Ethereum virtual machine fuzz testing method and device
By parsing and mutating the WebAssembly files of the Ethereum virtual machine, and generating diverse test inputs, it solves the problem that existing fuzz testing solutions are difficult to detect deep Ewasm code, and achieves efficient vulnerability detection.
Patent Information
- Application Number
- CN202510093397.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-20
- Publication Date
- 2025-05-13
AI Technical Summary
The existing Ethereum virtual machine fuzz testing scheme is difficult to detect deep-level Ewasm code, and there are problems such as poor test input validity, high randomness of mutation strategies, and low success rate of vulnerability discovery.
Provides an Ethereum virtual machine fuzz testing method, which can obtain WebAssembly files as test seeds, parse and mutate the parsing tree, generate diversified test inputs, improve the effectiveness of test inputs, and optimize vulnerability detection efficiency through snapshot pooling mechanism.
It realizes effective detection of deep-level Ewasm code, improves the effectiveness of test input and the success rate of vulnerability discovery, and is suitable for vulnerability detection of WebAssembly virtual machines.
Smart Images

Figure CN119987946A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of blockchain technology, and in particular to an Ethereum virtual machine fuzzy testing method and device. Background Art
[0002] Ethereum WebAssembly (Ewasm) is an important project in the Ethereum blockchain. Ewasm uses the WebAssembly standard as the execution engine of smart contracts, making the Ethereum network more flexible and efficient. However, although Ewasm has brought performance improvements to the Ethereum virtual machine execution environment, it has also inevitably introduced new security issues. Since the Ewasm input is a binary WebAssembly file, the existing fuzz testing scheme for the Ethereum virtual machine is difficult to detect deep Ewasm code, and there are problems such as poor test input validity, high randomness of mutation strategies, and low success rate of vulnerability discovery. Summary of the invention
[0003] One or more embodiments of this specification provide an Ethereum virtual machine fuzz testing method and device, which can mutate a variety of test inputs to detect deep-level Ewasm codes and improve the effectiveness of test inputs, and is particularly suitable for WebAssembly virtual machines.
[0004] In a first aspect, an Ethereum virtual machine fuzz testing method is provided, which is applicable to an Ethereum WebAssembly virtual machine. The method includes at least one round of fuzz testing, and each round of fuzz testing includes:
[0005] Obtain a WebAssembly file as a test seed, and input the test seed into a target WebAssembly virtual machine to run and obtain running information;
[0006] Parsing the test seed to obtain a parse tree;
[0007] Mutating the parse tree to obtain all variant parse trees of the parse tree;
[0008] Converting a variant parse tree of the parse tree into a WebAssembly file and inputting it into a target WebAssembly virtual machine for running, determining whether the variant parse tree is valid according to running information, and storing the valid variant parse tree as a seed parse tree in a snapshot pool;
[0009] For each seed parse tree in the snapshot pool, the seed parse tree is mutated and converted into a WebAssembly file, which is input into the target WebAssembly virtual machine for execution, and whether the mutated parse tree of the seed parse tree is valid is determined according to the operation information, and the valid mutated parse tree is stored as a new seed parse tree in the snapshot pool; this step is repeated until the snapshot pool is empty.
[0010] As an optional implementation manner of the method of the first aspect, the running information includes running process information of the target WebAssembly virtual machine; and determining whether the variant parse tree is valid according to the running information specifically includes:
[0011] According to the running process information of the target WebAssembly virtual machine, it is determined whether a new execution path is found or a new code area is covered during this running process. If a new execution path is found or a new code area is covered, it is determined that the variant parse tree is valid; otherwise, it is determined that the variant parse tree is invalid.
[0012] As an optional implementation manner of the method of the first aspect, the running information includes state information after the target WebAssembly virtual machine runs; and determining whether the variant parse tree is valid according to the running information specifically includes:
[0013] According to the state information after the target WebAssembly virtual machine runs, it is determined whether the target WebAssembly virtual machine crashes. If so, it is determined that the variant parse tree is valid; otherwise, it is determined that the variant parse tree is invalid.
[0014] As an optional implementation manner of the method of the first aspect, mutating the parse tree to obtain all mutated parse trees of the parse tree specifically includes:
[0015] Select a target node in the parse tree;
[0016] A mutation method is determined according to the node type of the target node, and the target node is mutated using the mutation method.
[0017] Specifically, selecting a target node in the parse tree specifically includes:
[0018] At least one of a branch node and a leaf node in the parse tree is selected as the target node using the Thompson sampling algorithm.
[0019] More specifically, determining a mutation mode according to the node type of the target node, and using the mutation mode to mutate the target node specifically includes:
[0020] If the target node is a branch node in the parse tree, performing structural mutation on the target node;
[0021] If the target node is a leaf node in the parse tree, data mutation is performed on the target node.
[0022] Specifically, the method further includes:
[0023] After the parse tree is mutated, the target node and nodes associated with the target node in the mutated parse tree are repaired from bottom to top, so that the mutated parse tree can be correctly parsed.
[0024] In a second aspect, an Ethereum virtual machine fuzz testing device is provided, which is applicable to an Ethereum WebAssembly virtual machine, and the device is used to perform at least one round of fuzz testing on the Ethereum WebAssembly virtual machine, and the device includes:
[0025] A data acquisition module is configured to acquire a WebAssembly file as a test seed in each round of fuzz testing, and input the test seed into a target WebAssembly virtual machine to run and obtain running information;
[0026] A parsing module, configured to parse the test seed to obtain a parse tree;
[0027] The fuzz testing module is configured to mutate the parse tree to obtain all mutated parse trees of the parse tree; convert the mutated parse trees of the parse tree into WebAssembly files and input them into a target WebAssembly virtual machine for running, determine whether the mutated parse trees are valid according to running information, and store the valid mutated parse trees as seed parse trees in a snapshot pool; for each seed parse tree in the snapshot pool, mutate the seed parse tree and convert it into a WebAssembly file and input it into a target WebAssembly virtual machine for running, determine whether the mutated parse trees of the seed parse tree are valid according to running information, and store the valid mutated parse trees as new seed parse trees in the snapshot pool; repeat this step until the snapshot pool is empty.
[0028] As an optional implementation manner of the device described in the second aspect, the fuzz testing module includes a mutation module and a conversion module; the mutation module is configured to mutate the input target parse tree; the conversion module is configured to convert the input target parse tree into a WebAssembly file.
[0029] Specifically, the mutation module is specifically used to select a target node in the parse tree; determine a mutation method according to a node type of the target node, and mutate the target node using the mutation method.
[0030] More specifically, the mutation module is specifically used to select at least one of a branch node and a leaf node in the parse tree as the target node by using the Thompson sampling algorithm.
[0031] More specifically, the mutation module is specifically used for:
[0032] When the target node is a branch node in the parse tree, performing structural mutation on the target node;
[0033] When the target node is a leaf node in the parse tree, data mutation is performed on the target node.
[0034] Specifically, the fuzz testing module also includes a repair module, which is configured to perform bottom-up repair on the target node and nodes associated with the target node in the mutated parse tree after mutating the parse tree, so that the mutated parse tree can be correctly parsed.
[0035] In a third aspect, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the processor executes the above-mentioned Ethereum virtual machine fuzz testing method.
[0036] In a fourth aspect, an electronic device is provided, including:
[0037] One or more processors; and a memory associated with the one or more processors, the memory being used to store program instructions, which, when read and executed by the one or more processors, cause the electronic device to execute the above-mentioned Ethereum virtual machine fuzz testing method.
[0038] The beneficial effect of the Ethereum virtual machine fuzz testing method described in one or more embodiments of this specification is that the method randomly obtains a WebAssembly file as a test seed in each round of testing, generates a parse tree of the test seed, and generates diversified test inputs with a high vulnerability triggering success rate based on the structural variation and validity test of the parse tree, so as to achieve a wide range, high efficiency, and high vulnerability triggering success rate Ethereum WebAssembly virtual machine vulnerability detection solution. The Ethereum virtual machine fuzz testing device described in the embodiments of this specification also has the above beneficial effects. BRIEF DESCRIPTION OF THE DRAWINGS
[0039] In order to more clearly illustrate the embodiments of this specification or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this specification. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0040] Figure 1 A flowchart of an Ethereum virtual machine fuzz testing method provided for one or more embodiments of this specification.
[0041] Figure 2 A schematic diagram of the structure of a parsing tree provided for one or more embodiments of this specification.
[0042] Figure 3 A schematic diagram of a parsing tree mutation process provided in one or more embodiments of this specification.
[0043] Figure 4 A schematic diagram of the structure of an Ethereum virtual machine fuzz testing device provided for one or more embodiments of this specification.
[0044] Figure 5 A schematic diagram of the structure of an electronic device provided in one or more embodiments of this specification. DETAILED DESCRIPTION
[0045] In order to enable those skilled in the art to better understand the technical solutions in this specification, the technical solutions in the embodiments of this specification will be clearly and completely described below in conjunction with the drawings in the embodiments of this specification. Obviously, the described embodiments are only part of the embodiments of this specification, not all of the embodiments. Based on the embodiments in this specification, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of this specification.
[0046] It should be noted that: in other embodiments, the steps of the corresponding method are not necessarily performed in the order shown and described in this specification. In some other embodiments, the steps included in the method may be more or less than those described in this specification. In addition, a single step described in this specification may be decomposed into multiple steps for description in other embodiments; and multiple steps described in this specification may be combined into a single step for description in other embodiments.
[0047] Those skilled in the art will appreciate that the terms used in the embodiments of the present invention are only for the purpose of describing specific embodiments, and are not intended to limit the present invention. The singular forms of "a", "said" and "the" used in the embodiments of the present invention and the appended claims are also intended to include plural forms, unless the context clearly indicates other meanings.
[0048] Ethereum Virtual Machine (EVM), as an important part of the Ethereum blockchain, is the execution environment for running smart contracts. EVM provides a set of instructions, including various opcodes, for performing arithmetic operations, logical operations, data storage and loading, contract calls and other operations. However, the current EVM architecture is very rigid and only supports low-performance programming languages such as Solidity, with low execution efficiency, which can easily cause congestion in the Ethereum network and limit the scalability of the network.
[0049] Ethereum WebAssembly (Ewasm) is an important project in the Ethereum blockchain, which aims to introduce WebAssembly as the execution environment for smart contracts. Unlike the traditional EVM, Ewasm uses the WebAssembly standard as its execution engine, making the Ethereum network more flexible and efficient; by enhancing transaction processing capabilities, it allows each block to contain more transactions per second, thereby improving the throughput and performance of the Ethereum network. However, although Ewasm has brought performance improvements to the Ethereum virtual machine execution environment, it has also inevitably introduced new security issues. The security vulnerabilities of the Ewasm virtual machine urgently need to be effectively detected and prevented.
[0050] At present, the industry usually adopts fuzz testing methods to address traditional EVM security issues, that is, by inputting unexpected smart contracts into the virtual machine and monitoring the abnormal results output by the virtual machine to discover vulnerabilities in the virtual machine.
[0051] However, the input of Ewasm is a binary WebAssembly file, and existing fuzz testing methods have difficulty in constructing valid test inputs that conform to its syntax to enter the deep logic of Ewasm. Therefore, when existing fuzz testing methods are applied to Ewasm, there are defects such as poor test input validity, high randomness of mutation strategies, and low success rate of vulnerability discovery.
[0052] In view of this, one or more embodiments of this specification propose an Ethereum virtual machine fuzz testing method and device, which can mutate a variety of test inputs to detect deep-level Ewasm codes and improve the effectiveness of test inputs, and is particularly suitable for WebAssembly virtual machines.
[0053] The Ethereum virtual machine fuzz testing method and device described in one or more embodiments of this specification will be further described in detail below in conjunction with the accompanying drawings and specific embodiments of the specification, but this detailed description does not constitute a limitation on the embodiments of this specification.
[0054] Please refer to Figure 1 , Figure 1 This is a flow chart of an Ethereum virtual machine fuzz testing method proposed in one or more embodiments of this specification. Figure 1 As shown, the Ethereum virtual machine fuzz testing method may include at least one round of fuzz testing, and each round of fuzz testing may include steps S100 to S108.
[0055] S100: Obtain a WebAssembly file as a test seed, and input the test seed into a target WebAssembly virtual machine to run and obtain running information.
[0056] In each round of fuzz testing, a WebAssembly file can be randomly obtained as a test seed, and the test seed can be input into the target WebAssembly virtual machine for running. The obtained running information is used as the initial reference information, so that in the next fuzz test, it can be determined based on the reference information whether the next fuzz test finds new vulnerabilities, and then determine whether the test input of the next fuzz test is valid.
[0057] It should be noted that the number of rounds of fuzz testing of the target WebAssembly virtual machine can be set according to the test requirements, and this embodiment does not limit this.
[0058] S102: Parse the test seed to obtain a parse tree.
[0059] Please refer to Table 1, which shows the basic structure and description of WebAssembly binary bytecode.
[0060] Table 1
[0061]
[0062] As shown in Table 1, WebAssembly files are binary bytecodes, and their basic unit is the module. The binary data of the wasm module is stored in the form of sections, and each section is a cluster of binary data with specific functions, such as Type, Function, Code, etc. in Table 1. In a wasm module, binary data with the same function or related information are usually placed together to form a section, and each different section describes part of the information about the wasm module. Therefore, the position of all sections in the wasm module represents the composition structure of the wasm module at the binary level. Based on this, for the test seed, the WebAssembly bytecode can be decoded and disassembled according to the binary format specification of the WebAssembly file; then, according to the connection between the sections in the WebAssembly file, a parse tree with nodes is output.
[0063] by Figure 2 Take the WebAssembly file shown as an example. The WebAssembly file consists of N Sections, each of which includes the fields id, payload length and payload. Among them, id is a unique identifier used to distinguish different messages, requests or data packets. It is usually used to track specific sessions or transactions. Payload represents payload data, which is the data part that carries actual information, excluding other metadata such as protocol headers, and can be any type of data, such as text, images, etc. The payload consists of multiple bodies, which may refer to multiple bodies or multiple messages contained in a data packet. In some protocols or formats, a data packet can carry multiple logical data parts. Payload length indicates the length of the payload, usually in bytes, which identifies the size of the payload part to help the receiver know how to read the data. After parsing the WebAssembly, you can get Figure 2 The parse tree shown in FIG. 1 includes a root node, branch nodes, and leaf nodes. Figure 2 In the parse tree shown, body_size refers to the size of a single "body", usually in bytes, similar to payload length, but can be used to indicate the length of a specific body. count indicates the number of items in a collection, such as how many payloads or data blocks there are in a message. local_count indicates the count within a specific context or region, usually compared with count, and can indicate the relevant count of the current session or current operation. Figure 2The parse tree structure shown can find all the node paths that can be tested from the WebAssembly binary file, such as Figure 2 The section->payload shown
[0064] >bodies->local_count.
[0065] S104: mutate the parse tree to obtain all variant parse trees of the parse tree.
[0066] Specifically, at least one of the branch nodes and leaf nodes of the parse tree can be selected as the target node for mutation, and all mutation methods of the parse tree can be exhausted in this way to obtain all mutation results of the parse tree, that is, all variant parse trees of the parse tree mentioned above.
[0067] like Figure 3 As shown, in some implementations, the Thompson sampling algorithm can be selected to adaptively select nodes at different levels in the parse tree as target nodes.
[0068] Thompson sampling is a Bayesian method, the basic idea of which is to randomly extract a probability distribution of an action at each step of selection, which is determined by the current estimated reward and uncertainty for each action. Specifically, at each decision, the algorithm calculates a probability distribution based on the current understanding of each action (i.e., mean and variance), and randomly samples an action (i.e., selects a branch node or a leaf node) to execute. In this way, Thompson sampling can find a balance between exploration and exploitation, thereby maximizing the long-term accumulated rewards, so that a better choice can be found when selecting the parse tree node this time.
[0069] After sampling and obtaining the target node, the target node is mutated. Different mutation operations can be used for different types of target nodes.
[0070] For example, if the target node sampled by the Thompson sampling algorithm is a branch node in the parse tree, then the branch node is subjected to structural mutation, including adding, deleting, replacing, cloning, and other operations on the data structure in the branch node. Figure 3 As shown, there is a count field in the Element section that records the number of ELESEGs. A new ELESEG is added for the branch node after structural variation.
[0071] For example, if the target node sampled by the Thompson sampling algorithm is a leaf node in the parse tree, then a data mutation operation can be performed on the valid data in the leaf node. Figure 3As shown, in ELESEG, valid data is stored in elements, so this field can be selected for data mutation, which includes byte and instruction flipping, adding, deleting, replacing, cloning, splicing and other operations.
[0072] In some implementations, after the parse tree is mutated, the mutated parse tree may be structurally repaired so that the mutated parse tree can still be parsed, thereby ensuring the validity of the new test input generated by the mutation.
[0073] Specifically, the variant parse tree can be repaired in the following ways:
[0074] First, a node class is defined to save the structural information of the target node to ensure that the current target node can accurately locate its parent node object.
[0075] Next, the target node of the parse tree and the nodes associated with the target node are repaired from bottom to top so that the variant parse tree can be correctly parsed. The repair of the parse tree includes the repair of the target node's own data and the repair of the corresponding parent node data, which are introduced below.
[0076] Target node data repair: Since the structural mutation process will destroy the data structure inside the node, corresponding repair methods can be designed for different sections to ensure that the mutated structure is still correct and can be parsed.
[0077] Parent node data repair: Since the size of the mutated node data may change, its size may be recorded in the parent node, so it needs to be passed from bottom to top to notify the parent node to complete the corresponding data repair.
[0078] Still Figure 3 For example, in Figure 3 There is a count field in the Element section that records the number of ELESEGs. A structural mutation is performed on the branch node, and a new ELESEG is added. At this time, the value in the count field should also increase accordingly. Therefore, it is necessary to repair the parse tree that has undergone structural mutation to ensure that the structure of the parse tree after mutation is still correct and can be parsed. In addition, since the parent node may record the size of the child node data, it is necessary to perform a bottom-up repair method to notify the parent node to complete the corresponding repair while repairing the node data.
[0079] S106: Convert the variant parse tree of the parse tree into a WebAssembly file and input it into the target WebAssembly virtual machine for running, determine whether the variant parse tree is valid according to the running information, and store the valid variant parse tree as a seed parse tree in the snapshot pool.
[0080] In some implementations, a restore function can be used to restore the variant parsing tree back to a WebAssembly file as a new test input for fuzz testing. During the fuzz testing process, the running information of the target WebAssembly virtual machine can be recorded, and the running information can include the running process information of the target WebAssembly virtual machine, and can also include the state information after the target WebAssembly virtual machine runs.
[0081] According to the current running process information of the target WebAssembly virtual machine and the running information of the test seed in step S100, it can be determined whether a new execution path is found or a new code area is covered during this running process. If a new execution path is found or a new code area is covered, it is determined that the variant parse tree is valid; otherwise, it is determined that the variant parse tree is invalid.
[0082] According to the state information after the target WebAssembly virtual machine is run, it can be determined whether the target WebAssembly virtual machine crashes during this run. If so, it is determined that the variant parse tree is valid; otherwise, it is determined that the variant parse tree is invalid.
[0083] Through the above method, the variant parse trees that can effectively trigger the target WebAssembly virtual machine vulnerability can be screened out, and these effective variant parse trees are stored in the snapshot pool as seed parse trees. In the subsequent fuzz testing process, the seed parse trees in the snapshot pool are preferentially selected for mutation and testing. Using these seed parse trees to generate new variant parse trees, and then generate new test inputs, there is a higher probability of triggering the target WebAssembly virtual machine vulnerability.
[0084] S108: For each seed parse tree in the snapshot pool, mutate the seed parse tree and convert it into a WebAssembly file, input it into the target WebAssembly virtual machine for execution, determine whether the mutated parse tree of the seed parse tree is valid based on the running information, and store the valid mutated parse tree as a new seed parse tree into the snapshot pool; repeat this step until the snapshot pool is empty.
[0085] In the following fuzz tests, each fuzz test selects a seed parsing tree in the snapshot pool for mutation and WebAssembly file conversion to obtain new test input. Based on the running information of each fuzz test and the feedback information of the previous fuzz test (i.e., the running information of the target WebAssembly virtual machine in the previous fuzz test), it determines whether the input test input is valid, and stores the mutated parsing tree corresponding to the valid test input as the new seed parsing tree in the snapshot pool. Repeat this step until the snapshot pool is empty.
[0086] In the above-mentioned process of fuzz testing based on the seed parsing tree, the corresponding methods in steps S104 to S106 can be used for the mutation, repair and WebAssembly file conversion of the seed parsing tree, which will not be repeated in this step.
[0087] The following will combine a specific implementation scenario to Figure 1 The Ethereum virtual machine fuzz testing method shown in FIG. 1 is used to illustrate the fuzz testing method of the Ethereum virtual machine. In this scenario, n WebAssembly files are randomly obtained as test seeds, denoted as A1 to An. These n test seeds constitute a set C, that is, C = {A1, A2, … ,An}. In this scenario, the above blockchain virtual machine defect detection method needs to be carried out for a total of n rounds, and each round corresponds to a test seed. The following takes the test seed A1 as an example to illustrate the specific process of each round of fuzz testing.
[0088] First, the test seed A1 is input into the target WebAssembly virtual machine to run the fuzz test, and the running information of the target WebAssembly virtual machine is recorded. The test seed A1 is parsed to generate a parsing tree T1.
[0089] Then, after mutating and repairing the parse tree T1, a mutated parse tree T1′ is obtained.
[0090] Next, the variant parse tree T1′ is restored to a WebAssembly file to obtain a new test input A1′. A1′ is input into the target WebAssembly virtual machine to run the fuzz test, and the running information of the target WebAssembly virtual machine is recorded, including whether the target WebAssembly virtual machine finds a new execution path or covers a new code area during this operation, or whether the target WebAssembly virtual machine crashes as a result of this operation. If the target WebAssembly virtual machine finds a new execution path or covers a new code area during this operation, or the target WebAssembly virtual machine crashes as a result of this operation, the variant parse tree T1′ is determined to be valid. At this time, the variant parse tree T1′ is stored in the snapshot pool as a seed parse tree. If the target WebAssembly virtual machine neither finds a new execution path nor covers a new code area during this operation, and the target WebAssembly virtual machine does not crash as a result of this operation, the variant parse tree T1′ is determined.
[0091] Invalid. For invalid variant parse tree T1′, it is necessary to confirm whether parse tree T1 has reached the upper limit of mutation times. If not, parse tree T1 is mutated again to obtain a new variant parse tree T1′, and then repeat this step for the new variant parse tree T1′. If parse tree T1 has reached the upper limit of mutation times, this round of fuzzy testing ends.
[0092] Next, for each seed parse tree in the snapshot pool, the seed parse tree is mutated and converted into a WebAssembly file, which is input into the target WebAssembly virtual machine for execution. Whether the mutated parse tree of the seed parse tree is valid is determined based on the running information, and the valid mutated parse tree is stored as a new seed parse tree in the snapshot pool. Repeat this step until the entire snapshot pool is traversed.
[0093] Finally, clear all snapshots of seed parsing trees in the snapshot pool to save storage resources.
[0094] The above is an Ethereum virtual machine fuzz testing method described in this embodiment. The method randomly selects a WebAssembly file as a test seed, parses the test seed to obtain a parse tree, and then generates diversified test inputs by mutating the parse tree, thereby improving the vulnerability discovery probability of the fuzz test.
[0095] This method also provides a structural repair solution for the mutated parse tree, which can ensure the correctness and validity of the test input after structural mutation, thereby ensuring the effectiveness of fuzz testing.
[0096] This method also proposes a seed parsing tree screening and updating method based on the target WebAssembly virtual machine running information feedback, which can quickly select and generate high-quality test inputs during fuzz testing, thereby improving the efficiency of fuzz testing.
[0097] Corresponding to the above-mentioned Ethereum virtual machine fuzz testing method, one or more embodiments of this specification also propose an Ethereum virtual machine fuzz testing device, which is applicable to the Ethereum WebAssembly virtual machine, and the device is used to perform at least one round of fuzz testing on the Ethereum WebAssembly virtual machine. Please refer to Figure 4 , Figure 4 The structure diagram of an Ethereum virtual machine fuzzy testing device proposed in one or more embodiments of this specification. The device can be used to implement the above-mentioned Ethereum virtual machine fuzzy testing method. It should be noted that the Ethereum virtual machine fuzzy testing method described in one or more embodiments of this application can rely on Figure 4 The Ethereum virtual machine fuzz testing device shown is implemented, but not limited to this device.
[0098] like Figure 4 As shown, the Ethereum virtual machine fuzz testing device includes:
[0099] The data acquisition module 401 is configured to obtain a WebAssembly file as a test seed in each round of fuzz testing, and input the test seed into the target WebAssembly virtual machine to run and obtain running information.
[0100] The parsing module 402 is configured to parse the test seed to obtain a parsing tree.
[0101] The fuzz testing module 403 is configured to mutate the parse tree to obtain all mutated parse trees of the parse tree; convert the mutated parse trees of the parse tree into a WebAssembly file and input the file into the target WebAssembly virtual machine for running, determine whether the mutated parse tree is valid according to the running information, and store the valid mutated parse tree as a seed parse tree in the snapshot pool; for each seed parse tree in the snapshot pool, mutate the seed parse tree and convert the file into a WebAssembly file and input the file into the target WebAssembly virtual machine for running, determine whether the mutated parse tree of the seed parse tree is valid according to the running information, and store the valid mutated parse tree as a new seed parse tree in the snapshot pool; repeat this step until the snapshot pool is empty.
[0102] For the above-mentioned data acquisition module 401, in each round of fuzz testing, the module can randomly obtain a WebAssembly file as a test seed, and input the test seed into the target WebAssembly virtual machine for operation, and the obtained operation information is used as initial reference information, so that in the next fuzz test, it is determined based on the reference information whether the next fuzz test finds new vulnerabilities, and then determine whether the test input of the next fuzz test is valid.
[0103] Regarding the above-mentioned parsing module 402, the module can decode and disassemble the WebAssembly bytecode of the test seed according to the binary format specification of the WebAssembly file; then, according to the connection between the Sections in the WebAssembly file, output a parsing tree with nodes.
[0104] Regarding the above-mentioned fuzz testing module 403, the module mainly includes a mutation module 4031 and a conversion module 4032. Among them, the mutation module 4031 is configured to mutate the input target parse tree. The conversion module 4032 is configured to convert the input target parse tree into a WebAssembly file.
[0105] The mutation module 4031 is specifically used to select a target node in the parse tree; determine a mutation method according to the node type of the target node, and mutate the target node using the mutation method. Specifically, the mutation module 4031 can select at least one of the branch node and the leaf node of the parse tree as the target node to mutate, and exhaust all mutation methods of the parse tree in this way to obtain all mutation results of the parse tree, that is, all variant parse trees of the parse tree mentioned above.
[0106] In some implementations, the mutation module 4031 may use the Thompson sampling algorithm to adaptively select nodes at different levels in the parse tree as target nodes, and then mutate the target nodes. Different mutation operations may be used for different types of target nodes.
[0107] For example, if the target node sampled by the mutation module 4031 using the Thompson sampling algorithm is a branch node in the parse tree, a structural mutation is performed on the branch node, including adding, deleting, replacing, cloning, and other operations on the data structure in the branch node.
[0108] For example, if the target node sampled by the mutation module 4031 using the Thompson sampling algorithm is a leaf node in the parse tree, a data mutation operation can be performed on the valid data in the leaf node.
[0109] The conversion module 4032 can use the restore function to restore the variant parse tree back to the WebAssembly file as a new test input for the fuzz test.
[0110] Optionally, the fuzzy test module 403 may further include a repair module 4033. The repair module 4033 is specifically used to perform structural repair on the variant parse tree, so that the variant parse tree after mutation can still be parsed, thereby ensuring the validity of the new test input generated by mutation.
[0111] Specifically, the repair module 4033 can repair the variant parse tree in the following manner:
[0112] First, a node class is defined to save the structural information of the target node to ensure that the current target node can accurately locate its parent node object.
[0113] Next, the target node of the parse tree and the nodes associated with the target node are repaired from bottom to top so that the variant parse tree can be correctly parsed. The repair of the parse tree includes the repair of the target node's own data and the repair of the corresponding parent node data, which are introduced below.
[0114] Target node data repair: Since the structural mutation process will destroy the data structure inside the node, corresponding repair methods can be designed for different sections to ensure that the mutated structure is still correct and can be parsed.
[0115] Parent node data repair: Since the size of the mutated node data may change, its size may be recorded in the parent node, so it needs to be passed from bottom to top to notify the parent node to complete the corresponding data repair.
[0116] For the above-mentioned Ethereum virtual machine fuzz testing device, taking a module as an example of a software functional unit, the data acquisition module 401 may include code running on a computing instance. Among them, the computing instance may include at least one of a physical host (computing device), a virtual machine, and a container. Further, the above-mentioned computing instance may be one or more. For example, the data acquisition module 401 may include code running on multiple hosts / virtual machines / containers. The multiple hosts / virtual machines / containers used to run the code may be distributed in the same region (region) or in different regions. Furthermore, the multiple hosts / virtual machines / containers used to run the code may be distributed in the same availability zone (AZ) or in different AZs, each AZ including a data center or multiple data centers with similar geographical locations. Among them, usually a region may include multiple AZs.
[0117] Similarly, multiple hosts / virtual machines / containers used to run the code can be distributed in the same virtual private cloud (VPC) or in multiple VPCs. Usually, a VPC is set up in a region. For cross-region communication between two VPCs in the same region and between VPCs in different regions, a communication gateway needs to be set up in each VPC to achieve interconnection between VPCs through the communication gateway.
[0118] As an example of a hardware functional unit, the data acquisition module 401 may include at least one computing device, such as a server, etc. Alternatively, the data acquisition module 401 may also be a device implemented using an application-specific integrated circuit (ASIC) or a programmable logic device (PLD). The PLD may be a complex programmable logical device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL) or any combination thereof.
[0119] The multiple computing devices included in the data acquisition module 401 can be distributed in the same region or in different regions. The multiple computing devices included in the data acquisition module 401 can be distributed in the same AZ or in different AZs. Similarly, the multiple computing devices included in the data acquisition module 401 can be distributed in the same VPC or in multiple VPCs. The multiple computing devices can be any combination of computing devices such as servers, ASICs, PLDs, CPLDs, FPGAs, and GALs.
[0120] In other embodiments, the data acquisition module 401 can be used to execute any step in the above-mentioned Ethereum virtual machine fuzzy testing method, the parsing module 402 can be used to execute any step in the above-mentioned Ethereum virtual machine fuzzy testing method, and the fuzzy testing module 403 can be used to execute any step in the above-mentioned Ethereum virtual machine fuzzy testing method. The steps that the data acquisition module 401, the parsing module 402 and the fuzzy testing module 403 are responsible for implementing can be specified as needed, and the data acquisition module 401, the parsing module 402 and the fuzzy testing module 403 respectively implement different steps in the above-mentioned Ethereum virtual machine fuzzy testing method to realize all the functions of the above-mentioned Ethereum virtual machine fuzzy testing device.
[0121] In this implementation, the Ethereum virtual machine fuzzy testing device can also be applied to computing devices such as computers and servers, or to a computing device cluster including at least one computing device, to realize the specific functions of the Ethereum virtual machine fuzzy testing device.
[0122] In some embodiments, an electronic device is also provided. Figure 5, the electronic device includes: a bus 501, a processor 502, a memory 503 and a communication interface 504. The processor 502, the memory 503 and the communication interface 504 communicate with each other through the bus 501. The electronic device can be a server or a terminal device. It should be understood that the present application does not limit the number of processors and memories in the electronic device.
[0123] The bus 501 may be a peripheral component interconnect (PCI) bus, or an extended industry standard architecture (EISA) bus, etc. The bus may be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 5 The use of only one line does not mean that there is only one bus or one type of bus. Bus 501 may include a path for transmitting information between various components of the electronic device (eg, processor 502, memory 503, and communication interface 504).
[0124] The processor 502 may include any one or more processors such as a CPU, a graphics processing unit (GPU), a microprocessor (MP), or a digital signal processor (DSP).
[0125] The memory 503 may include a volatile memory, such as a random access memory (RAM). The memory 503 may also include a non-volatile memory, such as a read-only memory (ROM), a flash memory, a hard disk drive (HDD), or a solid state drive (SSD).
[0126] The memory 503 stores executable program code, and the processor 502 executes the executable program code to implement the functions of the aforementioned Ethereum virtual machine fuzz testing device, that is, to implement the aforementioned Ethereum virtual machine fuzz testing method.
[0127] The communication interface 504 uses a transceiver module such as, but not limited to, a network interface card or a transceiver to implement communication between the electronic device and other devices or a communication network.
[0128] In some embodiments, a computer-readable storage medium is also provided, on which a computer program is stored. When the computer program is executed by a processor, the processor executes the above-mentioned Ethereum virtual machine fuzz testing method.
[0129] The computer-readable storage medium may be any available medium that can be stored by the electronic device or a data storage device such as a data center that includes one or more available media. The available medium may be a magnetic medium (e.g., a floppy disk, a hard disk, a tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid-state drive). The computer-readable storage medium includes instructions that instruct the electronic device to execute the above-mentioned Ethereum virtual machine fuzz testing method.
[0130] It is to be understood that the structure illustrated in the embodiments of this specification does not constitute a specific limitation on the system of the embodiments of this specification. In other embodiments of the specification, the above system may include more or fewer components than shown in the figure, or combine some components, or split some components, or arrange the components differently. The components shown in the figure may be implemented in hardware, software, or a combination of software and hardware.
[0131] Each embodiment in this specification is described in a progressive manner, and the same or similar parts between the embodiments can be referred to each other, and each embodiment focuses on the differences from other embodiments. In particular, for the device embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.
[0132] The above is a description of a specific embodiment of the specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recorded in the claims can be performed in an order different from that in the embodiments and still achieve the desired results. In addition, the processes depicted in the drawings do not necessarily require the specific order or continuous order shown to achieve the desired results. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0133] It should be noted that the above examples are only specific embodiments of the present invention, and the present invention is obviously not limited to the above examples, and there are many similar variations. All variations directly derived or associated from the contents disclosed by the technicians in this field should fall within the protection scope of the present invention.
Claims
1. A fuzz testing method for an Ethereum virtual machine, applicable to an Ethereum WebAssembly virtual machine, the method comprising at least one round of fuzz testing, each round of fuzz testing comprising: Obtain a WebAssembly file as a test seed, and input the test seed into a target WebAssembly virtual machine to run and obtain running information; Parsing the test seed to obtain a parse tree; Mutating the parse tree to obtain all variant parse trees of the parse tree; Converting a variant parse tree of the parse tree into a WebAssembly file and inputting it into a target WebAssembly virtual machine for running, determining whether the variant parse tree is valid according to running information, and storing the valid variant parse tree as a seed parse tree in a snapshot pool; For each seed parse tree in the snapshot pool, mutate the seed parse tree and convert it into a WebAssembly file, input it into the target WebAssembly virtual machine for running, determine whether the mutated parse tree of the seed parse tree is valid according to the running information, and store the valid mutated parse tree as a new seed parse tree in the snapshot pool; Repeat this step until the snapshot pool is empty.
2. According to the method of claim 1, the operation information includes operation process information of the target WebAssembly virtual machine; determining whether the variant parse tree is valid according to the operation information specifically includes: According to the running process information of the target WebAssembly virtual machine, it is determined whether a new execution path is found or a new code area is covered during this running process. If a new execution path is found or a new code area is covered, it is determined that the variant parse tree is valid; otherwise, it is determined that the variant parse tree is invalid.
3. According to the method of claim 1, the running information includes the state information after the target WebAssembly virtual machine runs; determining whether the variant parse tree is valid according to the running information specifically includes: According to the state information after the target WebAssembly virtual machine runs, it is determined whether the target WebAssembly virtual machine crashes. If so, it is determined that the variant parse tree is valid; otherwise, it is determined that the variant parse tree is invalid.
4. According to the method of claim 1, mutating the parse tree to obtain all variant parse trees of the parse tree specifically comprises: Select a target node in the parse tree; A mutation method is determined according to the node type of the target node, and the target node is mutated using the mutation method.
5. The method according to claim 4, wherein selecting a target node in the parse tree comprises: At least one of a branch node and a leaf node in the parse tree is selected as the target node using the Thompson sampling algorithm.
6. The method according to claim 5, determining a mutation mode according to the node type of the target node, and mutating the target node using the mutation mode, specifically comprises: If the target node is a branch node in the parse tree, performing structural mutation on the target node; If the target node is a leaf node in the parse tree, data mutation is performed on the target node.
7. The method according to claim 4, further comprising: After the parse tree is mutated, the target node and nodes associated with the target node in the mutated parse tree are repaired from bottom to top, so that the mutated parse tree can be correctly parsed.
8. An Ethereum virtual machine fuzz testing device, applicable to an Ethereum WebAssembly virtual machine, the device is used to perform at least one round of fuzz testing on the Ethereum WebAssembly virtual machine, the device comprising: A data acquisition module is configured to acquire a WebAssembly file as a test seed in each round of fuzz testing, and input the test seed into a target WebAssembly virtual machine to run and obtain running information; A parsing module, configured to parse the test seed to obtain a parse tree; A fuzzy testing module is configured to mutate the parse tree to obtain all mutated parse trees of the parse tree; Converting a variant parse tree of the parse tree into a WebAssembly file and inputting it into a target WebAssembly virtual machine for running, determining whether the variant parse tree is valid according to running information, and storing the valid variant parse tree as a seed parse tree in a snapshot pool; For each seed parse tree in the snapshot pool, mutate the seed parse tree and convert it into a WebAssembly file, input it into the target WebAssembly virtual machine for running, determine whether the mutated parse tree of the seed parse tree is valid according to the running information, and store the valid mutated parse tree as a new seed parse tree in the snapshot pool; Repeat this step until the snapshot pool is empty.
9. According to the device of claim 8, the fuzz testing module includes a mutation module and a conversion module; the mutation module is configured to mutate the input target parse tree; the conversion module is configured to convert the input target parse tree into a WebAssembly file.
10. The device according to claim 9, wherein the mutation module is specifically used to select a target node in the parse tree; determine a mutation method according to a node type of the target node, and mutate the target node using the mutation method.
11. The device according to claim 10, wherein the mutation module is specifically used to select at least one of a branch node and a leaf node in the parse tree as the target node by using a Thompson sampling algorithm.
12. The device according to claim 11, wherein the variation module is specifically used for: When the target node is a branch node in the parse tree, performing structural mutation on the target node; When the target node is a leaf node in the parse tree, data mutation is performed on the target node.
13. According to the device of claim 10, the fuzzy testing module also includes a repair module, and the repair module is configured to perform a bottom-up repair on the target node and the nodes associated with the target node in the mutated parse tree after mutating the parse tree, so that the mutated parse tree can be correctly parsed.
14. A computer-readable storage medium having a computer program stored thereon, wherein when the computer program is executed by a processor, the processor is caused to execute the method according to any one of claims 1 to 7.
15. An electronic device, comprising: one or more processors; And a memory associated with the one or more processors, the memory is used to store program instructions, and when the program instructions are read and executed by the one or more processors, the electronic device executes the method as claimed in any one of claims 1 to 7.