LTLf-based program runtime verification method

Through the LTLf-based program runtime verification method, the runtime efficiency evaluation value and fault verification safety evaluation value are obtained, and formal verification is performed in combination with the data parsing accuracy evaluation value, which solves the problem of low timeliness of program runtime verification and improves the timeliness and accuracy of verification.

CN119718892BActive Publication Date: 2025-10-10NORTHWESTERN POLYTECHNICAL UNIV
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202411922800.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-25
Publication Date
2025-10-10
Estimated Expiration
2044-12-25

AI Technical Summary

Technical Problem

In the existing technology, the timeliness of program runtime verification is low, and data cannot be received and analyzed in real time, resulting in delayed problem discovery and resolution.

Method used

Through the LTLf-based program runtime verification method, the runtime efficiency evaluation value is obtained to determine whether to make runtime efficiency adjustments. The fault verification safety evaluation value is obtained through network data and the evaluation value that meets the timeliness conditions. Finally, the encapsulated network data is parsed to obtain the parsing accuracy evaluation value for formal verification.

Benefits of technology

It improves the timeliness of program runtime verification, enhances the accuracy and reliability of formal verification, and ensures the security and reliability of program operation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119718892B_ABST
    Figure CN119718892B_ABST
Patent Text Reader

Abstract

The application discloses a program runtime verification method based on LTLf and relates to the technical field of electric digital data processing.The program runtime verification method based on LTLf comprises the following steps: timeliness evaluation, fault verification, data analysis and formal verification.The application obtains a runtime timeliness evaluation value through network data and judges whether to perform runtime timeliness adjustment, then obtains a fault verification safety evaluation value through network data and a runtime timeliness evaluation value meeting a timeliness condition and judges whether to perform fault safety adjustment, then obtains an analysis accuracy evaluation value through data analysis on encapsulated network data, finally judges whether to perform accuracy adjustment based on the analysis accuracy evaluation value, and performs formal verification on LTLf constraint data, so that the effect of improving the timeliness of program runtime verification is achieved, and the problem of low timeliness of program runtime verification in the prior art is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of electronic digital data processing, and in particular to a program runtime verification method based on LTLf. Background Art

[0002] LTLf (Linear Temporal Logic on Finite Traces) is a formal logic language and a formal method for describing and verifying system behavior or properties. It is suitable for processing sequences of events occurring within a finite timeframe and can precisely express the logical relationships between these sequences, making it useful for describing constraints within a system. Formal methods are a key theoretical foundation of computer science. Based on rigorous mathematical and mechanical methods, they model, specify, and verify mathematical theories or computational systems, solving and improving a wide range of mathematical and software security problems. In recent years, with the advancement of formal verification techniques and tools, formal verification has been introduced into numerous safety-critical fields, such as aerospace, rail transportation, and precision chip design. It can verify the properties of large, complex systems with minimal human intervention and accurately locate potential errors. As a valuable complement to simulation and testing processes, formal verification significantly enhances the robustness and reliability of system designs. By formally modeling the target system using appropriate modeling tools and accurately describing the system's properties in a logical language, an automated process can be initiated to formally verify these properties.

[0003] Existing program runtime verification mainly uses automatic search algorithms to comprehensively traverse the state space of the system model to verify whether the model meets the specified properties.

[0004] For example, the invention patent announcement with announcement number: CN111914250B discloses a method for verifying and controlling a Linux system script program at runtime, which includes defining global variables and interface functions for storing the script file interpreter path in the kernel, adding a configuration file and a boot service to the kernel, and adding a HOOK point to the execve system call; and loading the script file interpreter path into the kernel when the system starts.

[0005] For example, the invention patent with publication number CN117034258A discloses a runtime verification method for an IoT program based on Docker, which includes: based on the integrity measurement architecture, hashing the container image and writing it into a measurement list; storing the measurement value in the measurement list corresponding to the target container into the vPCR module corresponding to the target container; extending the vPCR module into the trusted platform module; verifying the identity information and status information of the host platform where the target container is located, and the container is successfully started if the verification passes; obtaining the memory binary information of the corresponding process at runtime based on the container ID, the process pid in the target container, and the collection time, and constructing a memory event; and realizing verification of the IoT program business process corresponding to the memory event by transferring the memory event received by the verification state machine end between states.

[0006] However, in the process of implementing the technical solutions of the invention in the embodiments of the present application, the present application found that the above technology has at least the following technical problems:

[0007] In the prior art, since the existing methods focus on static analysis, they are unable to receive and analyze data in real time while the system is running, and thus are unable to discover and solve problems in a timely manner, resulting in low timeliness of program runtime verification. Summary of the Invention

[0008] The embodiment of the present application solves the problem of low timeliness of program runtime verification in the prior art by providing a program runtime verification method based on LTLf, thereby improving the timeliness of program runtime verification.

[0009] An embodiment of the present application provides a program runtime verification method based on LTLf, comprising the following steps: S1, obtaining a runtime effectiveness evaluation value based on network data, and judging whether to perform runtime effectiveness adjustment based on the runtime effectiveness evaluation value; S2, obtaining a fault verification safety evaluation value based on the network data and the runtime effectiveness evaluation value that meets the timeliness condition, and judging whether to perform fault safety adjustment based on the fault verification safety evaluation value, wherein the runtime effectiveness evaluation value is used to evaluate the timeliness during network transmission, and the fault verification safety evaluation value is used to evaluate the safety during dynamic verification based on the received network data; S3, obtaining encapsulated network data based on the network data corresponding to the fault verification safety evaluation value that meets the safety condition, performing data parsing on the encapsulated network data to obtain a parsing accuracy evaluation value, and the parsing accuracy evaluation value is used to evaluate the accuracy of the encapsulated network data during the data parsing process; S4, judging whether to perform accuracy adjustment based on the parsing accuracy evaluation value, and performing formal verification on the LTLf constraint data corresponding to the parsing accuracy evaluation value that meets the parsing accuracy condition.

[0010] Further, the specific acquisition process of the network data is as follows: acquiring initial network data, the initial network data representing log data generated during runtime; buffering the initial network data through network transmission, and reading the buffered initial network data into a specified character array; encapsulating and identifying the initial network data to obtain network data; the network data including network data receiving delay, encapsulation and identification delay, runtime fault duration, runtime fault frequency, runtime length, fault maintenance time, parsing compliance frequency, and parsing compliance data volume; the parsing compliance frequency representing the parsing frequency of the encapsulated network data that meets the preset LTLf constraint condition after data parsing; and the parsing compliance data volume representing the data volume of the encapsulated network data that meets the preset LTLf constraint condition after data parsing.

[0011] Further, the specific process of obtaining the runtime efficiency evaluation value according to the network data is as follows: first, obtaining the network data receiving delay deviation by performing ratio operation and processing on the difference between the network data receiving delay and the preset receiving delay threshold value and the preset receiving delay threshold value; second, obtaining the encapsulation and identification delay deviation by performing ratio operation and processing on the difference between the encapsulation and identification delay and the preset identification threshold value and the preset identification threshold value; and third, obtaining the runtime efficiency evaluation value in combination with the network data receiving delay deviation and the encapsulation and identification delay deviation.

[0012] Further, the limit expression of the runtime efficiency evaluation value is as follows:

[0013]

[0014] In the formula, SXX p represents the runtime efficiency evaluation value corresponding to the network data in the pth preset time period, p = 1, 2, …, m, p represents the number of the preset time period, and m represents the total number of the preset time period, represents the network data receiving delay deviation corresponding to the network data in the pth preset time period, represents the encapsulation and identification delay deviation corresponding to the network data in the pth preset time period, ΔCS represents the reference data receiving delay range obtained from the database, ΔFS represents the reference encapsulation and identification delay range obtained from the database, and e represents the natural constant.

[0015] Furthermore, the specific process of obtaining the fault verification safety assessment value based on the network data and the runtime evaluation value that meets the timeliness conditions is as follows: the initial failure rate is obtained by performing a ratio operation on the running fault duration and the running duration; the running fault deviation is obtained by performing a ratio operation on the difference between the initial failure rate and the preset failure rate threshold obtained from the database and the preset failure rate threshold; the initial fault recovery time is obtained by performing a ratio operation on the fault maintenance time and the number of running faults; the running fault recovery deviation is obtained by performing a ratio operation on the difference between the initial fault recovery time and the preset fault recovery time threshold obtained from the database and the preset fault recovery time threshold; the fault verification safety assessment value is obtained by combining the running fault deviation, the running fault recovery deviation and the runtime evaluation value that meets the timeliness conditions.

[0016] Furthermore, the specific process of obtaining the analysis accuracy evaluation value by performing data analysis on the encapsulated network data is as follows: obtaining the analysis compliance ratio by performing a ratio operation on the analysis compliance number and the preset analysis number threshold obtained from the database; obtaining the analysis data volume compliance ratio by performing a ratio operation on the analysis compliance data volume and the preset analysis data volume threshold obtained from the database; and obtaining the analysis accuracy evaluation value by combining the analysis compliance ratio, the analysis data volume compliance ratio and the fault verification safety evaluation value that meets the safety conditions.

[0017] One or more technical solutions provided in the embodiments of this application have at least the following technical effects or advantages:

[0018] 1. Determine whether to make runtime adjustment based on the obtained runtime efficiency evaluation value. Then, obtain the fault verification safety evaluation value through network data and the runtime efficiency evaluation value that meets the timeliness conditions and determine whether to make fault safety adjustment. Then, obtain the parsing accuracy evaluation value by parsing the encapsulated network data. Finally, determine whether to make accuracy adjustment based on the parsing accuracy evaluation value and perform formal verification on the LTLf constraint data. This achieves dynamic verification of program operation safety and improves the timeliness of program runtime verification, effectively solving the problem of low timeliness of program runtime verification in the existing technology.

[0019] 2. By formally verifying the LTLf constraint data corresponding to the parsing accuracy evaluation value that meets the parsing accuracy conditions, if the formal constraint described in the LTLf language reaches the True state, the constraint is satisfied; if the formal constraint described in the LTLf language reaches the False state, the constraint is not satisfied, thereby achieving an improvement in the reliability of formal verification and further achieving an improvement in the accuracy of formal verification.

[0020] 3. The runtime effectiveness evaluation value is obtained by combining the network data reception delay deviation and the encapsulation identification delay deviation. Then, the fault verification safety evaluation value is obtained by combining the operation fault deviation, the operation fault recovery deviation and the runtime effectiveness evaluation value that meets the timeliness conditions. Finally, the parsing accuracy evaluation value is obtained by combining the parsing compliance ratio, the parsing data volume compliance ratio and the fault verification safety evaluation value that meets the safety conditions. This improves the accuracy of obtaining program operation-related data, and further improves the reliability of program runtime verification. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] Figure 1 A flowchart of a program runtime verification method based on LTLf provided in an embodiment of the present application;

[0022] Figure 2 An overall flow chart provided for the embodiments of this application;

[0023] Figure 3 A statistical graph showing the number of parsing matches versus the parsing match ratio provided in the embodiments of the present application;

[0024] Figure 4 A diagram of the verification framework provided for an embodiment of the present application. DETAILED DESCRIPTION

[0025] The embodiment of the present application solves the problem of low timeliness of program runtime verification in the prior art by providing a program runtime verification method based on LTLf. A runtime efficiency evaluation value is obtained through network data, and whether to perform runtime efficiency adjustment is determined based on the runtime efficiency evaluation value. Then, a fault verification safety evaluation value is obtained through network data and a runtime efficiency evaluation value that meets the timeliness condition, and whether to perform fault safety adjustment is determined based on the fault verification safety evaluation value. Then, encapsulated network data is obtained through network data corresponding to the fault verification safety evaluation value that meets the safety condition, and data is parsed on the encapsulated network data to obtain a parsing accuracy evaluation value. Finally, whether to perform accuracy adjustment is determined based on the parsing accuracy evaluation value, and the LTLf constraint data corresponding to the parsing accuracy evaluation value that meets the parsing accuracy condition is formally verified, thereby improving the timeliness of program runtime verification.

[0026] The technical solution in the embodiment of the present application is to solve the problem of low timeliness of verification during the operation of the above program. The overall idea is as follows:

[0027] The runtime efficiency evaluation value is used to determine whether to make runtime efficiency adjustments. Then, the fault verification safety evaluation value is obtained through network data and the runtime efficiency evaluation value that meets the timeliness conditions, and it is determined whether to make fault safety adjustments. Then, the parsing accuracy evaluation value is obtained by parsing the encapsulated network data. Finally, based on the parsing accuracy evaluation value, it is determined whether to make accuracy adjustments and formal verification, thereby achieving the effect of improving the timeliness of program runtime verification.

[0028] In order to better understand the above technical solution, the above technical solution will be described in detail below with reference to the accompanying drawings and specific implementation methods.

[0029] like Figure 1 As shown, it is a flow chart of a program runtime verification method based on LTLf provided by an embodiment of the present application, the method comprising the following steps: S1, timeliness evaluation: obtaining a runtime efficiency evaluation value according to network data, judging whether to perform runtime efficiency adjustment based on the runtime efficiency evaluation value, the runtime efficiency adjustment means adjusting the runtime efficiency evaluation value to meet the timeliness condition, and the network data is used to reflect the network transmission situation; S2, fault verification: obtaining a fault verification safety evaluation value according to the network data and the runtime efficiency evaluation value that meets the timeliness condition, judging whether to perform fault safety adjustment based on the fault verification safety evaluation value, the runtime efficiency evaluation value is used to evaluate the timeliness during network transmission, the fault verification safety evaluation value is used to evaluate the safety during dynamic verification according to the received network data, the fault Security adjustment means adjusting the fault verification safety assessment value to meet the security conditions; S3, data analysis: obtaining the encapsulated network data according to the network data corresponding to the fault verification safety assessment value that meets the security conditions, performing data analysis on the encapsulated network data to obtain the analysis accuracy assessment value, the analysis accuracy assessment value is used to evaluate the accuracy of the encapsulated network data during the data analysis process, the encapsulated network data means the encapsulated network data, and data analysis means converting the encapsulated network data into the form of LTLf constraints; S4, formal verification: judging whether to perform accuracy adjustment based on the analysis accuracy assessment value, performing formal verification on the LTLf constraint data corresponding to the analysis accuracy assessment value that meets the analysis accuracy conditions, and the accuracy adjustment is used to adjust the analysis accuracy assessment value to meet the analysis accuracy conditions.

[0030] In this embodiment, network transmission is implemented by creating threads 1, 2, and 3 to optimize resource utilization and improve processing efficiency. Threads 1 and 2 are each responsible for listening for and receiving data from different network ports. Both threads are configured with corresponding network sockets to listen for inbound connections on specific ports and receive and parse data streams. Thread 3, acting as the data collection and processing center, reads data from the buffers or queues of threads 1 and 2 and performs centralized processing. Furthermore, when the three threads are running concurrently, locks are used to control access to shared resources. This ensures that thread 3 can only begin parsing and completing data at the same time after threads 1 and 2 have fully received data at the same time, thus preventing data resource congestion. Network transmission uses network sockets, which serve as the main program's entry point for receiving external data. Their primary task is to receive network data sent by the verification object and encapsulate it into a recognizable object. The network transmission module first sets the corresponding IP (Internet Protocol) address and port number to receive data from the verification object under test. For incoming data, the network transmission module stores it in a cache and reads it into a string array. The data received is in the form of binary UDP (User Datagram Protocol) packets. Therefore, after receiving the data, the network transmission module processes the packets. First, the required binary data bits are intercepted from the binary packet according to the corresponding positions of different fields. Then, these binary bits are converted to the corresponding data types. In other words, the binary data is decoded and mapped to a series of recognizable basic data types, such as Boolean and floating-point types, to facilitate subsequent parsing and data processing using the C++ language.

[0031] It's important to understand that the runtime effectiveness evaluation value, fault verification safety evaluation value, and parsing accuracy evaluation value all influence each other. The effectiveness evaluation value affects the fault verification safety evaluation value and the efficiency of data parsing, while the fault verification safety evaluation value affects runtime effectiveness adjustments and the accuracy of data parsing. The high or low effectiveness evaluation value directly affects the timeliness of fault verification. A lower effectiveness evaluation value indicates network transmission delays, which may cause delays in fault verification and thus affect the accuracy of the fault verification safety evaluation value. This improves the timeliness of program runtime verification.

[0032] It should be added that the network data within a preset time period is measured by a network traffic monitor, and the specific process of obtaining the network data is as follows: obtaining the initial network data, the initial network data represents the log data generated during operation; caching the initial network data through network transmission, and reading the cached initial network data into a specified string array; encapsulating and identifying the initial network data to obtain the network data; the network data includes network data reception delay, encapsulation identification delay, operation fault duration, number of operation faults, operation duration, fault maintenance time, number of parsing compliance times and amount of parsing compliance data; the number of parsing compliance times represents the number of times the encapsulated network data meets the preset LTLf constraint conditions after data parsing; the amount of parsing compliance data represents the amount of data corresponding to the encapsulated network data that meets the preset LTLf constraint conditions after data parsing the encapsulated network data.

[0033] Furthermore, the specific process of obtaining the runtime efficiency evaluation value based on the network data is as follows: In the first step, the network data reception delay deviation (i.e., the value in the constraint expression of the runtime efficiency evaluation value) is obtained by performing a ratio operation on the difference between the network data reception delay and the preset reception delay threshold obtained from the database and the preset reception delay threshold. ); the network data reception delay deviation is used to reflect the deviation of the network data reception delay within the preset time period; the second step is to perform a ratio operation on the difference between the encapsulation recognition delay and the preset recognition threshold obtained from the database and the preset recognition threshold and process it to obtain the encapsulation recognition delay deviation (that is, the value in the constraint expression of the runtime efficiency evaluation value). ); the encapsulation identification delay is used to reflect the deviation of the encapsulation identification delay within a preset time period; the third step is to obtain a runtime effectiveness evaluation value by combining the network data reception delay deviation and the encapsulation identification delay deviation.

[0034] The constraint expression of the runtime efficiency evaluation value is as follows:

[0035]

[0036] Where SXX p represents the runtime efficiency evaluation value corresponding to the network data in the pth preset time period, p=1,2,...,m, p represents the number of the preset time period, m represents the total number of preset time periods, Indicates the network data receiving delay deviation corresponding to the network data in the p-th preset time period, Indicates the encapsulation identification delay deviation corresponding to the network data in the p-th preset time period, Indicates the network data receiving delay corresponding to the network data in the p-th preset time period, Indicates the encapsulation identification delay corresponding to the network data in the pth preset time period, Indicates the preset receiving delay threshold. represents the preset recognition threshold, ΔCS represents the reference data reception delay range obtained from the database, ΔFS represents the reference package recognition delay range obtained from the database, and e represents a natural constant.

[0037] In this embodiment, the aforementioned database is a database for storing various types of setting data established before the design of the LTLf-based program runtime verification method provided in the embodiment of the present application. The database includes but is not limited to program running time, failure time, network transmission delay, etc., and the various numerical values ​​therein are directly set by technical personnel. For example, the preset receiving delay threshold is represented by the average value of the program running verification receiving delay in the historical time period in the database, and the preset recognition threshold is represented by the average value of the program running verification recognition delay in the historical time period in the database.

[0038] The reference data reception delay range ΔCS is greater than or equal to 1 and less than or equal to In this embodiment, when the reference data reception delay range ΔCS is greater than Indicates that the network transmission delay has a great influence on the runtime efficiency evaluation value, resulting in inaccurate measurement results; the reference package identification delay range ΔFS is greater than or equal to 1 and less than or equal to In this embodiment, when the reference package identification delay range ΔFS is greater than This indicates that the package identification delay significantly interferes with the runtime efficiency evaluation value, causing inaccurate measurement results.

[0039] It should be understood that the algorithm of this embodiment combines comprehensive analysis of network data to obtain a runtime efficiency evaluation value. The network data in the algorithm of this embodiment does not exist independently, but is interrelated. The longer the network data reception delay, the greater the delay encountered by the data during transmission, which may cause the receiving end to be unable to receive the complete data packet for a long time, thereby affecting the encapsulation identification. The longer the encapsulation identification delay, the greater the probability of errors in the receiving end when processing subsequent data, thereby affecting the overall data processing efficiency, which may indirectly increase the network data reception delay, resulting in a decrease in the runtime efficiency evaluation value. The parameters of the algorithm of this embodiment need to be considered together to simultaneously consider their impact on the results.

[0040] Specifically, assuming that the network data reception delay deviation The range is 1-1.5, the package identification delay deviation The range is 1-1.5, As shown in Table 1, it is a statistical table of changes in the runtime efficiency evaluation value provided in the embodiment of the present application:

[0041] Table 1 Statistics of changes in runtime effectiveness evaluation values

[0042]

[0043] As can be seen from the above table, as the network data receiving time delay deviation and the encapsulation identification time delay deviation gradually increase, the running timeliness evaluation value gradually decreases, meaning that the timeliness during network transmission decreases, realizing the accurate quantification of the timeliness during network transmission, and further realizing the improvement of the program running timeliness verification.

[0044] Further, the specific process of judging whether to perform running timeliness adjustment based on the running timeliness evaluation value is as follows: step one, judging whether the running timeliness evaluation value meets the timeliness condition, if yes, not performing running timeliness adjustment, otherwise executing step two; step two, performing dynamic routing selection, when the monitored running timeliness evaluation value meets the timeliness condition, stopping performing running timeliness adjustment, otherwise executing step three, dynamic routing selection means avoiding congestion path through software defined network method; step three, performing load balancing processing, when the monitored running timeliness evaluation value meets the timeliness condition, stopping performing running timeliness adjustment, otherwise sending an alarm prompt to the preset personnel, load balancing processing means avoiding single node overload through deploying load balancer; the timeliness condition means the running timeliness evaluation value not lower than the preset running timeliness threshold value obtained from the database.

[0045] In the embodiment, the preset running timeliness threshold value is represented by the average value of the historical time period running timeliness evaluation value in the database, the software defined network method is a new type of network architecture, which separates the network control plane from the data forwarding plane, making the network control more flexible and programmable, when finding that a certain path appears congestion or failure, the network controller will dynamically adjust the routing strategy, selecting one or more backup paths to avoid congestion or failure area, the load balancer is responsible for dispersing network traffic to multiple servers or network nodes, to realize the balanced allocation of traffic; realizing the improvement of the program running timeliness verification.

[0046] Further, the specific process of obtaining the fault verification safety evaluation value according to the network data and the running timeliness evaluation value meeting the timeliness condition is as follows: obtaining the initial fault rate by ratio operation of the running fault duration and the running duration; obtaining the running fault deviation (i.e. the limit expression of the fault verification safety evaluation value in the formula) by ratio operation of the difference between the initial fault rate and the preset fault rate threshold value obtained from the database and the preset fault rate threshold value. ); the operation fault deviation is used to reflect the deviation condition of the operation fault occurring within the preset time period; the initial fault recovery time is obtained by ratio operation of the fault maintenance time and the operation fault times; the operation fault recovery deviation (i.e., the limit expression in the fault verification safety evaluation value) is obtained by ratio operation of the difference between the initial fault recovery time and the preset fault recovery time threshold value and the preset fault recovery time threshold value, which is obtained from the database. ); the operation fault recovery deviation is used to reflect the deviation condition of the operation fault recovery within the preset time period; the fault verification safety evaluation value is obtained by combining the operation fault deviation, the operation fault recovery deviation and the operation timeliness evaluation value meeting the timeliness condition.

[0047] The fault verification safety evaluation value is obtained by the following method:

[0048]

[0049]

[0050] In the formula, AQX p represents the fault verification safety evaluation value corresponding to the network data within the pth preset time period, p = 1, 2, …, m, p represents the number of the preset time period, and m represents the total number of the preset time period, represents the operation fault deviation corresponding to the network data within the pth preset time period, represents the operation fault recovery deviation corresponding to the network data within the pth preset time period, SXX p represents the operation timeliness evaluation value meeting the timeliness condition corresponding to the network data within the pth preset time period, represents the operation fault duration corresponding to the network data within the pth preset time period, represents the operation fault times corresponding to the network data within the pth preset time period, represents the operation duration corresponding to the network data within the pth preset time period, represents the fault maintenance time corresponding to the network data within the pth preset time period, represents the preset fault rate threshold value, represents the preset fault recovery time threshold value, ΔYG represents the reference operation fault range obtained from the database, ΔHF represents the reference average fault recovery range obtained from the database, and e represents the natural constant.

[0051] In the embodiment, the preset failure rate threshold is represented by the average value of the failure rate verified by the program running in the historical time period in the database, and the preset failure recovery time threshold is represented by the average value of the failure recovery time verified by the program running in the historical time period in the database; the reference running failure range ΔYG is greater than or equal to 0, and in the embodiment, when the reference running failure range ΔYG is less than 0, it indicates that the interference degree of the failure rate on the failure verification safety evaluation value is large, causing the measurement result to be inaccurate; the reference average failure recovery range ΔHF is greater than or equal to 0, and in the embodiment, when the reference average failure recovery range ΔHF is less than 0, it indicates that the interference degree of the failure recovery time on the failure verification safety evaluation value is large, causing the measurement result to be inaccurate.

[0052] It needs to be understood that the failure verification safety evaluation value in the embodiment is obtained by comprehensively analyzing the network data and the running timeliness evaluation value, and the network data and the running timeliness evaluation value in the embodiment algorithm are not independent, and have mutual correlation. The increase of the running failure time length and the failure times will cause the efficiency of the system in processing the network data to decrease, and then the running timeliness evaluation value decreases. The higher the running timeliness evaluation value is, the faster the system can receive and process the network data, so that the failure verification can be performed more timely, which is helpful to improve the safety. The parameters in the embodiment algorithm need to be considered together to affect the result; the precise quantification of the safety of the dynamic verification according to the received network data is realized; and the improvement of the verification timeliness during the program running is realized.

[0053] Further, the specific process of judging whether to perform the failure safety adjustment based on the failure verification safety evaluation value is as follows: VV1, judging whether the failure verification safety evaluation value meets the safety condition, if yes, not performing the failure safety adjustment, and otherwise executing VV2; VV2, performing data encryption, when the monitored failure verification safety evaluation value meets the safety condition, stopping the failure safety adjustment, and otherwise executing VV3, the data encryption means preventing the data from being stolen and tampered in the transmission process through the encryption algorithm; VV3, performing node fault tolerance processing, when the monitored failure verification safety evaluation value meets the safety condition, stopping the failure safety adjustment, and otherwise sending an alarm prompt to a preset person, the node fault tolerance processing means improving the network transmission fault tolerance through the redundant nodes; the safety condition means that the failure verification safety evaluation value is not lower than the preset failure safety threshold value obtained from the database.

[0054] In this embodiment, the preset fault safety threshold is represented by the average value of the fault verification safety assessment value of the historical time period in the database. The encryption algorithm (such as a symmetric encryption algorithm) converts the original data (plaintext) into ciphertext. Only the person or system holding the corresponding decryption key can restore the ciphertext to plaintext. During the program verification process, data needs to be transmitted and stored between different networks. Through data encryption, it can be ensured that the data is always in an encrypted state during transmission and storage, thereby enhancing the security of the entire verification process. Node fault tolerance processing is to improve the fault tolerance of transmission by introducing redundant nodes in the network. Even if some nodes fail, the entire network can still maintain normal operation; the timeliness of verification during program runtime is improved.

[0055] Furthermore, the specific process of obtaining the parsing accuracy evaluation value by parsing the encapsulated network data is as follows: the parsing accuracy ratio (i.e., the number of parsing matches in the restricted expression of the parsing accuracy evaluation value) is obtained by performing a ratio operation with the preset parsing number threshold obtained from the database. ); the parsing compliance ratio is used to reflect the number of times the encapsulated network data is parsed within a preset time period; the parsing data volume compliance ratio is obtained by performing a ratio operation on the parsing compliance data volume and the preset parsing data volume threshold obtained from the database (i.e., the number of parsing accuracy evaluation values ​​in the limiting expression). ); the parsed data volume compliance ratio is used to reflect the data volume compliance of the data parsing of the encapsulated network data within a preset time period; the parsing accuracy assessment value is obtained by combining the parsing compliance ratio, the parsing data volume compliance ratio and the fault verification safety assessment value that meets the safety conditions.

[0056] The parsing accuracy evaluation value is obtained by the following method:

[0057]

[0058] Where ZQX p represents the analysis accuracy evaluation value corresponding to the network data in the p-th preset time period, p=1,2,...,m, p represents the number of the preset time period, m represents the total number of preset time periods, Indicates the resolution matching ratio of network data in the pth preset time period. Indicates the ratio of the amount of parsed data corresponding to the network data in the p-th preset time period, AQX p ' represents the fault verification safety assessment value that meets the safety conditions corresponding to the network data in the pth preset time period, Indicates the number of times the network data is analyzed and matched within the p-th preset time period. Indicates the amount of data that corresponds to the resolution of network data in the pth preset time period. represents a preset analysis times threshold, represents a preset analysis data amount threshold, e represents a natural constant.

[0059] In the embodiment, the preset analysis times threshold is represented by an average value of the analysis times of the program running verification in the historical time period in the database, and the preset analysis data amount threshold is represented by an average value of the analysis data amount of the program running verification in the historical time period in the database.

[0060] It should be noted that the data analysis obtains discrete or continuous numerical variables, and the FP (Formula Progression) method can only verify Boolean variables in the form of LTLf formula and cannot process the numerical type directly obtained by analysis. Therefore, in the process from binary data to LTLf, the arithmetic expression processing is introduced as an intermediate step, the truth value of the Boolean proposition is analyzed according to the value of the real-time numerical variable, and then the FP method is used to complete the remaining work, so as to realize the verification task. The currently supported arithmetic expression can be recursively defined as follows:

[0061] exp = (e1 = e2) | (e1 ≠ e2) | (e1 > e2) | (e1 < e2) | (e1 ≥ e2) | (e1 ≤ e2) | (e1++);

[0062] k = v1 | (v1 + v2) | (v1 - v2) | (v1 * v2) | (v1 / v2);

[0063] wherein, v i is an arbitrary variable (variable) or constant (constant), e1++ means that e1 will continuously increase, that is, the value of e1 at the next moment will be greater than the value of e1 at the current moment; the rest of the symbols such as '=' and '+' are the operations in the general arithmetic expression; k represents an event, e n represents the nth event, n = 1, 2,..., m, n represents the number of events, m represents the number of events, and exp represents the value of the introduced intermediate step.

[0064] Then, appropriate generation rule APIs (Application Programming Interface) are selected to combine these arithmetic expressions to obtain equivalent LTLf formulas. These generation rule APIs include:

[0065] API for directly generating rules

[0066] always (event / LTL_Event k)

[0067] Meaning: Event k always satisfies

[0068] conditionAlways(event cond, event / LTL_Event k)

[0069] Meaning: event k always holds when condition cond holds; i.e. cond→k always holds

[0070] executeByOrder(event e1, event e2,...)

[0071] Meaning: the given events e1, e2,... must occur in the specified order

[0072] executeUnder(event / LTL_Event k, event cond)

[0073] Meaning: event k occurs when condition cond must hold; i.e. k→cond always holds

[0074] last_moment(event e1, event e2,...)

[0075] Meaning: the last moment requires that e1, e2,... all hold

[0076] last_moments_seg(event e1, event e2,...)

[0077] Meaning: the last segment of time requires that e1, e2,... all hold

[0078] Helper function API

[0079] e1&e2 or AND(e1, e2)

[0080] e1|e2 or OR(e1, e2)

[0081] !e1 or NOT(e1)

[0082] transition(event e1, event e2)

[0083] Using the generation rules, it is convenient to combine arithmetic expressions into LTLf formulas. Finally, the LTLf formulas generated by the API are exported to a file as input to the main program for formal verification. For example, if the arithmetic expression is e1: condition = 3, the formula after combination using the generation rules is always(e1), and the corresponding LTLf formula is G(e1).

[0084] It should be understood that the algorithm of this embodiment combines network data and fault verification safety assessment values ​​for comprehensive analysis to obtain a parsing accuracy assessment value. In the algorithm of this embodiment, network data and fault verification safety assessment values ​​do not exist independently, but are interrelated. An increase in the number of parsing matches and the amount of parsing match data generally means a higher accuracy in the data parsing process, which helps to improve the safety of fault verification. A higher fault verification safety assessment value means that the system can more accurately identify and handle potential network faults, which helps to reduce data parsing errors caused by faults, thereby increasing the parsing accuracy assessment value. The parameters of the algorithm of this embodiment need to be considered together and simultaneously in their impact on the results.

[0085] Specifically, assuming the parsing matches the number of The range is 50-100 (times), and the preset analysis number threshold Fixed to 75 (times), such as Figure 3 As shown in the figure, the statistical diagram of the change of the number of parsing coincidences-parsing coincidence ratio provided by the embodiment of the present application is shown in the figure. Figure 3 As we know, as the number of parsing matches Gradually increases, and the parsing compliance ratio gradually increases, which means that the accuracy of the data parsing process of encapsulated network data is gradually improved, realizing the precise quantification of the accuracy of the data parsing process of encapsulated network data, and thus realizing the improvement of the timeliness of verification during program runtime.

[0086] Furthermore, the specific process of judging whether to make an accuracy adjustment based on the parsing accuracy evaluation value is as follows: QQ1, judging whether the parsing accuracy evaluation value meets the parsing accuracy condition, if so, no accuracy adjustment is made, otherwise QQ2 is executed; QQ2, performing noise reduction processing, when the monitored parsing accuracy evaluation value meets the parsing accuracy condition, the accuracy adjustment is stopped, otherwise QQ3 is executed, noise reduction processing means correcting errors caused by noise through an error correction algorithm at a preset receiving end through redundant decoding (such as Hamming code and convolutional code); QQ3, performing timing constraints, when the monitored parsing accuracy evaluation value meets the parsing accuracy condition, the accuracy adjustment is stopped, otherwise an alarm is sent to the preset personnel, and the timing constraints are used to ensure that the LTLf constraint data can effectively cover all possible paths; the parsing accuracy condition means that the parsing accuracy evaluation value is not lower than the preset parsing accuracy threshold obtained from the database.

[0087] In this embodiment, the preset parsing accuracy threshold is represented by the average of the parsing accuracy assessment values ​​over historical time periods in the database. Hamming code is a linear block code that detects and corrects single-bit errors by adding additional check bits. At the transmitter, the original data is encoded into a Hamming code containing check bits. At the receiver, the check bits are calculated to detect the presence and location of errors, and then an error correction algorithm is used to correct the errors. Convolutional code is a mnemonic encoding method that exploits the correlation between data blocks. At the transmitter, the original data is convolutionally encoded into codewords containing redundant information. At the receiver, algorithms such as maximum likelihood decoding are used to correct errors introduced during transmission. Timing constraints ensure that all possible paths can be verified within a limited time.

[0088] Furthermore, the specific process of formally verifying the LTLf constraint data corresponding to the parsing accuracy evaluation value that meets the parsing accuracy conditions is as follows: if the formal constraint described in the LTLf language reaches the True state, the constraint is satisfied; if the formal constraint described in the LTLf language reaches the False state, the constraint is not satisfied; formal verification means verifying the LTLf constraint data through the FP method.

[0089] like Figure 4 As shown, this is a verification framework diagram provided in an embodiment of the present application. After obtaining the LTLf formula, the automaton can be dynamically constructed and satisfiability checking can be performed through the FP (Formula Progression) method. The formalization principle of the FP method is specifically introduced below.

[0090] For an LTLf formula φ and a non-empty finite locus ρ, let the progression formula be fp(φ,ρ), then fp(φ,ρ) can be recursively defined as:

[0091] –fp(tt,ρ)=tt and fp(ff,ρ)=ff;

[0092] –If p∈ρ[0], then fp(p,ρ)=tt; if Then fp(p,ρ)=ff;

[0093]

[0094] –fp(φ1∧φ2,ρ)=fp(φ1,ρ)∧fp(φ2,ρ);

[0095] –fp(φ1∨φ2,ρ)=fp(φ1,ρ)∨fp(φ2,ρ);

[0096] – If |ρ|=1, then fp(○φ,ρ)=φ; otherwise fp(○φ,ρ)=fp(φ,ρ1);

[0097] – If |ρ|=1, then fp(●φ,ρ)=φ; otherwise fp(●φ,ρ)=fp(φ,ρ1);

[0098] –fp(φ1Uφ2,ρ)=fp(φ2,ρ)∨(fp(φ1,ρ)∧fp(○(φ1Uφ2),ρ));

[0099] –fp(φ1Rφ2,ρ)=fp(φ2,ρ)∧(fp(φ1,ρ)∨fp(●(φ1Rφ2),ρ)).

[0100] Based on this progressive formula, we construct the automaton Aφ(2P,S,δ,s0,T) corresponding to the LTLf constraint, where:

[0101] -2P is a finite alphabet, P is an atomic proposition on φ

[0102] -S is a finite set of states,

[0103] -s0 is the initial state

[0104] -δ is the migration rule S×2P→S, for all s∈S, σ∈2P, δ(s,σ)=fp(s,σ) (here σ is considered to be a migration trajectory of length 1);

[0105] -T is a series of receiving states, where

[0106] Using the above progressive formula and the automaton it constructs, the next transition state, next_state, can be obtained each time based on the current state, current_state, the transition trajectory, edge, and the transition rule, Formula_Progression. The FP function for constructing the next transition state is: next_state = Formula_Progression(current_state, edge). When the state of next_state changes to True or False, this marks the end of that round of the program. True indicates that the property is satisfied, while False indicates that the property is violated, indicating a possible error or abnormal behavior in the system. This marks the conclusion of the verification of this property and allows the next property to be verified, thus improving the timeliness of verification during program runtime.

[0107] To summarize, the embodiment of the present application obtains a runtime effectiveness evaluation value through network data and determines whether to make runtime effectiveness adjustments, then obtains a fault verification safety evaluation value through network data and a runtime effectiveness evaluation value that satisfies the timeliness conditions and determines whether to make fault safety adjustments, then obtains a parsing accuracy evaluation value by performing data parsing on the encapsulated network data, and finally determines whether to make accuracy adjustments based on the parsing accuracy evaluation value, and performs formal verification on the LTLf constraint data, thereby achieving dynamic verification of program operation safety, and further achieving improved timeliness of program runtime verification, effectively solving the problem of low timeliness of program runtime verification in the prior art.

[0108] It will be understood by those skilled in the art that embodiments of the present invention may be provided as methods, systems, or computer program products. Thus, the present invention may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware. Furthermore, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0109] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowcharts and / or block diagrams, as well as combinations of processes and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowcharts and / or block diagrams. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0110] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.

[0111] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.

[0112] Although the preferred embodiments of the present invention have been described, those skilled in the art may make additional changes and modifications to these embodiments once they have learned the basic creative concept. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of the present invention.

[0113] Obviously, those skilled in the art may make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if such changes and modifications fall within the scope of the claims and their equivalents, the present invention is intended to include such changes and modifications.

Claims

1. A program runtime verification method based on LTLf, characterized in that: The following steps are involved: S1, obtaining a runtime efficiency evaluation value based on network data, and determining whether to perform runtime efficiency adjustment based on the runtime efficiency evaluation value; S2, obtaining a fault verification safety evaluation value based on the network data and a runtime effectiveness evaluation value that satisfies the timeliness condition, and determining whether to perform a fault safety adjustment based on the fault verification safety evaluation value, wherein the runtime effectiveness evaluation value is used to evaluate the timeliness during network transmission, and the fault verification safety evaluation value is used to evaluate the safety during dynamic verification based on the received network data; S3, obtaining encapsulated network data based on the network data corresponding to the fault verification safety evaluation value that meets the safety condition, and performing data parsing on the encapsulated network data to obtain a parsing accuracy evaluation value, wherein the parsing accuracy evaluation value is used to evaluate the accuracy of the encapsulated network data during the data parsing process; S4, judging whether to make accuracy adjustments based on the parsing accuracy evaluation value, and performing formal verification on the LTLf constraint data corresponding to the parsing accuracy evaluation value that meets the parsing accuracy condition; The specific process of obtaining the network data is as follows: Acquire initial network data, where the initial network data represents log data generated during runtime; Cache the initial network data through network transmission, and read the cached initial network data into the specified string array; Encapsulate and identify the initial network data to obtain network data; The network data includes network data reception delay, encapsulation identification delay, operation fault duration, operation fault number, operation duration, fault maintenance time, parsing match number and parsing match data volume; The parsing compliance number indicates the number of times the encapsulated network data meets the preset LTLf constraint condition after data parsing; The parsing data volume represents the amount of data corresponding to the encapsulated network data that meets the preset LTLf constraints after data parsing of the encapsulated network data; The specific process of obtaining the runtime efficiency evaluation value based on network data is as follows: In the first step, a network data reception delay deviation is obtained by performing a ratio operation on the difference between the network data reception delay and the preset reception delay threshold obtained from the database and processing the difference with the preset reception delay threshold; In the second step, the difference between the package identification delay and the preset identification threshold obtained from the database is compared with the preset identification threshold and processed to obtain the package identification delay deviation; The third step is to combine the network data reception delay deviation and the encapsulation recognition delay deviation to obtain the runtime efficiency evaluation value; The specific process of obtaining the fault verification safety evaluation value based on the network data and the runtime effectiveness evaluation value that meets the timeliness condition is as follows: The initial failure rate is obtained by performing a ratio calculation between the running failure time and the running time; Obtaining the operating fault deviation by performing a ratio operation between the difference between the initial fault rate and the preset fault rate threshold obtained from the database and the preset fault rate threshold; The initial fault recovery time is obtained by performing a ratio calculation based on the fault maintenance time and the number of operating faults; The running fault recovery deviation is obtained by performing a ratio operation on the difference between the initial fault recovery time and the preset fault recovery time threshold obtained from the database and the preset fault recovery time threshold; The fault verification safety assessment value is obtained by combining the operation fault deviation, the operation fault recovery deviation and the operation timeliness assessment value that meets the timeliness conditions; The specific process of performing data parsing on the encapsulated network data to obtain the parsing accuracy evaluation value is as follows: Obtaining an analysis coincidence ratio by performing a ratio calculation between the analysis coincidence times and a preset analysis coincidence times threshold value obtained from a database; Obtaining a parsed data volume coincidence ratio by performing a ratio operation between the parsed coincident data volume and a preset parsed data volume threshold obtained from a database; The parsing accuracy evaluation value is obtained by combining the parsing compliance ratio, the parsing data volume compliance ratio and the fault verification safety evaluation value that meets the safety conditions.

2. A program runtime verification method based on LTLf as claimed in claim 1, characterized in that: The constraint expression of the runtime efficiency evaluation value is as follows: ; Where, It represents the runtime efficiency evaluation value of the network data in the p-th preset time period. , p represents the number of the preset time period, m represents the total number of preset time periods, Indicates the network data receiving delay deviation corresponding to the network data in the p-th preset time period, Indicates the encapsulation identification delay deviation corresponding to the network data in the p-th preset time period, Indicates the delay range of receiving reference data obtained from the database. Indicates the reference package identification delay range obtained from the database.

3. The LTLf-based program runtime verification method according to claim 1, characterized in that: The specific process of determining whether to adjust the runtime efficiency based on the runtime efficiency evaluation value is as follows: Step 1: Determine whether the runtime efficiency evaluation value meets the timeliness condition. If so, no runtime efficiency adjustment is performed. Otherwise, execute step 2. Step 2: Dynamic routing selection is performed. When the monitored runtime efficiency evaluation value meets the timeliness condition, the runtime efficiency adjustment is stopped. Otherwise, step 3 is executed. Step 3: Perform load balancing. When the monitored runtime efficiency evaluation value meets the timeliness condition, stop adjusting the runtime efficiency. Otherwise, send an alarm to the preset personnel. The timeliness condition represents a runtime effectiveness evaluation value that is not lower than a preset runtime effectiveness threshold value obtained from a database.

4. The LTLf-based program runtime verification method according to claim 1, wherein: The specific process of determining whether to perform fault safety adjustment based on the fault verification safety assessment value is as follows: VV1, determines whether the fault verification safety assessment value meets the safety conditions. If so, no fault safety adjustment is performed. Otherwise, VV2 is executed; VV2, performs data encryption. When the monitored fault verification safety assessment value meets the safety condition, stops the fault safety adjustment, otherwise executes VV3; VV3, performs node fault tolerance processing. When the monitored fault verification safety assessment value meets the safety conditions, the fault safety adjustment is stopped. Otherwise, an alarm prompt is sent to the preset personnel; The safety condition indicates that the fault verification safety assessment value is not lower than a preset fault safety threshold obtained from a database.

5. The LTLf-based program runtime verification method according to claim 1, wherein: The specific process of determining whether to perform accuracy adjustment based on the analytical accuracy evaluation value is as follows: QQ1, determines whether the parsing accuracy evaluation value meets the parsing accuracy condition. If so, no accuracy adjustment is performed. Otherwise, QQ2 is executed; QQ2, performs noise reduction processing. When the monitored analytical accuracy evaluation value meets the analytical accuracy condition, the accuracy adjustment is stopped. Otherwise, QQ3 is executed; QQ3, performs timing constraints, and stops adjusting the accuracy when the monitored analysis accuracy evaluation value meets the analysis accuracy condition. Otherwise, an alarm prompt is sent to the preset personnel; The analysis accuracy condition indicates that the analysis accuracy evaluation value is not lower than a preset analysis accuracy threshold obtained from a database.

6. A program runtime verification method based on LTLf as claimed in claim 1, characterized in that: The specific process of formally verifying the LTLf constraint data corresponding to the parsing accuracy evaluation value that meets the parsing accuracy condition is as follows: If the formal constraints described in the LTLf language reach the True state, the constraints are satisfied; If the formal constraints described in the LTLf language reach the False state, the constraints are not satisfied.

Citation Information

Patent Citations

  • A method for runtime verification and control of Linux system scripts

    CN111914250B

  • Internet of Things program runtime verification method based on Docker

    CN117034258A

  • Embedded software testing method based on AADL (Architecture Analysis and Design Language) mode time automata model

    CN102063369A

  • Method for measuring monitorability probability of properties in runtime verification

    CN111352848A