Automatic analysis method for TCP / IP hierarchical model protocol cross-layer interaction vulnerability

By preprocessing and consistency detection of the source code and RFC documents of the TCP/IP protocol stack, a cross-layer interactive state machine is built and a definition document is generated, which solves the problem that the existing technology is difficult to analyze and solve the cross-layer interactive security problem of the protocol stack, and realizes efficient security analysis and vulnerability repair.

CN120050059AActive Publication Date: 2025-05-27TSINGHUA UNIVERSITY
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202411899742.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-23
Publication Date
2025-05-27
Estimated Expiration
2044-12-23

AI Technical Summary

Technical Problem

Existing analysis tools and methods are difficult to effectively analyze and solve potential security problems in cross-layer interactions of TCP/IP protocol stacks, mainly due to the complexity of cross-layer interaction behavior, the limitations of single-layer perspectives, and the lack of automated analysis tools.

Method used

An automated analysis method is proposed, by cleaning, splitting and pre-processing the source code and RFC documents of the TCP/IP protocol stack, generating intermediate representations IR-C and IR-Ri, performing consistency detection and adjustment, building a cross-layer interactive state machine, and automatically generating cross-layer interaction definition documents that conform to the RFC document style.

Benefits of technology

This method can effectively identify and fix the inconsistency between protocol code and RFC documents, build a clear cross-layer interactive state machine, significantly improve the security and robustness of the protocol stack, and is suitable for security analysis of TCP/IP protocol stack and other complex network protocols.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120050059A_ABST
    Figure CN120050059A_ABST
Patent Text Reader

Abstract

The invention provides an automatic analysis method for TCP / IP hierarchical model protocol cross-layer interaction vulnerabilities. The method comprises the steps that source codes and RFC documents of a TCP / IP protocol stack are cleaned, split and preprocessed; based on the preprocessed source code and the RFC document, respectively generating intermediate representations, extracting protocol processing logic and a cross-layer interaction process from the source code, and generating an intermediate representation IR-C; extracting a protocol state description and a logic structure from the RFC document, and generating a plurality of intermediate representations IR-Ri; performing differential analysis on IR-C and IR-Ri, checking whether the description of the protocol code and the description of the RFC document on the logic level are consistent or not, identifying potential inconsistency and performing adjustment; based on a consistency comparison and adjustment result, expanding from a single-layer protocol to cross-layer interaction logic, and constructing a protocol cross-layer interaction state machine; and automatically generating a cross-layer interactive definition document consistent with the RFC document in style by using the generated state machine. The clear definition and vulnerability mining of cross-layer interaction behaviors are realized, and the efficiency and accuracy of protocol stack security analysis are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer network security technology, and particularly relates to an automated analysis method for cross-layer interaction vulnerabilities in the TCP / IP hierarchical model protocol. Background Art

[0002] Network protocols are an important cornerstone for the normal operation of the entire network space. Their main function is to standardize the information exchange method between network devices to ensure that messages can be successfully generated, transmitted, correctly received, and understood between devices. To reduce the complexity of development and maintenance, network protocol stacks usually adopt a hierarchical design. Typical structures include the OSI seven-layer model and the TCP / IP four-layer model. Through layer division, each layer protocol can independently perform specific functions. For example, the link layer is responsible for frame relay, the IP layer performs packet routing, and the transport layer is responsible for flow control and reliable transmission, etc. This modular design makes the network protocol stack relatively independent in function and has strong scalability. At the same time, it also enables the protocols to have experienced long-term development and optimization at their respective levels, and their security can largely resist various types of network attacks.

[0003] However, the hierarchical design of the protocol stack must rely on the interaction between layers during data processing, forming a dynamic cross-layer cooperation relationship. This cross-layer interaction makes the network protocol stack more efficient in processing and transmitting data, but also introduces new security risks. During the process of data sending and receiving, each layer protocol not only needs to complete its own function but also needs to interact with adjacent layers through function calls or interfaces. For example, during the transmission of an HTTP message, it is necessary to call DNS to resolve the domain name, use TCP to establish a connection, encapsulate the data packet through the IP protocol, obtain the target MAC address using the ARP protocol, and may use the ICMP protocol for debugging or feedback. Although this inter-layer cooperation improves the flexibility of the protocol stack, it also makes the behavior of cross-layer calls unpredictable and increases the possibility of network attacks.

[0004] Existing analysis tools and methods mostly analyze the functional implementation of a single layer of the protocol stack. Usually, based on the RFC documents of a single layer protocol, static analysis, fuzz testing, or symbolic execution is carried out. However, for the protocol stack code level and the automated analysis of potential security issues during the cross-layer interaction process, there are still the following technical bottlenecks:

[0005] (1) Complexity of cross-layer interaction behavior: The function call chain in cross-layer interaction may be very complex, including both forward processing processes such as data encapsulation and routing, and may also involve reverse paths such as exception handling and status feedback. Traditional analysis methods cannot effectively capture the state transfer logic and dependency relationships in cross-layer interaction.

[0006] (2) Limitations of the single - layer perspective: Existing analysis methods mostly focus on the implementation of a single protocol, ignoring the dependencies and synergies between protocols. This results in the inability to comprehensively discover potential security vulnerabilities in the cross - layer interaction process of the protocol stack.

[0007] (3) Lack of automated analysis tools: Although existing analysis methods can already conduct a certain degree of vulnerability discovery on the code of single - layer protocols, there are almost no comprehensive automated analysis tools for cross - layer interaction code, especially lacking pertinence in dynamic analysis and state - machine modeling.

[0008] Currently, the vulnerability problem in the cross - layer interaction of the network protocol stack has gradually become a key area of network security research. However, due to the complexity and uncertainty of cross - layer interaction, even if a single - layer protocol is secure enough, it is difficult to avoid potential security hazards caused by cross - layer interaction. Therefore, there is an urgent need for an automated analysis method for the cross - layer interaction behavior of the protocol stack to efficiently discover and solve security problems in the cross - layer interaction process. Summary of the Invention

[0009] This application aims to solve at least one of the technical problems in the related art to some extent.

[0010] To this end, the first objective of this application is to propose an automated analysis method for cross - layer interaction vulnerabilities of TCP / IP hierarchical model protocols.

[0011] The second objective of this application is to propose an automated analysis device for cross - layer interaction vulnerabilities of TCP / IP hierarchical model protocols.

[0012] The third objective of this application is to propose an electronic device.

[0013] The fourth objective of this application is to propose a computer - readable storage medium.

[0014] The fifth objective of this application is to propose a computer program product.

[0015] To achieve the above objectives, the first - aspect embodiment of this application proposes an automated analysis method for cross - layer interaction vulnerabilities of TCP / IP hierarchical model protocols, which is characterized by including the following steps:

[0016] Clean, split, and pre - process the source code of the TCP / IP protocol stack and RFC documents, and extract the core information of protocol design and implementation;

[0017] Based on the preprocessed source code and RFC documents, intermediate representations are generated respectively, where: the protocol processing logic and cross-layer interaction process are extracted from the source code to generate the protocol processing intermediate representation IR-C; the protocol state description and logical structure are extracted from the RFC documents to generate multiple intermediate representations IR-Ri;

[0018] Perform differential analysis on IR-C and IR-Ri to check whether the descriptions of the protocol code and RFC documents are consistent at the logical level, identify potential inconsistencies between the code and the document, and make corresponding adjustments;

[0019] Based on the results of consistency comparison and adjustment, extend from the single-layer protocol to the cross-layer protocol interaction, and construct a protocol cross-layer interaction state machine that describes the cross-layer interaction logic;

[0020] Use the protocol cross-layer interaction state machine to generate a cross-layer interaction definition document that conforms to the RFC document style.

[0021] Optionally, the cleaning, splitting, and preprocessing of the source code and RFC documents of the TCP / IP protocol stack include:

[0022] Parse the source code by functional modules, and extract the packet structure, state definition, event handling function, and state transition logic related to the protocol implementation;

[0023] Split the RFC document according to the state definition, packet structure, event handling logic, and state transition diagram, and filter out the content irrelevant to the protocol design.

[0024] Optionally, the generation of intermediate representations based on the preprocessed source code and RFC documents respectively includes:

[0025] For the source code, by designing a Prompt that adapts to the characteristics of the network protocol stack, use the text analysis ability of the large language model to extract key logical information from the kernel protocol stack code, and construct an intermediate representation IR-C that represents the protocol processing and cross-layer interaction process;

[0026] For the RFC document, use domain-specific language and syntax analysis techniques to parse the protocol logic, detect ambiguities in the description, and generate multiple intermediate representations IR-Ri for polysemy.

[0027] Optionally, the use of the text analysis ability of the large language model to extract key logical information from the kernel protocol stack code includes:

[0028] Extract the header structure and field information of the protocol to generate the corresponding header state information;

[0029] Analyze the logic of the protocol processing function and extract the process related to the protocol state transition;

[0030] Identify the key code paths in the recognition protocol implementation that interact with other protocol layers, and extract the logic of cross-layer information transfer.

[0031] Optionally, perform differential analysis on IR-C and IR-Ri, check whether the descriptions of the protocol code and the RFC document are consistent at the logical level, identify potential inconsistencies between the code and the document, and make corresponding adjustments, including:

[0032] Use a large language model combined with Prompt to perform differential analysis on IR-C and IR-Ri. By comparing their symbols, logical structures, and control flow graphs, check whether the descriptions of the protocol code and the RFC document are consistent at the logical level;

[0033] Mark the logical differences found in the differential analysis;

[0034] Adjust the ambiguous descriptions in the RFC document to eliminate the inconsistencies caused by the polysemy of natural language, and modify the implementation logic of the source code as needed to ensure the consistency of IR-C and IR-Ri at the logical level.

[0035] Optionally, the logical differences detected during the differential analysis include:

[0036] The misalignment between the logical description defined in the RFC document and the code implementation symbols;

[0037] The polysemy problems caused by the natural language ambiguity in the RFC document;

[0038] Protocol logic vulnerabilities not covered in the code implementation.

[0039] Optionally, based on the results of the consistency comparison and adjustment, extend from a single-layer protocol to cross-layer protocol interaction, and construct a protocol cross-layer interaction state machine that describes the cross-layer interaction logic, including:

[0040] Based on the intermediate representation IR-R of the RFC specification obtained after consistency adjustment, perform supervised model training from IR-C to IR-R;

[0041] Based on the trained model, use the protocol stack cross-layer interaction code as input to generate the intermediate representation IR-C of cross-layer interaction;

[0042] Use the generated IR-C as the representation of the protocol cross-layer interaction state machine to describe the protocol cross-layer interaction logic.

[0043] Optionally, it further includes:

[0044] Use a visualization tool to perform visual output on the protocol cross-layer interaction state machine.

[0045] Optionally, using the protocol cross-layer interaction state machine to generate a cross-layer interaction definition document that conforms to the RFC document style, including:

[0046] Based on the generated protocol cross-layer interaction state machine, process the IR-C through a large language model to generate a cross-layer interaction definition document consistent with the RFC document style.

[0047] To achieve the above object, an embodiment of the second aspect of the present application proposes an automated analysis device for TCP / IP hierarchical model protocol cross-layer interaction vulnerabilities, including:

[0048] A source code and RFC document parsing module for cleaning, splitting, and preprocessing the source code of the TCP / IP protocol stack and the RFC document, and extracting the core information of protocol design and implementation;

[0049] An intermediate representation generation module for generating intermediate representations based on the preprocessed source code and RFC document respectively, where: extract the protocol processing logic and cross-layer interaction process from the source code to generate the protocol processing intermediate representation IR-C; extract the protocol state description and logical structure from the RFC document to generate multiple intermediate representations IR-Ri;

[0050] An intermediate representation consistency detection module for performing differential analysis on IR-C and IR-Ri, checking whether the descriptions of the protocol code and the RFC document are consistent at the logical level, identifying potential inconsistencies between the code and the document, and making corresponding adjustments;

[0051] A cross-layer interaction state machine generation module for expanding from a single-layer protocol to cross-layer protocol interaction based on the results of consistency comparison and adjustment, and constructing a protocol cross-layer interaction state machine that describes cross-layer interaction logic;

[0052] A cross-layer interaction document generation module for using the protocol cross-layer interaction state machine to generate a cross-layer interaction definition document that conforms to the RFC document style.

[0053] To achieve the above object, an embodiment of the third aspect of the present application proposes an electronic device, including: a processor, and a memory communicatively connected to the processor;

[0054] The memory stores computer execution instructions;

[0055] The processor executes the computer execution instructions stored in the memory to implement the method according to any one of the first aspect.

[0056] To achieve the above object, an embodiment of the fourth aspect of the present application provides a computer-readable storage medium, in which computer-executable instructions are stored, and when the computer-executable instructions are executed by a processor, they are used to implement the method described in any one of the first aspect.

[0057] To achieve the above object, an embodiment of the fifth aspect of the present application provides a computer program product, and when the computer program is executed by a processor, it implements the method described in any one of the first aspect.

[0058] The technical solutions provided by the embodiments of the present application at least bring the following beneficial effects:

[0059] The present application combines the large language model (LLM) and Fuzzing technology to propose a method for automatically analyzing cross-layer interaction vulnerabilities in the network protocol stack. Through the cleaning and preprocessing of the protocol stack source code and RFC documents, intermediate representations IR-C and IR-Ri are generated, and consistency detection and adjustment are performed to identify and repair the inconsistencies between the protocol code and the RFC documents. The present application constructs a cross-layer interaction state machine to clearly describe the cross-layer interaction logic, and at the same time automatically generates a cross-layer interaction definition document consistent with the RFC document style. Through automated scanning and analysis, hidden high-risk vulnerabilities in the target protocol stack can be effectively discovered and repaired, significantly improving the security and robustness of the protocol stack, and is applicable to the security analysis of TCP / IP protocol stacks and other complex network protocols.

[0060] The additional aspects and advantages of the present application will be partially given in the following description, partially become obvious from the following description, or be understood through the practice of the present application. BRIEF DESCRIPTION OF THE DRAWINGS

[0061] The above and / or additional aspects and advantages of the present application will become obvious and easy to understand from the following description of the embodiments in conjunction with the drawings, where:

[0062] Figure 1 is a schematic flow chart of a method for automatically analyzing cross-layer interaction vulnerabilities in a TCP / IP hierarchical model protocol provided by an embodiment of the present application;

[0063] Figure 2 is a schematic structural diagram of an apparatus for automatically analyzing cross-layer interaction vulnerabilities in a TCP / IP hierarchical model protocol provided by an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0064] Embodiments of the present application will be described in detail below. Examples of the embodiments are shown in the accompanying drawings, where the same or similar reference numerals denote the same or similar elements or elements having the same or similar functions throughout. The embodiments described below with reference to the accompanying drawings are exemplary and are intended to explain the present application, and should not be construed as a limitation to the present application.

[0065] In view of the problems existing in the prior art, an embodiment of the present application provides an automated analysis method for cross-layer interaction vulnerabilities in the TCP / IP hierarchical model protocol. Figure 1 It is a schematic flowchart of an automated analysis method for cross-layer interaction vulnerabilities in the TCP / IP hierarchical model protocol provided by an embodiment of the present application. As Figure 1 shown, the method includes the following steps:

[0066] Step 101: Clean, split, and preprocess the source code of the TCP / IP protocol stack and RFC documents, and extract the core information of the protocol design and implementation.

[0067] In this step, by systematically cleaning, splitting, and preprocessing the source code of the TCP / IP protocol stack and RFC documents, the key information in the protocol design and implementation is extracted, laying a data foundation for the subsequent generation of intermediate representations and consistency detection.

[0068] First, for the source code part, by parsing its functional modules, the core content directly related to the protocol implementation is extracted. Specifically, it includes: extracting the packet structure of the protocol, such as the definition of header fields, field types, and their logical relationships; extracting the state definitions in the protocol, including the initial state of the protocol, event trigger conditions, and state transition relationships; parsing the event handling functions in the protocol, such as parsing and processing handler functions for different message types; extracting the state transition logic of the protocol, such as explicit or implicit state switches in function calls.

[0069] Taking the ICMP protocol as an example, the source code can be further split into four parts: icmp type&code, icmp_controlhandler, processing functions, and transfer functions. By cleaning and preprocessing, redundant code irrelevant to the protocol logic is removed, and only the core function implementation part is retained, providing high-quality data input for the subsequent generation of the intermediate representation IR-C.

[0070] Secondly, for the RFC document part, it is split and extracted according to the content such as status definition, data packet structure, event handling logic, and state transition diagram. RFC documents usually contain protocol specifications, design principles, and reference information. Some content is irrelevant to the analysis, so it is necessary to filter out irrelevant parts such as tables of contents, author information, acknowledgments, and references. When extracting effective information, a heuristic search method is adopted to quickly locate the core content by screening specific text features (such as "_handler", "+-----+", etc.). The specific processing includes: extracting the protocol states defined in the RFC and their logical relationships, such as the state descriptions of different message types (such as Echo Request and Echo Reply) in the ICMP protocol; extracting data packet structure information, such as the definitions and logics of header fields (such as Type, Code, Checksum); extracting event handling logic, such as the complete process of message reception, verification, processing, and response; extracting the state transition diagram (data flow diagram), such as the trigger conditions and path relationships between the various states of the protocol.

[0071] Taking the ICMP protocol as an example, the RFC document can be split into four parts: status definition, data packet structure, event handling, and state transition diagram, and each part is cleaned and chunked. The status definition part describes the status of different ICMP messages and their trigger conditions; the data packet structure part clarifies the functions and logical relationships of the fields in the ICMP header; the event handling part details the specific behaviors of ICMP messages when received and processed; the state transition diagram part provides a full-process description of the transfer of ICMP messages between various states.

[0072] Through the above steps, the source code and RFC documents are cleaned, split, and preprocessed, and the core logic and design elements of the protocol are extracted as standardized input data, ensuring that the intermediate representation IR-C generated from the source code and the intermediate representation IR-Ri generated from the RFC document have a high-quality content basis, providing a reliable guarantee for subsequent consistency detection and vulnerability analysis.

[0073] Step 102: Based on the preprocessed source code and RFC documents, intermediate representations are generated respectively, where: the protocol processing logic and cross-layer interaction process are extracted from the source code to generate the protocol processing intermediate representation IR-C; the protocol state descriptions and logical structures are extracted from the RFC document to generate multiple intermediate representations IR-Ri.

[0074] After preprocessing the source code and RFC documents, the goal of this step is to generate two types of intermediate representations through Prompt and syntax analysis techniques that adapt to the characteristics of the network protocol stack: IR-C is used to represent the protocol processing logic and cross-layer interaction process, and IR-Ri is used to represent the protocol states and logical structures in the RFC document, providing a basis for subsequent consistency detection.

[0075] In the embodiments of this application, for source code, by designing Prompts that adapt to the characteristics of the network protocol stack, the text analysis ability of the large language model (LLM) is used to extract key logical information from the kernel protocol stack code, and an intermediate representation IR-C is constructed. The extracted content includes the following three core aspects:

[0076] (1) Extract the header structure and field information of the protocol: Analyze the protocol header definition, extract the function and data type of each field, and generate the header status information of the protocol.

[0077] (2) Analyze the logic of the protocol processing function: Parse the protocol processing function, extract the processes related to state transitions in the protocol implementation, and clarify the input and output conditions of different states.

[0078] (3) Identify the key code paths for interaction with other protocol layers in the protocol: For function calls involving cross-layer interactions in the protocol, extract the logical paths for cross-layer information transfer, including the dependency relationships and interface call methods between the upper and lower layers.

[0079] In actual implementation, the design of the Prompt needs to parse layer by layer for different code parts (such as headers, state transition logic, and cross-layer interaction functions), and the LLM gradually extracts key information through iterative interaction. To cope with the input length limit of the LLM, during the code cleaning process, the code needs to be reasonably segmented according to the size of the tokens, and the results are extracted separately and then merged. Finally, IR-C clearly describes the core logic of the protocol code through a comprehensive analysis of the header status information, protocol processing logic, and cross-layer interaction processes.

[0080] For RFC documents, the embodiments of this application use domain-specific language (DSL) and syntax analysis techniques to parse the logical structure of the protocol and construct multiple intermediate representations IR-Ri. The specific implementation includes:

[0081] (1) Perform block parsing on the protocol state definitions, event responses, packet structures, and state transition diagrams described in the RFC document, and extract the core content.

[0082] (2) Detect natural language ambiguities in the document, such as the polysemy of the same field in different scenarios, and generate multiple possible interpretation versions through the LLM.

[0083] (3) For ambiguous sentences, combine the domain-specific language and the syntax analysis function of the LLM to generate multiple intermediate expression forms (IR-Ri) to ensure coverage of all possible logical branches in the RFC document.

[0084] It should be noted that during the generation of the intermediate representation, in order to maintain the logical level consistency between IR-C and IR-Ri, this step uses the LLM to uniformly generate two types of intermediate representations, rather than adopting other intermediate representation methods (such as LLVM IR). IR-C and IR-Ri can be represented in the form of data flow graphs and control flow graphs, which is convenient for subsequent differential analysis and consistency detection.

[0085] Through the above method, the generated IR-C comprehensively describes the processing logic of the protocol source code and the cross-layer interaction process, while IR-Ri extracts the protocol state description and logical structure from the RFC document. The unified modeling of the two lays the foundation for differential analysis, consistency detection, and vulnerability mining in the subsequent steps.

[0086] Step 103: Perform differential analysis on IR-C and IR-Ri to check whether the descriptions of the protocol code and the RFC document are consistent at the logical level, identify potential inconsistencies between the code and the document, and make corresponding adjustments.

[0087] In this step, differential analysis is performed on the intermediate representation IR-C generated from the source code and the intermediate representation IR-Ri generated from the RFC document to check whether their descriptions are consistent at the logical level, mark potential inconsistencies, and adjust the RFC document and code implementation as needed to ensure the logical consistency of the protocol design and implementation.

[0088] Although IR-C and IR-Ri come from the code and the RFC document respectively and belong to the same level at the logical level, there is usually a problem of symbol misalignment. For example, in the ICMP protocol, the RFC document may define the "redirect" operation in the form of an explanatory description, while the specific implementation in the code is the icmp_redirect function. Through differential analysis, this kind of symbol inconsistency can be identified, and the symbol relationship between the two can be gradually aligned through the combination of the large language model (LLM) and Prompt.

[0089] First, through the combination of the large language model and Prompt, perform a logical comparison between IR-C and IR-Ri, and analyze their differences in aspects such as protocol state definition, event handling logic, and control flow graph. For example, in the ICMP protocol, the RFC document may use "redirect" to describe a certain operation, while in the code it is implemented as the icmp_redirect function. This kind of symbol misalignment needs to be marked through comparison and the corresponding symbol mapping relationship is generated. In addition, differential analysis will pay attention to the ambiguity of the natural language description in the RFC document. For example, the same logical description may be interpreted in different ways. By comparing the generation of multiple IR-Ri, a clear logical version can be generated to eliminate the ambiguity in the document.

[0090] In addition, differential analysis also compares the logical processes. By checking the control flow graph in IR-C and the state transition graph in IR-Ri, potential logical omissions in the code implementation can be found. For example, the state transition paths defined in some RFC documents are not implemented in the code, or some states are not correctly processed. These differences will be marked as potential vulnerabilities to prompt developers for improvement.

[0091] For the detected inconsistencies, the embodiments of the present application will correct them through corresponding adjustment measures. On the one hand, by modifying the ambiguous sentences in the RFC document to clarify their logical meanings, misunderstandings in the code implementation can be avoided; on the other hand, the omitted or deviated logic in the code implementation is supplemented or modified to ensure that it fully complies with the specifications of the RFC document. For example, by adjusting the ambiguous description in the RFC document, "redirect" is clarified to be the same operation logic as the icmp_redirect function; at the same time, the state transition conditions not processed in the code are supplemented and implemented. In this way, IR-C and IR-Ri can be consistent at the logical level, providing high-quality input for the generation of the subsequent cross-layer interaction state machine.

[0092] The final results of differential analysis include the symbol alignment relationship, the difference points of the control flow graph, and the marking of potential security vulnerabilities. This result provides guidance for further optimizing the protocol design and code implementation, and at the same time lays a reliable foundation for the generation of the subsequent cross-layer interaction state machine. Through consistency detection, the present application can not only eliminate hidden vulnerabilities, but also ensure the robustness and security of the protocol stack, thereby improving the reliability of the protocol in practical applications.

[0093] Step 104: Based on the results of consistency comparison and adjustment, extend from a single-layer protocol to cross-layer protocol interaction, and construct a protocol cross-layer interaction state machine that describes the cross-layer interaction logic.

[0094] After completing the consistency detection and adjustment, the embodiments of the present application use the RFC specification intermediate representation IR-R after consistency adjustment, combined with the intermediate representation IR-C generated from the source code, to further construct the cross-layer interaction state machine of the protocol to completely describe the cross-layer interaction logic of the protocol.

[0095] First, based on the intermediate representation IR-R of the RFC specification after consistency adjustment, supervised model training from IR-C to IR-R is carried out. Through model training, a mapping relationship is established between the protocol logic (IR-C) extracted from the code and the protocol logic (IR-R) described in the RFC document to ensure that the generated IR-C matches the logical requirements of the RFC document. During the training process, the model is iteratively optimized to improve the accuracy and consistency of IR-C generation. Especially when dealing with complex cross-layer interaction logic, the model can more accurately extract and restore the behavior of the state machine.

[0096] Subsequently, based on the trained model, using the protocol stack cross-layer interaction code as input, an intermediate representation IR-C of cross-layer interaction is generated. Through the logical mapping ability of the model, the cross-layer interaction process of the protocol stack is extracted from the code, including the call, transfer, and processing logic of data packets between different protocol layers, and a complete cross-layer interaction IR-C is generated. This intermediate representation covers key information such as interface call relationships, data flow paths, and state transitions between various protocol layers in the protocol stack.

[0097] Finally, the generated IR-C is used as the representation of the protocol cross-layer interaction state machine. The state machine clearly describes the protocol cross-layer interaction logic in a graphical manner, presenting the entire process from data generation to transfer and processing. The state machine includes key nodes of different protocol layers, call paths of cross-layer interfaces, and transition relationships between states, thus providing a complete description of the cross-layer interaction logic.

[0098] Through this step, the processing flow of a single-layer protocol is extended to the cross-layer interaction process between multiple protocols, and the protocol cross-layer interaction state machine is constructed. On this basis, combined with the intermediate representation IR-R after eliminating RFC ambiguity, it is further ensured that the state machine can accurately reflect the logical behavior of the protocol stack. The construction of the cross-layer interaction state machine not only provides a logical model for subsequent vulnerability detection but also provides reliable input data for generating cross-layer interaction documents consistent with the RFC style.

[0099] In addition, after constructing the protocol cross-layer interaction state machine, in order to facilitate the intuitive analysis and verification of the protocol logic, a visualization tool can be further used to graphically output the protocol cross-layer interaction state machine. The visual output can clearly display the logical relationships, key paths, and transition behaviors between states of cross-layer interaction. During the implementation process, tools such as pygraphviz and graphviz can be used to directly convert the data structure of the state machine (such as the intermediate representation IR-C) into a visual graph. This application does not make specific descriptions and limitations on the visualization tool.

[0100] Step 105: Use the protocol cross-layer interaction state machine to generate a cross-layer interaction definition document that conforms to the RFC document style.

[0101] After completing the construction of the protocol cross-layer interaction state machine, based on the generated state machine, the intermediate representation IR-C can be processed by a large language model (LLM) to automatically generate a cross-layer interaction definition document that conforms to the RFC document style. This step aims to clearly describe the protocol cross-layer interaction logic in natural language and solve the problem of the lack of documented definitions for cross-layer interaction behaviors in current network protocols.

[0102] Specifically, as the intermediate representation of the state machine, IR-C contains key information on cross-layer interaction logic, including the states of protocol layers, event trigger conditions, state transition paths, and interface call relationships. Through the text generation ability of the large language model and by using Prompt and in-context learning techniques, this information is transformed into natural language descriptions that conform to the RFC document style.

[0103] It should be noted that in this process, the reason for choosing the large language model as the implementation method lies in its powerful language generation ability, especially the informalize ability, which can generate accurate and coherent text outputs with a small amount of context prompts without additional training. By designing Prompts that adapt to the protocol logic, the model can extract key information from IR-C and generate cross-layer interaction definition documents according to the organizational structure of RFC documents.

[0104] Finally, the generated document style is consistent with RFC, including titles, text, and standardized protocol interaction processes. In this way, the generated cross-layer interaction definition document can not only make up for the lack of detailed descriptions of cross-layer interactions in existing protocols but also provide clear behavioral specifications for developers, facilitating implementation and maintenance. In addition, the document can be directly used as a reference for security analysis, vulnerability detection, and subsequent protocol extensions.

[0105] To implement the above embodiments, the present application also proposes an automated analysis device for cross-layer interaction vulnerabilities in the TCP / IP hierarchical model protocol. Figure 2 The structure diagram of an automated analysis device for cross-layer interaction vulnerabilities in the TCP / IP hierarchical model protocol provided by the embodiments of the present application. As Figure 2 shown, the device includes:

[0106] The source code and RFC document parsing module 100 is used to clean, split, and preprocess the source code of the TCP / IP protocol stack and RFC documents, and extract the core information of protocol design and implementation;

[0107] The intermediate representation generation module 200 is used to generate intermediate representations based on the preprocessed source code and RFC documents respectively. Specifically: extract the protocol processing logic and cross-layer interaction process from the source code to generate the protocol processing intermediate representation IR-C; extract the protocol state description and logical structure from the RFC document to generate multiple intermediate representations IR-Ri;

[0108] The intermediate representation consistency detection module 300 is used to perform differential analysis on IR-C and IR-Ri, check whether the descriptions of the protocol code and RFC document are consistent at the logical level, identify potential inconsistencies between the code and the document, and make corresponding adjustments;

[0109] The cross-layer interaction state machine generation module 400 is used to expand from a single-layer protocol to cross-layer protocol interaction based on the results of consistency comparison and adjustment, and construct a protocol cross-layer interaction state machine that describes the cross-layer interaction logic;

[0110] The cross-layer interaction document generation module 500 is used to generate a cross-layer interaction definition document that conforms to the RFC document style by using the protocol cross-layer interaction state machine.

[0111] To implement the above embodiments, the present application also proposes an electronic device, including: a processor, and a memory communicatively connected to the processor; the memory stores computer-executable instructions; the processor executes the computer-executable instructions stored in the memory to implement the method provided in the foregoing embodiments.

[0112] To implement the above embodiments, the present application also proposes a computer-readable storage medium storing computer-executable instructions, and the computer-executable instructions are used to implement the method provided in the foregoing embodiments when executed by a processor.

[0113] To implement the above embodiments, the present application also proposes a computer program product including a computer program, and the computer program implements the method provided in the foregoing embodiments when executed by a processor.

[0114] The collection, storage, use, processing, transmission, provision, and disclosure of the user's personal information involved in the present application and other such processing all comply with the provisions of relevant laws and regulations and do not violate public order and good customs.

[0115] It should be noted that personal information from users should be collected for legal and reasonable purposes and not shared or sold outside of these legitimate uses. In addition, such collection / sharing should be carried out after obtaining the informed consent of the user, including but not limited to notifying the user to read the user agreement / user notice and signing an agreement / authorization including authorizing relevant user information before the user uses the function. In addition, any necessary steps need to be taken to protect and safeguard access to such personal information data and ensure that others with access to personal information data comply with their privacy policies and procedures.

[0116] The present application anticipates providing an implementation plan for users to selectively block the use or access of personal information data. That is, the present disclosure anticipates providing hardware and / or software to prevent or block access to such personal information data. Once personal information data is no longer needed, the risk can be minimized by restricting data collection and deleting the data. In addition, when applicable, personal identifiers are removed from such personal information to protect the privacy of users.

[0117] In the descriptions of the foregoing embodiments, the descriptions referring to the terms "one embodiment", "some embodiments", "example", "specific example", or "some examples", etc. mean that the specific features, structures, materials, or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present application. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described may be combined in any one or more embodiments or examples in a suitable manner. In addition, without contradiction, those skilled in the art may combine and combine the different embodiments or examples described in this specification and the features of different embodiments or examples.

[0118] In addition, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the quantity of the indicated technical features. Thus, the features defined with "first" and "second" may explicitly or implicitly include at least one of the features. In the description of the present application, "a plurality of" means at least two, such as two, three, etc., unless otherwise specifically defined.

[0119] Any process or method description in a flowchart or described otherwise herein can be understood to represent a module, segment, or portion of code including one or more executable instructions for implementing a customized logic function or process, and the scope of the preferred embodiments of the present application includes additional implementations, where the functions may be executed in a substantially simultaneous manner or in a reverse order according to the involved functions, rather than in the order shown or discussed, which should be understood by those skilled in the art to which the embodiments of the present application pertain.

[0120] The logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as a definable list of executable instructions for implementing logical functions, and can be embodied specifically in any computer-readable medium for use by an instruction execution system, apparatus, or device (such as a computer-based system, a system including a processor, or other systems that can fetch and execute instructions from the instruction execution system, apparatus, or device), or in conjunction with these instruction execution systems, apparatuses, or devices. For the purposes of this specification, a "computer-readable medium" can be any device that can contain, store, communicate, propagate, or transport a program for use by or in conjunction with an instruction execution system, apparatus, or device. More specific examples (non-exhaustive list) of computer-readable media include the following: an electrical connection portion with one or more wirings (electronic device), a portable computer diskette (magnetic device), a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber device, and a portable compact disc read-only memory (CDROM). Additionally, the computer-readable medium can even be paper or other suitable media on which the program can be printed, because the program can be obtained electronically, for example, by optically scanning the paper or other media, followed by editing, interpretation, or otherwise processing as appropriate, and then stored in a computer memory.

[0121] It should be understood that various parts of the present application can be implemented by hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented by software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented in hardware, as in another embodiment, any one or a combination of the following techniques well known in the art can be used: discrete logic circuits having logic gate circuits for implementing logical functions on data signals, application specific integrated circuits having suitable combinational logic gate circuits, programmable gate arrays (PGAs), field programmable gate arrays (FPGAs), etc.

[0122] Those of ordinary skill in the art of this technology can understand that all or part of the steps carried by the method of the above embodiments can be completed by a program instructing relevant hardware, and the program can be stored in a computer-readable storage medium. When the program is executed, it includes one or a combination of the steps of the method embodiments.

[0123] In addition, each functional unit in various embodiments of the present application may be integrated into a processing module, may exist physically alone for each unit, or two or more units may be integrated into one module. The above-mentioned integrated module may be implemented in the form of hardware or in the form of a software functional module. When the integrated module is implemented in the form of a software functional module and sold or used as an independent product, it may also be stored in a computer-readable storage medium.

[0124] The above-mentioned storage medium may be a read-only memory, a magnetic disk, an optical disc, etc. Although the embodiments of the present application have been shown and described above, it can be understood that the above embodiments are exemplary and should not be construed as limiting the present application. Those of ordinary skill in the art can make changes, modifications, substitutions, and variations to the above embodiments within the scope of the present application.

[0125] It should be understood that various forms of the processes shown above can be used, steps can be reordered, added, or deleted. For example, the steps described in the present application can be executed in parallel, sequentially, or in a different order, as long as the desired results of the technical solution of the present application can be achieved, and no limitations are imposed herein.

[0126] The above specific implementation manners do not constitute a limitation on the protection scope of the present application. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principle of the present application shall be included within the protection scope of the present application.

Claims

1. An automated analysis method for cross-layer interaction vulnerabilities of TCP / IP layered model protocols, characterized in that: The following steps are involved: Clean, split and preprocess the source code and RFC documents of the TCP / IP protocol stack to extract the core information of protocol design and implementation; Based on the preprocessed source code and RFC documents, intermediate representations are generated respectively, including: extracting the protocol processing logic and cross-layer interaction process from the source code to generate the protocol processing intermediate representation IR-C; extracting the protocol state description and logical structure from the RFC document to generate multiple intermediate representations IR-Ri; Perform differential analysis on IR-C and IR-Ri to check whether the protocol code and RFC document are consistent in their logical descriptions, identify potential inconsistencies between the code and the document, and make corresponding adjustments; Based on the results of consistency comparison and adjustment, we expand from single-layer protocols to cross-layer protocol interactions, and build a protocol cross-layer interaction state machine that describes the cross-layer interaction logic. The protocol cross-layer interaction state machine is used to generate a cross-layer interaction definition document that complies with the RFC document style.

2. The method according to claim 1, characterized in that The cleaning, splitting and preprocessing of the source code and RFC documents of the TCP / IP protocol stack include: Parse the source code by functional modules to extract the data packet structure, state definition, event processing function and state transfer logic related to the protocol implementation; The RFC document is split according to state definition, data packet structure, event processing logic and state transition diagram, and the content irrelevant to protocol design is filtered out.

3. The method according to claim 2, characterized in that The intermediate representations are generated based on the preprocessed source code and RFC document, respectively, including: For the source code, we designed a prompt that adapts to the characteristics of the network protocol stack, used the text analysis capabilities of the large language model to extract key logic information from the kernel protocol stack code, and constructed an intermediate representation IR-C that represents the protocol processing and cross-layer interaction process. For RFC documents, domain-specific language and syntax analysis technology are used to parse the protocol logic, detect ambiguities in the description, and generate multiple intermediate representations IR-Ri for ambiguity.

4. The method according to claim 3, characterized in that The text analysis capability of the large language model is used to extract key logic information from the kernel protocol stack code, including: Extract the packet header structure and field information of the protocol and generate corresponding packet header status information; Analyze the logic of the protocol processing function and extract the processes related to the protocol state transition; Identify the key code paths in the protocol implementation that interact with other protocol layers and extract the logic of cross-layer information transmission.

5. The method according to claim 4, characterized in that The differential analysis of IR-C and IR-Ri is performed to check whether the protocol code and RFC document are consistent in their logical descriptions, identify potential inconsistencies between the code and the document, and make corresponding adjustments, including: The large language model combined with Prompt is used to perform differential analysis on IR-C and IR-Ri. By comparing the symbols, logical structures and control flow graphs of the two, it is checked whether the descriptions of the protocol code and the RFC document at the logical level are consistent; Mark logical differences found in differential analysis; Adjust the ambiguous descriptions in the RFC document to eliminate the inconsistencies caused by the ambiguity of natural language, and modify the implementation logic of the source code as needed to ensure the consistency of IR-C and IR-Ri at the logical level.

6. The method according to claim 5, characterized in that The logical differences detected during the differential analysis process include: The misalignment between the logic description defined in the RFC document and the code implementation symbols; The ambiguity of natural language in RFC documents leads to polysemy; Protocol logic vulnerabilities not covered in the code implementation.

7. The method according to claim 6, characterized in that The results of the consistency comparison and adjustment are extended from the single-layer protocol to the cross-layer protocol interaction, and a protocol cross-layer interaction state machine describing the cross-layer interaction logic is constructed, including: Based on the intermediate representation IR-R of the RFC specification obtained after consistency adjustment, supervised model training from IR-C to IR-R is performed; Based on the trained model, the protocol stack cross-layer interaction code is used as input to generate the intermediate representation IR-C of the cross-layer interaction; The generated IR-C is used as the representation of the protocol cross-layer interaction state machine to describe the protocol cross-layer interaction logic.

8. The method according to claim 7, characterized in that Also includes: A visualization tool is used to visualize the cross-layer interaction state machine of the protocol.

9. The method according to claim 8, characterized in that The method of using the protocol cross-layer interaction state machine to generate a cross-layer interaction definition document that conforms to the RFC document style includes: Based on the generated cross-layer interaction state machine of the protocol, IR-C is processed through a large language model to generate a cross-layer interaction definition document consistent with the RFC document style.

10. An automated analysis device for cross-layer interaction vulnerabilities of TCP / IP layered model protocols, characterized in that: include: Source code and RFC document parsing module, used to clean, split and pre-process the source code and RFC documents of the TCP / IP protocol stack to extract the core information of protocol design and implementation; The intermediate representation generation module is used to generate intermediate representations based on the preprocessed source code and RFC documents, including: extracting the protocol processing logic and cross-layer interaction process from the source code to generate the protocol processing intermediate representation IR-C; extracting the protocol state description and logical structure from the RFC document to generate multiple intermediate representations IR-Ri; The intermediate representation consistency detection module is used to perform differential analysis on IR-C and IR-Ri, check whether the description of the protocol code and the RFC document at the logical level is consistent, identify potential inconsistencies between the code and the document, and make corresponding adjustments; The cross-layer interaction state machine generation module is used to expand from a single-layer protocol to a cross-layer protocol interaction based on the results of consistency comparison and adjustment, and to build a protocol cross-layer interaction state machine that describes the cross-layer interaction logic; The cross-layer interaction document generation module is used to generate a cross-layer interaction definition document that conforms to the RFC document style by using the protocol cross-layer interaction state machine.

Citation Information

Patent Citations

  • Protocol inconsistency vulnerability mining method and device based on man-machine cooperation

    CN115529167A

  • Interactive security analysis method and system for TCP / IP hierarchical network model

    CN115604026A

  • RFC evolution guided protocol implementation vulnerability mining method

    CN117254932A

  • Immediate ready implementation of virtually congestion free guaranteed service capable network : nextgentcp / ftp / UDP intermediate buffer cyclical sack re-use

    US20100020689A1