Generation scheduling method for kernel fuzzy test configuration related seeds
Through the configuration system call classification generation and behavior-related-driven test execution scheduling and generation methods based on large language models, the problem of kernel fuzzy test seed generation does not consider kernel configuration modification related system calls, which significantly improves the coverage rate and vulnerability discovery capabilities of kernel fuzzy tests.
Patent Information
- Application Number
- CN202510531673.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-25
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2045-04-25
AI Technical Summary
The existing kernel fuzz test seed generation method fails to effectively consider kernel configuration modification related system calls, resulting in insufficient coverage and vulnerability discovery capabilities of kernel fuzz test.
The configuration system call classification generation method based on a large language model is adopted. By analyzing the kernel characteristic configuration scope, initial corpus input is generated that is highly related to the kernel configuration items, and test execution scheduling and generation driven by behavioral association and configuration code association are optimized to optimize test efficiency.
The coverage rate and vulnerability discovery capabilities of kernel fuzz testing have been significantly improved, the configuration-sensitive fuzz testing theory in kernel testing scenarios has been explored, and the configuration-sensitive kernel fuzz testing framework has been built, which has improved the kernel defect detection capabilities and efficiency.
Smart Images

Figure CN120066972A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of computer operating system kernels, and specifically refers to a method for generating and scheduling seeds related to kernel fuzz testing configurations. Background Art
[0002] The kernel is a core component of a computer operating system, responsible for managing file systems, I / O, scheduling, memory, etc. The kernel directly affects the stability and efficiency of the system, and its security is extremely important. In recent years, many testing methods have emerged to detect existing vulnerabilities.
[0003] Fuzz testing is a current mainstream software testing method. It uses an automatic or semi-automatic method to generate test cases, then inputs the test cases to the target system, and captures vulnerabilities by monitoring abnormal system behaviors during the execution of the test cases. Currently, applying fuzz testing to the field of kernel security has achieved good results.
[0004] For operating system kernel fuzz testing, the system call sequence is used as the seed input during the fuzz testing process. Random parameters and sequences are generated for the operating system to execute, and at the same time, a defect detection tool in the kernel is used to monitor the operation of the operating system to discover abnormal states during the operation of the operating system.
[0005] In the current field of kernel fuzz testing, the system calls generated by the seed usually do not involve system calls related to kernel dynamic configuration. Firstly, due to the complexity and diversity of kernel configuration itself, it is very difficult to generate configuration-related system calls. Secondly, the uniqueness of kernel configuration means that configuration changes may have significant impacts. Modifying kernel configuration without guidance will lead to irreparable serious consequences. Therefore, how to reasonably schedule configuration-related system calls is worthy of attention, and how to reasonably schedule seeds related to configuration-related system calls has not been deeply studied. Thirdly, the application scenarios of configuration-related system calls in actual testing have not been deeply explored.
[0006] Seed generation is one of the key steps in fuzz testing. A reasonable seed generation scheme can significantly increase the probability of discovering vulnerabilities. The current kernel fuzz testing seed generation does not consider system calls related to kernel configuration modification. Adding the generation of this type of system call can better help improve the coverage collection ability and vulnerability discovery ability of kernel fuzz testing. Summary of the Invention
[0007] The technical problem to be solved by the present invention is to provide a method for generating and scheduling seeds related to kernel fuzz testing configurations in view of the deficiencies mentioned in the above background art.
[0008] To solve the above technical problems, the technical solution provided by the present invention is as follows: A method for generating and scheduling seeds related to kernel fuzz testing configuration, which includes the following: First, generating configuration system call classification based on a large language model: Analyze the kernel feature configuration range through a large language model, study the gap between traditional use case descriptions and actual kernel configurations, construct a unified representation of test inputs that integrates kernel configurations, and automatically generate test specification templates for kernel fuzz testing system calls to obtain an initial corpus input highly relevant to kernel configuration items; Second, test execution scheduling and generation based on behavior association: By constructing an association representation between configuration system calls and traditional system calls, design a targeted use case scheduling and mutation mechanism for kernel configurations to achieve test execution covering feature configuration combinations; The association representation is an association degree table used to guide the generation of fuzz testing seeds; Third, optimizing test efficiency driven by configuration-code association: Through feature code coverage extraction, construct a configuration-code association representation to improve the quality of configuration-related fuzz testing outputs and increase the utilization rate of configuration-related fuzz testing outputs; Feature code coverage extraction is to perform fuzz testing according to the generated fuzz testing seeds and scheduling strategies and collect code coverage.
[0009] Further, the generation of configuration system call classification based on a large language model specifically includes the following steps: (1): Extracting and screening kernel dynamic configurations; (2): Classifying data structures; (3): Generating dynamic configuration system call templates; (4): Generating pseudo-system call classification based on a large language model; (5): Fuzz testing.
[0010] Further, the extraction and screening of the kernel dynamic configuration specifically means extracting all dynamic configuration options from the operating system kernel source code and screening out the feature items that significantly affect the kernel behavior; The classification of data structures specifically means classifying kernel dynamic configuration items into boolean type, integer type, floating-point type, string type, etc. for subsequent processing; The generation of dynamic configuration system call templates specifically means formulating generation strategies for different types of configuration items and writing pseudo-system call templates; The generation of pseudo-system call classification based on a large language model specifically means using a large language model to analyze the value range of kernel feature options, generating system calls for modifying dynamic configuration items and incorporating them into the seed generation tool; The continuous fuzz testing specifically refers to the content of optimizing test efficiency driven by configuration-code association.
[0011] Further, the test execution scheduling and generation based on behavior association specifically include the following steps: (1): Scheduling the execution use case system call based on the configured behavior; (2): Minimizing the system call sequence; (3): Generating the execution use case based on the call association.
[0012] Further, the scheduling of the execution use case system call based on the configured behavior is specifically to insert a recovery system call at the end of the sequence containing the system calls related to the configuration to ensure the stability of the kernel environment.
[0013] The minimization of the system call sequence is specifically to traverse the system call sequence in reverse, extract the system calls that generate new coverage information, and obtain the smallest sequence with unchanged coverage.
[0014] The generation of the execution use case based on the call association is specifically to perform a combined static and dynamic correlation analysis on the minimized test cases in the test execution scheduling and generation based on behavior association, and use the obtained correlation table to guide the generation of fuzz testing seeds.
[0015] Further, the optimization of the test efficiency based on the configuration code association drive specifically includes the following steps: (1): Continuous fuzz testing; (2): Extracting the code coverage rate of a single configuration system call; (3): Establishing a configuration item code relationship database; (4): Inputting the location of the targeted fuzz testing code; (5): Automatically enabling the configuration items related to the targeted code; (6): Deep targeted fuzz testing.
[0016] Further, the continuous fuzz testing is specifically to perform kernel fuzz testing for a long time using the previously generated fuzz testing seeds and scheduling strategies.
[0017] The extraction of the code coverage rate of a single configuration system call is specifically to extract the code coverage rate of a single configuration system call. After performing multiple long-term fuzz tests, the code coverage rate of a single configuration system call can be collected.
[0018] The establishment of the configuration item code relationship database is specifically to establish a database based on the code coverage rate of a single configuration item and record the code locations affected by the system calls of the configuration item.
[0019] The input of the location of the targeted fuzz testing code is specifically to input the targeted code block and search for relevant configurations in the database.
[0020] The specific configuration item for automatically enabling the target code is to generate a system call sequence with a script and add it to the fuzzing sequence after finding the relevant dynamic configuration item.
[0021] The so-called in-depth target fuzzing is to perform tests by combining the original system calls and the system calls related to the target code configuration system, and to discover coverage and vulnerabilities.
[0022] The above solution of this application has the following beneficial effects: In terms of theory: Explore the theory of configuration-sensitive fuzzing in the kernel test scenario, construct a kernel fuzzing framework based on configuration sensitivity, and improve the ability and efficiency of kernel defect detection.
[0023] In terms of technology: Deeply integrate large language models, relational learning and dynamic analysis technologies, with technical characteristics and innovation.
[0024] In terms of application: Implement a kernel configuration code detection tool, and plan to construct a code-related configuration detection service for the Linux mainline kernel and domestic open-source operating system kernels, improving the ability and automation level of kernel defect detection.
[0025] Other beneficial effects of this application will be described in detail in the subsequent specific implementation part. Description of the Drawings
[0026] Figure 1 is a schematic flow diagram of a method for generating and scheduling seeds related to kernel fuzzing configuration; Figure 2 is a schematic diagram of a research framework for generating configuration system calls based on a large language model; Figure 3 is a schematic diagram comparing traditional system calls and pseudo-system calls; Figure 4 is a schematic diagram of scheduling execution use cases based on configuration behavior; Figure 5 is a schematic diagram of generating execution use cases based on call association; Figure 6 is a schematic diagram of a static and dynamic detection framework; Figure 7 is a schematic diagram of a test efficiency enhancement framework driven by configuration code association; Specific Implementation
[0027] In the following description, specific details such as specific system architectures and technologies are presented for the purpose of illustration rather than limitation, so as to thoroughly understand the embodiments of the present application. However, those skilled in the art should understand that the present application can also be implemented in other embodiments without these specific details. In other cases, detailed descriptions of well-known systems, devices, circuits, and methods are omitted to avoid unnecessary details from interfering with the description of the present application.
[0028] It should be understood that when used in the specification of the present application and the appended claims, the term "comprising" indicates the presence of the described features, wholes, steps, operations, elements, and / or components, but does not exclude the presence or addition of one or more other features, wholes, steps, operations, elements, components, and / or their combinations.
[0029] It should also be understood that the term "and / or" used in the specification of the present application and the appended claims refers to any combination and all possible combinations of one or more of the associated listed items, and includes these combinations.
[0030] First, the relevant technical terms of the present application will be explained below.
[0031] Operating system kernel: The operating system kernel is the core part of the operating system, responsible for managing system hardware resources and providing basic services for upper-layer software. The kernel provides an interface for user programs to interact with hardware through system calls, and undertakes key functions such as process management, memory management, and file system management.
[0032] Kernel dynamic configuration: Kernel dynamic configuration refers to the kernel parameter configuration items that can be changed manually. These configuration items allow users and administrators to adjust kernel behavior and system performance while the operating system is running.
[0033] System call: A system call is an interface for interaction between user-space programs and the kernel. When a user program needs services provided by the operating system (such as file operations, process control, memory allocation, etc.), it initiates a system call. System calls are programming interfaces provided by the operating system for application programs to achieve interaction with hardware or the kernel.
[0034] System calls related to kernel dynamic configuration: Specifically refers to system calls for modifying the parameters of kernel dynamic configuration items in this article.
[0035] Fuzz testing: Fuzz testing is an automated software program testing technique that probes for vulnerabilities, abnormal behaviors, or security holes in software by inputting random, invalid, or abnormal data into the software program.
[0036] Test case: A test case refers to a specific test scenario or condition used to verify the functionality or performance of software during the software testing process. Each test case includes a set of input data, expected output, and execution steps. In kernel fuzz testing, a test case represents a sequence of system calls.
[0037] Kernel fuzz testing: The fuzz testing tool passes random, abnormal, or invalid system call sequences to the kernel system calls and observes how the system processes these data to discover potential vulnerabilities or abnormal behaviors.
[0038] Code coverage: It is a metric used to measure the quality of software testing. It indicates how much of the code has been executed and inspected during the testing process. The main purpose of code coverage is to ensure that as many code paths as possible are tested, thereby improving the reliability and stability of the software. Code coverage can be precise to a specific line of kernel code.
[0039] Kernel-targeted fuzz testing: Kernel-targeted fuzz testing is a security testing technique mainly used to discover vulnerabilities in the operating system kernel and its modules. Its core concept is to test the robustness and security of the kernel code by automatically generating a large number of random or specific-format inputs. Compared with ordinary fuzz testing, the focus is on the concentrated testing of specific modules or specific code.
[0040] Target: In fuzz testing, the target refers to the system component or function being tested. The target is usually a specific module, function, or interface in the operating system kernel, where attackers are likely to exploit. The selection of the target is crucial for the effectiveness of fuzz testing.
[0041] The following further elaborates on the present invention in conjunction with the accompanying drawings.
[0042] The existing seed generation schemes all have their advantages and disadvantages. In actual use, multiple methods are usually combined to improve the comprehensiveness and effectiveness of testing. In kernel fuzz testing, selecting a suitable seed generation scheme can effectively increase the probability and efficiency of vulnerability discovery. However, the above-mentioned seed generation strategies do not consider the generation and scheduling of seeds related to kernel dynamic configuration items. In this regard, in conjunction with the attached Figure 1 , the present invention adopts the following method: A method for generating and scheduling seeds related to kernel fuzz testing configuration, which includes the following: 1. Generation of configuration system call classification based on large language model: Analyze the kernel feature configuration range through the large language model, study the gap between traditional use case descriptions and actual kernel configurations, construct a unified representation of test inputs that integrates kernel configurations, and automatically generate a test specification template for kernel fuzz testing system calls to obtain an initial corpus input highly related to kernel configuration items.
[0043] 2. Test Execution Scheduling and Generation Based on Behavior Association: By constructing an association representation that configures system calls and traditional system calls, a targeted use case scheduling and mutation mechanism for kernel configuration is designed to achieve test execution covering feature configuration combinations; the association representation is an association degree table used to guide the generation of fuzz testing seeds.
[0044] 3. Test Efficiency Optimization Driven by Configuration-Code Association: Based on feature code coverage extraction, a configuration-code association representation is constructed to improve the quality of fuzz testing output related to configuration and increase the utilization rate of fuzz testing output related to configuration; feature code coverage extraction is to perform fuzz testing according to the generated fuzz testing seeds and scheduling strategies and collect code coverage.
[0045] Combined with Figures 2-3 As shown, Configuration System Call Classification Generation Based on Large Language Model: Through the large language model to analyze the kernel feature configuration range, study the gap between traditional use case descriptions and actual kernel configurations, construct a unified representation of test inputs that integrates kernel configurations, and automatically generate a test specification template for kernel fuzz testing system calls to obtain an initial corpus input highly relevant to kernel configuration items.
[0046] (1) Kernel Dynamic Configuration Extraction and Screening: Extract all dynamic configuration options from the operating system kernel source code. These options are usually defined during kernel runtime and determine the kernel's functions and behaviors. Then, screen the extracted feature options, focusing on selecting those feature items that have a significant impact on kernel behavior and excluding some configuration items irrelevant to kernel operation. The goal of this step is to identify options that have a key impact on kernel features to ensure that the subsequent generated system calls can cover these core functions and features.
[0047] (2) Data Structure Classification: Classify the kernel dynamic configuration items by data structure type. Among the screened dynamic configuration items, classify these dynamic configuration items by data structure type, which may include classification as boolean, integer, floating-point, and string types, etc., for subsequent processing and analysis. Through this classification, the type and generation strategy of each feature item can be systematically understood, laying a foundation for subsequent system call generation.
[0048] (3) Dynamic Configuration System Call Template Generation: Based on the different types of configuration items obtained from data structure classification, different generation strategies are formulated, and different pseudo-system call templates for dynamic configuration items are written to ensure that system calls that can be detected by fuzz testing tools can be generated. The reason for choosing to use the pseudo-system call method is that it can achieve unified packaging of multiple system calls and more functions compared to traditional single system calls. The differences between traditional system calls and pseudo-system calls are as follows Figure 3As shown, the pseudo-system call function can encapsulate more functions compared to traditional system calls, such as error detection and result output during execution, etc.
[0049] (4)Classification and generation of pseudo-system calls based on large language models: Analyze the value range of different kernel feature options using large language models, and formulate different generation strategies based on different types of features obtained from data structure classification to generate all pseudo-system calls for modifying dynamic configuration items, ensuring the effectiveness of the generated pseudo-system calls. For example, Figure 3 in the configuration item, the parameter range is from 0 to 1, and the actual preset value is from 0 to 2. A certain amount of invalid space is reserved to facilitate observing the behavior of test cases when dealing with the invalid interval, ensuring the depth and breadth of testing. Organize all selected feature configuration items and input them into the fuzzer as the initial corpus for testing.
[0050] (5)Fuzz testing: Conduct long-term kernel fuzz testing using the previously generated fuzz testing seeds and scheduling strategies. More specifically, combine the generated system calls related to dynamic configuration with the original system calls in the kernel fuzz testing tool for fuzz testing.
[0051] Combined with Figures 4-6 As shown, test execution scheduling and generation based on behavior association: Solve the problem that related vulnerabilities are difficult to reproduce through execution case scheduling based on configuration behavior, and guide the generation of configuration system calls through execution case generation based on call association.
[0052] (1)Execution case scheduling system calls based on configuration behavior: For a sequence containing system calls related to configuration, insert a recovery system call at the end to ensure the stability of the kernel environment. Specifically, as Figure 4 shown, for a group of initial system call sequences, whenever there is one or more feature configuration system calls in the execution sequence of this group, a corresponding recovery system call will be inserted at the end of the sequence execution. Each dynamic configuration system call has its corresponding recovery system call. The recovery system call is extracted from the kernel before each kernel fuzz testing and is a fixed value. It is written as a normal system call that can be recognized by the kernel in the first step. The purpose is to restore the value modified by the feature configuration system call to the initial state value of the system after the execution of the recovery system call, ensuring that the modification of the dynamic configuration system call will not affect the overall kernel and thus affect the subsequent test process.
[0053] (2)Minimization of system call sequence: Traverse the system call sequence in reverse, extract the system calls that generate new coverage information, and obtain a sequence that is minimized and has the same coverage. Specifically, perform minimization on a set of test data (i.e., system call sequences). The minimization logic is to traverse the system call sequence in reverse and extract those system calls that generate new coverage information. These system calls include ordinary system calls and feature-related system calls, so that a system call sequence that is as small as possible and has the same coverage can be obtained.
[0054] (3)Generation of execution test cases based on call association: As Figures 5-6 shown, first perform static detection on the system calls related to dynamic configuration extracted from the kernel, initially construct the association relationship representation between the configuration-related seed test cases and ordinary seed test cases, use it as the basis for test case generation, and put it into test execution. During the execution process, continuously collect each set of system call sequences, perform dynamic analysis based on the minimized system call sequence, and continuously improve the association relationship representation between the configuration-related seed test cases and ordinary seed test cases, so as to guide the generation of test cases and improve the breadth and depth of testing, including: 1. Static detection: First perform static detection on the system calls related to dynamic configuration extracted from the kernel. Based on whether they access the same module through the information contained in the system calls themselves, use the string comparison mechanism to analyze the relationship between the configuration system calls and ordinary system calls. For example, as Figure 6 shown, assume that the cfg2 configuration system call modifies a certain configuration item under / proc / sys / net / netfilte, and sys1 and sys2 access the net directory and / net / netfilte respectively. Then it is determined that there is a certain association between cfg2 and sys1 and sys2, and the data in their relationship table are set to 5 and 10 respectively. For each additional identical string, the association degree is increased by 5, and the association table is continuously maintained in this way.
[0055] 2. Dynamic detection: During the test execution process, the fuzzer performs association degree analysis on each set of system call sequences actually tested. First, perform minimization on the system call sequence, that is, traverse the system call sequence in reverse and extract those system calls that generate new coverage information (including ordinary system calls and configuration-related system calls) to obtain a minimized system call sequence with the smallest number but without affecting the overall coverage rate. Then analyze this sequence. If there is a configuration system call in the sequence, it is determined that there is a relationship between it and other ordinary system calls in the sequence, and the data in the relationship table are set to 10, and it is combined with the association relationship table obtained from static detection to form a static-dynamic combined association relationship table.
[0056] 3. Use Case Generation Guidance: By combining static and dynamic analysis, continuously maintain the system call association relationship table during the testing process, optimize it using the sparse characteristics of the association relationship table, use a hash table to improve the retrieval efficiency, and rely on the association relationship table. After each instantiation of a system call, probabilistically generate related configuration system calls based on the data in the table, thereby enhancing the ability and efficiency of configuration-sensitive kernel fuzz testing.
[0057] Combined with Figure 7 As shown, the optimization of test efficiency driven by configuration code association: Combine configuration-sensitive kernel fuzz testing with targeted fuzz testing to strengthen the ability and efficiency of configuration fuzz testing. Specifically, take the output result of configuration-sensitive kernel fuzz testing for dynamic configuration as the entry point, construct the association relationship representation between configuration-related system calls and kernel code, so as to enhance the ability of configuration-sensitive kernel fuzz testing under resource constraints.
[0058] Combined with Figure 7 The optimization of test efficiency driven by configuration code association described above specifically includes the following steps: (1) Continuous Fuzz Testing: Use the test cases and scheduling strategies generated in the above steps to conduct long-term continuous kernel fuzz testing, in order to better adjust the system call generation strategy of the kernel fuzz testing tool as much as possible and better explore and play the role of dynamic configuration in the fuzz testing process; (2) Extract the code coverage rate of a single configuration system call: After extracting the code coverage rate of a single configuration system call and conducting multiple long-term fuzz tests, the code coverage rate of a single configuration system call can be collected. This data shows the code locations that can be directly affected after the change of this configuration item, which can help with targeted fuzz testing.
[0059] (3) Establish a configuration item code relationship database: Establish a configuration item code relationship database based on the code coverage rate of a single configuration item, and record the code locations that can be directly affected by all configuration item system calls; (4) Input the code location for targeted fuzz testing: Input the code location for targeted fuzz testing, input the targeted code block of the program, and search for the configuration related to the code block in the database in step eight. For example, for the targeted fuzz testing of the net module, all dynamic configuration items related to the net module can be directly found in the configuration item code relationship database.
[0060] (5) Automatically enable the configuration items related to the targeted code: After searching for the dynamic configuration items related to the targeted code, a script can be used to automatically generate the system call sequence of the relevant dynamic configuration items and synchronously add it to the fuzz testing system call sequence.
[0061] (6)Deep targeted fuzz testing: Use the original system calls and the configuration system calls related to the targeted code for fuzz testing to dig deeper into the coverage and vulnerabilities related to the target.
[0062] The present invention proposes an innovative method that can use large language models to automatically generate targeted system calls related to dynamic configuration, and is equipped with a comprehensive analysis and scheduling mechanism for the generated configuration-related system calls and ordinary system calls. This mechanism can effectively manage and schedule the generation and mutation of ordinary system calls and configuration-related system calls to ensure that they can cover a wider range of operating system kernel scenarios, thereby helping to discover more potential kernel vulnerabilities. At the same time, the present invention also deeply explores the related application scenarios of configuration-related system calls, establishes a configuration item-code relationship database, and proposes a practical operation method for adding target-related kernel configuration items in kernel targeted fuzz testing.
[0063] Specifically, after analyzing the kernel configuration, the large language model can intelligently generate system calls suitable for specific kernel configurations. These system calls can trigger various boundary conditions and special scenarios, thereby revealing potential defects in the kernel implementation. In addition, the scheduling mechanism of this method ensures the effectiveness and efficiency during the testing process by intelligently sorting and adjusting the priorities of the generated system calls. Empowered by the configuration item-code relationship database obtained from multiple tests, it improves the code coverage related to the target and safeguards the kernel security. Through this system, the tool of the present invention significantly improves the coverage range and depth of kernel targeted fuzz testing, providing more powerful guarantee for the security of the operating system.
[0064] After adopting the above content, the present invention aims at the quality assurance of the operating system kernel, explores the key technologies to improve the defect detection ability and efficiency of kernel fuzz testing, and systematically solves the problems of poor testing ability and lack of pertinence of fuzz testing means in the field related to kernel configuration by constructing a configuration-sensitive kernel fuzz testing framework. The specific features and innovations are as follows: Theoretical innovation: Aiming at the lack of detection ability related to kernel configuration in current kernel fuzz testing, the project starts from the contradiction between test input and test requirements, explores the configuration-sensitive fuzz testing theory in the kernel test scenario, and improves the kernel defect detection ability and efficiency by constructing a configuration-sensitive kernel fuzz testing framework, which has certain theoretical characteristics and innovation; Technological Innovation: The project deeply integrates large language models, relational learning, and dynamic analysis techniques to propose a configuration-sensitive kernel fuzz testing method, which has certain technological characteristics and innovativeness. Specifically, the project constructs an initial corpus input highly relevant to kernel configurations through large language models, realizes the analysis and scheduling of configuration-related test cases based on relational learning, and improves the utilization rate of configuration-related fuzz testing outputs based on dynamic analysis techniques; Application Innovation: The project implements a kernel configuration code detection tool based on the configuration kernel fuzz testing method, and plans to build a code-related configuration detection service for the Linux mainline kernel and domestic open-source operating system kernels, improving the kernel defect detection ability and automation level, which has certain application characteristics and innovativeness.
[0065] The above describes the present invention and its implementation manners, and this description is not restrictive. The actual structure is not limited thereto. Generally speaking, if those of ordinary skill in the art are inspired by it and design similar structural manners and embodiments to this technical solution without creative efforts without departing from the purpose of the present invention, they shall fall within the protection scope of the present invention.
Claims
1. A method for generating and scheduling kernel fuzzy test configuration related seeds, characterized in that: It includes the following: Configuration system call classification generation based on large language model: Analyze the kernel feature configuration range through large language model, study the gap between traditional use case description and actual kernel configuration, build a unified representation of test input that integrates kernel configuration, and automatically generate test specification templates for kernel fuzz test system calls to obtain initial corpus input that is highly relevant to kernel configuration items; Test execution scheduling and generation based on behavior association: By building the association representation between configuration system calls and traditional system calls, we design targeted use case scheduling and mutation mechanisms for kernel configurations to implement test execution that covers feature configuration combinations. The association representation is a correlation table for guiding the generation of fuzz test seeds; Test efficiency optimization based on configuration code association drive: Through feature code coverage extraction, build configuration-code association representation, improve the quality of configuration-related fuzz test output, and improve the utilization rate of configuration-related fuzz test output; The feature code coverage extraction is to perform fuzz testing according to the generated fuzz testing seeds and scheduling strategy, and collect code coverage.
2. According to claim 1, a method for generating and scheduling kernel fuzzy test configuration related seeds is characterized in that: The configuration system call classification generation based on the large language model specifically includes the following steps: (1): Kernel dynamic configuration extraction and screening; (2): Data structure classification; (3): Dynamic configuration system call template generation; (4): Pseudo system call classification generation based on large language model; (5): Fuzz testing.
3. The method for generating and scheduling kernel fuzzy test configuration related seeds according to claim 2, characterized in that: The kernel dynamic configuration extraction and screening specifically involves extracting all dynamic configuration options from the operating system kernel source code and screening out characteristic items that have a significant impact on kernel behavior; The data structure classification specifically divides the kernel dynamic configuration items into Boolean, integer, floating point and string types to facilitate subsequent processing; The dynamic configuration system call template generation is specifically as follows: formulating generation strategies for different types of configuration items and writing pseudo system call templates; The pseudo system call classification generation based on the large language model specifically uses the large language model to analyze the value range of the kernel feature option, generates a system call to modify the dynamic configuration item and compiles it into the seed generation tool; The continuous fuzz testing is specifically about optimizing the test efficiency based on the configuration code association drive.
4. The method for generating and scheduling kernel fuzzy test configuration related seeds according to claim 1, characterized in that: The test execution scheduling and generation based on behavior association specifically includes the following steps: (1): Scheduling system calls based on the execution of configured behaviors; (2): Minimize the system call sequence; (3): Generation of execution use cases based on call associations.
5. The method for generating and scheduling kernel fuzzy test configuration related seeds according to claim 4, characterized in that: The execution case scheduling system call based on the configuration behavior is specifically to insert a recovery system call at the end of the sequence containing configuration-related system calls to ensure the stability of the kernel environment; The system call sequence minimization is specifically to traverse the system call sequence in reverse, extract the system call that generates new coverage information, and obtain the smallest sequence with unchanged coverage; The execution case generation based on call association is specifically test execution scheduling and generation based on behavior association, performing static and dynamic combined correlation analysis on the minimized test cases, and using the obtained correlation table to guide the generation of fuzzy test seeds.
6. The method for generating and scheduling kernel fuzzy test configuration related seeds according to claim 1, characterized in that: The test efficiency optimization based on configuration code association drive specifically includes the following steps: (1): Continuous fuzz testing; (2): Extract the code coverage of a single configuration system call; (3): Establish a configuration item code relationship database; (4): Input the target fuzz testing code location; (5): Automatically enable configuration items related to the targeted code; (6): Deep targeted fuzz testing.
7. The method for generating and scheduling kernel fuzzy test configuration related seeds according to claim 6, characterized in that: The continuous fuzz testing specifically includes using the previously generated fuzz testing seeds and scheduling strategies to perform kernel fuzz testing for a long time; The extracting of the code coverage of a single configuration system call specifically refers to extracting the code coverage of a single configuration system call. After multiple long-term fuzz tests, the code coverage of a single configuration system call can be collected. The establishment of the configuration item code relationship database specifically includes establishing a database based on the code coverage of a single configuration item, and recording the code location affected by the configuration item system call; The input target fuzz test code position is specifically the input target code block, and the relevant configuration is searched in the database; The automatic activation of the configuration items related to the target code is specifically to generate a system call sequence with a script and add the fuzz test sequence after finding the relevant dynamic configuration items; The deep targeted fuzz testing specifically combines the original system calls and the targeted code related configuration system calls to perform testing to explore coverage and vulnerabilities.
Citation Information
Patent Citations
Kernel fuzzy test case generation method based on system call dependency graph
CN112559367A
Kernel fuzzy test case generation method and device, equipment and storage medium
CN112948257A
Fuzzy testing method and system for trusted execution environment of Internet of Things
CN114610640A
Context-aware dependency-guided kernel fuzz test case variation method and system
CN116541268A
Method and apparatus for kernel module testing
US20030074604A1
Cited By
Operating system kernel directional fuzzy testing method based on LLM auxiliary system call inference
CN121234377A