Industrial control protocol vulnerability automatic fuzzy test method

By introducing the GRU-SACNNFuzzer model in industrial control systems, the global characteristics of the self-attention layer and the GRU/convolutional neural network learning protocol are used to solve the problem of low vulnerability mining efficiency in the existing technology, and achieve higher test case pass rate and abnormal discovery capabilities.

CN119938499APending Publication Date: 2025-05-06CHENGDU YISHUQIAO TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311420714.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-10-30
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

The prior art has low vulnerability mining efficiency in industrial control systems and is difficult to effectively utilize the global characteristics of the protocol, resulting in low pass rate of test cases and insufficient abnormal discovery capabilities.

Method used

A GRU-SACNNFuzzer model is proposed. By introducing a self-attention layer into the generator and discriminator of the generative adversarial network, the global features of the protocol are learned, and combined with the GRU neural network and the convolutional neural network, the protocol features are comprehensively learned from the two dimensions of timing and space.

Benefits of technology

Improve the test case pass rate, enhance the abnormal discovery ability and the diversity of samples generated, and improve execution efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure SMS_1
    Figure SMS_1
  • Figure SMS_4
    Figure SMS_4
  • Figure SMS_5
    Figure SMS_5
Patent Text Reader

Abstract

The invention provides an automatic high-efficiency fuzz test model GRU-SACNNFuzzer for solving the problems that a traditional fuzz test based on generation depends on manual extraction protocol specifications, the test case passing rate is low and the like. Aiming at the fact that only local features of protocol fields are considered when protocol specifications are extracted in an existing fuzzy test method, self-attention layers are introduced into a generator and a discriminator of the generative adversarial network, and overall connection between the protocol fields is considered, so that global features of a protocol are learned. In order to solve the problem that only the time step dimension feature of a protocol is considered and the spatial structure feature of the protocol is ignored in the existing research, the invention provides a combined network of a gated recurrent neural network and a self-attention convolutional neural network as a discriminator, and the feature information of the protocol is fully learned from the two dimensions. The model provided by the invention has better performance in the aspect of test case passing rate, and meanwhile, the model provided by the invention also has stronger exception discovery capability and better generated sample diversity, and is higher in execution efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to industrial control processing, and specifically relates to an automatic fuzzy testing method for industrial control protocol vulnerabilities, which is used to realize automatic and efficient mining of protocol vulnerabilities in industrial control systems. Background Art

[0004] There is an urgent need to take high-performance measures to mine and prevent vulnerabilities in industrial control systems. However, since the architecture of ICS networks is significantly different from that of traditional Internet networks, the real-time and continuity of communication between devices has a deeper impact, while the security of communication is neglected. It is also relatively easy to exploit system vulnerabilities in current industrial control systems. The security of industrial control systems is still an urgent task, and it is urgent to develop industrial control vulnerability mining technologies with high efficiency, strong discovery capabilities, and wide adaptability.

[0005] In summary, it is necessary to design an automatic fuzz testing method for industrial control protocol vulnerabilities. Summary of the invention

[0006] In view of the problems that traditional generation-based fuzz testing relies on manual extraction of protocol specifications and has a low test case pass rate, the present invention proposes an automatic and efficient fuzz testing model GRU-SACNNFuzzer. In view of the fact that the existing fuzz testing methods only consider the local features of the protocol fields when extracting protocol specifications, the present invention introduces a self-attention layer in both the generator and the discriminator of the generative adversarial network, considering the overall connection between the protocol fields, thereby learning the global features of the protocol. In view of the fact that existing studies only consider the time step dimension features of the protocol and ignore the spatial structured features of the protocol, the present invention proposes a joint network of GRU-SACNN as a discriminator, which fully learns the feature information of the protocol from these two dimensions. Due to the better degree of learning of protocol features, the model proposed by the present invention has better performance in the test case pass rate. At the same time, the model proposed by the present invention also has a stronger anomaly detection ability and better generation sample diversity, and has higher execution efficiency.

[0007] The technical solution adopted by the present invention comprises the following steps:

[0008] Step 1: Collect industrial control protocol sample data in an industrial control environment.

[0009] Step 2: Preprocess the data, including two-dimensional data type conversion, data clustering, and data amplification.

[0010] Step 3: Generate fuzzy test cases based on the protocol structure and key fields.

[0011] Step 3.1: Use a generative adversarial network. The generator uses random noise as the initial input and outputs a test sample. The discriminator determines the authenticity of the sample generated by the generator. Finally, the generator can generate samples that conform to the real data, and the discriminator can distinguish the test samples generated by the generator from the real data.

[0012] Step 3.2: The generator uses convolution to extract local protocol feature information and uses the self-attention layer to extract global feature information. The calculation formula of the self-attention layer is as follows:

[0013] s ij =f(x i ) T g(x j )

[0014]

[0015] Where f(x) = W f (x), g(x) = W g (x), h(x) = W h (x) are three feature spaces, including the protocol feature information obtained by convolution. W is the weight matrix of 1×1 convolution, which will be continuously updated during the training process; in order to obtain the attention relationship matrix S, the feature space f(x) at position i is i ) after transposition and the feature space g(x j ) to obtain s containing the interaction relationship between positions i and j ij ; Further activation by softmax activation function obtains the attention weight relationship β between positions i and j j,i . β j,i It refers to the attention weight of the j-th sequence feature part to the i-th part when learning sequence features.

[0016] Step 3.3: Relate the self-attention weight relationship β j,i Perform matrix dot multiplication with the h(x) feature space to form the output of the attention layer As shown in the formula:

[0017]

[0018] h(x)=W h x i ,v(x)=W v x i

[0019] Step 3.4: After obtaining the output o of the attention layer, further multiply the output of the attention layer by the scale parameter γ, and add the output with the self-attention weight relationship to the input feature map xi The final output of the self-attention layer is obtained, that is, the self-attention feature map y i , as shown in the formula:

[0020] y i =γo i +x i

[0021] Step 3.5: Use a gated recurrent neural network (GRU) to learn the temporal features of the protocol data.

[0022] Step 3.6: Use the output of the GRU network together with the output of the generator as the input data of the discriminator to judge its authenticity.

[0023] Step 4: Send the fuzz test case to the target device or simulator for testing.

[0024] Step 5: Monitor the response of the target device or simulator to detect whether the vulnerability is triggered.

[0025] Step 6: Based on the recorded vulnerability information, optimize the fuzzy test case generation algorithm to improve the vulnerability discovery rate.

[0026] Positive effects of the present invention

[0027] (1) The present invention uses a generative adversarial network to automatically generate samples that are identical in format and similar in content to real protocol data, which can pass the detection of the target application and discover vulnerabilities.

[0028] (2) The present invention proposes a self-attention layer in the generative adversarial network, which can extract the connection between different fields of the protocol and learn the global feature information of the protocol.

[0029] (3) The present invention uses a GRU neural network model to learn the temporal features of the protocol, and uses a convolutional neural network combined with a self-attention layer to learn the spatial structural features of the protocol. BRIEF DESCRIPTION OF THE DRAWINGS

[0030] Figure 1 It is a schematic diagram of the model design of the implementation method of the present invention.

[0031] Figure 2 It is a basic flow chart of the implementation method of the present invention. DETAILED DESCRIPTION

[0032] The present invention is generally divided into five processes. Data collection: Collect sample data of industrial control protocols, including protocol messages, commands and responses, etc.; Test case generation: Based on the collected sample data, a large number of test cases are generated through fuzz testing technology. These test cases will cover various boundary conditions and abnormal conditions of the protocol to detect potential vulnerabilities; Test execution: Send the generated test cases to the target device or simulator for testing. These test cases may contain intentionally constructed malicious data in an attempt to trigger vulnerabilities in the protocol; Response monitoring: Monitor the response of the target device or simulator to detect whether a vulnerability is triggered. The presence of a vulnerability can be determined by monitoring the abnormal behavior, error response or crash of the device; Vulnerability recording. Among them, the specific implementation method of the technical solution adopted is as follows:

[0033] Step 1: Collect industrial control protocol sample data in an industrial control environment.

[0034] Step 2: Preprocess the data, including two-dimensional data type conversion, data clustering, and data amplification.

[0035] Step 3: Generate fuzzy test cases based on the protocol structure and key fields.

[0036] Step 3.1: Use a generative adversarial network. The generator uses random noise as the initial input and outputs a test sample. The discriminator determines the authenticity of the sample generated by the generator. Finally, the generator can generate samples that conform to the real data, and the discriminator can distinguish the test samples generated by the generator from the real data.

[0037] Step 3.2: The generator uses convolution to extract local protocol feature information and uses the self-attention layer to extract global feature information. The calculation formula of the self-attention layer is as follows:

[0038] s ij =f(x i ) T g(x i )

[0039]

[0040] Where f(x) = W f (x), g(x) = W g (x), h(x) = W h (x) are three feature spaces, including the protocol feature information obtained by convolution. W is the weight matrix of 1×1 convolution, which will be continuously updated during the training process; in order to obtain the attention relationship matrix S, the feature space f(x) at position i is i ) after transposition and the feature space g(x j) to obtain s containing the interaction relationship between positions i and j ij ; Further activation by softmax activation function obtains the attention weight relationship β between positions i and j j,i . β j,i It refers to the attention weight of the j-th sequence feature part to the i-th part when learning sequence features.

[0041] Step 3.3: Relate the self-attention weight relationship β j,i Perform matrix dot multiplication with the h(x) feature space to form the output of the attention layer As shown in the formula:

[0042]

[0043] h(x)=W h x i ,v(x)=W v x i

[0044] Step 3.4: After obtaining the output o of the attention layer, further multiply the output of the attention layer by the scale parameter γ, and add the output with the self-attention weight relationship to the input feature map x i The final output of the self-attention layer is obtained, that is, the self-attention feature map y i , as shown in the formula:

[0045] y i =γo i +x i

[0046] Step 3.5: Use a gated recurrent neural network (GRU) to learn the temporal features of the protocol data.

[0047] Step 3.6: Use the output of the GRU network together with the output of the generator as the input data of the discriminator to judge its authenticity.

[0048] Step 4: Send the fuzz test case to the target device or simulator for testing.

[0049] Step 5: Monitor the response of the target device or simulator to detect whether the vulnerability is triggered.

[0050] Step 6: Based on the recorded vulnerability information, optimize the fuzzy test case generation algorithm to improve the vulnerability discovery rate.

Claims

1. An automatic fuzzy testing method for industrial control protocol vulnerabilities, characterized in that: The steps are as follows: An automatic fuzzy testing method for industrial control protocol vulnerabilities is characterized by the following steps: step 1: collecting industrial control protocol sample data; step 2: preprocessing the sample data, including analyzing the protocol structure and extracting key fields; step 3: generating fuzzy test cases based on the protocol structure and key fields; Step 4: Send the fuzz test case to the target device or simulator for testing; Step 5: Monitor the response of the target device or simulator to detect whether the vulnerability is triggered; Step 6: Record the test case and related information triggered by the vulnerability; Step 7: According to the recorded vulnerability information, optimize the fuzz test case generation algorithm to improve the vulnerability discovery rate; Step 8: Repeat steps 4 to 7 until the preset test goal is achieved.

2. According to claim 1, the method for automatic fuzzy testing of industrial control protocol vulnerabilities is characterized by: Learn the protocol structure and field features to generate fuzzy test cases; send the test cases to the target device for testing.

3. According to claim 1, the method for automatic fuzzy testing of industrial control protocol vulnerabilities is characterized by: The protocol feature learning is performed using a joint model of self-attention generative adversarial network and gated recurrent neural network (GRU); the formula of the self-attention layer is as follows: s ij =f(x i ) T g(x j ) Where f(x) = W f (x), g(x) = W g (x), h(x) = W h (x) are three feature spaces, including the protocol feature information obtained by convolution, where W is the weight matrix of 1×1 convolution, which will be continuously updated during the training process; in order to obtain the attention relationship matrix S, the feature space f(x) at position i is i ) after transposition and the feature space g(x j ) to obtain s containing the interaction relationship between positions i and j ij ; Further activation by softmax activation function obtains the attention weight relationship β between positions i and j j,i , β j,i It refers to the attention weight of the j-th sequence feature part to the i-th part when learning sequence features.

4. According to claim 1, the method for automatic fuzzy testing of industrial control protocol vulnerabilities is characterized by: By calculating the self-attention weight relationship between different protocol fields, the global feature information of the protocol is obtained.

5. The method for automatic fuzzy testing of industrial control protocol vulnerabilities according to claim 1 is characterized in that: The temporal features are learned through the GRU neural network, the spatial structure features are learned through the convolutional neural network combined with the self-attention layer, and the authenticity of the generated samples is judged in the discriminator of the generative adversarial model.