Vulnerability detection method and device, equipment, medium and product

By acquiring and analyzing the state machine of the target protocol program, determining the maximum resource consumption state and performing attack simulation, the problem of failure to accurately detect unknown DoS attack vulnerabilities in the prior art is solved, and a higher vulnerability detection accuracy is achieved.

CN119995954AActive Publication Date: 2025-05-13ZHEJIANG GEELY HLDG GRP CO LTD +1
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202510069612.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-16
Publication Date
2025-05-13
Estimated Expiration
2045-01-16

AI Technical Summary

Technical Problem

The existing technology lacks effective methods to detect unknown or new DoS attack vulnerabilities, resulting in inaccurate vulnerabilities detection.

Method used

By obtaining the target state machine corresponding to the target protocol program, determining the protocol state corresponding to the maximum resource consumption, and using this state, the target protocol program is attacked to determine the vulnerability type.

Benefits of technology

Improve the accuracy of vulnerability detection and can effectively identify resource-depleted and non-resource-depleted vulnerabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119995954A_ABST
    Figure CN119995954A_ABST
Patent Text Reader

Abstract

The invention provides a vulnerability detection method and device, equipment, a medium and a product, and relates to the technical field of network security. The method comprises the following steps: acquiring a target state machine corresponding to a target protocol program, wherein the target state machine comprises a plurality of protocol states and resource consumption corresponding to each protocol state; determining a target protocol state from the plurality of protocol states; the target protocol state is a protocol state corresponding to the maximum resource consumption in the target state machine; performing attack simulation on the target protocol program based on the target protocol state, and determining an attack vulnerability type of the target protocol program; the attack vulnerability type is a resource depletion type vulnerability or a non-resource depletion type vulnerability. Therefore, the resource consumption is introduced into the state machine, and the protocol state for attack simulation is determined based on the resource consumption, so that the attack vulnerability type of the target protocol program can be determined, and the attack vulnerability type of the target protocol program can be mined based on the resource consumption among the protocol states, thereby improving the vulnerability detection accuracy.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular to a vulnerability detection method, device, equipment, medium and product. Background Art

[0002] Denial of Service (DoS) attacks aim to hinder the availability of a target. Based on the type of vulnerability exploited, DoS attacks can be categorized into two main types: 1) Crash Attacks: These attacks exploit vulnerabilities that can cause the target to crash (e.g., cause a segmentation fault), rendering it unavailable. 2) Resource Exhaustion Attacks: These attacks exploit resource exhaustion vulnerabilities by flooding the target with requests, causing it to exhaust its resources and thus rendering the service unavailable to legitimate users.

[0003] To defend against DoS attacks, existing technologies have proposed a variety of prevention and mitigation measures. However, these measures are designed and tested based on known DoS vulnerabilities, but lack detection methods for unknown or new DoS vulnerabilities, resulting in inaccurate vulnerability detection. Summary of the Invention

[0004] The purpose of the embodiments of the present application is to provide a vulnerability detection method, apparatus, device, medium and product to improve the accuracy of vulnerability detection.

[0005] In a first aspect, an embodiment of the present application provides a vulnerability detection method, the vulnerability detection method comprising:

[0006] Obtaining a target state machine corresponding to a target protocol program, wherein the target state machine includes a plurality of protocol states and resource consumption corresponding to each of the protocol states;

[0007] Determining a target protocol state from the multiple protocol states; the target protocol state is the protocol state corresponding to the maximum resource consumption in the target state machine;

[0008] An attack simulation is performed on the target protocol program based on the target protocol state to determine the attack vulnerability type of the target protocol program; the attack vulnerability type is a resource exhaustion vulnerability or a non-resource exhaustion vulnerability.

[0009] In some implementations, obtaining a target state machine corresponding to a target protocol program includes:

[0010] determining a first protocol state from an initial state machine corresponding to the target protocol program based on parameters of each protocol state in the initial state machine, wherein the parameters include resource consumption;

[0011] Performing a fuzzy test on the first protocol state to obtain a second protocol state and a first resource consumption of the second protocol state; the second protocol state is obtained based on the conversion of the first protocol state;

[0012] The initial state machine is updated according to the second protocol state and the first resource consumption of the second protocol state to obtain the target state machine.

[0013] In some embodiments, the parameters further include: the number of active times and the number of selected times; and the determining of the first protocol state from the initial state machine based on the parameters of each protocol state in the initial state machine corresponding to the target protocol program includes:

[0014] For each protocol state in the initial state machine corresponding to the target protocol program, input the parameter of the protocol state into the target formula to obtain a selection probability value corresponding to the protocol state;

[0015] Determining the protocol state corresponding to the maximum value among the selection probability values ​​as the first protocol state;

[0016] Wherein, the target formula is:

[0017]

[0018] Among them, Score(m) represents the selection probability value corresponding to the m-th protocol state, MC(m) represents the resource consumption of the m-th protocol state, UN(m) represents the number of active times of the m-th protocol state, SN(m) represents the number of selection times of the m-th protocol state, and m is a positive integer.

[0019] In some embodiments, the parameters further include: the number of times selected;

[0020] The updating of the initial state machine according to the second protocol state and the first resource consumption of the second protocol state to obtain a target state machine includes:

[0021] If a first condition is met, the first resource consumption is updated to the initial state machine, the number of times the first protocol state in the initial state machine is selected is increased by 1, and parameters for executing each protocol state in the initial state machine corresponding to the target protocol program are returned, and the first protocol state is determined from the initial state machine until a preset fuzz test stop condition is met, thereby obtaining the target state machine;

[0022] The first condition is any one of the following:

[0023] The initial state machine does not include the second protocol state;

[0024] The initial state machine includes a second resource consumption of the second protocol state, and the second resource consumption is less than the first resource consumption.

[0025] In some embodiments, the parameters further include: the number of times selected;

[0026] The updating of the initial state machine according to the second protocol state and the first resource consumption of the second protocol state to obtain a target state machine includes:

[0027] If the second condition is met, the number of times the first protocol state in the initial state machine is selected is increased by 1, and parameters for executing each protocol state in the initial state machine corresponding to the target protocol program are returned, and the first protocol state is determined from the initial state machine until a preset fuzz test stop condition is met, thereby obtaining the target state machine;

[0028] The second condition is that the initial state machine includes the second resource consumption of the second protocol state, and the second resource consumption is greater than or equal to the first resource consumption.

[0029] In some implementations, performing fuzzy testing on the first protocol state to obtain the second protocol state and the first resource consumption of the second protocol state includes:

[0030] Determining a first seed corresponding to the first protocol state in an initial seed pool;

[0031] mutating the first seed to obtain a second seed;

[0032] The second seed is input into the target protocol program to obtain a second protocol state obtained by converting the first protocol state triggered by the second seed and a first resource consumption of the second protocol state.

[0033] In some embodiments, before determining the first protocol state from the initial state machine based on parameters of each protocol state in the initial state machine corresponding to the target protocol program, the detection method further includes:

[0034] Get the initial seed pool;

[0035] sequentially inputting seeds from the initial seed pool into the target protocol program, extracting protocol states triggered by various sub-programs and resource consumption of the protocol states;

[0036] The initial state machine is constructed based on the protocol states of various sub-triggers and the resource consumption of the protocol states.

[0037] In a second aspect, an embodiment of the present application provides a vulnerability detection device, comprising:

[0038] An acquisition module, configured to acquire a target state machine corresponding to a target protocol program, wherein the target state machine includes a plurality of protocol states and resource consumption corresponding to each of the protocol states;

[0039] a determination module, configured to determine a target protocol state from the plurality of protocol states; the target protocol state being the protocol state corresponding to the maximum resource consumption in the target state machine;

[0040] A simulation module is used to perform attack simulation on the target protocol program based on the target protocol state to determine the attack vulnerability type of the target protocol program; the attack vulnerability type is a resource exhaustion vulnerability or a non-resource exhaustion vulnerability.

[0041] In a third aspect, an embodiment of the present application provides an electronic device, including:

[0042] a memory configured to store instructions; and

[0043] The processor is configured to call the instructions from the memory and to implement the vulnerability detection method provided in the first aspect of the embodiment of the present application when executing the instructions.

[0044] In a fourth aspect, an embodiment of the present application provides a machine-readable storage medium, on which instructions are stored, and the instructions are used to enable a machine to execute the vulnerability detection method described above.

[0045] In a fifth aspect, an embodiment of the present application provides a computer program product. When the instructions in the computer program product are executed by a processor of an electronic device, the electronic device executes the vulnerability detection method as described above.

[0046] In an embodiment of the present application, first, a target state machine corresponding to a target protocol program is obtained, wherein the target state machine includes a plurality of protocol states and resource consumption corresponding to each protocol state. Then, a target protocol state is determined from the plurality of protocol states; the target protocol state is the protocol state corresponding to the maximum resource consumption in the target state machine. Finally, an attack simulation is performed on the target protocol program based on the target protocol state to determine the attack vulnerability type of the target protocol program; the attack vulnerability type is a resource exhaustion type vulnerability or a non-resource exhaustion type vulnerability. In this way, by introducing resource consumption into the state machine and determining the protocol state for attack simulation based on resource consumption, the attack vulnerability type of the target protocol program can be determined, and the attack vulnerability type of the target protocol program can be mined based on the resource consumption between the protocol states, thereby improving the accuracy of vulnerability detection. BRIEF DESCRIPTION OF THE DRAWINGS

[0047] Figure 1 This is a flow chart of a vulnerability detection method provided by an embodiment of the present application;

[0048] Figure 2 Schematic diagram of the structure of the vulnerability detection device provided in the embodiment of the present application;

[0049] Figure 3 This is a schematic diagram of the structure of the vulnerability detection system provided by the embodiment of the present application;

[0050] Figure 4 It is a structural diagram of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0051] The following will be combined with the accompanying drawings in the embodiments of the present application to clearly describe the technical solutions in the embodiments of the present application. Obviously, the embodiments described are part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field are within the scope of protection of this application.

[0052] The terms "first," "second," and the like in the specification and claims of this application are used to distinguish similar objects, and are not used to describe a specific order or precedence. It should be understood that the terms used in this manner are interchangeable where appropriate, so that the embodiments of this application can be implemented in an order other than that illustrated or described herein, and that the objects distinguished by "first," "second," and the like are generally of the same type, and do not limit the number of objects; for example, the first object can be one or more. In addition, the term "and / or" in the specification and claims represents at least one of the connected objects, and the character " / " generally indicates that the objects associated with each other are in an "or" relationship.

[0053] The following, in conjunction with the accompanying drawings, describes in detail the vulnerability detection method, device, equipment, medium and product provided in the embodiments of the present application through specific embodiments and their application scenarios.

[0054] See Figure 1 , is a flow chart of a vulnerability detection method provided by an embodiment of the present application, which is applied to electronic devices. Figure 1 As shown, the vulnerability detection method includes the following steps S100 to S300.

[0055] Step S100: obtaining a target state machine corresponding to a target protocol program, wherein the target state machine includes a plurality of protocol states and resource consumption corresponding to each of the protocol states.

[0056] In-vehicle systems contain dozens or even hundreds of electronic control units (ECUs), such as the Domain Head Unit (DHU), Ternary Content Addressable Memory (TCAM), and Bluetooth Network Controller Module (BNCM). These electronic units communicate with each other and with the outside world using a variety of protocols. The logic that handles protocols within these electronic units is called a protocol program. The target protocol program can be understood as the protocol program to be tested for vulnerabilities.

[0057] In an embodiment of the present application, the state machine can be understood as a model for describing the transition of the vehicle system between different states. The target state machine may include multiple protocol states and the resource consumption corresponding to each protocol state. The protocol state can be understood as the current state of the target protocol program. In one example, the protocol state may include: successful login state, successful command execution state, and file state, normal opening of data connection port state, etc. The resource consumption corresponding to the protocol state can be understood as the resource consumption of the protocol state during the conversion process. In one example, the resource consumption generated in the process of converting from the first protocol state to the second protocol state can be understood as the resource consumption of the second protocol state.

[0058] Step S200: determining a target protocol state from the multiple protocol states; the target protocol state is the protocol state corresponding to the maximum resource consumption in the target state machine.

[0059] In the embodiments of the present application, the target protocol state can be understood as a protocol state that may trigger a resource exhaustion vulnerability. The process of protocol state transition is accompanied by resource consumption, and excessive resource consumption may lead to resource exhaustion of the target protocol program. Therefore, when determining the target protocol state, the protocol state corresponding to the maximum resource consumption in the target state machine can be determined as the target protocol state.

[0060] Step S300: performing attack simulation on the target protocol program based on the target protocol state to determine the attack vulnerability type of the target protocol program; the attack vulnerability type is a resource exhaustion vulnerability or a non-resource exhaustion vulnerability.

[0061] In an embodiment of the present application, attack simulation can be understood as simulating whether the attack input can cause a denial of service of the protocol program being tested. During the attack simulation, an experimental environment for simulating a denial of service (DoS) is first constructed, and the target protocol program is run therein. Then an "attacker" is created to send the constructed attack to the target protocol program. The status of the attacked target protocol program is monitored. Before performing an attack simulation, the attack simulation can be adjusted by configuring parameters such as system memory limit, monitoring duration, attack time, and attack intensity. The system memory limit can determine the maximum memory limit of the experimental environment, the monitoring duration can determine the total time for the simulation, the attack time can determine the time to start the attack after setting the experimental environment, and the attack intensity can determine how many attack input sequences are sent to the target protocol program per second.

[0062] In an embodiment of the present application, after determining the target protocol state, the attack vulnerability type of the target protocol program can be determined by attacking the target protocol state. The attack vulnerability type can include resource exhaustion type vulnerability and non-resource exhaustion type vulnerability. Specifically, in an environment with given resource constraints (such as memory limit 16G), if there is excessive resource consumption causing the target protocol program to crash or fail to respond to services normally, it is judged to be a resource exhaustion type vulnerability. On the contrary, if there is no excessive resource consumption causing the target protocol program to crash or fail to respond to services normally, it is judged to be a non-resource exhaustion type vulnerability.

[0063] Through the above steps S100-S300, the target state machine corresponding to the target protocol program is obtained, and the target state machine includes multiple protocol states and the resource consumption corresponding to each protocol state. Then the target protocol state is determined from the multiple protocol states; the target protocol state is the protocol state corresponding to the maximum resource consumption in the target state machine. Finally, an attack simulation is performed on the target protocol program based on the target protocol state to determine the attack vulnerability type of the target protocol program; the attack vulnerability type is a resource exhaustion type vulnerability or a non-resource exhaustion type vulnerability. In this way, by introducing resource consumption into the state machine and determining the protocol state for attack simulation based on resource consumption, the attack vulnerability type of the target protocol program can be determined, and the attack vulnerability type of the target protocol program can be mined based on the resource consumption between the protocol states, thereby improving the accuracy of vulnerability detection.

[0064] In some implementations, obtaining a target state machine corresponding to a target protocol program includes:

[0065] determining a first protocol state from an initial state machine corresponding to the target protocol program based on parameters of each protocol state in the initial state machine, wherein the parameters include resource consumption;

[0066] Performing a fuzzy test on the first protocol state to obtain a second protocol state and a first resource consumption of the second protocol state; the second protocol state is obtained based on the conversion of the first protocol state;

[0067] The initial state machine is updated according to the second protocol state and the first resource consumption of the second protocol state to obtain the target state machine.

[0068] Specifically, the initial state machine can be understood as a state machine constructed based on protocol state and resource consumption information, which is constructed by inputting the initial seed from the initial seed pool into the target program for execution, extracting the protocol state triggered by it, and monitoring the resources consumed during each state transition. In this state machine, nodes represent protocol states, and edges represent state transitions. An attribute is attached to the initial state machine, indicating the maximum resource consumption during that state transition.

[0069] In the embodiments of the present application, the first protocol state can be understood as a protocol state selected from the initial state machine. When selecting the first protocol state, the selection can be made based on the parameters of each protocol state in the initial state machine. The parameters of each protocol state in the initial state machine may include, but are not limited to, resource consumption.

[0070] In the embodiment of the present application, fuzz testing can be understood as a testing method that discovers loopholes, crashes, errors and security weaknesses in a program by providing a large amount of random, invalid or malformed input data to the protocol program.

[0071] In an embodiment of the present application, resource consumption is introduced into the fuzz testing process. In addition to observing the execution state of the program, the resource consumption during each state transition is also monitored. When fuzz testing the first protocol state, a seed corresponding to the first protocol state is obtained and mutated. The mutated seed is then input into the target protocol program to obtain the second protocol state and the first resource consumption of the second protocol state. The first resource consumption of the second protocol state can be understood as the resource consumption during the process of transitioning from the first protocol state to the second protocol state.

[0072] In an embodiment of the present application, after the first resource consumption of the second protocol state and the second protocol state is obtained through fuzz testing, the initial state machine can be updated according to the first resource consumption of the second protocol state and the second protocol state. The initial state machine includes multiple protocol states and the resource consumption of each protocol state stored after fuzz testing based on the seeds in the initial seed pool. In the case that the first resource consumption of the second protocol state and the second protocol state is not included in the initial state machine, the first resource consumption of the second protocol state and the second protocol state is added to the initial state machine to obtain an updated state machine, and the protocol state is reselected for fuzz testing until the preset fuzz test stop condition is met to obtain the target state machine. The preset fuzz test stop condition may include but is not limited to a preset number of tests and a preset time.

[0073] In this embodiment, by constructing a target state machine combined with resource consumption, it is possible to mine protocol states that may cause resource exhaustion vulnerabilities based on resource consumption between various protocol states.

[0074] In some embodiments, the parameters further include: the number of active times and the number of selected times; and the determining of the first protocol state from the initial state machine based on the parameters of each protocol state in the initial state machine corresponding to the target protocol program includes:

[0075] For each protocol state in the initial state machine corresponding to the target protocol program, input the parameter of the protocol state into the target formula to obtain a selection probability value corresponding to the protocol state;

[0076] Determining the protocol state corresponding to the maximum value among the selection probability values ​​as the first protocol state;

[0077] Wherein, the target formula is:

[0078]

[0079] Among them, Score(m) represents the selection probability value corresponding to the m-th protocol state, MC(m) represents the resource consumption of the m-th protocol state, UN(m) represents the number of active times of the m-th protocol state, SN(m) represents the number of selection times of the m-th protocol state, and m is a positive integer.

[0080] Specifically, the parameters of each protocol state in the initial state machine corresponding to the target protocol program may include, in addition to resource consumption, the number of active times and the number of selected times.

[0081] Resource consumption can be understood as the maximum resource consumption during the protocol state transition process. Intuitively, mutating the seed corresponding to the protocol state with higher resource consumption is more likely to discover greater resource consumption.

[0082] The number of active times can be understood as the number of times the resource consumption attribute of the protocol state has been updated. The logic is that if the resource consumption attribute of the protocol state is updated frequently, then mutating the seed corresponding to the protocol state is more likely to generate new resource consumption.

[0083] The number of selections can be understood as the number of times the protocol state has been selected, or the number of times the seed corresponding to the protocol state has been selected for mutation. If the protocol state has been selected many times, it should be avoided to avoid exhausting the opportunities to select other protocol states.

[0084] In the embodiment of the present application, the selection probability value of each protocol state can be determined based on the resource consumption, active times, and selected times of each protocol state, and the protocol state corresponding to the maximum value among the selection probability values ​​is determined as the first protocol state. When calculating the selection probability value, the resource consumption, active times, and selected times of each protocol state can be substituted into formula (1), that is, the target formula:

[0085]

[0086] In the embodiment of the present application, the protocol state with the largest resource consumption may also be directly determined as the first protocol state.

[0087] In this embodiment, by determining the first protocol state according to resource consumption, active times, and selected times of each protocol state, multiple factors can be combined to determine a more optimal protocol state as the first protocol state.

[0088] In some embodiments, the parameters further include: the number of times selected;

[0089] The updating of the initial state machine according to the second protocol state and the first resource consumption of the second protocol state to obtain a target state machine includes:

[0090] If a first condition is met, the first resource consumption is updated to the initial state machine, the number of times the first protocol state in the initial state machine is selected is increased by 1, and parameters for executing each protocol state in the initial state machine corresponding to the target protocol program are returned, and the first protocol state is determined from the initial state machine until a preset fuzz test stop condition is met, thereby obtaining the target state machine;

[0091] The first condition is any one of the following:

[0092] The initial state machine does not include the second protocol state;

[0093] The initial state machine includes a second resource consumption of the second protocol state, and the second resource consumption is less than the first resource consumption.

[0094] Specifically, the initial state machine includes multiple protocol states and resource consumption of each protocol state stored after fuzz testing based on seeds in the initial seed pool. After the second protocol state and the first resource consumption of the second protocol state are obtained through fuzz testing, it can be determined whether the initial state machine needs to be updated by determining whether the second protocol state and the first resource consumption of the second protocol state are included in the initial state machine.

[0095] In an embodiment of the present application, if the initial state machine does not include the second protocol state, the second protocol state and the first resource consumption of the second protocol state are added to the initial state machine. The updated initial state machine includes, in addition to the multiple protocol states and resource consumption of each protocol state included in the initial state machine, the second protocol state and the first resource consumption of the second protocol state.

[0096] If the initial state machine includes a second protocol state, and if a second resource consumption of the second protocol state included in the initial state machine is less than a first resource consumption generated by fuzz testing, the first resource consumption is updated into the initial state machine. The updated initial state machine includes the first resource consumption of the second protocol state in addition to the multiple protocol states included in the initial state machine and the resource consumption of each protocol state.

[0097] After obtaining the updated initial state machine, the program returns to execute the parameters of each protocol state in the initial state machine corresponding to the target protocol program, and determines the first protocol state from the initial state machine. That is, the protocol state is determined based on the updated initial state machine. When determining the new protocol state, the number of times the first protocol state has been selected is incremented by 1, and the number of times the second protocol state has been active is incremented by 1. Fuzz testing is then performed until the preset fuzz testing stop conditions are met, resulting in the target state machine. The preset fuzz testing stop conditions may include, but are not limited to, a preset number of tests and a preset time.

[0098] In this embodiment, by updating the initial state machine and performing a cyclic fuzzy test without including the second protocol state or the first resource consumption of the second protocol state in the initial state machine, the accuracy of each fuzzy test can be improved.

[0099] In some embodiments, the parameters further include: the number of times selected;

[0100] The updating of the initial state machine according to the second protocol state and the first resource consumption of the second protocol state to obtain a target state machine includes:

[0101] If the second condition is met, the number of times the first protocol state in the initial state machine is selected is increased by 1, and parameters for executing each protocol state in the initial state machine corresponding to the target protocol program are returned, and the first protocol state is determined from the initial state machine until a preset fuzz test stop condition is met, thereby obtaining the target state machine;

[0102] The second condition is that the initial state machine includes the second resource consumption of the second protocol state, and the second resource consumption is greater than or equal to the first resource consumption.

[0103] Specifically, the parameters for each protocol state also include the number of selections. This can be understood as the number of times the protocol state has been selected, or the number of times the seed corresponding to the protocol state has been selected for mutation. If a protocol state has been selected many times, it should be avoided to prevent exhausting the opportunities to select other protocol states.

[0104] In this embodiment of the present application, if the initial state machine includes the second resource consumption of the second protocol state, and the second resource consumption is greater than or equal to the first resource consumption, that is, the resource consumption during the new state transition process is less than the resource consumption stored in the state machine, then there is no need to update the initial state machine. The number of times the first protocol state in the initial state machine has been selected is incremented by 1.

[0105] In this embodiment of the present application, after the number of times the first protocol state in the initial state machine has been selected is incremented by 1, the parameters of each protocol state in the initial state machine corresponding to the target protocol program are returned and the first protocol state is determined from the initial state machine. That is, the first protocol state is determined based on the updated parameters until a preset fuzz testing stop condition is met, thereby obtaining the target state machine.

[0106] In this embodiment, the accuracy of each fuzzy test can be improved by updating the parameters of each protocol state in real time.

[0107] In some implementations, performing fuzzy testing on the first protocol state to obtain the second protocol state and the first resource consumption of the second protocol state includes:

[0108] Determining a first seed corresponding to the first protocol state in an initial seed pool;

[0109] mutating the first seed to obtain a second seed;

[0110] The second seed is input into the target protocol program to obtain a second protocol state obtained by converting the first protocol state triggered by the second seed and a first resource consumption of the second protocol state.

[0111] Specifically, the embodiments of the present application introduce resource consumption into the fuzz testing process. When fuzz testing a first protocol state, a first seed corresponding to the first protocol state is first obtained from an initial seed pool. The first seed is then mutated to obtain a mutated seed, i.e., a second seed. The second seed is then input into the target protocol program, the execution state of the target protocol program is observed, and the protocol state and resource consumption triggered by the second seed are extracted, i.e., the second protocol state obtained by converting the first protocol state and the first resource consumption of the second protocol state.

[0112] In this embodiment, by introducing resource consumption into the framework of fuzz testing, the resource consumption between various protocol states in the protocol program can be explored based on resource consumption feedback, and potential resource consumption vulnerabilities can be discovered.

[0113] In some embodiments, before determining the first protocol state from the initial state machine based on parameters of each protocol state in the initial state machine corresponding to the target protocol program, the detection method further includes:

[0114] Get the initial seed pool;

[0115] sequentially inputting seeds from the initial seed pool into the target protocol program, extracting protocol states triggered by various sub-programs and resource consumption of the protocol states;

[0116] The initial state machine is constructed based on the protocol states of various sub-triggers and the resource consumption of the protocol states.

[0117] Specifically, before determining the first protocol state from the initial state machine based on the parameters of each protocol state in the initial state machine corresponding to the target protocol program, the initial state machine may be constructed first.

[0118] In an embodiment of the present application, before constructing the initial state machine, the materials required for fuzz testing are obtained. These materials may include but are not limited to the target protocol program to be tested, the initial seed pool for fuzz testing, and the state extractor code for extracting the protocol state. First, the seeds in the initial seed pool are sequentially input into the target protocol program, the protocol state triggered by it is extracted by the state extractor code, and the resource consumption during each state transition is monitored. The protocol state and resource consumption corresponding to each seed are used to construct the initial state machine. In the initial state machine, the node represents the protocol state, the edge represents the state transition, and an attribute is attached to represent the maximum resource consumption during the state transition, thereby improving the accuracy of vulnerability detection.

[0119] In this embodiment, by building a state machine in combination with resource consumption, the accuracy of fuzz testing can be improved.

[0120] See Figure 2, is a schematic diagram of the structure of a vulnerability detection device provided in an embodiment of the present application. In a second aspect, an embodiment of the present application provides a vulnerability detection device 20, which includes:

[0121] An acquisition module 21 is configured to acquire a target state machine corresponding to a target protocol program, wherein the target state machine includes a plurality of protocol states and resource consumption corresponding to each of the protocol states;

[0122] A determination module 22 is configured to determine a target protocol state from the plurality of protocol states; the target protocol state being the protocol state corresponding to the maximum resource consumption in the target state machine;

[0123] The simulation module 23 is used to perform attack simulation on the target protocol program based on the target protocol state to determine the attack vulnerability type of the target protocol program; the attack vulnerability type is a resource exhaustion vulnerability or a non-resource exhaustion vulnerability.

[0124] The vulnerability detection device 20 provided in the second aspect of the embodiment of the present application can implement each process implemented in the above method embodiment and achieve the same beneficial effects. To avoid repetition, it will not be described here.

[0125] See Figure 3 , is a schematic diagram of the structure of the vulnerability detection system provided in the embodiment of the present application, such as Figure 3 As shown, vulnerability detection is divided into three phases: pre-fuzz testing, fuzz testing, and post-fuzz testing. Before fuzz testing, the target protocol program to be tested, the initial seed for fuzz testing, the state extractor code for extracting protocol states, and the format parser code for parsing sent request messages are first obtained. During fuzz testing, a seed is first selected and mutated using the seed selection module. The mutated seed is then input into the target protocol program for execution. The state extractor code extracts the triggered protocol state, and the monitoring module monitors the resource consumption during each state transition. The state machine is updated based on the triggered protocol state and the resource consumption of the protocol state, resulting in a state machine that incorporates resource consumption. After fuzz testing, the resource consumption state machine describes the resource consumption of the target protocol program in each protocol state. This resource consumption state machine can be used to generate protocol states that could lead to resource exhaustion DoS attacks. DoS attacks can then be simulated in a simulation environment to verify the existence of resource exhaustion vulnerabilities that could cause DoS attacks.

[0126] See Figure 4, is a structural diagram of an electronic device provided in an embodiment of the present application. An embodiment of the present application provides an electronic device 4000, including a processor 4100 and a memory 4200. The memory 4200 stores machine-executable instructions that can be executed by the processor 4100. The processor 4100 can execute the machine-executable instructions to implement the above-mentioned vulnerability detection method.

[0127] In some implementations, the embodiments of the present application further provide a machine-readable storage medium, on which instructions are stored. When the instructions are executed by a processor, the processor implements the above-mentioned vulnerability detection method.

[0128] In some embodiments, the embodiments of the present application further provide a computer program product, including a computer program, which implements the vulnerability detection method according to the above embodiment when executed by a processor.

[0129] Those skilled in the art will appreciate that the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.

[0130] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the steps in the process. Figure 1 a process or multiple processes and / or boxes Figure 1 These computer program instructions can also be stored in a computer-readable memory that can guide a computer or other programmable data processing device to work in a specific way, so that the instructions stored in the computer-readable memory produce a product including the instruction device, which implements the function specified in the process. Figure 1 a process or multiple processes and / or boxes Figure 1These computer program instructions can also be loaded onto a computer or other programmable data processing device, so that a series of operation steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process in the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.

[0131] In a typical configuration, a computing device includes one or more processors (CPUs), input / output interfaces, network interfaces, and memory.

[0132] The memory may include non-permanent memory in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. The memory is an example of a computer-readable medium.

[0133] Computer-readable media includes permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. The information can be computer-readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, magnetic tape, magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer-readable media does not include transitory computer-readable media (transitory media), such as modulated data signals and carrier waves.

[0134] It should also be noted that the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, commodity, or apparatus that includes a series of elements includes not only those elements but also other elements not explicitly listed, or includes elements inherent to such process, method, commodity, or apparatus. In the absence of further limitations, an element defined by the phrase "comprises a ..." does not exclude the presence of other identical elements in the process, method, commodity, or apparatus that includes the element.

[0135] The above are merely embodiments of the present application and are not intended to limit the present application. For those skilled in the art, the present application may have various changes and variations. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present application should all be included within the scope of the claims of the present application.

[0136] In addition, the various embodiments of the present invention may be arbitrarily combined, and as long as they do not violate the concept of the present invention, they should also be regarded as the contents disclosed by the present invention.

Claims

1. A vulnerability detection method, characterized in that: The vulnerability detection method comprises: Obtaining a target state machine corresponding to a target protocol program, wherein the target state machine includes a plurality of protocol states and resource consumption corresponding to each of the protocol states; Determining a target protocol state from the multiple protocol states; the target protocol state is a protocol state corresponding to the maximum resource consumption in the target state machine; An attack simulation is performed on the target protocol program based on the target protocol state to determine the attack vulnerability type of the target protocol program; the attack vulnerability type is a resource exhaustion type vulnerability or a non-resource exhaustion type vulnerability.

2. The vulnerability detection method according to claim 1, characterized in that: The target state machine corresponding to the target protocol program is obtained as follows: Determining a first protocol state from an initial state machine corresponding to the target protocol program based on parameters of each protocol state in the initial state machine; the parameters including resource consumption; Performing a fuzzy test on the first protocol state to obtain a second protocol state and a first resource consumption of the second protocol state; the second protocol state is obtained based on the conversion of the first protocol state; The initial state machine is updated according to the second protocol state and the first resource consumption of the second protocol state to obtain the target state machine.

3. The vulnerability detection method according to claim 2, characterized in that: The parameters also include: the number of active times and the number of selected times; the parameters of each protocol state in the initial state machine corresponding to the target protocol program, and determining the first protocol state from the initial state machine, include: For each protocol state in the initial state machine corresponding to the target protocol program, input the parameter of the protocol state into the target formula to obtain a selection probability value corresponding to the protocol state; Determine the protocol state corresponding to the maximum value among the selection probability values ​​as the first protocol state; Wherein, the target formula is: Among them, Score(m) represents the selection probability value corresponding to the mth protocol state, MC(m) represents the resource consumption of the mth protocol state, UN(m) represents the number of active times of the mth protocol state, SN(m) represents the number of selection times of the mth protocol state, and m is a positive integer.

4. The vulnerability detection method according to claim 2, characterized in that: The parameters also include: the number of times selected; The updating the initial state machine according to the second protocol state and the first resource consumption of the second protocol state to obtain the target state machine includes: When the first condition is met, the first resource consumption is updated to the initial state machine, the number of selections corresponding to the first protocol state in the initial state machine is increased by 1, and the parameters of each protocol state in the initial state machine corresponding to the target protocol program are returned, and the first protocol state is determined from the initial state machine until the preset fuzzy test stop condition is met to obtain the target state machine; Wherein, the first condition is any one of the following: The initial state machine does not include the second protocol state; The initial state machine includes a second resource consumption of the second protocol state, and the second resource consumption is less than the first resource consumption.

5. The vulnerability detection method according to claim 2, characterized in that: The parameters also include: the number of times selected; The updating the initial state machine according to the second protocol state and the first resource consumption of the second protocol state to obtain the target state machine includes: When the second condition is met, the number of times the first protocol state in the initial state machine is selected is increased by 1, and the parameters of each protocol state in the initial state machine corresponding to the target protocol program are returned, and the first protocol state is determined from the initial state machine until the preset fuzzy test stop condition is met to obtain the target state machine; The second condition is that the initial state machine includes the second resource consumption of the second protocol state, and the second resource consumption is greater than or equal to the first resource consumption.

6. The vulnerability detection method according to claim 2, characterized in that: The performing fuzzy testing on the first protocol state to obtain a second protocol state and a first resource consumption of the second protocol state includes: Determining a first seed corresponding to the first protocol state in an initial seed pool; mutating the first seed to obtain a second seed; The second seed is input into the target protocol program to obtain a second protocol state obtained by converting the first protocol state and triggered by the second seed, and a first resource consumption of the second protocol state.

7. The vulnerability detection method according to claim 2, characterized in that: Before determining the first protocol state from the initial state machine based on the parameters of each protocol state in the initial state machine corresponding to the target protocol program, the detection method further includes: Get the initial seed pool; sequentially inputting seeds in the initial seed pool into the target protocol program, extracting protocol states of various sub-triggers and resource consumption of the protocol states; The initial state machine is constructed based on the protocol states of various sub-triggers and the resource consumption of the protocol states.

8. A vulnerability detection device, characterized in that: The vulnerability detection device comprises: An acquisition module, used to acquire a target state machine corresponding to a target protocol program, wherein the target state machine includes a plurality of protocol states and resource consumption corresponding to each of the protocol states; A determination module, configured to determine a target protocol state from the multiple protocol states; the target protocol state is a protocol state corresponding to the maximum resource consumption in the target state machine; A simulation module is used to perform attack simulation on the target protocol program based on the target protocol state to determine the attack vulnerability type of the target protocol program; the attack vulnerability type is a resource exhaustion type vulnerability or a non-resource exhaustion type vulnerability.

9. An electronic device, characterized in that: include: a memory configured to store instructions; as well as A processor is configured to call the instructions from the memory and implement the vulnerability detection method according to any one of claims 1 to 7 when executing the instructions.

10. A machine-readable storage medium, characterized in that: The machine-readable storage medium stores instructions, and the instructions are used to enable a machine to execute the vulnerability detection method according to any one of claims 1 to 7.

11. A computer program product, characterized in that When the instructions in the computer program product are executed by a processor of an electronic device, the electronic device executes the vulnerability detection method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Stateful network protocol vulnerability test method and system based on state selection optimization

    CN116827835A

  • Network protocol fuzz testing method, system, device and medium

    CN117714351A

  • Network protocol fuzzy test method based on Seq2Seq model, medium and product

    CN118540255A

  • Protocol vulnerability analysis system and method based on state storage / recovery

    CN119071083A

  • Increasing security of network resources utilizing virtual honeypots

    US20200067980A1