Method for improving network protocol fuzz test efficiency based on shared memory
By creating a shared memory area between the fuzz testing tool and the target program, the problem of low fuzz testing in traditional network protocols is solved, and more efficient data transmission and context switching is achieved, improving testing efficiency and flexibility.
Patent Information
- Application Number
- CN202510254781.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-05
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2045-03-05
AI Technical Summary
The traditional network protocol fuzz testing method is low in efficiency, mainly due to the large data transmission overhead and frequent context switching.
Using a shared memory-based approach, data transfer and context switching are reduced by creating shared memory areas between the fuzz testing tool and the target program, storing test cases and test results.
It improves the efficiency of network protocol fuzz testing, reduces data transmission overhead and the number of context switching, enhances testing flexibility and simplifies the testing process.
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of network security, and in particular relates to a method for improving the efficiency of network protocol fuzz testing based on shared memory. Background Art
[0002] Fuzz testing is an effective software vulnerability mining technology that triggers program exceptions by inputting a large amount of unexpected data into the target program, thereby discovering potential security vulnerabilities. Network protocol fuzz testing is a fuzz test for network protocol implementations, and its goal is to discover vulnerabilities in network protocol implementations.
[0003] Traditional network protocol fuzz testing methods are usually implemented using inter-process communication (IPC) mechanisms, such as pipes and sockets, to transfer test cases from the fuzz testing tool to the target program. However, this method is inefficient for the following reasons:
[0004] High data transmission overhead: The IPC mechanism requires multiple data copies, which increases the data transmission overhead.
[0005] Frequent context switching: The IPC mechanism requires frequent context switching, which reduces test efficiency. Summary of the invention
[0006] 1. Technical issues to be resolved
[0007] The technical problem to be solved by the present invention is to provide a method for improving the efficiency of network protocol fuzz testing.
[0008] (II) Technical solution
[0009] In order to solve the above technical problems, the present invention provides a method for improving the efficiency of network protocol fuzz testing based on shared memory, comprising the following steps:
[0010] Step 1: Create a shared memory area: Create a shared memory area between the fuzz testing tool and the target program to store test cases and test results;
[0011] Step 2: Initialize the shared memory area: The fuzz testing tool and the target program initialize the shared memory area respectively and establish a communication mechanism;
[0012] Step 3: Generate test cases: The fuzz testing tool generates test cases and writes them into the shared memory area;
[0013] Step 4: Execute the test case: The target program reads the test case from the shared memory area and executes it, and writes the execution result to the shared memory area;
[0014] Step 5: Monitor execution results: The fuzz testing tool monitors the execution results in the shared memory area to determine whether an exception occurs in the target program;
[0015] Repeat steps 3-5: Repeat steps 3-5 until the preset test stop condition is reached.
[0016] Preferably, in step 1, a shared memory area is created using a shared memory API provided by the operating system, the size of the shared memory area is dynamically adjusted according to the size and number of test cases, and can accommodate all test cases and test results; when creating a shared memory area, a dynamic sharding strategy is introduced to automatically divide memory blocks based on protocol field characteristics, and each field corresponds to an independent memory shard; at the same time, Bloom Filter is used to detect memory access hotspots, and the cache strategy of preset high-frequency access shards is dynamically adjusted; in addition, the protocol header and the payload are stored separately, the protocol header part uses fixed sharding, and the payload part uses elastic sharding.
[0017] Preferably, when the shared memory area is initialized in step 2, the fuzz testing tool and the target program respectively map the shared memory area to their respective address spaces and establish a communication mechanism, which includes synchronization mechanisms such as semaphores and mutex locks to ensure that the fuzz testing tool and the target program have mutually exclusive access to the shared memory area.
[0018] Preferably, the communication mechanism established in step 2 includes a lock-free synchronization mechanism based on atomic operations, and supports batch test case delivery by introducing a ring buffer read-write pointer.
[0019] Preferably, in the method, a three-level state machine is also provided to realize test process control, wherein state 0 represents that the test case is ready; state 1 represents that the test case is being executed; and state 2 represents that the result is to be read.
[0020] Preferably, in step 3, the fuzz testing tool uses a variety of methods to generate test cases, including random generation, rule-based generation, and model-based generation, and the generated test cases cover various boundary conditions and abnormal situations of the network protocol.
[0021] Preferably, when the target program executes the test case in step 4, a stub code is inserted into the target program, or the target program is analyzed using symbolic execution technology.
[0022] Preferably, the anomalies monitored by the fuzz testing tool in step 5 include crashes of the target program, memory leaks, and abnormal outputs. At the same time, after the anomalies are monitored, the execution results of the anomalies are analyzed to locate the location and cause of the vulnerability.
[0023] Preferably, in step 1, shmget is used to create a shared memory area, and shmat is used to attach it to the process address space; when the shared memory area is initialized in step 2, sem_open is also used to create two semaphores, which are respectively used to synchronize the transmission of test cases and results; in step 3, a fuzz testing tool Fuzzer is used to generate a test case and write it into the shared memory, and the semaphore sem_test_case is used to notify the target program Target Program that the test case is ready; in step 4, when the target program Target Program reads the test case from the shared memory area and executes it, string processing is used to simulate the execution of the network protocol, the execution result is written into the shared memory area, and the semaphore sem_result is used to notify the fuzz testing tool.
[0024] The present invention also provides a system for implementing the method.
[0025] (III) Beneficial effects
[0026] The method for improving the efficiency of network protocol fuzz testing based on shared memory provided by the present invention has the following beneficial effects:
[0027] Improve test efficiency: Through the shared memory mechanism, data transmission overhead and context switching times are reduced, thereby improving test efficiency.
[0028] Enhanced test flexibility: The size of the shared memory area can be dynamically adjusted according to test requirements, which enhances test flexibility.
[0029] Simplify the testing process: The shared memory mechanism simplifies the communication process between the fuzz testing tool and the target program, reducing the complexity of the test. DETAILED DESCRIPTION
[0030] In order to make the purpose, content and advantages of the present invention more clear, the specific implementation methods of the present invention are further described in detail below in conjunction with embodiments.
[0031] The method for improving network protocol fuzz testing based on shared memory provided by an embodiment of the present invention comprises the following steps:
[0032] Step 1: Create a shared memory area: Create a shared memory area between the fuzz testing tool and the target program to store test cases and test results.
[0033] Step 2: Initialize the shared memory area: The fuzz testing tool and the target program initialize the shared memory area respectively and establish a communication mechanism.
[0034] Step 3: Generate test cases: The fuzz testing tool generates test cases and writes the test cases into the shared memory area.
[0035] Step 4: Execute the test case: The target program reads the test case from the shared memory area and executes it, and writes the execution result to the shared memory area.
[0036] Step 5: Monitor execution results: The fuzz testing tool monitors the execution results in the shared memory area to determine whether an exception occurs in the target program.
[0037] Repeat steps 3-5: Repeat steps 3-5 until the preset test stop condition is reached.
[0038] The details are as follows:
[0039] 1. Creation and initialization of shared memory area
[0040] The shared memory area is a memory area shared between the fuzz testing tool and the target program, and is used to store test cases and test results. The creation and initialization of the shared memory area is a key step of the method of the present invention.
[0041] Create a shared memory area: Use the shared memory API provided by the operating system (for example, the shmget and shmat functions in the Linux system) to create a shared memory area. The size of the shared memory area should be dynamically adjusted according to the size and number of test cases to ensure that all test cases and test results can be accommodated. A dynamic sharding strategy is introduced to automatically divide memory blocks based on protocol field characteristics, and each field corresponds to an independent memory shard. At the same time, Bloom Filter is used to detect memory access hotspots and dynamically adjust the cache strategy of high-frequency access shards. In addition, the protocol header and the payload are stored separately, with fixed sharding used for the protocol header and elastic sharding used for the payload.
[0042] Initialize the shared memory area: The fuzz testing tool and the target program need to map the shared memory area to their respective address spaces and establish a communication mechanism. The communication mechanism includes synchronization mechanisms such as semaphores and mutexes to ensure that the fuzz testing tool and the target program have mutually exclusive access to the shared memory area. Specifically, it implements a lock-free synchronization mechanism based on atomic operations and supports batch test case delivery by introducing a ring buffer read and write pointer. A three-level state machine is set up to implement test process control, where state 0 represents that the test case is ready; state 1 represents that it is being executed; and state 2 represents that the result is to be read.
[0043] 2. Test case generation and execution
[0044] The generation and execution of test cases are the core steps of network protocol fuzz testing. The method of the invention improves the transmission efficiency of test cases through a shared memory mechanism.
[0045] Generate test cases: Fuzz testing tools can use a variety of methods to generate test cases, including random generation, rule-based generation, model-based generation, etc. The generated test cases should cover various boundary conditions and abnormal situations of the network protocol.
[0046] Execute test cases: The target program reads test cases from the shared memory area and executes them. In order to improve the test coverage, when the target program executes the test cases, stub codes are inserted into the target program, or symbolic execution technology is used to analyze the target program.
[0047] 3. Monitoring and analysis of execution results
[0048] Monitoring and analyzing execution results are key steps to discover network protocol vulnerabilities. The method of the present invention improves the transmission efficiency of execution results through a shared memory mechanism.
[0049] Monitor execution results: The fuzz testing tool needs to monitor the execution results in the shared memory area to determine whether the target program has any exceptions. The monitored exceptions include crashes, memory leaks, abnormal outputs, etc. At the same time, after monitoring the exception, the abnormal execution results are analyzed to locate the location and cause of the vulnerability.
[0050] In this embodiment, shmget is used to create a shared memory area, and shmat is used to attach it to the process address space. When the shared memory area is initialized, sem_open is also used to create two semaphores, which are used to synchronize the delivery of test cases and results. Fuzz testing tool Fuzzer is used to generate test cases and write them into shared memory. Semaphore sem_test_case is used to notify the target program that the test case is ready. Wait for the target program to return the execution result and synchronize it through semaphore sem_result.
[0051] When executing a test case, the target program reads the test case from the shared memory and executes it (here, simple string processing is used to simulate the execution of the network protocol). The execution result is written to the shared memory and the fuzz testing tool is notified through the semaphore sem_result.
[0052] When cleaning up resources, use shmdt and shmctl to release shared memory; use sem_unlink to delete the semaphore.
[0053] The following takes the testing of a simple network protocol as an example to illustrate the specific implementation of the present invention.
[0054] Create a shared memory area: Use the shared memory API provided by the operating system to create a shared memory area of 1 MB.
[0055] Initialize the shared memory area: The fuzz testing tool and the target program map the shared memory area to their respective address spaces and use the semaphore mechanism for synchronization.
[0056] Generate test cases: The fuzz testing tool uses a random generation method to generate 1,000 test cases and writes the test cases into the shared memory area.
[0057] Execute test cases: The target program reads test cases from the shared memory area and executes them, and writes the execution results to the shared memory area.
[0058] Monitor execution results: The fuzz testing tool monitors the execution results in the shared memory area to determine whether the target program has crashes, memory leaks, and other anomalies.
[0059] Repeat steps 3-5 until all test cases are tested.
[0060] The program operation process includes four steps:
[0061] 1. The parent process (fuzz testing tool) generates test cases and writes them to shared memory.
[0062] 2. The child process (target program) reads the test case from the shared memory and executes it.
[0063] 3. The target program writes the execution results to the shared memory.
[0064] 4. The fuzz testing tool reads the execution results and outputs them.
[0065] It can be seen that the method for improving network protocol fuzzy testing based on shared memory provided by the present invention can effectively improve the efficiency of network protocol fuzzy testing through a shared memory mechanism, and has high practical value. In practical applications, the method of the present invention can be optimized and improved according to specific test requirements and environments.
[0066] The above is only a preferred embodiment of the present invention. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the technical principles of the present invention. These improvements and modifications should also be regarded as the scope of protection of the present invention.
Claims
1. A method for improving the efficiency of network protocol fuzz testing based on shared memory, characterized in that: The following steps are involved: Step 1: Create a shared memory area: Create a shared memory area between the fuzz testing tool and the target program to store test cases and test results; Step 2: Initialize the shared memory area: The fuzz testing tool and the target program initialize the shared memory area respectively and establish a communication mechanism; Step 3: Generate test cases: The fuzz testing tool generates test cases and writes them into the shared memory area; Step 4: Execute the test case: The target program reads the test case from the shared memory area and executes it, and writes the execution result to the shared memory area; Step 5: Monitor execution results: The fuzz testing tool monitors the execution results in the shared memory area to determine whether an exception occurs in the target program; Repeat steps 3-5: Repeat steps 3-5 until the preset test stop condition is reached.
2. The method according to claim 1, characterized in that In step 1, a shared memory area is created using the shared memory API provided by the operating system. The size of the shared memory area is dynamically adjusted according to the size and number of test cases and can accommodate all test cases and test results. When creating a shared memory area, a dynamic sharding strategy is introduced to automatically divide memory blocks based on protocol field characteristics, with each field corresponding to an independent memory shard. At the same time, Bloom Filter is used to detect memory access hotspots and dynamically adjust the cache strategy of preset high-frequency access shards. In addition, the protocol header and the payload are stored separately, with fixed fragmentation used for the protocol header and elastic fragmentation used for the payload.
3. The method according to claim 2, characterized in that When the shared memory area is initialized in step 2, the fuzz testing tool and the target program respectively map the shared memory area to their respective address spaces and establish a communication mechanism. The communication mechanism includes synchronization mechanisms such as semaphores and mutex locks to ensure that the fuzz testing tool and the target program have mutually exclusive access to the shared memory area.
4. The method according to claim 3, characterized in that The communication mechanism established in step 2 includes a lock-free synchronization mechanism based on atomic operations, which supports batch test case delivery by introducing ring buffer read and write pointers.
5. The method according to claim 4, characterized in that In this method, a three-level state machine is also set to realize test process control, wherein state 0 represents that the test case is ready; state 1 represents that it is being executed; and state 2 represents that the result is to be read.
6. The method according to claim 4, characterized in that In step 3, the fuzz testing tool uses a variety of methods to generate test cases, including random generation, rule-based generation, and model-based generation. The generated test cases cover various boundary conditions and abnormal situations of the network protocol.
7. The method according to claim 6, characterized in that When the target program executes the test case in step 4, the stub code is inserted into the target program, or the symbolic execution technology is used to analyze the target program.
8. The method according to claim 7, characterized in that In step 5, the anomalies monitored by the fuzz testing tool include crashes of the target program, memory leaks, and abnormal outputs. At the same time, after monitoring the anomalies, the execution results of the anomalies are analyzed to locate the location and cause of the vulnerability.
9. The method according to claim 8, characterized in that In step 1, shmget is used to create a shared memory area, and shmat is used to attach it to the process address space. When the shared memory area is initialized in step 2, sem_open is also used to create two semaphores, which are used to synchronize the delivery of test cases and results respectively. In step 3, the fuzz testing tool Fuzzer is used to generate test cases and write them into shared memory, and the semaphore sem_test_case is used to notify the target program Target Program that the test case is ready. In step 4, when the target program Target Program reads the test case from the shared memory area and executes it, string processing is used to simulate the execution of the network protocol, the execution result is written into the shared memory area, and the semaphore sem_result is used to notify the fuzz testing tool.
10. A system for implementing the method according to any one of claims 1 to 9.
Citation Information
Patent Citations
Automation software loophole verification system and method based on loophole library
CN107480531A
VxWorks kernel fuzzy test method guided by a coverage rate
CN111709031A
Fuzzy test method based on annotations
CN112506801A
Processing method and device for testing embedded operating system, equipment and medium
CN118069531A