Protocol Fuzzing Test Method and System Based on Multiple States
By introducing field relationship tables and probability selection tables between state data models in protocol fuzz testing, the problem of selecting a single type in the field combination variation between state data models in the prior art is solved, and more efficient branch coverage and test diversity are achieved, and the efficiency of fuzz testing is improved.
Patent Information
- Application Number
- CN202510281101.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-11
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2045-03-11
AI Technical Summary
The existing protocol fuzz testing technology based on syntax generation and coverage feedback has the problem of single choice in field combination variation between state data models, which leads to the inability to accurately focus on key combination fields within a limited test time, limiting the effectiveness and efficiency of fuzz testing.
By introducing the field relationship table and probability selection table between the state data model, the recursive selection field combination stage and the replacement and variation stage of valuable seeds are used to dynamically calculate the relationship values of the mutated fields in the state data model before and after, and select related fields through probability mapping to improve branch coverage and test diversity.
Significantly improve branch coverage and test diversity, improve testing efficiency, and ensure accurate focus on combined fields that have a significant impact on coverage within a limited time.
Smart Images

Figure CN119782191B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of fuzz testing, and particularly relates to a protocol fuzz testing method and system based on cross-multi-state. Background Art
[0002] Network protocol fuzz testing is a security testing method used to identify potential security vulnerabilities in computer programs or systems. Its basic principle is to send a large number of random or incomplete-format data to the target network service or protocol to observe the system's response and behavioral changes. This technology can help find system crashes, undefined behaviors, or other security issues caused by abnormal inputs. For example, CVE-2015-5477 is a vulnerability affecting the BIND DNS server. This vulnerability involves the processing of TKEY queries. Attackers can cause an assertion failure in BIND by sending a specially crafted TKEY DNS request, which can then lead to a system crash, enabling malicious users to launch a denial-of-service attack.
[0003] In recent years, protocol fuzz testing technology based on grammar generation has developed rapidly. Emerging methods combine grammar generation and coverage guidance, significantly enhancing the ability and depth of protocol vulnerability detection. This method uses coverage branch feedback as the main criterion, combines grammar-driven generation and dynamic analysis, and realizes intelligent test case construction. Its core idea is that the generated test cases should not only conform to the protocol grammar but also specifically explore the program execution path, thereby increasing the chance of discovering potential defects. Therefore, this new method not only improves the test efficiency but also more precisely achieves code coverage, helping to reveal more hidden and deep-seated security risks. Currently, the work related to protocol fuzz testing based on grammar generation and coverage guidance includes the following:
[0004] When Charon mutates the fields of the selected state data model, if the mutation of a certain field in the state increases the covered branch, it keeps the mutated value of this field unchanged and mutates the fields of the next state data model. This strategy can pass the effective code trigger value to the subsequent state. However, the test complexity of this method is relatively high. If there are too many states, it may overly focus on the mutation of the fields of the subsequent state data model while ignoring the mutation of the fields of the previous state.
[0005] PAVFuzz automatically learns the relationship between two mutated fields in adjacent state models during testing to guide the testing. When a certain field needs to be mutated, PAVFuzz queries the relationship table, finds the mutated field of the previous state model with the largest relationship value, and mutates it together with the current mutated field. This process aims to guide the fuzz testing towards the direction of maximizing coverage.
[0006] In summary, although the protocol fuzz testing technology based on grammar generation and coverage feedback has achieved certain results, there are still problems in the field combination mutation between state data models, such as a large number of involved fields and a single selection. The actual situation shows that only the field combination mutation of specific pre- and post-state data models can significantly improve the coverage rate. Within the limited test time, the inability to accurately focus on the key combination fields will limit the effect and efficiency of fuzz testing. Therefore, identifying and preferentially processing the combination fields that have a significant impact on the coverage rate is the key to improving the effectiveness of the mutation strategy. Summary of the Invention
[0007] The technical problem to be solved by the present invention is to provide a protocol fuzz testing method and system based on multiple states, which can improve the branch coverage rate and test diversity, and effectively improve the test efficiency by introducing a field relationship table and a probability selection table between state data models.
[0008] The present invention provides a protocol fuzz testing method based on multiple states, which is characterized by including the following steps:
[0009] S1: Preprocess the target protocol entity program to prepare for testing;
[0010] S2: Perform fuzz testing, which includes a recursive field combination selection stage and a valuable seed replacement and mutation stage during the fuzz testing process, and simultaneously update the mutated field relationship table and the mutated field selection probability table;
[0011] S3: Provide feedback on the result information.
[0012] Preferably, the specific steps of the step S1 include:
[0013] S1.1: Use an instrumentation compilation tool to perform instrumentation compilation on the target protocol entity program to generate a corresponding binary executable file;
[0014] S1.2: Combine the official protocol specifications of the target protocol entity program, and use the data model definition function provided by the Boofuzz fuzz testing framework to define the protocol data model set , and its calculation formula is:
[0015] ={ ,..., ,..., }, i = 1,..., n,
[0016] where n is the total number of data models;
[0017] S1.3: Use the state model definition function provided by the Boofuzz fuzz testing framework to define the protocol state model set, and its calculation formula is:
[0018] = { ,..., ,..., }, j = 1, …, m,
[0019] wherein, represents a state model, and the state model is composed of several data models in the data model set in a certain front - back sequence relationship, and m is the length of the state model set;
[0020] S1.4: Run the binary executable file generated in step S1.1, and allocate a shared memory ShareMem with a size of 64KB to statistically analyze the covered branch information of the target protocol entity program in real time.
[0021] Preferably, the specific steps of step S2 include:
[0022] S2.1: State model selection; Select a state model from the state model set in sequence, and turn to step S2.2. If the traversal of the state model set ends, re - enter step S2.1 until the set test time ends;
[0023] S2.2: Data model selection; According to the sequence relationship of the data models in the state model in the above - mentioned step S2.1, traverse the state model to obtain the data model , and initialize the mutation value of the data model . Turn to step S2.3. If the traversal of the state model ends, reset the target protocol entity program to the initial state and turn to step S2.1,
[0024] The calculation formula for initializing the mutation value of the data model is:
[0025] = DM,
[0026] wherein, is the mutation value of the initialized data model , DM is the fixed number of mutations, and its value is the number of new test cases generated under the data model in the selection field mutation stage;
[0027] S2.3: Recursive selection field combination stage; Extract the mutation field set composed of multiple mutation fields in the data model , and its calculation formula is:
[0028] = { ,..., ,..., }, where i = 1,..., n and f = 1,..., k.
[0029] Among them, n is the total number of data models, and k is the number of mutated fields contained in the data model;
[0030] The mutated field relationship table is a tree-like data structure of a prefix tree, specifically used to process the prefix matching of strings. The string saved by each non-leaf node is the data model name or field subscript, and the leaf node additionally contains the specific relationship value value;
[0031] The mutated field selection probability table is a tree-like data structure of a prefix tree, specifically used to process the prefix matching of strings. The string saved by each non-leaf node is the data model name or field subscript, and the leaf node additionally contains the specific selection probability value probability;
[0032] Under the guidance of the mutated field selection probability table, use the probability selection algorithm of the tree array to select a field relationship tuple ( , ) from the mutated field relationship table, where is the string concatenated by the model name and mutated field subscript of the current data model , and is the string concatenated by the model name and mutated field subscript of the previous data model of the current data model in the state model. Then, according to go to the mutated field relationship table to select the field relationship tuple of the previous data model of the data model in the state model . If the field and all the field relationship values value of the previous data model are 0, then select from the set of all fields of and the previous data model until all the data models in the state model are traversed; add all the selected field relationship tuples to the field relationship tuple set , and clear the field relationship tuple set after each test; add each mutated field in the field relationship tuple set to the mutated field set , and clear this set after each test;
[0033] S2.4: Replacement and Mutation Phase of Valuable Seeds; For each field in the mutation field set in step S2.3, perform mutation or value replacement, and add all mutated fields to the mutated field value set in. After each test, clear the mutated field value set ; Generate a data model The mutated data packet , and then form a data packet set , and its calculation formula is:
[0034] ={ ,..., ,..., }, l = 1,..., s,
[0035] where s is the total number of data models in the state model . After each test, clear this set;
[0036] Combine the data packets in the data packet set in the order of the state model to generate test cases ; The test cases contain data packets after field mutation or value replacement for each data model in the state model ;
[0037] S2.5: Inject the test cases into the target protocol entity program, and count the covered branch information of the opened shared memory ShareMem and the status information returned by the target protocol entity program.
[0038] Preferably, the specific steps of step S2 further include:
[0039] When the test cases generated in step S2.4 cause the target protocol entity program to crash, record the exception log and save the test cases for vulnerability analysis work after the test ends.
[0040] Preferably, add the values that can increase the covered branches in the mutated field value set collected in step S2.4 to the valuable seed pool, and preferentially use the values in the valuable seed pool for replacement or mutation.
[0041] Preferably, in the update stage of the mutant field relationship table and the mutant field selection probability table in step S2, update the relationship values of each relevant mutant field in the mutant field relationship table and the probability values of the mutant field selection probability table, and quantitatively represent them. The specific steps include:
[0042] S2.6: Collect the covered branch information in step S2.5; after each test case is executed, determine whether there is a new covered branch. If there is a new covered branch, enter steps S2.7 and S2.8; if not, re-enter step S2.4.
[0043] S2.7: Update the relationship values in the mutant field relationship table and the probability values in the mutant field selection probability table. For all field tuples in the field relationship tuple set of step S2.3 update the relationship values in the mutant field relationship table and the probability values in the mutant field selection probability table.
[0044] S2.8 Update the valuable seed pool.
[0045] Preferably, for the update of the relationship value value in the mutant field relationship table, the specific steps are to find each field relationship tuple in the field relationship tuple set and splice the strings formed. Search for the specific leaf node and increment the value of the corresponding leaf node by 1. , )
[0046] For the update of the probability value in the mutant field selection probability table, the specific steps are as follows:
[0047] Perform a prefix match on the mutant field relationship table. The specific steps are to find the first half of each field relationship tuple in the field relationship tuple set and splice the strings formed. , ) Return all mutant fields, that is, leaf nodes, related to . The value of the leaf node is the relationship value. Map the value to a probability using the softmax formula. The formula is as follows:
[0048]
[0049] where, represents the selection probability of the field relationship tuple ( , ) y; takes values from 1 to v, representing the number of all related fields of the field with subscript 0 in the i-th data model;
[0050] Then, in the mutation field selection probability table, according to the string concatenated by the field relationship tuple ( , ), search for the specific leaf node and update the probability of the corresponding leaf node;
[0051] Preferably, in step S3, the collected coverage branch data information is visually presented in real time in the user interface, intuitively reflecting the test progress of the current fuzz testing.
[0052] A system for a protocol fuzz testing method based on cross-multiple states, including a test preparation module, a fuzz testing module, and a result information feedback module;
[0053] The test preparation module; provides the input of the data to be tested and pre-processes the input of the data to be tested; uses an instrumentation compilation tool to perform instrumentation compilation on the target protocol entity program to generate a corresponding binary executable file; refers to the official protocol specification of the target protocol entity program, writes a test template, and forms a data model set and a state model set ; opens up a shared memory ShareMem with a size of 64KB to statistically collect the coverage branch information of the target protocol entity program in real time;
[0054] The fuzz testing module; according to the sequential relationship of the data models in the state model , traverses the state model to obtain the data model , and then executes the recursive selection field combination stage therein; uses the probability selection algorithm of the tree array to select the mutation field set according to the mutation field relationship table , and performs value replacement or mutation on each mutation field to generate a test case , injects the test case into the target protocol entity program, collects feedback information, and then performs the update steps of the relationship values in the mutation field relationship table, the probability values in the mutation field selection probability table, and the valuable seed pool;
[0055] The result information feedback module; analyzes the result after the test case is input into the target protocol entity program, visually presents the collected coverage branch data information in real time in the user interface, and intuitively reflects the test progress of the current fuzz testing.
[0056] The present invention has the following technical effects:
[0057] 1. The transitivity of field relationships is used to perform combined mutations on the fields of data models of all adjacent related states, reducing unnecessary mutation operations. The mutation field relationships are efficiently used for combined mutations. By introducing the field relationship table and probability selection table between state data models, the branch coverage and test diversity are improved, effectively improving the test efficiency.
[0058] 2. The relationship values of the mutated fields in the data model before and after the dynamic calculation are used, and the relevant fields are selected through probability mapping. The probability selection algorithm is used instead of only selecting the field with the largest relationship value to improve the diversity of field selection. BRIEF DESCRIPTION OF THE DRAWINGS
[0059] Figure 1 It is a flowchart of the protocol fuzzy testing method based on multiple states of the present invention;
[0060] Figure 2 A schematic diagram of a data model set defined by the protocol fuzzy testing method across multiple states of the present invention, taking the RTSP protocol as an example;
[0061] Figure 3 A schematic diagram of a state model set defined by the protocol fuzzy testing method across multiple states of the present invention, taking the RTSP protocol as an example;
[0062] Figure 4 The present invention is based on the cross-multi-state protocol fuzzy testing method, taking the RTSP protocol as an example, and defines a recursive selection field schematic diagram. DETAILED DESCRIPTION
[0063] In order to make the objectives, technical solutions and advantages of the present invention more clear, the present invention is described in detail below with reference to the accompanying drawings.
[0064] like Figure 1 As shown, the protocol fuzz testing method based on cross-multi-states includes the following steps:
[0065] S1: Preprocess the target protocol entity program to prepare for testing;
[0066] S1.1: Use the stub compilation tool to perform stub compilation on the target protocol entity program to generate the corresponding binary executable file; Use the gcc and g++ compilation tools that come with AFL-Net to perform stub compilation on the target protocol entity program to generate the corresponding binary executable file. Its essence is to mark each static program block of the program under test. In the subsequent execution of a test case, the entire execution path of the test case can be determined according to different marks;
[0067] S1.2: Combine with the official protocol specification of the target protocol entity program, and use the data model definition function provided by the Boofuzz fuzz testing framework to define the protocol's data model set , and its calculation formula is:
[0068] ={ ,..., ,..., }, i = 1,…,n,
[0069] where n is the total number of data models;
[0070] S1.3: Use the state model definition function provided by the Boofuzz fuzz testing framework to define the protocol's state model set, and its calculation formula is:
[0071] ={ ,..., ,..., }, j = 1,…,m,
[0072] where represents a state model, and the state model is composed of several data models in the data model set in a certain order before and after, and m is the length of the state model set;
[0073] The defined data model set and the state model set are used as the protocol specification templates for generating new test cases;
[0074] As Figure 2 shown, using the RTSP protocol, the defined data model set = {Options, Description 1, Description 2, Setup, Announce, Record, Play, Pause, Stop, Get Parameters, Set Parameter 1, Set Parameter 2};
[0075] As Figure 3 shown, using the RTSP protocol, the defined state model set = {Description 1 -> Announce, Description 2 -> Announce, Options -> Record, Setup -> Get Parameters, Setup -> Set Parameter 1, Setup -> Set Parameter 2, Setup -> Play, Setup -> Play -> Pause, Setup -> Play -> Pause -> Stop};
[0076] S1.4: Run the binary executable file generated in step S1.1, and allocate a shared memory ShareMem with a size of 64KB. 64,000 bytes can represent 65,536 branches, which is greater than the number of branches of the vast majority of target protocol entity programs and can meet the branch coverage statistics requirements of the vast majority of target protocol entity programs to statistically count the covered branch information of the target protocol entity program in real time.
[0077] S2: Perform fuzz testing, which includes a recursive selection of field combinations phase and a replacement and mutation phase of valuable seeds during the fuzz testing process, and simultaneously update the mutation field relationship table and the mutation field selection probability table;
[0078] S2.1: State model selection; Select a state model sequentially from the state model set , and turn to step S2.2. If the traversal of the state model set ends, re-enter step S2.1 until the set test time ends;
[0079] S2.2: Data model selection; According to the order relationship of the data models in the state model in step S2.1 above, traverse the state model to obtain the data model , and initialize the mutation value of the data model , and turn to step S2.3. If the traversal of the state model ends, reset the target protocol entity program to the initial state and turn to step S2.1, The calculation formula for initializing the mutation value of the data model
[0080] is:
[0081] = DM,
[0082] where is the mutation value for initializing the data model , DM is the fixed number of mutations, and its value is the number of new test cases generated under the data model during the selection field mutation phase. Let DM = 2000;
[0083] Turn to step S2.3. If the traversal of the state model ends, reset the protocol entity program to the initial state and turn to step S2.1;
[0084] S2.3: Recursive selection of field combinations phase; Extract the mutation field set containing multiple mutation fields from the data model , and its calculation formula is:
[0085] = { ,..., ,..., }, where i = 1, …, n, f = 1, …, k,
[0086] where n is the total number of data models, and k is the number of mutated fields included in the data model;
[0087] The mutated field relationship table is a tree - like data structure of a prefix tree, specifically used for processing prefix matching of strings. The string saved by each non - leaf node is the data model name or field subscript, and the leaf node additionally contains the specific relationship value value;
[0088] The mutated field selection probability table is a tree - like data structure of a prefix tree, specifically used for processing prefix matching of strings. The string saved by each non - leaf node is the data model name or field subscript, and the leaf node additionally contains the specific selection probability value probability;
[0089] The probability selection algorithm of the binary indexed tree is a method for generating random samples that follow a specified probability distribution, especially suitable for discrete probability distributions. Its main idea is to use the binary indexed tree to assist in the rapid construction, query, and update operations of the cumulative probability table. Because binary search is used, the time complexity is O( ), thus supporting efficient discrete probability selection. This algorithm has been tested with millions of samples, and the results conform to the expected discrete probability distribution.
[0090] The sampling process of the original probability array P using the probability selection algorithm of the binary indexed tree is as follows:
[0091] 1) Initialize the binary indexed tree: Create a binary indexed tree with a length of N + 1 and initialize all elements to 0. One more element in the array is because the binary indexed tree usually starts with index 1, and N is the length of the original probability array;
[0092] 2) Build the binary indexed tree; Traverse the probability array P, and for each event, update it in the binary indexed tree. This process involves defining an update function, which is responsible for adding a value at a given subscript position and then adjusting the relevant nodes. Specifically, the function starts from this subscript and moves upward step - by - step by performing a bit - wise AND operation between the current subscript and its binary complement until it exceeds the array length.
[0093] 3) Sampling process: calculate the total weight (i.e., cumulative probability sum), generate a random floating point number between 0 and the total weight, use the binary search algorithm to determine which event's cumulative probability interval the random number belongs to, and traverse the prefix sum to determine the appropriate event subscript.
[0094] Under the guidance of the variant field selection probability table, a probability selection algorithm of a tree array is used to select a field relation tuple from the variant field relation table according to probability ( , ),in Is the current data model The string concatenated with the model name and the variant field subscript. Is the current data model In the state model The previous data model in The model name and the variant field subscript concatenated string, and then according to Select data model in the relationship table of demutated fields In the state model The field relation tuple of the previous data model in If the value of all fields in the previous data model is 0, then Select from all the fields in the previous data model until the state model is traversed Data model in; add all selected field relation tuples to the field relation tuple set , after each test, the field relation tuple set Clear; set the field relation tuple Each variant field in is added to the variant field collection , clear the collection after each test; Figure 4 As shown, a schematic diagram of a recursive selection field defined using the RTSP protocol;
[0095] S2.4: Replacement and mutation phase of valuable seeds; set of mutation fields in step S2.3 Mutate or replace the value of each field in the , and add all mutated fields to the mutated field value set In the example, after each test, the mutated field value set Clear; generate data model The mutated data packet , thus forming a data packet set , and its calculation formula is:
[0096] ={ ,..., ,...,}, l = 1, …, s,
[0097] where s is the total number of data models in the state model, and this set is cleared after each test;
[0098] Combine the data packets in the data packet set in the order of the state model to generate test cases ; The test cases contain data packets after field mutation or value replacement for each data model in the state model ;
[0099] S2.5: Inject the test cases into the target protocol entity program, and count the covered branch information of the shared memory ShareMem opened and the status information returned by the target protocol entity program.
[0100] When the test cases generated in step S2.4 cause the target protocol entity program to crash, exception logging is performed and the test cases are saved for vulnerability analysis work after the test ends.
[0101] Add the values that can increase the covered branches in the mutated field value set collected in step S2.4 to the valuable seed pool, and preferentially use the values in the valuable seed pool for replacement or mutation.
[0102] In the update stage of the mutated field relationship table and the mutated field selection probability table in step S2, update the relationship values of each relevant mutated field in the mutated field relationship table and the probability values of the mutated field selection probability table, and quantitatively represent them. The specific steps include:
[0103] S2.6: Collect the covered branch information in step S2.5; After each test case is executed, determine whether there are new covered branches. If there are new covered branches, enter steps S2.7 and S2.8. If not, re-enter step S2.4;
[0104] S2.7: Update the relationship values in the mutated field relationship table and the probability values in the mutated field selection probability table. For all field tuples in the field relationship tuple set in step S2.3, update the relationship values in the mutated field relationship table and the probability values in the mutated field selection probability table;
[0105] S2.8 Update the valuable seed pool.
[0106] Update of the relationship value value in the mutant field relationship table. The specific steps are to search for the set of field relationship tuples in each field relationship tuple ( , ) to splice the resulting string, search for the specific leaf node, and increment the value of the corresponding leaf node by 1;
[0107] Update of the probability value in the mutant field selection probability table. The specific steps are as follows:
[0108] Perform prefix matching on the mutant field relationship table. The specific steps are to search for the set of field relationship tuples in each field relationship tuple ( , ) for the first half to splice the resulting string, and return all mutant fields (i.e., leaf nodes) related to . The value of the leaf node is the relationship value. Map the value to a probability using the softmax formula. The formula is as follows:
[0109]
[0110] where, represents the selection probability of the field relationship tuple ( , ) y; takes values from 1 to v, representing the number of all related fields of the field with index 0 in the i-th data model;
[0111] Then, in the mutant field selection probability table, based on the string spliced from the field relationship tuple ( , ), search for the specific leaf node and update the probability of the corresponding leaf node;
[0112] S3: Provide feedback on the result information.
[0113] In step S3, the collected coverage branch data information is visually presented in real time in the user interface to intuitively feedback the test progress of the current fuzz testing. At the same time, the number of times the target protocol entity program crashes is tracked and displayed in real time to ensure timely identification of system stability risks. In addition, the system automatically records and saves in detail each test case that causes the target protocol entity program to crash , providing a key basis for subsequent crash reproduction and in-depth analysis.
[0114] For this embodiment, experimental verification was carried out on the RTSP protocol and the MQTT protocol. Among them, the control group selected the currently most advanced fuzzer Boofuzz. The time for each group of experiments was 24H. In order to reduce the influence of randomness in fuzz testing, all experiments were repeated three times, and the results were averaged.
[0115] The experimental results are shown in Table 1 below:
[0116] Table 1
[0117] Target protocol Target protocol implementation Number of branches covered by Boofuzz Number of branches covered by this embodiment Improvement of this embodiment compared to Boofuzz RTSP Live555 3023 3216 6.4% MQTT mosquitto 1942 2057 5.9%
[0118] As can be seen from Table 1 above, in the RTSP protocol, the number of covered branches in this embodiment is 193 more than that of Boofuzz, with a relative increase of 6.4%; in the MQTT protocol, the number of covered branches in this embodiment is 115 more than that of Boofuzz, with a relative increase of 5.9%; this embodiment has a significant improvement in the number of covered branches. This embodiment uses the transitivity of field relationships to combine and mutate the fields of the data models of all adjacent related states, reducing unnecessary mutation operations, and efficiently using the mutated field relationships for combined mutation. By introducing a field relationship table and a probability selection table between state data models, the branch coverage rate and test diversity are improved, effectively enhancing the test efficiency.
[0119] Any of the above methods or steps can be stored as computer instructions or programs in various types of computer memories, and the computer instructions or programs can be recognized by various types of computer processors, thereby implementing any of the above methods or steps.
[0120] The above-described embodiments are only descriptions of the preferred embodiments of the present invention, and do not limit the scope of the present invention. Without departing from the design spirit of the present invention, various deformations and improvements made by those of ordinary skill in the art to the technical solutions of the present invention shall fall within the protection scope determined by the claims of the present invention.
Claims
1. A protocol fuzz testing method based on multiple states, characterized by: The steps include: S1: Preprocess the target protocol entity program to prepare for testing; S2: Perform fuzz testing, which includes a recursive field combination selection phase and a valuable seed replacement and mutation phase, and simultaneously updates the mutation field relationship table and the mutation field selection probability table; S3: Feedback on the result information; The specific steps of step S1 include: S1.1: Use the stub compilation tool to perform stub compilation on the target protocol entity program to generate the corresponding binary executable file; S1.2: Combined with the official protocol specification of the target protocol entity program, use the data model definition function provided by the Boofuzz fuzz testing framework to define the data model set of the protocol , and its calculation formula is: ={ ,..., ,..., }, i=1,…,n, Where n is the total number of data models; S1.3: Use the state model definition function provided by the Boofuzz fuzz testing framework to define the state model set of the protocol. The calculation formula is: ={ ,..., ,..., }, j=1,…,m, in, Represents a state model, which is a collection of data models It is composed of several data models, and m is the length of the state model set; S1.4: Run the binary executable file generated in step S1.1, and open a shared memory ShareMem of 64KB, and count the coverage branch information of the target protocol entity program in real time; The specific steps of step S2 include: S2.1: State model selection; from the state model set Select a state model in order , go to step S2.2, if the state model set When the traversal is completed, the process re-enters step S2.1 until the set test time is over; S2.2: Data model selection; based on the state model in step S2.1 above The sequential relationship of the data model in the traversal state model Get the data model , and initialize the data model The mutation value of , go to step S2.3, if for the state model When the traversal is completed, the target protocol entity program is reset to the initial state and goes to step S2.
1. Initialize the data model The calculation formula of the variation value is: =DM, in, To initialize the data model The mutation value, DM is the fixed number of mutations, which is taken in the data model during the field selection phase. The number of new test cases generated under S2.3: Recursive selection of field combination phase; extracting data model A collection of mutation fields consisting of multiple mutation fields , and its calculation formula is: ={ ,..., ,..., }, i=1,…,n ,f=1,…,k, Among them, n is the total number of data models, k is the number of data models The number of variant fields included in ; The variant field relationship table is a tree data structure of a prefix tree, which is used to process string prefix matching. The string stored in each non-leaf node is the data model name or field subscript, and the leaf node also contains the specific relationship value; The variant field selection probability table is a tree data structure of a prefix tree, which is used to process string prefix matching. The string stored in each non-leaf node is the data model name or field subscript, and the leaf node also contains the specific selection probability value probability; Under the guidance of the variant field selection probability table, a probability selection algorithm of a tree array is used to select a field relation tuple from the variant field relation table according to probability ( , ),in Is the current data model The string concatenated with the model name and the variant field subscript. Is the current data model In the state model The previous data model in The model name and the variant field subscript concatenated string, and then according to Select data model in the relationship table of demutated fields In the state model The field relation tuple of the previous data model in If the value of all fields in the previous data model is 0, then Select from all the fields in the previous data model until the state model is traversed Data model in; add all selected field relation tuples to the field relation tuple set , after each test, the field relation tuple set Clear; set the field relation tuple Each variant field in is added to the variant field collection , clear the collection after each test; S2.4: Replacement and mutation phase of valuable seeds; set of mutation fields in step S2.3 Mutate or replace the value of each field in the , and add all mutated fields to the mutated field value set In the example, after each test, the mutated field value set Clear; generate data model The mutated data packet , thus forming a data packet set , and its calculation formula is: ={ ,..., ,..., }, l=1,…,s, Among them, s is the state model The total number of data models in the set, and the set is cleared after each test; Gathering Data Packets The data packets in the state model The sequential combination of ; Test cases The state model is included The data packet after the field mutation or value replacement of each data model in the data; S2.5: Test cases Inject into the target protocol entity program, count the coverage branch information of the opened shared memory ShareMem and the status information returned by the target protocol entity program; The specific steps of step S2 also include: When the test case generated in step S2.4 When the target protocol entity program crashes, the exception log is recorded and the test case is saved , used for vulnerability analysis after the test; The mutated field value set collected in step S2.4 Increase the value of the coverage branch, add it to the valuable seed pool, and give priority to using the value in the valuable seed pool for replacement or mutation; In the update phase of the mutation field relationship table and the mutation field selection probability table in step S2, the relationship values of the relevant mutation fields in the mutation field relationship table and the probability values of the mutation field selection probability table are updated and quantitatively represented. The specific steps include: S2.6: Collect the coverage branch information of step S2.5; in each test case After execution, determine whether there is a new coverage branch. If there is a new coverage branch, go to step S2.7 and step S2.
8. If not, go back to step S2.
4. S2.7: Update the relationship values in the mutation field relationship table and the probability values in the mutation field selection probability table. For the field relationship tuple set in step S2.3 All the field tuples in the mutated field relationship table are updated with relation values, and the mutated field selection probability table is updated with probability values; S2.8 Update of valuable seed pool; Update the relation value in the mutated field relation table. The specific steps are to find the field relation tuple set. Each field relation tuple in , ) to search for a specific leaf node and add 1 to the value of the corresponding leaf node; The probability value in the mutation field selection probability table is updated. The specific steps are: Prefix matching is performed on the variant field relationship table. The specific steps are to find the field relationship tuple set Each field relation tuple in , ) The concatenated string will be returned with All relevant variant fields are leaf nodes. The value of the leaf node is the relationship value. The value is mapped to probability and the softmax formula is used. The formula is as follows: , Among them, probability represents the field relation tuple ( , )’s selection probability; The value of ranges from 1 to v, which is the number of all relationship fields with the field with index 0 in the i-th data model; Then, in the variant field selection probability table, according to the field relationship tuple ( , ) to search for a specific leaf node and update the probability of the corresponding leaf node.
2. The protocol fuzz testing method based on spanning multiple states according to claim 1 is characterized in that: The step S3 presents the collected coverage branch data information in real time and visually in the user interface, providing intuitive feedback on the test progress of the current fuzz test.
3. A system comprising the protocol fuzz testing method based on multiple states according to claim 1, characterized in that: It includes test preparation module, fuzzy test module and result information feedback module; Test preparation module: providing test data input and pre-processing the test data input; Use the stub compilation tool to perform stub compilation on the target protocol entity program to generate the corresponding binary executable file; refer to the official protocol specification of the target protocol entity program, write a test template, and form a data model set and state model collection ; Open up a 64KB shared memory ShareMem to count the coverage branch information of the target protocol entity program in real time; Fuzz testing module; state model The sequential relationship of the data model in the traversal state model Get the data model , and then execute the recursive field selection stage; use the tree array probability selection algorithm to select the mutation field set according to the mutation field relationship table , and replace or mutate the value of each mutated field to generate test cases , the test case Inject into the target protocol entity program, collect feedback information, and then update the relationship value in the mutation field relationship table, the probability value in the mutation field selection probability table, and the valuable seed pool; Result information feedback module; for test cases The results after being input into the target protocol entity program are analyzed, and the collected coverage branch data information is visualized in real time in the user interface, providing intuitive feedback on the test progress of the current fuzz test.
Citation Information
Patent Citations
Parallel fuzzy test method, system and device, storage medium and product
CN118708470A
Network protocol fuzz testing method and device based on state guidance and seed variation
CN119402400A
Protocol fuzz testing method and system based on multi-dimensional feedback information
CN119561879A