the protection function is abnormal, and the test result of the protection function of the static trusted verification function;

[0154] Based on the context analysis result of the context environment, confirm whether the abnormality of the protection function is caused by the static trusted verification function, and determine the specific manifestation and impact scope of the abnormality of the protection function;

[0155] The above-mentioned analysis and processing of the relevant logs of the static trusted verification function to find error messages, abnormal behaviors or inconsistent log entries can be an entry in each record in the statistical log where the operation result is "reject", such as "file name: / dir1 / file3.txt, operation time: 2024-12-19:10:30:01 operation action: modify, operation result: reject;", and write this record into the "reject" log table;

[0156] The above-mentioned analysis of the behavior pattern and system resource usage of the static trusted verification function when an abnormality occurs in the protection function of the file or directory in combination with the system monitoring data may be performed by analyzing the system resource usage of the file " / dir1 / file3.txt " in the system monitoring log and appending it to the "rejection" log table;

[0157] The above-mentioned context environment when the protection function occurs anomaly is constructed based on the log entries, the behavior pattern and system resource usage when the protection function occurs anomaly, and the test result of the protection function of the static trusted verification function. The file context information obtained by using stat / dir1 / file3.txt in the statistical context environment log table, that is, before the static trusted verification function executes the second editing operation, the stat result is recorded; after executing the second editing operation, the stat result is recorded, the two stat results are compared, and the difference is analyzed, and appended to the "rejection" log table as the analysis result of the specific manifestation and impact scope of the anomaly of the protection function.

[0158] The problem locating process, analysis results, problem confirmation status, and related logs, screenshots, or video evidence of the abnormal protection function are organized into a test report.

[0159] As a preferred solution, during the test process, if there is a problem with the static trusted verification function, in order to more accurately locate the problem and verify its scope of impact, the test program needs to perform a series of detailed and targeted operations. The following is a specific problem location and verification solution:

[0160] 1. Steps to reproduce the problem: Make sure you can reproduce the problem reliably. This may require re-executing the specific sequence of actions that previously caused the problem, or adjusting the test conditions to trigger the same problem.

[0161] Record in detail the operation steps that led to the problem, input data, system status (such as memory usage, CPU load, etc.), and any abnormal output or error logs. CPU is the Central Processing Unit.

[0162] 2. Narrow the scope of the problem: Narrow the scope of the test to the smallest possible problem area. For example, if the problem occurs on file operations in a specific directory, try to test only a few files in that directory.

[0163] By modifying the test conditions (such as changing the file type, permission settings, etc.), factors that may not cause the problem can be gradually eliminated, thus gradually approaching the root cause of the problem.

[0164] 3. Detailed operation test: Design and perform more detailed operations such as read, write, delete, and rename for the problematic directory or file. These operations should cover all possible boundary conditions and abnormal situations as much as possible.

[0165] Try to read and write different types of data (such as text, binary, large files, etc.), and record key indicators such as read and write speed and data integrity.

[0166] Try to delete the file and check whether it succeeds, while observing the impact of the deletion operation on the system state and static trust verification functions.

[0167] Rename the file to check whether it is successful and verify whether the static trusted verification status of the file remains unchanged after the rename.

[0168] Modify the file attributes, such as modifying the file group and permissions, check whether it is successful, and verify whether the static trusted verification status of the file remains unchanged after the attributes are modified.

[0169] During the test, use appropriate monitoring tools to record the system status (such as resource usage, process activity, md5sum check of file integrity, etc.) and the behavior of the test program (such as operation sequence, result output, etc.).

[0170] 4. Analyze results in context: Carefully analyze the log files generated during the test, especially those related to the static trust verification function. Look for possible error messages, unusual behavior, or inconsistent log entries.

[0171] Combined with system monitoring data (such as CPU and memory usage), analyze the behavior patterns and system resource usage of the static trusted verification function when problems occur.

[0172] Build the context of the problem based on log analysis, system status analysis, and test reports. This helps understand the root cause and triggering conditions of the problem.

[0173] 5. Problem confirmation and reporting: Based on the context analysis results, confirm whether the problem is indeed caused by the static trusted verification function, and determine the specific manifestation and impact scope of the problem.

[0174] Organize the problem location process, analysis results, problem confirmation, and any related logs, screenshots, or video evidence into a detailed test report.

[0175] Submit the test report to the relevant development team or support personnel so that they can fix the problem based on the information in the report.

[0176] 6. Subsequent verification: After the development team fixes the problem, re-execute the test program to verify that the problem has been resolved. Ensure that all related test scenarios pass correctly and no new problems are introduced.

[0177] Update relevant test documents, user manuals, or development guides based on test reports and fixes to ensure that future development and testing work can be based on accurate and up-to-date information.

[0178] like Figure 3 As shown, the present invention also provides a DCS controller static trustworthy verification function automatic test system 300, comprising:

[0179] A loading module 301 is used to load the test program and configuration file into the DCS controller in the actual production environment;

[0180] The verification module 302 is used to start or stop the static trusted verification function of the DCS controller through the test program, and verify whether the static trusted verification function is started or stopped normally; wherein, during the verification process, the test program monitors the running state of the static trusted verification function to ensure that the static trusted verification function can be started and stopped normally;

[0181] The test module 303 is used to perform a first editing operation on the file indicated in the configuration file through the test program, and test whether the protection of the file indicated in the configuration file by the static trusted verification function is normal; and / or, perform a first editing operation on a specific file of the DCS controller through the test program, and test whether the protection of the specific file of the static trusted verification function is normal, wherein the first editing operation includes at least one of batch reading, writing, deleting, renaming, and modifying attributes;

[0182] An acquisition module 304 is used to perform a second editing operation on the directory or file where the protection of the static trusted verification function has problems through the test program, and obtain a context test result of the second editing operation, wherein the second editing operation includes at least one of reading, writing, deleting, renaming, and modifying attributes, and the context test result includes a test result and context information of the protection function of the static trusted verification function;

[0183] The summary module 305 is used to summarize and output a test report based on the context test results through the test program.

[0184] Optionally, the test program and configuration file are loaded into the / dev / shm directory of the DCS controller; the files indicated in the configuration file include files in the tested directory indicated in the configuration file, and the tested files indicated in the configuration file;

[0185] The DCS controller static trusted verification function automated testing system 300 also includes:

[0186] The modification module is used to modify the configuration file through the test program, and determine the tested directory and the tested file according to the modified configuration file.

[0187] Optionally, the test report is in HTML format.

[0188] Optionally, the testing module 303 is further configured to:

[0189] Performing a first editing operation on the file indicated in the configuration file by the test program;

[0190] In the process of executing the first editing operation, using the static trusted verification function to perform static trusted verification on the file indicated in the configuration file;

[0191] Check whether the static trusted verification function prevents the first editing operation from being performed on the protected file, and record the operation result of the first editing operation.

[0192] Optionally, the acquisition module 304 is further configured to:

[0193] Reading the parent directory of the directory or file where the protection of the static trusted verification function has problems through the test program;

[0194] Add the upper-level directory to the configuration file, use the upper-level directory as a new test target, and perform a static trusted verification function test;

[0195] A directory that records the static trusted verification functional tests that have been performed;

[0196] The test report is determined based on the test results of the files in the directory where the static trusted verification function test has been executed and the context information of the test process, and the test report includes: problem location process, analysis results, problem confirmation status and related logs, screenshots or video evidence.

[0197] Optionally, the second editing operation on the file includes at least one of the following:

[0198] Read file attributes, including file size, user group, and permissions;

[0199] Read the file contents;

[0200] Random write;

[0201] Append write;

[0202] Delete files;

[0203] Rename the file;

[0204] Modify properties;

[0205] The second editing operation on the directory includes at least one of the following:

[0206] Read directory properties;

[0207] Create a new file in the directory;

[0208] Delete a directory;

[0209] Rename the directory;

[0210] Modify properties;

[0211] In the process of performing the second editing operation on the directory or file, the monitoring tool provided by the operating system is used to record the system status and the behavior of the test program as a problem locating process log.

[0212] Optionally, the acquisition module 304 is further configured to:

[0213] Obtaining a log related to the static trusted verification function during the process of performing the second editing operation on the directory or file;

[0214] Analyze and process the logs related to the static trusted verification function to find error messages, abnormal behaviors or inconsistent log entries;

[0215] In combination with system monitoring data, analyzing the behavior pattern and system resource usage of the static trusted verification function when an abnormality occurs in the protection function of the file or directory;

[0216] Constructing a context environment when the protection function is abnormal based on the log entry, the behavior pattern and system resource usage when the protection function is abnormal, and the test result of the protection function of the static trusted verification function;

[0217] Based on the context analysis result of the context environment, confirm whether the abnormality of the protection function is caused by the static trusted verification function, and determine the specific manifestation and impact scope of the abnormality of the protection function;

[0218] The aggregation module 305 is further used for:

[0219] The problem locating process, analysis results, problem confirmation status, and related logs, screenshots, or video evidence of the abnormal protection function are organized into a test report.

[0220] The modules in the DCS controller static trusted verification function automated testing system 300 provided by the present invention can implement each step in the aforementioned DCS controller static trusted verification function automated testing method of the present invention, and can achieve similar beneficial effects as the aforementioned DCS controller static trusted verification function automated testing method embodiment of the present invention. To avoid repetition, they will not be described here.

[0221] The present invention provides an electronic device, comprising a memory, a processor and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, an automatic testing method for a static trusted verification function of a DCS controller is implemented.

[0222] The electronic device provided by the present invention can realize each function in the aforementioned automatic testing method for the static trusted verification function of the DCS controller of the present invention, and can achieve similar beneficial effects as the aforementioned automatic testing method for the static trusted verification function of the DCS controller of the present invention. To avoid repetition, it will not be described here.

[0223] The present invention also provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the automatic testing method for the static trusted verification function of the DCS controller is implemented.

[0224] The computer-readable storage medium provided by the present invention can realize each function in the aforementioned automatic testing method for the static trusted verification function of a DCS controller of the present invention, and can achieve similar beneficial effects as the aforementioned embodiment of the automatic testing method for the static trusted verification function of a DCS controller of the present invention. To avoid repetition, it will not be described here.

[0225] Due to the advanced nature of the present invention, it can be widely used in application fields such as industrial control systems, software development and network security. First, in industrial control systems, DCS controllers are key equipment, and the normal operation of their static trusted verification function is crucial to ensuring the safety and reliability of the production process. The online automated testing method proposed by the present invention can effectively verify the static trusted verification function of the DCS controller, avoid the problem of inaccurate test reports caused by different environments, and improve the efficiency and accuracy of the test. Therefore, the present invention has broad application prospects in the security and reliability of industrial control systems. Secondly, in the field of software development, the reliability and security of software are crucial. The automated testing method of the present invention can be used to test the static trusted verification function of software to ensure that the software can work normally in different environments and conditions. This method can not only improve the reliability and security of the software, but also reduce test time and resource consumption, and improve test efficiency.

[0226] Therefore, the present invention has broad application prospects in the field of software development. Finally, in the field of network security, the trusted verification function is an important mechanism to ensure the security of systems and applications. The automated testing method of the present invention can be used to test the static trusted verification function of a network security system to ensure the reliability and security of the network security system. This method can not only improve the reliability of the network security system, but also reduce testing time and resource consumption, and improve testing efficiency. Therefore, the present invention has broad application prospects in the field of network security. In general, the automated testing method of the present invention, due to its high efficiency, accuracy and flexibility, can not only improve the reliability and security of industrial control systems, software and network security systems, but also reduce testing time and resource consumption, and improve testing efficiency, and therefore has broad application prospects and market demand in multiple application fields.

[0227] It will be appreciated by those skilled in the art that embodiments of the present invention may be provided as methods, systems, or computer program products. Therefore, the present invention may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Furthermore, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, optical storage, etc.) containing computer-usable program code.

[0228] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0229] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.

[0230] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.

[0231] It will be appreciated by those skilled in the art that all or some of the steps, systems, and functional modules / units in the methods disclosed above may be implemented as software, firmware, hardware, and appropriate combinations thereof. In a hardware implementation, the division between the functional modules / units mentioned in the above description does not necessarily correspond to the division of physical components; for example, a physical component may have multiple functions, or a function or step may be performed by several physical components in cooperation. Some or all components may be implemented as software executed by a processor, such as a digital signal processor or a microprocessor, or implemented as hardware, or implemented as an integrated circuit, such as an application-specific integrated circuit. Such software may be distributed on a computer-readable medium, which may include a computer storage medium (or a non-transitory medium) and a communication medium (or a temporary medium).

[0232] As is well known to those of ordinary skill in the art, the term computer storage media includes volatile and nonvolatile, removable and non-removable media implemented in any method or technology for storage of information such as computer readable instructions, data structures, program modules or other data. Computer storage media include, but are not limited to, flash memory or other memory technology, digital versatile disks or other optical disk storage, magnetic cassettes, magnetic tapes, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to store the desired information and can be accessed by a computer. In addition, it is well known to those of ordinary skill in the art that communication media typically contains computer readable instructions, data structures, program modules or other data in a modulated data signal such as a carrier wave or other transport mechanism, and may include any information delivery media.

Claims

1. A DCS controller static trust verification function automated testing method, characterized in that: include: Load the test program and configuration file into the DCS controller in the actual production environment; Starting or stopping the static trusted verification function of the DCS controller through the test program, and verifying whether the static trusted verification function is started or stopped normally; wherein, during the verification process, the test program monitors the running state of the static trusted verification function to ensure that the static trusted verification function can be started and stopped normally; Performing a first editing operation on the file indicated in the configuration file through the test program, and testing whether the static trusted verification function protects the file indicated in the configuration file normally; and / or, performing a first editing operation on a specific file of the DCS controller through the test program, and testing whether the static trusted verification function protects the specific file normally, wherein the first editing operation includes at least one of batch reading, writing, deleting, renaming, and modifying attributes; Performing a second editing operation on the directory or file where the protection of the static trusted verification function has problems through the test program, and obtaining a context test result of the second editing operation, wherein the second editing operation includes at least one of reading, writing, deleting, renaming, and modifying attributes, and the context test result includes a test result and context information of the protection function of the static trusted verification function; Outputting a test report based on the context test result summary by the test program; The performing a second editing operation on the directory or file where the protection of the static trusted verification function has problems through the test program includes: Reading the parent directory of the directory or file where the protection of the static trusted verification function has problems through the test program; Add the upper-level directory to the configuration file, use the upper-level directory as a new test target, and perform a static trusted verification function test; A directory that records the static trusted verification functional tests that have been performed; The test report is determined based on the test results of the files in the directory where the static trusted verification function test has been performed and the context information of the test process, and the test report includes: the problem location process, analysis results, problem confirmation status and related logs, screenshots or video evidence; The obtaining of the context test result of the second editing operation, and outputting a test report based on the context test result by the test program, comprises: Obtaining a log related to the static trusted verification function during the process of performing the second editing operation on the directory or file; Analyze and process the logs related to the static trusted verification function to find error messages, abnormal behaviors or inconsistent log entries; In combination with system monitoring data, analyzing the behavior pattern and system resource usage of the static trusted verification function when an abnormality occurs in the protection function of the file or directory; Constructing a context environment when the protection function is abnormal based on the log entry, the behavior pattern and system resource usage when the protection function is abnormal, and the test result of the protection function of the static trusted verification function; Based on the context analysis result of the context environment, confirm whether the abnormality of the protection function is caused by the static trusted verification function, and determine the specific manifestation and impact scope of the abnormality of the protection function; The problem locating process, analysis results, problem confirmation status, and related logs, screenshots, or video evidence of the abnormal protection function are organized into a test report.

2. The method for automated testing of static trusted verification function of a DCS controller according to claim 1, characterized in that: The test program and configuration file are loaded into the / dev / shm directory of the DCS controller; The files indicated in the configuration file include files in the tested directory indicated in the configuration file, and the tested files indicated in the configuration file; The method further comprises: The configuration file is modified by the test program, and the tested directory and the tested file are determined according to the modified configuration file.

3. The method for automated testing of static trusted verification function of a DCS controller according to claim 1, characterized in that: The test report is in HTML format.

4. The method for automated testing of static trusted verification function of a DCS controller according to claim 1, characterized in that: The performing a first editing operation on the file indicated in the configuration file by the test program includes: Performing a first editing operation on the file indicated in the configuration file by the test program; In the process of executing the first editing operation, using the static trusted verification function to perform static trusted verification on the file indicated in the configuration file; Check whether the static trusted verification function prevents the first editing operation from being performed on the protected file, and record the operation result of the first editing operation.

5. The method for automated testing of static trusted verification function of a DCS controller according to claim 1, characterized in that: The second editing operation on the file includes at least one of the following: Read file attributes, including file size, user group, and permissions; Read the file contents; Random write; Append write; Delete files; Rename the file; Modify properties; The second editing operation on the directory includes at least one of the following: Read directory properties; Create a new file in the directory; Delete a directory; Rename the directory; Modify properties; In the process of performing the second editing operation on the directory or file, the monitoring tool provided by the operating system is used to record the system status and the behavior of the test program as a problem locating process log.

6. A DCS controller static trustworthy verification function automated testing system, which implements the DCS controller static trustworthy verification function automated testing method according to any one of claims 1 to 5, characterized in that: include: Loading module, used to load test programs and configuration files into the DCS controller in the actual production environment; A verification module, used to start or stop the static trusted verification function of the DCS controller through the test program, and verify whether the static trusted verification function is started or stopped normally; wherein, during the verification process, the test program monitors the running state of the static trusted verification function to ensure that the static trusted verification function can be started and stopped normally; A test module, used to perform a first editing operation on the file indicated in the configuration file through the test program, and test whether the protection of the file indicated in the configuration file by the static trusted verification function is normal; and / or, perform a first editing operation on a specific file of the DCS controller through the test program, and test whether the protection of the specific file of the static trusted verification function is normal, wherein the first editing operation includes at least one of batch reading, writing, deleting, renaming, and modifying attributes; an acquisition module, used to perform a second editing operation on the directory or file where the protection of the static trusted verification function has problems through the test program, and obtain a context test result of the second editing operation, wherein the second editing operation includes at least one of reading, writing, deleting, renaming, and modifying attributes, and the context test result includes a test result and context information of the protection function of the static trusted verification function; A summary module is used to summarize and output a test report based on the context test results through the test program.

7. An electronic device, characterized in that: The invention comprises a memory, a processor and a computer program stored in the memory and executable on the processor, wherein the processor implements the automatic testing method for the static trusted verification function of a DCS controller as claimed in any one of claims 1 to 5 when executing the computer program.

8. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the automated testing method for the static trusted verification function of a DCS controller according to any one of claims 1 to 5 is implemented.

Citation Information

Patent Citations

  • Web-based static trusted verification function test method and system

    CN118897795A

  • DCS controller application program access control automatic test method and system

    CN119271558A