Attack path automatic generation method, computer equipment and computer readable storage medium
By introducing a layout-oriented approach in fuzz testing, using layout contributor directed graphs to guide fuzz testing, the inefficiency problem of existing fuzz testing technologies in attack path exploration and exploitable state search is solved, and more efficient and accurate attack path generation is achieved.
Patent Information
- Application Number
- CN202411965035.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-30
- Publication Date
- 2025-05-13
AI Technical Summary
Existing fuzz testing techniques have scalability issues in attack path exploration and exploitable state search, the possibility of ignoring certain exploitable states, and the lack of targets of components, resulting in inefficiency in testing.
Using a layout-oriented fuzz testing method, by constructing a directed graph of the layout contributors of the program under test, layout-oriented fuzz testing finds divergent inputs that trigger the same layout contributor slice as the PoC input, and synthesizes a new vulnerability attack path through divergent input and PoC input.
It improves the efficiency and accuracy of attack path generation, and can more effectively discover and repair security vulnerabilities in the software.
Smart Images

Figure CN119989355A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of computer security technology, and more specifically, the present invention relates to an attack path automatic generation method, a computer device and a computer-readable storage medium. Background Art
[0002] In the field of computer security, especially in the field of fuzz testing technology, discovering and exploiting security vulnerabilities in software is an important and challenging task. Existing attack path generation schemes, such as AEG and Mayhem, mainly rely on fuzz testing technology to explore crash paths or reachable paths from the vulnerability point in order to explore and search for exploitable states along the path. However, fuzz testing technology has several serious challenges in path exploration, which limits its effectiveness in path exploration or exploitable state search.
[0003] (1) Fuzz testing technology faces scalability issues in path exploration. It is affected by the path explosion problem caused by branches and loops in the program, resulting in a large amount of resources being consumed even for analyzing one path. In addition, the test cases generated by fuzz testing may not be sufficient to cover all possible execution paths, resulting in some exploitable states being ignored;
[0004] (2) Fuzz testing may ignore certain exploitable states. During the exploration process, fuzz testing needs to generate inputs that can trigger specific vulnerabilities, but since it is impossible to try all candidate inputs, some values may be missed, resulting in certain exploitable states being ignored. For example, fuzz testing may generate a large number of invalid or irrelevant inputs that cannot trigger vulnerabilities or fail to explore key exploitable states;
[0005] (3) Solutions that use fuzz testing techniques to explore attack paths usually lack targets, so they cannot effectively find exploitable states. The randomness of fuzz testing may lead to inefficient testing and make it difficult to focus resources on exploring the paths that are most likely to lead to vulnerabilities. Summary of the invention
[0006] The present invention provides an automatic generation method of attack paths based on layout-oriented fuzzy testing, aiming to improve the above-mentioned problem.
[0007] The present invention is implemented as follows: a method for automatically generating attack paths based on layout-oriented fuzzy testing, the method is specifically as follows:
[0008] S1. Construct a directed graph of layout contributors of the program under test;
[0009] S2. Through layout-oriented fuzz testing, find the divergent input that triggers the same layout contributor slice as the PoC input;
[0010] S3, the program under test executes the instructions corresponding to the divergent input, detects its execution path to obtain several divergent paths, and filters the divergent input;
[0011] S4. The program under test executes the instructions corresponding to the divergent input to obtain the divergent path, and splices the splicing points of the divergent path with the splicing points of the crash path to form an attack path.
[0012] Furthermore, the method for obtaining divergent input is as follows:
[0013] (1) Select a seed from the seed queue. The seed is the input instruction that triggers the program under test.
[0014] (2) Mutate the input seeds to form multiple seeds for testing. Input the seeds into the program under test one by one. Select valid seeds that can trigger the crash of the program under test based on code coverage. Put the valid seeds into the seed queue. Meanwhile, use the currently selected valid seeds as divergent input.
[0015] Furthermore, the seed preferentially selects input instructions that hit all layout contribution instructions in the same order as the guide slice, and secondly selects input instructions with the longest common subsequence LCSP, and finally selects input instructions with the shortest layout contributor instruction list La.
[0016] Furthermore, the formation process of the layout contributor instruction list La of the input instruction Ia is as follows:
[0017] The program under test executes the input instruction Ia, monitors the execution path of the instruction Ia, and in the process of executing the instruction Ia, records all layout contributor instructions that hit the layout contributor directed graph and puts them into the layout contributor instruction list La.
[0018] Furthermore, the filtering method of divergent input is as follows:
[0019] Align the layout contributor directed graph of the divergent path with the target layout contributor directed graph of the crash path. If the two are aligned, keep the corresponding divergent input. If not, find the abnormal instruction object that causes the misalignment in the divergent path, build a new layout contributor directed graph of the abnormal instruction object, align the new layout contributor directed graph with the target layout contributor directed graph of the crash path, and keep the divergent input corresponding to the divergent path aligned with the target layout contributor directed graph.
[0020] The constructed PoC input, the program under test executes the instructions corresponding to the PoC input, and monitors the execution path to obtain the path crash path; the program under test executes the instructions corresponding to the divergent input, and monitors its execution path to obtain the divergent path corresponding to the divergent instructions.
[0021] Furthermore, the location where the abnormal object is destroyed in the crash path is selected as the splicing point
[0022] Furthermore, the method for identifying the splicing points in the divergent path is as follows:
[0023] Construct a directed graph of layout contributors of the operands of the exploitable operations in the divergent path, match the directed graph of layout contributors with the directed graph of the exception objects in the crash path, and if the former is a subgraph of the latter, select the next instruction in the divergent path immediately after the last write access of the operands of the exploitable operations as the splicing point; if the former is not a subgraph of the latter, select the instruction in the forked path that earliest causes the difference between the directed graph of layout contributors of the forked path and the directed graph of layout contributors of the exception objects in the crash path as the splicing point.
[0024] The present invention is implemented in this way: a computer device includes a memory and a processor, wherein the memory stores a computer program, and is characterized in that when the processor executes the computer program, the steps of the above-mentioned method for automatically generating attack paths based on layout-guided fuzz testing are implemented.
[0025] The present invention is implemented as follows: a computer-readable storage medium stores a computer program thereon, characterized in that when the computer program is executed by a processor, the steps of the above-mentioned method for automatically generating attack paths based on layout-guided fuzz testing are implemented.
[0026] The present invention uses layout-guided fuzz testing, guided by a directed graph of layout contributors, to explore divergent paths and search for exploitable states; through layout-oriented fuzz testing, divergent inputs that can trigger the same layout contributor slices as the PoC input are found; new vulnerability attack paths are synthesized through PoC input and divergent input. The present invention improves the efficiency and accuracy of attack path generation by extending the existing coverage-guided fuzz tester AFL and introducing a directed graph of layout contributors to guide path exploration and mutation, thereby assisting security researchers and developers to more effectively discover and fix security vulnerabilities in software. BRIEF DESCRIPTION OF THE DRAWINGS
[0027] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings required for use in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other accompanying drawings can be obtained based on these accompanying drawings without paying creative work.
[0028] Figure 1 The input principle of the hit guide slice provided by the embodiment of the present invention;
[0029] Figure 2A fuzz tester test principle diagram based on the extended fuzz tester AFL provided in an embodiment of the present invention;
[0030] Figure 3 A schematic diagram of the filtering principle of the divergent input provided by an embodiment of the present invention;
[0031] Figure 4 A schematic diagram of attack path splicing provided by an embodiment of the present invention;
[0032] Figure 5 An example diagram of a call stack of a splicing point in a divergent path and a crash path provided by an embodiment of the present invention. Implementation
[0034] The specific implementation modes of the present invention are further explained in detail below by describing the embodiments with reference to the accompanying drawings, so as to help those skilled in the art to have a more complete, accurate and in-depth understanding of the inventive concept and technical solution of the present invention.
[0035] In order to facilitate the understanding of the technical solution, the following professional terms are explained as follows:
[0036] (1) Layout Contributor Directed Graph: It is a graphical representation method used to describe the memory layout construction process in a program. It is mainly used to guide fuzz testing to explore divergent paths that may lead to vulnerability exploitation. The specific formation process is as follows:
[0037] First, we identify the instructions that contribute to the memory layout during program execution, which are called layout contributor instructions, including operations such as memory allocation, object creation, attribute modification, and memory release. Second, we construct a directed graph based on the execution order of layout contributor instructions and the dependencies between them. Each layout contributor instruction is used as a node in the layout contributor directed graph, and the edges between nodes represent the control flow or data dependency between layout contributor instructions.
[0038] Whenever a layout contributor instruction is executed, a node is added to the layout contributor directed graph, and edges are added according to the call relationship and data flow between the layout contributor instructions. After the layout contributor instruction is executed, the construction of the layout contributor directed graph is completed, reflecting the construction process of the memory layout in the program. In the layout contributor directed graph, each node represents a layout contributor instruction, which has a direct impact on the memory layout of the program. Specifically, the nodes corresponding to the layout contributor instructions can represent: (a) memory allocation: for example, malloc or new operations, which allocate memory on the heap and may create objects required for vulnerability exploitation. (b) object attribute modification: for example, setting the attributes of an object or changing the relationship between objects, these operations may affect the state of the object and make it part of the vulnerability exploitation. (c) other operations that affect the memory layout: any operation that may affect the memory layout of the program, such as array out-of-bounds write, type conversion error, etc., may become a node.
[0039] The nodes not only represent individual layout contributor instructions, but also imply the impact of these instructions on the memory state after execution, including the created objects, modified object properties, and the reference relationships between them. By analyzing these nodes and the edges between them, we can better understand how the program builds a specific memory layout, which is crucial for discovering and exploiting vulnerabilities.
[0040] (2) Boot slice (abbreviated as slice): It is a set of instruction sequences (slice sequences) related to a specific vulnerability. The instruction sequence is considered necessary to build an exploit of the vulnerability. The boot slice is pre-defined based on the analysis and understanding of the vulnerability.
[0041] (3) PoC input is a specific input used to prove the existence of a vulnerability. It can trigger the vulnerability in the program and lead to a specific memory layout. This memory layout is known to be exploitable. The specific input information of PoC input includes: Instruction sequence that triggers the vulnerability: PoC input contains a series of instructions that can trigger a specific vulnerability. These instructions can cause the program to enter an exploitable state. Memory layout construction: PoC input constructs a specific memory layout by executing a specific instruction sequence. This layout is the basis for vulnerability exploitation.
[0042] (4) Crash path: refers to the execution path that causes the program to crash. The formation process usually involves the following steps:
[0043] Triggering vulnerabilities: Through specific inputs (such as PoC inputs), security vulnerabilities in the program are triggered, such as buffer overflows, use-after-free, etc. Destruction of abnormal objects: In the crash path, each write access violation will destroy an abnormal object, for example, a memory area that has been released is written again. Tracking of memory state: Analyze the changes in memory state when the PoC input is executed, and record the instruction sequence that causes the destruction of abnormal objects. Construct a directed graph of target layout contributors: By analyzing the crash path, a directed graph of target layout contributors is constructed, which reflects the creation and destruction process of abnormal objects and the reference relationship between them.
[0044] (5) Divergent paths: Divergent paths refer to other possible execution paths that are different from the crash path. They may trigger the same layout contributor slices as the PoC input, but the specific data flow and control flow may be different. The process of forming a divergent path includes:
[0045] Layout-oriented fuzz testing: Through an extended fuzz tester (such as extended AFL), explore paths that can trigger the same or similar layout contributor slices as the PoC input. Mutation and exploration: The fuzz tester generates new test cases by mutating the PoC input and executes these test cases to explore new paths. Matching of layout contributor slices: During the fuzz testing process, identify divergent inputs that can trigger the same layout contributor slices as the PoC input. Construct a new layout contributor directed graph: For each divergent path, a new layout contributor directed graph is constructed by backward slicing, which reflects the creation and destruction process of abnormal objects in the divergent path. Matching and filtering: The new layout contributor directed graph constructed by the divergent path is matched with the target layout contributor directed graph of the crash path to determine whether the divergent path matches the target layout contributor directed graph.
[0046] Through these steps, multiple possible divergent paths can be formed, and through the matching and filtering process, those divergent paths that may match the directed graph of the target layout contributors are found, which can be used for further vulnerability exploitation analysis and synthesis of exploitation paths.
[0047] (5) Exploitable operations refer to those operations that can trigger security vulnerabilities, such as out-of-bounds writes, use after free, type confusion, etc. These operations are not allowed in normal program execution, but they become key attack points when attackers try to exploit program vulnerabilities.
[0048] (6) Operand refers to the object of the operation, which can be data or memory address. In the context of vulnerability exploitation, a specific operand (such as a pointer to a specific memory area or a specific data value) is required to perform the exploitable operation.
[0049] The present invention uses layout-guided fuzz testing, guided by a directed graph of layout contributors, to explore divergent paths and search for exploitable states; through layout-oriented fuzz testing, divergent inputs that can trigger the same layout contributor slices as the PoC input are found; new vulnerability attack paths are synthesized through PoC input and divergent input. The present invention improves the efficiency and accuracy of attack path generation by extending the existing coverage-guided fuzz tester AFL and introducing a directed graph of layout contributors to guide path exploration and mutation, thereby assisting security researchers and developers to more effectively discover and fix security vulnerabilities in software.
[0050] Figure 1 A flowchart of a method for automatically generating attack paths based on layout-guided fuzz testing provided by an embodiment of the present invention, the method specifically comprises the following steps:
[0051] S1. Construct a directed graph of layout contributors of the program under test;
[0052] S2. Through layout-oriented fuzz testing, find the divergent input that triggers the same layout contributor slice as the PoC input. The layout contributor slice is the slice in the layout contributor directed graph of the program under test.
[0053] S3, the program under test executes the instructions corresponding to the divergent input, and detects its execution path to obtain several divergent paths;
[0054] S4. After filtering the divergent input, the program under test executes the instructions corresponding to the filtered divergent input, and obtains the divergent path, and splices the splicing points of the divergent path with the splicing points of the crash path to form an attack path.
[0055] For a given input instruction Ia, execute instruction Ia and monitor its execution path. During the execution of instruction Ia, record all layout contributor instructions that hit the layout contributor directed graph, build a layout contributor instruction list La, compare the layout contributor instruction list La with the guide slice, and determine the longest common subsequence LCSP_Pa between the layout contributor instruction list La and the guide slice; by analyzing the longest common subsequence LCSP_Pa, it can be determined that the layout contributor instructions in the input instruction Ia match the guide slice, thereby evaluating the potential of instruction Ia in constructing vulnerability exploitation paths; using the collected slice hit information, adjust the direction of fuzz testing, and give priority to those seeds with longer LCS and fewer slice hits for mutation to discover exploitable vulnerabilities faster. This design choice is based on the following three heuristics:
[0056] (1) Inputs that hit all layout contribution instructions in the same order as the guide slice can build a memory layout similar to the vulnerability; the layout contributor instructions are responsible for creating the exception object of the vulnerability and its index object, and setting the pointing relationship between them. Therefore, inputs that hit the complete layout contributor slice may be able to build a similar memory layout.
[0057] (2) Inputs that hit a longer subsequence of the guide slice are more likely to get inputs that hit the full slice. In other words, if the LCS_Pa of input instruction Ia is longer than the LCS_Pb of input instruction Ib, then input instruction Ia is better than input instruction Ib;
[0058] (3) Inputs with fewer layout contributor instructions are more likely to cause less trouble for further vulnerability generation. For two inputs Ia and Ib, if LCS_Pa and LCS_Pb have the same length, but the layout contributor instruction list La is longer than Lb, then input Ib is better than input Ia. In this case, input Ia has more repeated or out-of-order contributor instructions than Ib, which may lead to redundant object creation or layout construction, making the memory layout too complex to exploit.
[0059] Reference Figure 1 As shown, assuming that the guide slice is in the path a=>c=>e=>f, the input of the execution path a=>c=>d is better than other inputs of the execution path a=>b. Further mutation of the input of the execution path a=>c=>d can obtain the input that hits the guide slice faster.
[0060] Combination Figure 2 The exploration path based on extending the popular fuzz tester AFL is described as follows:
[0061] (1) Select a seed from the seed queue. The seed is the input instruction that triggers the program under test. The input instruction that hits all layout contribution instructions in the same order as the guide slice is selected first, followed by the input instruction with a longer longest common subsequence LCSP, and finally the input instruction with a shorter corresponding layout contributor instruction list La;
[0062] (2) Mutate the input seeds to form multiple seeds for testing. Input the seeds into the program under test one by one. Select valid seeds that can trigger the crash of the program under test based on code coverage. Put the valid seeds into the seed queue. Meanwhile, use the currently selected valid seeds as divergent input.
[0063] In an embodiment of the present invention, in order to track the number of slice hits. In addition to the existing bitmap for code coverage tracking, an additional buffer HIT is added in the shared memory between QEMU and the fuzzer driver. HIT[0] is used to track the count of slice hits, and HIT[i] is used to track whether the i-th instruction (slice) in the boot slice is hit. Each time the layout contributor instruction is executed, QEMU will increase the slice hit count HIT[0]. If the layout contributor instruction hits the n-th (n>=1) instruction in the boot slice, QEMU will set HIT[n] if and only if HIT[n-1] is set. By traversing all instructions in the boot slice, the fuzzer driver can obtain the slice hit count in HIT[0] and the longest common subsequence LCS of the boot slice in HIT[1:N], where N is the total number of instructions in the boot slice.
[0064] Through layout-oriented fuzz testing, we can find divergent inputs that trigger the same layout contributor slice as the PoC input. However, unlike the layout contributor directed graph, the lack of data flow constraints in the layout contributor slice causes the divergent input to sometimes not match the target layout contributor directed graph built from the crash path. Therefore, we isolate the divergent inputs that may not match the target layout contributor directed graph. The isolation process is as follows:
[0065] like Figure 3 As shown, the constructed PoC is input into the program under test, the program under test executes the PoC input, and monitors its execution path, which is the path crash path. The crash path is analyzed, and a target layout contributor directed graph is constructed. The program under test executes the instruction corresponding to the divergent input, and monitors its execution path to obtain the divergent path corresponding to the divergent instruction. Usually, the layout contributor directed graph of the divergent path is first aligned with the target layout contributor directed graph of the crash path. If the two are aligned, the corresponding divergent input is retained. If not, the abnormal instruction object that causes the misalignment between the two is found in the divergent path, and a new layout contributor directed graph of the abnormal instruction object is constructed. The new layout contributor directed graph is matched with the target layout contributor directed graph of the crash path, and the memory label of each node in the two directed graphs and the address of its creator instruction are compared to determine whether the divergent path matches the target layout contributor directed graph, and the divergent input corresponding to the divergent path aligned with the target layout contributor directed graph is retained.
[0066] Once an exploitable state is found in a path, existing AEG solutions usually generate exploits by solving paths, vulnerabilities, and exploit constraints. However, pure symbolic execution does not work well in exploit generation. Therefore, symbolic execution is used as little as possible. It uses lightweight symbolic execution as a link to stitch together crash paths and divergent paths, and reuses PoC inputs and divergent inputs to further reduce complex constraints, making symbolic execution more practical.
[0067] like Figure 4 As shown, firstly, the splicing points in the crash path and the divergent path are determined respectively, then the subpaths between the splicing points are explored and the vulnerability exploitation path is synthesized to identify the splicing points in the crash path and the divergent path. In an embodiment of the present invention, the splicing point identification method in the crash path is specifically as follows:
[0068] In order to successfully exploit the victim program, its vulnerability must first be triggered and some exception objects destroyed. Therefore, the location where the exception object is destroyed in the crash path is selected as the splicing point. In the crash path, each write access violation will destroy an exception object, so it is a candidate splicing point. For each read access violation in the UAF vulnerability, the exception object is an object that has been released but is still pointed to by a dangling pointer. The memory area of this exception object will be occupied by another memory allocation. The new memory allocation operation is taken as a candidate splicing point. Since there may be multiple violations in a crash path, there may also be multiple splicing points. Each splicing point is spliced with the splicing point in the divergent path.
[0069] In an embodiment of the present invention, the method for identifying a splicing point in a divergent path is specifically as follows:
[0070] Construct a directed graph of layout contributors of the operands of the exploitable operations in the divergent path, and match this directed graph with the directed graph of the abnormal objects in the crash path. If the former is a subgraph of the latter, it means that the crash path has set all data dependencies for the exploitable operations, and the next instruction immediately after the last write access of the operands of the exploitable operations in the divergent path is selected as the splicing point; if the former is not a subgraph of the latter, there are different nodes or edges in the directed graph of layout contributors of the forked path in the divergent path, that is, the forked path changes the dependencies of the exploitable operations. In this case, select the instruction (object creation or writing) in the forked path that causes the earliest difference between the directed graph of layout contributors of the forked path and the directed graph of layout contributors of the abnormal objects in the crash path as the splicing point. The difference between the directed graph of layout contributors of the forked path and the directed graph of layout contributors of the abnormal objects in the crash path specifically refers to the difference in structure and content between the two directed graphs.
[0071] When determining the splicing point, we focus on the last write access instruction in the divergent path that is directly related to the exploitable operation. This write access instruction is the instruction that modifies the memory location of the operand of the exploitable operation. The instruction immediately following the last write access of the operand of the exploitable operation means finding the next instruction after this write access instruction, and this next instruction is considered the splicing point. In short, the splicing point is the instruction in the divergent path that immediately follows the last write operation that modifies the exploitable operand. This point is chosen as the splicing point because the path after this will try to match and splice with the corresponding part in the crash path in order to build a complete attack path for the exploit.
[0072] In order to splice the crash path with the divergent paths to get the attack path, potential subpaths connecting the splicing points in these paths are explored. Usually, it relies on symbolic execution to explore the paths. However, multiple heuristic methods are utilized to effectively guide symbolic execution.
[0073] First, the function call stack is used to guide the path exploration. It checks the call stacks at the two splicing points separately and finds the differences. Figure 5 As shown, two example call stacks are shown. These differences in the call stacks indicate the direction of path exploration. Function calls in the crash path (e.g., g1, g2, ..., gM in the figure) should be returned one by one first, while function calls in the forked path (e.g., h1, h2, ..., hK in the figure) should be called one by one later.
[0074] That is, when exploring potential paths, the return instructions of functions gM, ..., g2, g1 are added as target instructions one by one, and the entry points of functions h1, h2, ..., hK are added as target instructions one by one. These target instructions are the dominating points between two splicing points. Then, potential subpaths between these intermediate target instructions are explored. The burden of subpath exploration is further reduced by reusing existing paths. For example, if a subpath connecting two intermediate destinations already exists in a forked path or a crashed path, the subpath is reused. A simple loop identification algorithm is also executed to find a subpath that jumps out of the loop as quickly as possible to reduce the burden of symbolic execution. Sometimes, reused subpaths will cause the overall path to be unsolvable, and attempts will be made to delete these subpaths and search for alternative subpaths. In this way, the burden of symbolic execution is greatly reduced when exploring subpaths connecting splicing points.
[0075] The logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as an ordered list of executable instructions for implementing logical functions, and can be embodied in any computer-readable medium for use by an instruction execution system, device or apparatus (such as a computer-based system, a system including a processor, or other system that can fetch instructions from an instruction execution system, device or apparatus and execute instructions), or in conjunction with such instruction execution systems, devices or apparatuses. For the purposes of this specification, "computer-readable medium" can be any device that can contain, store, communicate, propagate or transmit a program for use by an instruction execution system, device or apparatus, or in conjunction with such instruction execution systems, devices or apparatuses.
[0076] More specific examples of computer-readable media (a non-exhaustive list) include the following: an electrical connection with one or more wires (electronic device), a portable computer disk case (magnetic device), a random access memory (RAM), a read-only memory (ROM), an erasable and programmable read-only memory (EPROM or flash memory), an optical fiber device, and a portable compact disk read-only memory (CDROM). In addition, the computer-readable medium may even be a paper or other suitable medium on which the program is printed, since the program may be obtained electronically, for example, by optically scanning the paper or other medium, followed by editing, deciphering, or processing in another suitable manner as necessary, and then stored in a computer memory.
[0077] It should be understood that the various parts of the present invention can be implemented by hardware, software, firmware or a combination thereof. In the above-mentioned embodiments, multiple steps or methods can be implemented by software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented by hardware, as in another embodiment, it can be implemented by any one of the following technologies known in the art or their combination: a discrete logic circuit having a logic gate circuit for implementing a logic function for a data signal, a dedicated integrated circuit having a suitable combination of logic gate circuits, a programmable gate array (PGA), a field programmable gate array (FPGA), etc. It should be noted that the above embodiments are only used to illustrate the technical solution of the present invention and are not limited. Although the present invention is described in detail with reference to the preferred embodiments, it should be understood by those skilled in the art that the technical solution of the present invention can be modified or replaced by equivalents without departing from the spirit and scope of the technical solution of the present invention, which should be included in the scope of the claims of the present invention.
[0078] The present invention has been described exemplarily. Obviously, the specific implementation of the present invention is not limited to the above-mentioned method. As long as various non-substantial improvements are made using the method concept and technical solution of the present invention, or the concept and technical solution of the present invention are directly applied to other occasions without improvement, they are all within the protection scope of the present invention.
Claims
1. A method for automatically generating attack paths based on layout-oriented fuzz testing, characterized in that: The method is specifically as follows: S1. Construct a directed graph of layout contributors of the program under test; S2. Through layout-oriented fuzz testing, find the divergent input that triggers the same layout contributor slice as the PoC input; S3, the program under test executes the instructions corresponding to the divergent input, detects its execution path to obtain several divergent paths, and filters the divergent input; S4. The program under test executes the instructions corresponding to the divergent input to obtain the divergent path, and splices the splicing points of the divergent path with the splicing points of the crash path to form an attack path.
2. The method for automatically generating attack paths based on layout-guided fuzz testing according to claim 1, characterized in that: The specific method for obtaining divergent input is as follows: (1) Select a seed from the seed queue. The seed is the input instruction that triggers the program under test. (2) Mutate the input seeds to form multiple seeds for testing. Input the seeds into the program under test one by one. Select valid seeds that can trigger the crash of the program under test based on code coverage. Put the valid seeds into the seed queue. Meanwhile, use the currently selected valid seeds as divergent input.
3. The method for automatically generating attack paths based on layout-guided fuzz testing according to claim 2, characterized in that: The seed prioritizes input instructions that hit all layout contribution instructions in the same order as the guide slice, secondly selects input instructions with the longest common subsequence LCSP being long, and finally selects input instructions with the shortest layout contributor instruction list La.
4. The method for automatically generating attack paths based on layout-guided fuzz testing according to claim 3, characterized in that: The formation process of the layout contributor instruction list La of the input instruction Ia is as follows: The program under test executes the input instruction Ia, monitors the execution path of the instruction Ia, and in the process of executing the instruction Ia, records all layout contributor instructions that hit the layout contributor directed graph and puts them into the layout contributor instruction list La.
5. The method for automatically generating attack paths based on layout-guided fuzz testing according to claim 1, characterized in that: The filtering method for divergent input is as follows: Align the layout contributor directed graph of the divergent path with the target layout contributor directed graph of the crash path. If the two are aligned, keep the corresponding divergent input. If not, find the abnormal instruction object that causes the misalignment in the divergent path, build a new layout contributor directed graph of the abnormal instruction object, align the new layout contributor directed graph with the target layout contributor directed graph of the crash path, and keep the divergent input corresponding to the divergent path aligned with the target layout contributor directed graph. The constructed PoC input, the program under test executes the instructions corresponding to the PoC input, and monitors the execution path to obtain the crash path; The program under test executes the instructions corresponding to the divergent inputs and monitors its execution path to obtain the divergent paths corresponding to the divergent instructions.
6. The method for automatically generating attack paths based on layout-guided fuzz testing according to claim 1, characterized in that: The location where the abnormal object is destroyed in the crash path is selected as the splicing point.
7. The method for automatically generating attack paths based on layout-guided fuzz testing according to claim 1, characterized in that: The method for identifying the splicing points in the divergent path is as follows: Construct a directed graph of layout contributors of the operands of the exploitable operations in the divergent path, match the directed graph of layout contributors with the directed graph of the abnormal objects in the crash path, and if the former is a subgraph of the latter, select the next instruction in the divergent path immediately after the last write access of the operands of the exploitable operations as the splicing point; If the former is not a subgraph of the latter, the instruction in the forked path that earliest causes the difference between the layout contributor directed graph of the forked path and the layout contributor directed graph of the abnormal object of the crash path is selected as the splicing point.
8. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method for automatically generating attack paths based on layout-guided fuzz testing according to any one of claims 1 to 7 are implemented.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method for automatically generating attack paths based on layout-guided fuzz testing according to any one of claims 1 to 7 are implemented.