Parallel fuzzy test method and system based on input field division
Through a parallel fuzz testing method based on input domain division, the fuzz testing task is divided into multiple subdomains, and the seed selection order and energy allocation are adjusted through local aggregation degree and test returns, dynamic adjustment of computing resources and comprehensive coverage of input domains are achieved. Cooperation between parallel instances solves the problems of low task division efficiency, lack of control in the task execution process and lack of collaboration in task instances, and improves testing efficiency and resource utilization efficiency.
Patent Information
- Application Number
- CN202510204119.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-24
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2045-02-24
AI Technical Summary
The existing parallel fuzz testing technology has problems such as low task division efficiency, lack of control during task execution, and lack of collaboration in task instances, resulting in large resource consumption and low testing efficiency.
Through the method based on input domain division, the input domain of the fuzzy test task is divided into multiple subdomains with the maximum difference according to the number of parallel instances, and the local aggregation degree and test returns are calculated based on the distance between seeds in the subdomain, the seed selection order and energy allocation are adjusted, and the dynamic adjustment of computing resources and the comprehensive coverage of the input domain are achieved. Coordinate between parallel instances, seeds beyond the scope of the subdomain are scheduled to their own or nearest subdomain for variation testing, and periodically check the subdomain overlap and re-dividing the input domain.
It realizes efficient division of tasks and effective coordination between parallel instances, reduces task conflicts, improves testing efficiency and resource usage efficiency, and ultimately improves the effect of parallel fuzz testing.
Smart Images

Figure CN120045464A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of software fuzz testing, and mainly relates to a parallel fuzz testing method and system based on input domain partitioning. Background Art
[0002] With the wide application of Internet information technology and the development of the "software-defined" technology system, Internet information technology has gradually been integrated into all walks of life in the country, and the importance of software security has become increasingly prominent. As an automated software testing technology, fuzz testing has greatly improved the efficiency of software testing. Since its inception, a large number of undisclosed vulnerabilities have been discovered in real software, and it has become an important means for software testing and vulnerability discovery in many large technology companies. With the accelerating frequency of software version updates and iterations, how to perform more rapid and comprehensive fuzz testing on the entire program has become a research hotspot in the industry. Parallel fuzz testing technology can extend traditional single-core fuzz testing to multi-core or multi-machine, aiming to improve the efficiency of fuzz testing by increasing the input of computing resources.
[0003] Traditional parallel fuzz testing simply repeats the seeds of other instances except itself at regular intervals to synchronize the global test progress and avoid repeated exploration of the same paths among different instances. However, there are still many redundant tests and it does not achieve good results. Existing research has mainly improved parallel fuzz testing from two aspects: task partitioning and synchronization enhancement, but there are still some problems in existing research. The patent "Distributed Parallel Fuzz Testing Method and System Based on Dynamic Centralized Scheduling" with publication number CN113590281A proposes a distributed parallel fuzz testing method based on dynamic centralized scheduling. Through the centralized dynamic scheduling of the central scheduler node, priority evaluation and energy allocation are performed on the center from a global perspective, and parallel instances apply for seeds for further testing; at the same time, a computing power elastic allocation policy is used to elastically allocate the computing power of fuzz testing and seed evaluation, thereby avoiding the bottleneck caused by seed evaluation. The centralized scheduling method strengthens the synchronization between different instances. However, this task partitioning and scheduling at the seed granularity itself will cause a large amount of resource consumption.
[0004] The patent "A Method, Device and Storage Medium for Mitigating Task Conflicts in Parallel Fuzz Testing" with publication number CN118069311A calculates the hash of the content of all seeds using simhash, and constructs a weighted undirected complete graph using the Hamming distance between seed hashes, and then uses spectral clustering to partition the seeds into different parallel instances on this basis. This method assigns seeds with relatively large differences to different fuzz testing instances. However, there is insufficient control over task execution during the fuzz testing process.
[0005] The patent "A Method and System for Program Structure-Sensitive Engine Task Partitioning in Parallel Fuzz Testing Scenarios" with the publication number CN118535449A maintains the runtime control flow graph through static analysis and dynamic complementation. On this basis, it identifies the covered and uncovered boundary basic blocks, partitions these basic blocks into different parallel instances, and the parallel instances select different test cases for testing according to the target basic blocks assigned to them. This method realizes the task partitioning with clear program structure goals, effectively reducing the generation and execution of invalid test cases. However, the analysis and dynamic complementation of the program structure have a relatively large overhead in large programs with complex program structures.
[0006] In summary, some of the current research and published patents in the field of parallel fuzz testing still have the following problems to be solved: ① Low task partitioning efficiency: The method of partitioning tasks through static analysis information is difficult to apply to large-scale programs, restricting the application scenarios of parallel fuzz testing. ② Lack of control in the task execution process: Many works partition tasks well in the partitioning stage, but lack intervention in the execution process of fuzz testing, resulting in parallel instances not exploring well within the tasks. ③ Lack of cooperation among task instances: Due to the randomness of the fuzz testing process, it is difficult for each parallel instance to be completely independent during execution. Existing parallel fuzz testing instances are relatively independent during the task execution stage and lack a cooperation mechanism. Summary of the Invention
[0007] The present invention precisely aims at the problems existing in the prior art and proposes a parallel fuzz testing method and system based on input domain partitioning. First, according to the distance difference of the coverage feedback executed by the seeds, the input domain of the fuzz testing task is divided into multiple initially non-overlapping subdomains with maximized differences according to the number of parallel instances; then, the local aggregation degree of the seeds is calculated according to the distance between the seeds within the subdomain, and the selection order and energy of the seeds are adjusted according to the local aggregation degree and test benefits, realizing the dynamic adjustment of the computing resource allocation and the comprehensive coverage of the input domain; subsequently, cooperation is carried out among the parallel fuzz testing instances, and the seeds exceeding their own subdomain range are scheduled to the subdomain to which they belong or the nearest subdomain for mutation testing, and the subdomain receiving the cooperative seeds adjusts its radius; finally, the overlap degree between each subdomain is regularly checked, and when the overlap degree is greater than the preset threshold, the input domain partitioning is re-performed. This method divides the input domain of parallel fuzz testing into different subdomains, restricts different parallel instances to test within the subdomains, and at the same time, the parallel instances share information through cooperation, effectively reducing the task conflicts of parallel fuzz testing and improving the testing efficiency.
[0008] To achieve the above object, the technical solution adopted by the present invention is: A parallel fuzz testing method based on input domain partitioning, comprising the following steps:
[0009] S1. Input domain division: According to the distance difference of the coverage feedback executed by the seeds, divide the input domain of the fuzz testing task into multiple initially non-overlapping subdomains that maximize the difference according to the number of parallel instances. Each subdomain consists of a subdomain center and a subdomain radius;
[0010] S2. Subdomain adaptive testing: Calculate the local aggregation degree for the seeds according to the distance between the seeds within the subdomain, and adjust the selection order and energy of the seeds according to the local aggregation degree and the testing benefit, so as to realize the scheduling of computing resources and the uniform coverage of the input domain;
[0011] S3. Subdomain cooperation: Spontaneous cooperation is carried out among parallel fuzz testing instances, and the seeds that exceed their own subdomain range are scheduled to the subdomain to which they belong or the nearest subdomain, and the subdomain that receives the cooperative seeds adjusts its radius;
[0012] S4. Subdomain adjustment: Regularly check the overlap degree between each subdomain. When the overlap degree is greater than the preset threshold, return to step S1 and re-divide the input domain.
[0013] As an improvement of the present invention, in step S1, compress the coverage feedback after the seeds are executed into a bitmap, and the Hamming distance between two bitmaps is the distance between two input seeds; the subdomain center is the n seeds with the farthest distance among all the seeds in the current input domain, where n is the number of parallel instances; after selecting the subdomain center, use the nearest assignment principle to divide all the seeds in the input domain into subdomains, and the subdomain radius is the maximum value of the distance between the seeds in the subdomain and the subdomain center.
[0014] As another improvement of the present invention, the specific method for dividing the seeds in the input domain in step S1 is: Select two seeds with the largest distance as the initial subdomain centers, and according to the number n (n≥2) of parallel instances, use the maximum-minimum distance method to determine the remaining n-2 subdomain centers:
[0015]
[0016] where Q is the seeds that are not subdomain centers in the current input domain, C is the currently selected subdomain centers, D is the cached distance between two seeds, and c ′ is the next subdomain center to be selected;
[0017] After each new subdomain center is selected, add it to the set C of the already selected subdomain centers, and continue to select the next subdomain center with the farthest distance until a subdomain center is assigned to all parallel instances; assign all the seeds in the input domain to the nearest subdomain center.
[0018] As another improvement of the present invention, the specific method for calculating the local aggregation degree of the seeds in step S2 is:
[0019]
[0020] Among them, A s is the local polymerization degree of the seed s, D is the Hamming distance between the two seed stake point coverage bitmaps, and Q i is the set of seeds within the subdomain i;
[0021] The test benefit of the said seed is specifically:
[0022]
[0023] Among them, d(s) is the number of offspring that trigger new coverage and are added to the seed queue after one round of mutation of the seed s, and fuzz_level(s) is the number of times the seed s is selected and undergoes one round of mutation testing;
[0024] The calculation method of the seed energy adjustment factor f(s) is as follows:
[0025]
[0026] Among them is the normalized local polymerization degree, is the normalized test benefit, and α is the memory factor.
[0027] As another improvement of the present invention, the subdomain collaboration in step S3 specifically includes the following steps:
[0028] S31: After the parallel instance discovers a new interesting seed, it judges whether it is within the current subdomain according to the subdomain center and the subdomain radius; if the new seed is not within the subdomain range of the current instance, it enters step S32; if the new seed is within the subdomain range of the current instance, the new seed is added to the seed queue of the current instance for the next mutation test;
[0029] S32: Judge its distance from all subdomain centers and forward it to the subdomain with the closest distance;
[0030] S33: According to step S32, the subdomain that receives the collaborative seed adds the seed to the seed queue of the fuzz testing instance and calculates the distance between the seed and the subdomain center. If the distance is greater than the subdomain radius, the radius is adjusted to the distance between the collaborative seed and the subdomain center.
[0031] As a further improvement of the present invention, the calculation method of the subdomain overlap degree in step S1 is:
[0032]
[0033] Among them, overlap(i,j) is the overlap degree between subdomains i and j, Q i and Q jThey are respectively seed sets where the distances from the centers of sub-domains i and j in the input domain are less than the radii of the corresponding sub-domains.
[0034] To achieve the above object, the technical solution adopted by the present invention is also: a parallel fuzz testing system based on input domain partitioning, which at least includes an input domain update and partitioning module, a sub-domain adaptive testing module, and a collaborative scheduling module.
[0035] The input domain update and partitioning module: is used to summarize all newly discovered seeds in the system, calculate and cache the distances between the de-duplicated seeds, and update the distribution of the test domain; it also includes monitoring the degree of sub-domain overlap and timely partitioning the input domain into sub-domains.
[0036] The sub-domain adaptive testing module: According to the sub-domains assigned by the input domain update and partitioning module, it completes the processes of seed selection, energy allocation, and mutation execution within the sub-domain range, and completes the adaptive testing of the sub-domain; at the same time, it transmits the newly discovered seeds to the input domain update and partitioning module.
[0037] The collaborative scheduling module: exists between parallel instances. When a new seed that is not within its own sub-domain is found during instance mutation, the seed is scheduled to the instance with the closest distance; after receiving a new seed, it determines whether to retain it. After retention, it adjusts the sub-domain radius according to the distance of the collaborative seed from the sub-domain center.
[0038] Compared with the prior art, the present invention has the following beneficial effects:
[0039] (1) The method of the present invention uses a method based on input domain partitioning to divide tasks. According to the distribution of the input domain, it determines the sub-domain centers with the farthest distances and allocates all seeds nearby, achieving efficient partitioning of tasks. Compared with the existing parallel fuzz testing task partitioning methods, this method has higher efficiency and stronger scalability.
[0040] (2) The method of the present invention restricts different parallel instances to perform tests within different sub-domains through sub-domain radii, constrains the execution process of sub-tasks in parallel fuzz testing, and reduces the redundancy brought by the randomness of fuzz testing during the execution process. At the same time, it calculates the local aggregation degree of each seed within the sub-domain, and adjusts the allocation of computing resources according to the differences in the distribution of each seed in the input sub-domain, achieving a more balanced and comprehensive test within the sub-domain.
[0041] (3) In the fuzz testing process of the method of the present invention, each parallel instance shares all sub-domain centers and radii, effectively coordinates valuable seeds that exceed the sub-domain range during the random testing process, realizes lightweight collaboration between parallel instances, and effectively utilizes the benefits brought by each random mutation on the premise that tasks are relatively independent. Description of the Drawings
[0042] Figure 1 Schematic diagram of a parallel fuzz testing method based on input domain partitioning;
[0043] Figure 2 Schematic diagram of the architecture of a parallel fuzz testing system based on input domain partitioning. Specific implementation manners
[0044] The present invention will be further clarified below in conjunction with the accompanying drawings and specific implementation manners. It should be understood that the following specific implementation manners are only used to illustrate the present invention and not to limit the scope of the present invention.
[0045] Embodiment 1
[0046] A parallel fuzz testing method based on input domain partitioning, as Figure 1 shown, includes the following steps:
[0047] Step S1, input domain partitioning: According to the distance difference of the coverage feedback executed by the seeds, the input domain of the fuzz testing task is divided into multiple initially non-overlapping subdomains with maximized differences according to the number of parallel instances. Each subdomain consists of a subdomain center and a subdomain radius.
[0048] Based on the coverage bitmap of the stubs after the seeds are executed, calculate the Hamming distance between the seeds to analyze the distribution of the input domain. Select the n seeds with the farthest distances as the subdomain centers according to the number of parallel instances, assign the remaining seeds to the nearest subdomain centers, and use the maximum distance from the seeds within the subdomain to the subdomain center as the subdomain radius.
[0049] Compress the coverage bitmap (trace_bits) after the seeds are executed. Each bit of the compressed coverage bitmap (trace_min i) represents the coverage situation of a stub. Use the Hamming distance of the compressed coverage bitmap as the measurement standard for the distance between the seeds. Thus, the distance calculation method between seeds s 1 and s 2 is as follows: where n is the number of stubs inserted into the program under test, and respectively represent the coverage situations of the i-th stub by seeds s 1 and s 2 ; represents that the stub is not covered by the seed execution path, represents that the stub is covered by the seed execution path. Use this Hamming distance as the evaluation standard for the input domain distribution, and cache the distance between the seeds using an upper triangular matrix.
[0050] First, select the two seeds with the largest distance as the initial sub-domain centers. Then, according to the number n (n≥2) of parallel instances, use the max-min distance method to determine the remaining n-2 sub-domain centers:
[0051]
[0052] where Q is the seeds in the current input domain that are not sub-domain centers, C is the currently selected sub-domain centers, D is the distance cached between two seeds, and c ′ is the next sub-domain center to be selected. After each new sub-domain center is selected, add it to the set C of the already selected sub-domain centers, and continue to select the next sub-domain center with the farthest distance until a sub-domain center is assigned to all parallel instances.
[0053] Assign all the seeds in the input domain to the sub-domain center with the closest distance, and calculate the maximum value of the distances from all the seeds in the sub-domain to the sub-domain center as the sub-domain radius.
[0054] Step S2, Sub-domain Adaptive Testing: The parallel fuzz testing instances perform tests on the seeds within the sub-domain. Calculate the local aggregation degree for the seeds based on the distances between the seeds within the sub-domain, and adjust the selection order and energy of the seeds according to the local aggregation degree and the test benefit, so as to achieve the scheduling of computing resources and the uniform coverage of the input domain.
[0055] According to the distribution of the seeds within the sub-domain, calculate the local aggregation degree of each seed, and preferentially select the seeds in the sparse area within the sub-domain for priority testing and allocate more initial energy; for the seeds that have completed at least one mutation test, calculate and evaluate their test benefits, and adjust their energies.
[0056] First, calculate the local aggregation degree of all the seeds within the sub-domain. The calculation method is as follows: where A s is the local aggregation degree of the seed s, D is the Hamming distance between the two seed stake coverage bitmaps, and Q i is the set of seeds within the range of sub-domain i.
[0057] Then, calculate the test benefits of the seeds within the sub-domain. During the testing process, update the benefits of the seed mutation tests each time a seed is selected for mutation. The calculation method is as follows: where d(s) is the number of offspring obtained after one round of mutation of the seed s that trigger new coverage and are added to the seed queue, and fuzz_level(s) is the number of times the seed s is selected and undergoes one round of mutation testing.
[0058] Adjust the energy according to the local aggregation degree and test benefits of the seeds, and adjust the computing resources to the areas where the test cases are sparsely distributed and the exploration value is relatively large in the input sub-domain. It is necessary to calculate the normalized local aggregation degree and the normalized test yield The seed energy adjustment factor f(s) is calculated as follows:
[0059]
[0060] Where α is the memory factor, which reduces the influence of local aggregation as the number of seed test rounds increases, and is usually set to 0.1. Finally, the influence factor is applied to the original energy of AFL++ to amplify or reduce the energy: p(s) = p o (s)·2 8 ·f(s)-4 , where p o (s) Energy allocated for AFL++ raw computation.
[0061] Step S3, subdomain collaboration: Parallel fuzz test instances collaborate spontaneously. After discovering new seeds, they dispatch seeds that exceed their own subdomain range to the subdomain to which they belong or the nearest subdomain. The subdomain that receives the collaborative seeds adjusts its radius.
[0062] After the parallel instance finds a new interesting seed, it determines whether it is in the current subdomain based on its distance from the center of the current subdomain. If the new seed is not within the subdomain range of the current instance, it will be forwarded to the subdomain closest to it. The subdomain that receives the collaborative seed will add the seed to the seed queue of the fuzz test instance and calculate the distance between the seed and the subdomain center. If the distance is greater than the subdomain radius, the radius is adjusted to the distance between the collaborative seed and the subdomain center. The specific algorithm is as follows:
[0063]
[0064]
[0065] As can be seen from Algorithm 1, after discovering a new interesting seed, the parallel fuzz test instance calculates the distance between the new seed and the subdomain center. If it is greater than the subdomain radius of the current subdomain, it calculates the distance to the centers of the remaining subdomains and forwards the new seed to the nearest subdomain for collaboration. The instance that receives the collaborative seed removes the duplicate seeds, adds them, and calculates the distance from the subdomain center. If it is greater than the subdomain radius, the subdomain radius is modified to be the distance from the current collaborative seed to the subdomain center.
[0066] Step S4, subdomain adjustment: regularly check the overlap between subdomains, and when the overlap is greater than a preset threshold, re-divide the input domain.
[0067] After receiving the new seeds summarized by the parallel instances, the master instance performs deduplication, calculates the Hamming distance for the valuable new seeds that are retained and caches them, and calculates the overlap between subdomains every 10 minutes. The specific calculation method for the overlap between subdomains is: where overlap(i,j) is the overlap degree between sub-domains i and j, and Q i and Q j are the seed sets in the input domain where the distances from the centers of sub-domains i and j are less than the radii of the corresponding sub-domains, respectively.
[0068] When the overlap degree between two instances exceeds the threshold, the input domain partitioning in step S1 is redone, and the parallel instances are notified to update the sub-domain ranges. In this embodiment, the threshold can be set to 0.5.
[0069] Embodiment 2
[0070] A parallel fuzz testing system based on input domain partitioning, which implements the method described in Embodiment 1, and its system structure is as Figure 2 shown, and it consists of at least three parts: an input domain update and partitioning module, a sub-domain adaptive testing module, and a collaborative scheduling module.
[0071] The input domain update and partitioning module traverses and summarizes all the newly discovered seeds of all parallel instances, updates and maintains the currently discovered input domain, and at the same time completes the partitioning of the input domain into non-overlapping sub-domains. Among them, this module consists of four sub-modules: a seed summarization and duplicate removal component, a distance calculation cache component, an input domain partitioning component, and a sub-domain overlap monitoring component. The seed summarization and duplicate removal component collects the newly discovered seeds in the fuzz testing process from all parallel instances, removes duplicates in the main instance to discard the seeds that trigger duplicate coverage, and retains all the seeds that trigger new coverage; the distance calculation cache component calculates the distances between the newly added global seeds and the remaining seeds in the seed queue, and is asynchronously started according to the signal of the newly added seeds in the seed queue to provide support for subsequent input domain partitioning; the input domain partitioning component uses the distances to evaluate the input domain distribution, selects the seeds with the farthest distances as the sub-domain centers according to the number of parallel instances, and partitions all the seeds near each sub-domain center, and uses the maximum distance from the seeds in the sub-domain to the sub-domain center as the sub-domain radius; the sub-domain overlap monitoring module is cyclically started at short time intervals, evaluates the sub-domain overlap degree according to the intersection of the seeds within each sub-domain range, and dynamically adjusts the re-partitioning of the input domain when the sub-domain range changes and causes a large overlap degree.
[0072] The sub-domain adaptive testing module tests the seeds within the sub-domain range, and at the same time, regulates the resource allocation during the testing process according to their local aggregation degree and the benefits after investing computing resources. Among them, this module consists of three sub-modules: an aggregation degree evaluation component, a benefit evaluation component, and an energy regulation component. The aggregation degree evaluation component evaluates the local aggregation of a seed within the sub-domain according to the distance between the seed within the sub-domain and the other seeds; the benefit evaluation component evaluates the benefits of the seeds within the sub-domain according to the number of mutation times of the seeds and the number of newly discovered seeds; the energy regulation component magnifies or reduces the energy of the seeds within the sub-domain according to the local aggregation degree and benefit situation of the seeds, and tilts the computing resources towards the seeds with lower local aggregation degree and higher benefits.
[0073] The cooperative scheduling module receives the seeds beyond the sub-domain range from the sub-domain adaptive testing module, sends them to the sub-domain to which they belong or the nearest sub-domain, and makes corresponding adjustments to the range of the sub-domain. Among them, this module includes two parts: a seed sub-domain identification component and a sub-domain range adjustment component. The seed sub-domain identification component evaluates the distance between the seeds beyond the current sub-domain range and the centers of the other sub-domains, identifies the sub-domain to which they should belong or the nearest sub-domain, and forwards them to the corresponding sub-domain for subsequent mutation testing; the sub-domain range adjustment component is activated when the seeds exceed the range of the destination sub-domain to which they are forwarded, and adjusts the radius of the destination sub-domain to include the forwarded seeds within its sub-domain range.
[0074] In summary, the present invention discloses a parallel fuzz testing method and system based on input domain partitioning. According to the distance difference of the coverage feedback executed by the seeds, the input domain of the fuzz testing task is partitioned into multiple initial non-overlapping sub-domains with maximized differences according to the number of parallel instances; the parallel fuzz testing instances test on the seeds within the sub-domain, calculate the local aggregation degree for the seeds according to the distance between the seeds within the sub-domain, and adjust the selection order and energy of the seeds according to the local aggregation degree and testing benefits, so as to realize the dynamic adjustment of the computing resource allocation and the comprehensive coverage of the input domain; the parallel fuzz testing instances cooperate with each other, schedule the seeds beyond their own sub-domain range to the sub-domain to which they belong or the nearest sub-domain for mutation testing, and the sub-domain receiving the cooperative seeds adjusts its radius; regularly check the overlap degree between each sub-domain, and when the overlap degree is greater than the preset threshold, re-partition the input domain. This method can achieve efficient partitioning of tasks, and the parallel instances can effectively and evenly test the sub-tasks obtained by partitioning, thereby improving the resource utilization efficiency, ultimately improving the parallel fuzz testing effect, and discovering vulnerabilities in the program.
[0075] It should be noted that the above content only illustrates the technical idea of the present invention and cannot be used to limit the protection scope of the present invention. For those of ordinary skill in the art, without departing from the principle of the present invention, several improvements and refinements can still be made, and these improvements and refinements all fall within the protection scope of the claims of the present invention.
Claims
1. A parallel fuzz testing method based on input domain partitioning, characterized in that: The following steps are involved: S1. Input domain division: According to the distance difference of seed execution coverage feedback, the input domain of the fuzz testing task is divided into multiple initially non-overlapping subdomains with maximized differences according to the number of parallel instances, and the subdomains are composed of subdomain centers and subdomain radii; S2, subdomain adaptive test: calculate the local aggregation degree for the seeds according to the distance between the seeds in the subdomain, adjust the seed selection order and energy according to the local aggregation degree and test benefits, and realize the scheduling of computing resources and uniform coverage of the input domain; S3, subdomain collaboration: Parallel fuzz testing instances collaborate spontaneously, dispatching seeds that exceed their own subdomain range to their own or nearest subdomain, and the subdomain that receives the collaborative seeds adjusts its radius; S4, subdomain adjustment: regularly check the overlap between subdomains. When the overlap is greater than a preset threshold, return to step S1 and re-divide the input domain.
2. A parallel fuzzy testing method based on input domain partitioning as claimed in claim 1, characterized in that: In the step S1, the coverage feedback after the seed execution is compressed into a bitmap, and the Hamming distance between the two bitmaps is the distance between the two input seeds; the subdomain center is the n seeds with the farthest distance among all the seeds in the current input domain, and n is the number of parallel instances; after the subdomain center is selected, all the seeds in the input domain are divided into subdomains using the principle of nearest allocation, and the subdomain radius is the maximum value of the distance between the seeds in the subdomain and the subdomain center.
3. A parallel fuzzy testing method based on input domain partitioning as claimed in claim 2, characterized in that: The specific method of seed division in the input domain in step S1 is: select the two seeds with the largest distance as the initial subdomain centers, and determine the remaining n-2 subdomain centers using the maximum and minimum distance method according to the number of parallel instances n (n≥2): Among them, Q is the seed of all non-subdomain centers in the current input domain, C is the currently selected subdomain center, D is the cached distance between two seeds, and c ′ is the next subdomain center to be selected; After each new subdomain center is selected, it is added to the subdomain center set C that has been selected, and the next farthest subdomain center is selected until all parallel instances are assigned a subdomain center; all seeds in the input domain are assigned to the subdomain center that is closest to them.
4. The parallel fuzzy testing method based on input domain partitioning as claimed in claim 1, characterized in that: The method for calculating the local polymerization degree of the seeds in step S2 is specifically as follows: Among them A s is the local aggregation degree of seed s, D is the Hamming distance between the coverage bitmaps of two seed points, Q i is the seed set within the subdomain i; The test benefits of the seed are as follows: Where d(s) is the number of offspring that trigger new coverage and are added to the seed queue after a round of mutation of seed s, and fuzz_level(s) is the number of times seed s is selected and subjected to a round of mutation testing; The seed energy adjustment factor f(s) is calculated as follows: in is the normalized local aggregation degree, is the normalized test return, and α is the memory factor.
5. The parallel fuzzy testing method based on input domain partitioning as claimed in claim 1, characterized in that: The step S3 subdomain collaboration specifically includes the following steps: S31: After the parallel instance finds a new interesting seed, it determines whether it is in the current subdomain according to the subdomain center and the subdomain radius; if the new seed is not in the subdomain range of the current instance, it proceeds to step S32; if the new seed is in the subdomain range of the current instance, it adds the new seed to the seed queue of the current instance for mutation testing; S32: Determine the distance between it and the centers of all subdomains, and forward it to the subdomain closest to it; S33: According to step S32, the subdomain of the collaborative seed is received, the seed is added to the seed queue of the fuzzy test instance and the distance between the seed and the subdomain center is calculated. If the distance is greater than the subdomain radius, the radius is adjusted to the distance between the collaborative seed and the subdomain center.
6. A parallel fuzzy testing method based on input domain partitioning as claimed in claim 5, characterized in that: The calculation method of the subdomain overlap in step S1 is: Where overlap(i,j) is the overlap between subdomains i and j, Q i and Q j They are the seed sets in the input domain whose distance from the center of subdomains i and j is less than the radius of the corresponding subdomain.
7. A parallel fuzzy testing system based on input domain partitioning, characterized in that: At least includes an input domain update and division module, a subdomain adaptive test module and a collaborative scheduling module. The input domain update and division module is used to summarize all newly discovered seeds in the system, calculate and cache the distance between the deduplicated seeds, and update the distribution of the test domain; it also includes monitoring the degree of overlap of subdomains and dividing the input domain into subdomains in a timely manner; The subdomain adaptive testing module: according to the subdomain assigned by the input domain updating and partitioning module, completes the seed selection, energy allocation and mutation execution process within the subdomain range, and completes the adaptive testing of the subdomain; at the same time, transmits the newly discovered seeds to the input domain updating and partitioning module; The collaborative scheduling module exists between parallel instances. When an instance mutates and finds a new seed that is not in its own subdomain, the seed is scheduled to the instance closest to it. After receiving the new seed, it determines whether it needs to be retained. After retaining it, the subdomain radius is adjusted according to the distance between the collaborative seed and the subdomain center.
Citation Information
Patent Citations
Distributed parallel fuzzy test method and system based on dynamic centralized scheduling
CN113590281A
Program structure sensitive engine task division method and system in parallel fuzzy test scene
CN118535449A
Method for carrying out grouping fuzz testing on software
CN114281690A
Parallel fuzzy test method and system based on target point task division
CN114328213A
Multi-machine collaborative vulnerability detection system based on vulnerability clustering and distance space division
CN115828260A