Multi-target directional fuzzy test acceleration method based on dynamic and static pruning
Through the multi-objective directional fuzz testing acceleration method based on dynamic and static pruning, combined with precondition analysis and adaptive scheduling algorithm, the problems of high resource consumption and low efficiency in multi-objective processing are solved, and efficient and accurate reproduction of multi-objective vulnerabilities are achieved.
Patent Information
- Application Number
- CN202411969815.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-30
- Publication Date
- 2025-05-30
AI Technical Summary
When traditional directed fuzz testing methods deal with multiple targets, they consume high resources and are inefficient, and cannot effectively reproduce multiple target vulnerabilities in the program.
The multi-objective directional fuzz testing acceleration method based on dynamic and static pruning is adopted. Through precondition analysis and insertion technology, test cases that cannot reach the target position are pruned, and seed scheduling is optimized using an adaptive scheduling algorithm.
It effectively reduces resource consumption, improves the efficiency and accuracy of fuzzing testing, and can reproduce multiple target vulnerabilities faster under limited resources.
Smart Images

Figure CN120068078A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of software testing technology, and particularly to a multi-objective directed fuzz testing acceleration method based on dynamic and static pruning. Background Art
[0002] With the increasing scale and development speed of software systems, the number of vulnerabilities in modern software projects has also increased exponentially. Developers often need to handle a large number of vulnerabilities in the program simultaneously to ensure software quality. A single static analysis tool may report more than 1000 potential vulnerabilities or security issues in a single version of a software project, which need to be verified by developers. This huge number of targets poses a great challenge to traditional vulnerability mining and verification work. Traditional directed fuzz testing methods usually test each target separately, consuming a large amount of computing resources.
[0003] To accelerate the speed of vulnerability verification, a common strategy is to increase computing resources. For example, use multi-core processors to start multiple concurrent fuzz testing instances for each target. However, the cost of this solution may be very high. Considering the above example, if 1000 targets need to be verified and traditional directed fuzz testing needs to run on a separate CPU core for each target, a large amount of computing time and resources are required. Therefore, it has become crucial to develop efficient and economical vulnerability verification methods to cope with the increasing number of targets and resource limitations. These efficient methods need to be able to handle multiple targets more effectively with limited resources, for example, by more intelligently scheduling and optimizing the fuzz testing process, improving the efficiency and accuracy of fuzz testing while reducing resource consumption.
[0004] Many current research works focus on improving the efficiency of directed fuzz testing, and many program analysis techniques are applied to directed fuzz testing. The current optimization directions are mainly divided into the following two categories. The first category is to optimize input generation. Researchers generate inputs that are more likely to reproduce target vulnerabilities by analyzing program information related to the target. For example, use sanitizers to identify potentially vulnerable code and guide seed mutation; use semantic analysis to obtain semantic information related to the target to guide input generation and seed mutation; adopt pollution tracking techniques to find input variables related to target conditions and prioritize mutation of these variables. The second category is to optimize seed selection. Some research aims to select inputs that are more likely to reach the target location. For example, data flow analysis and control flow analysis are used to calculate the seed distance and select seeds closer to the target based on this; machine learning methods are used to predict and filter inputs that cannot reach the target location; memory function analysis is used to identify seeds with more memory access operations; function complexity evaluation is used to select seeds closer to potentially vulnerable functions.
[0005] The above-mentioned techniques applied to directed fuzz testing effectively improve the efficiency of single-target directed fuzz testing. However, the techniques for optimizing input generation cannot guarantee that the generated input will definitely reach the target location, and the techniques for optimizing seed selection only consider the case of a single target and cannot effectively select seeds that are more conducive to reproducing multiple target vulnerabilities. These problems also result in the current directed fuzz testing being unable to effectively reproduce multiple targets in the program. Summary of the Invention
[0006] The present application provides a multi-target directed fuzz testing acceleration method based on dynamic and static pruning, which can be used to solve the technical problems of multi-target directed fuzz testing.
[0007] To solve the problems existing in the above situation, reproduce the vulnerabilities in the program with fewer resources and less time, and help developers verify and fix multiple vulnerabilities in the program, the present invention proposes a multi-target directed fuzz testing acceleration method based on dynamic and static pruning, including:
[0008] Step 1: Extract the error code lines from the vulnerability information report and regard the code as the location of the target vulnerability as the input.
[0009] Step 2: Use the compiler to compile the target program into llvm IR, and then analyze the IR of the target program to obtain the preconditions and reachability information of the target set.
[0010] Step 3: Use the preconditions and reachability information to instrument the IR of the target program, and then compile the IR of the target program into an executable file.
[0011] Step 4: Execute the target program with a large number of random inputs.
[0012] Further, Step 1 includes:
[0013] The program error message collection module collects relevant information from the vulnerability information report of the program and finds the line numbers of the code related to the program error.
[0014] The vulnerability location preprocessing module takes the line number of the last line of the error message as the location of the vulnerability, and then adds it to the target of the directed fuzz testing for verification; it is possible to input the line numbers of multiple vulnerabilities at the same time.
[0015] Further, the method of Step 2 includes:
[0016] Compile the target program into intermediate code in the form of LLVM IR and retain the debugging information; the debugging information includes the source code line numbers corresponding to the instructions of the intermediate code.
[0017] The intermediate code in LLVM IR form is in static single assignment form, where each variable in the program is defined only once for subsequent instrumentation operations;
[0018] Use a complete pointer analysis to parse function pointers on the intermediate code of the program and construct an interprocedural control flow graph for the target program;
[0019] Determine the target instructions in the intermediate code and the basic blocks where the target instructions are located for the source code line numbers collected in the first step according to the debug information of the program;
[0020] Perform reachability analysis on the interprocedural control flow graph and divide all basic blocks in the program into two categories: the first category can reach the target basic block on the control flow graph; the second category cannot reach any target basic block on the control flow graph.
[0021] While searching for the basic blocks where each target vulnerability is located, assign a different number to each basic block as a unique identifier,
[0022] Perform reachability analysis again based on the interprocedural control flow graph to obtain the reachability information of the basic blocks, which is represented by a set of identifiers;
[0023] Traverse each target in reverse and add the identifier of the target to the reachability information set of each basic block traversed;
[0024] Traverse the program instructions in reverse starting from the target position and analyze the preconditions that the input needs to meet for each target to make the program execute to the target position;
[0025] The process of precondition analysis is as follows:
[0026] (1) Traverse in reverse from the target position. When a branch statement is traversed, obtain the branch condition and get the conditional expression according to the satisfiability of the analysis condition;
[0027] (2) Analyze in reverse from the target position on the interprocedural control flow graph and transfer and deduce conditions between program variables according to program instructions and predicates;
[0028] (3) When deducing preconditions, first convert the conditional expression to interval domain representation according to the interval abstraction function, then calculate according to the interval operation rules, and finally convert the deduced interval domain back to the conditional expression;
[0029] (4) During the precondition analysis process, save the preconditions for multiple targets separately and deduce multiple preconditions simultaneously when analyzing a program instruction in reverse;
[0030] Disjunct the preconditions for multiple targets to ensure that the final precondition does not reject inputs that can reach any of the targets.
[0031] Further, step three includes:
[0032] Perform precondition instrumentation. Determine the program variables to be instrumented according to the preconditions analyzed in step two, and convert the interval domain of the program variables into conditional expressions.
[0033] Determine the code location where the program variables to be instrumented are first defined in the static single assignment form of the intermediate code.
[0034] Use the conditional expression of the program variable as the condition of the assertion statement, and then insert the assertion statement after the program location where the program variable is first defined.
[0035] Perform reachability information instrumentation. Write the reachability information analyzed in step two as the parameter of the function for statistical execution information into the corresponding basic block.
[0036] The principle for basic block reachability information instrumentation is as follows: for basic blocks with the same reachability information, only select the basic block closest to the program entry for instrumentation.
[0037] Coverage instrumentation. Insert statements for statistical code coverage and path coverage into the basic blocks in the program, and collect coverage information during the testing process.
[0038] Further, step four includes:
[0039] Mutate the seeds to generate test cases and execute the program under test.
[0040] Since test cases that do not meet the preconditions cannot reach the target location, all test cases that do not meet the preconditions are terminated early according to the assertion statements inserted in step three.
[0041] Collect the reachability information and coverage information during the execution of the test cases, and add the test cases as new seeds to the seed pool.
[0042] Schedule the seeds according to the collected reachability information. Among them, calculate the score according to the reachability information of the seed execution, and allocate energy to the seeds accordingly. The method is as follows:
[0043]
[0044] Where #Target is the number of targets for single - time multi - target directed fuzz testing, and Num represents the number of targets that the seed can reach during execution; Num reflects the execution situation of the test case, which is calculated according to the reachability information of the execution path. The determination method is as follows:
[0045] Num = |S b ΛS all |
[0046] where S b represents the reachability information of basic blocks on the execution path and the execution situation feedback by the instrumentation code during the execution of the program under test, and S all represents the number of target reproductions still required currently.
[0047] According to the above two formulas, it can be implemented to assign a lower priority to the seeds reaching the reproduced target vulnerabilities and a higher priority to the seeds closer to the unreproduced target vulnerabilities;
[0048] Furthermore, the interval domain abstraction in step 2 is as follows:
[0049] In the precondition analysis, for the function α that converts a conditional expression into an interval domain, it is as follows:
[0050]
[0051] where Γ(v) represents the conditional expression of program variable v, represents the universal set, and ⊥ represents the empty set;
[0052] And the function β that converts an interval domain into a conditional expression is as follows:
[0053]
[0054] where Λ(v) represents the interval domain of program variable v, true represents the condition is true, and false represents the condition is false.
[0055] The seed scheduling strategy includes:
[0056] At the beginning of fuzz testing, a global set containing all target identifiers is generated, and this set represents all targets that need to be reproduced in this fuzz testing;
[0057] During the fuzz testing process, when a target vulnerability is triggered, the fuzzer synchronously collects the identifier of the vulnerability and removes the identifier from the global set, indicating that it no longer pays attention to this target vulnerability;
[0058] The smaller the Num of a test case, the closer it is to the target location, and it will be assigned a higher score when added to the seed pool;
[0059] In addition, for a test case with Num being 0, it means that it cannot reach any target location, so it is assigned a lowest score;
[0060] After a target is reproduced, the information in the global set is changed, which also affects the scores of some seeds.
[0061] The beneficial effects of this application include:
[0062] Through precondition pruning, the satisfiability of the target preconditions is used to reject a large number of test cases that cannot reach the target location, effectively solving the problem of infeasible path explosion in directed fuzz testing;
[0063] Instrumentation is performed at the program location where the program variables are first defined, ensuring that inputs that do not meet the preconditions do not execute for too long;
[0064] The relational expressions of variables in the program are deduced using interval arithmetic rules. Finally, only the interval domain of the program variables needs to be retained, making the final instrumented conditional expression a relational expression between program variables and constants. Compared with the relational expression between program variables and program variables, the former has less time overhead.
[0065] This method effectively ensures that test cases that do not satisfy this disjunctive formula cannot reach any target location by disjoining the preconditions of multiple targets to obtain a disjunctive formula;
[0066] Use a scheduling algorithm based on the simulated annealing algorithm to gradually allocate energy to seeds with higher scores during the fuzz testing process; during the fuzz testing process, through an adaptive scheduling mechanism that can be dynamically adjusted, less energy is allocated to seeds that reach a reproduced vulnerability, thereby achieving the purpose of distributing seeds more to the target vulnerability locations that have not been reproduced yet. BRIEF DESCRIPTION OF THE DRAWINGS
[0067] Figure 1 It is a flowchart of a multi-target directed fuzz testing method for verifying program vulnerabilities of the present invention;
[0068] Figure 2 It is a flowchart of static analysis of the present invention;
[0069] Figure 3 It is a flowchart of fuzz testing of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0070] To make the objectives, technical solutions, and advantages of this application clearer, the embodiments of this application will be described in further detail below in conjunction with the accompanying drawings.
[0071] First, the embodiments of this application will be introduced below in conjunction with the accompanying drawings.
[0072] In view of the current limitation that developers need to verify multiple potential vulnerabilities in a program, the present invention proposes a method for accelerating multi-target directed fuzz testing. By performing precondition analysis, preconditions for reaching the targets are analyzed for multiple targets in the program, and the inputs that cannot reach the target positions are pruned using these preconditions. In addition, the present invention disjuncts multiple preconditions to ensure that inputs that can reach one of the target positions are not wrongly pruned. On this basis, the present invention also uses an adaptive scheduling mechanism that can be dynamically adjusted. By observing the recurrence of the targets, the number of targets that need to be analyzed currently is recorded. At the same time, based on the reachability information obtained from static analysis, the execution situation of test cases is understood, and the reachability information of test case execution is used to calculate scores, which are finally added to the seed pool. In the test case generation stage, this method will prioritize the seeds according to the scores of the seeds and select the seed with the highest priority for mutation and generate test cases. It should be particularly emphasized that since the contribution value of the seeds is calculated from the reachability information and the target vulnerability set, and the target vulnerability set changes with the recurrence of the targets, this calculation method can effectively assign a smaller contribution value to the seeds close to a reproduced vulnerability, and thus assign a smaller priority to this type of seeds. To better understand the present invention, the content of the present invention will be further described below in conjunction with the accompanying drawings of the specification and embodiments.
[0073] Embodiment 1:
[0074] Step 1: Extract the error code lines from the vulnerability information report and regard their positions as the positions of the target vulnerabilities as the input of this method;
[0075] Step 2: Use a compiler to compile the target program into llvm IR, and then analyze the IR of the target program to obtain the preconditions and reachability information of the target set;
[0076] Step 3: Use the preconditions and reachability information to instrument the IR of the target program, and then compile the IR of the target program into an executable file.
[0077] Step 4: Execute the target program with a large number of random inputs.
[0078] According to the process described in Step 1, it is characterized by including:
[0079] Program error message collection module: responsible for collecting relevant information from the program's vulnerability information report and finding the line numbers of the code related to the program error;
[0080] Vulnerability location preprocessing module: regard the line number of the last line of the error message as the location of the vulnerability, and then add it to the targets of the directed fuzz testing for verification. This method can input the line numbers of multiple vulnerabilities at the same time;
[0081] According to the process described in Step 2, it is characterized in that it includes:
[0082] Compile the target program into intermediate code in the form of LLVM IR and retain debugging information, mainly including the source code line numbers corresponding to the instructions of the intermediate code;
[0083] The intermediate code in the form of LLVM IR is in static single assignment form, and its feature is that each variable in the program is defined only once for subsequent instrumentation operations;
[0084] Use a complete pointer analysis to parse function pointers on the intermediate code of the program and construct an inter-procedural control flow graph for the target program;
[0085] Determine the target instructions in the intermediate code and the basic blocks where the target instructions are located for the source code line numbers collected in Step 1 according to the debugging information of the program;
[0086] Perform reachability analysis on the inter-procedural control flow graph, and divide all basic blocks in the program into two categories: those that can reach the target basic block on the control flow graph; those that cannot reach any target basic block on the control flow graph.
[0087] While searching for the basic blocks where each target vulnerability is located, assign a different number to each basic block as a unique identifier,
[0088] Perform reachability analysis again based on the inter-procedural control flow graph to obtain the reachability information of the basic blocks, which is represented by a set of identifiers.
[0089] Traverse each target in reverse and add the identifier of the target to the reachability information set of each basic block traversed;
[0090] Traverse the program instructions in reverse from the target location and analyze the preconditions that the input needs to meet for each target to make the program execute to the target location;
[0091] The process of precondition analysis of the present invention is as follows:
[0092] (1) Traverse in reverse from the target location. When a branch statement is traversed, obtain the branch condition and obtain a conditional expression according to the satisfiability of the analysis condition;
[0093] (2) Analyze in reverse from the target location on the inter-procedural control flow graph, and transfer and deduce conditions between program variables according to program instructions and predicates;
[0094] (3) When the present invention deduces preconditions, it first converts the conditional expression into an interval domain representation according to the interval abstraction function, then calculates according to the interval operation rules, and finally converts the deduced interval domain into a conditional expression;
[0095] (4) During the precondition analysis process, the preconditions for multiple targets are saved separately, and when reverse-analyzing a program instruction, the preconditions for multiple targets are deduced simultaneously;
[0096] The present invention disjuncts the preconditions for multiple targets to ensure that the final precondition does not reject inputs that can reach any one of the targets;
[0097] According to the process described in Step 3, it is characterized by including:
[0098] Perform precondition instrumentation. Determine the program variables to be instrumented according to the preconditions analyzed in Step 2, and convert the interval domain of the program variables into a conditional expression;
[0099] Determine the code position where the program variables to be instrumented are first defined in the intermediate code in static single assignment form;
[0100] Use the conditional expression of the program variable as the condition of the assertion statement, and then insert the assertion statement after the program position where the program variable is first defined;
[0101] Perform reachability information instrumentation. Use the reachability information analyzed in Step 2 as the parameter of the program instruction for statistical execution information, and insert the statement into the corresponding basic block;
[0102] The principle for basic block reachability information instrumentation is as follows: for basic blocks with the same reachability information, only select the basic block closest to the program entry for instrumentation;
[0103] Coverage instrumentation. Insert statements for statistical code coverage and path coverage into the basic blocks in the program to collect coverage information during the testing process;
[0104] According to the process described in Step 4, it is characterized by including:
[0105] Mutate the seeds to generate test cases and execute the program under test;
[0106] Since test cases that do not meet the preconditions cannot reach the target position, all test cases that do not meet the preconditions are terminated early according to the assertion statements inserted in Step 3;
[0107] Collect the reachability information and coverage information during the execution process of the test cases, and add the test cases as new seeds to the seed pool;
[0108] Schedule the seeds according to the collected reachability information. Among them, calculate scores according to the reachability information of the seed execution, and allocate energy to the seeds accordingly. The formula is as follows:
[0109]
[0110] Where #Target is the number of targets for single - time multi - target directed fuzz testing, and Num represents the number of targets that the seed can reach during execution.
[0111] Num in the above formula reflects the execution situation of the test case, which is calculated from the reachability information of the execution path. The calculation formula is as follows:
[0112] Num = |S b ΛS all |
[0113] Where S b represents the reachability information of basic blocks on the execution path, which is the execution situation feedback by the instrumentation code during the execution of the program under test, and S all represents the number of targets that still need to be reproduced currently.
[0114] For the above - mentioned interval domain abstraction, it is characterized by including:
[0115] In the pre - condition analysis, the function α for converting a conditional expression to an interval domain is as follows:
[0116]
[0117] Where Γ(v) represents the conditional expression of program variable v, T represents the universal set, and ⊥ represents the empty set.
[0118] And the function β for converting an interval domain to a conditional expression is as follows:
[0119]
[0120] Where Λ(v) represents the interval domain of program variable v, true represents the condition is true, and false represents the condition is false.
[0121] According to the pre - condition pruning described above, the achieved effects include:
[0122] Using the satisfiability of the target pre - condition rejects a large number of test cases that cannot reach the target location, effectively solving the problem of infeasible path explosion in directed fuzz testing;
[0123] Test cases that do not satisfy the target pre - condition will definitely not be able to execute to the corresponding target location, and test cases that can reach the target location are selected through the satisfiability of the pre - condition;
[0124] Instrumentation is performed at the program location where the program variable is first defined, ensuring that inputs that do not satisfy the pre - condition do not execute for too long;
[0125] Use interval arithmetic rules to deduce the variable relationships in the program. Eventually, only the interval domains of the program variables need to be retained, which makes the final instrumentation condition expression a relational expression between program variables and constants. Compared with the relational expression between program variables and program variables, the former has less time overhead.
[0126] This method effectively ensures that test cases that do not satisfy this disjunctive formula cannot reach any target location by disjuncting the preconditions of multiple targets and obtaining a disjunctive formula;
[0127] According to the above-mentioned seed scheduling strategy, including:
[0128] At the beginning of fuzz testing, a global set containing the identifiers of all targets is generated. This set represents all the targets that need to be reproduced in this fuzz testing;
[0129] During the fuzz testing process, when a target vulnerability is triggered, the fuzzer synchronously collects the identifier of the vulnerability and removes the identifier from the global set, indicating that it no longer pays attention to this target vulnerability;
[0130] According to the above formula, the smaller the Num of the test cases, the closer these test cases are to the target location, and they will be assigned a higher score when added to the seed pool;
[0131] In addition, for test cases with Num being 0, it means that they cannot reach any target location, so a lowest score is assigned;
[0132] According to the above formula, when a target is reproduced, the information in the global set is changed, and it will also affect the scores of some seeds;
[0133] Use an adaptive scheduling algorithm based on the simulated annealing algorithm to gradually allocate energy to seeds with higher scores during the fuzz testing process;
[0134] During the fuzz testing process, through the above-mentioned dynamically adjustable adaptive scheduling mechanism, less energy is allocated to seeds that reach a vulnerability that has already been reproduced, so as to achieve the purpose of distributing more seeds at the target vulnerability locations that have not been reproduced yet;
[0135] The above-described embodiments of the present application do not constitute a limitation on the protection scope of the present application.
Claims
1. A multi-target directional fuzzy testing acceleration method based on dynamic and static pruning, characterized in that: The method comprises: Step 1: Extract the error code line from the vulnerability information report and take the code as the location of the target vulnerability as input; Step 2: Use the compiler to compile the target program into llvm IR, and then analyze the IR of the target program to obtain the preconditions and reachability information of the target set; Step 3: Use the precondition and reachability information to instrument the IR of the target program, and then compile the IR of the target program into an executable file; Step 4: Execute the target program with a large number of random inputs.
2. The method according to claim 1, characterized in that: Step 1 includes: The program error information collection module collects relevant information from the program's vulnerability information report and finds out the code line number related to the program error; The vulnerability location preprocessing module takes the last line of code in the error message as the location of the vulnerability, and then adds it to the target of the directed fuzz test for verification; it can input the code line numbers of multiple vulnerabilities at the same time.
3. The method according to claim 2, characterized in that Step 2 method includes: Compile the target program into intermediate code in the form of LLVM IR and retain debugging information; the debugging information includes the source code line number corresponding to the instruction of the intermediate code; The intermediate code in LLVM IR format is a static single assignment format, where each variable in the program is defined only once to facilitate subsequent instrumentation operations. Use a complete pointer analysis on the program's intermediate code to resolve function pointers and build an interprocedural control flow graph for the target program; Determine the target instruction in the intermediate code and the basic block where the target instruction is located according to the debugging information of the program; Perform reachability analysis on the inter-procedural control flow graph and divide all basic blocks in the program into two categories: the first category is the target basic block that can be reached on the control flow graph; the second category is the target basic block that cannot be reached on the control flow graph; While searching for the basic blocks where each target vulnerability is located, a different number is assigned to each basic block as a unique identifier; Reachability analysis is performed again based on the inter-procedural control flow graph to obtain the reachability information of the basic block, which is represented by a set of identifiers; Traverse each target in reverse order and add the target identifier to the reachability information set of each basic block traversed; Traverse the program instructions backward from the target position, and analyze the preconditions that need to be met for each target input to execute the program to the target position; The process of precondition analysis is: Step 21, traverse backward from the target position, obtain the branch condition when traversing to the branch statement, and obtain the conditional expression according to the satisfiability of the analysis condition; Step 22, reverse analysis is started from the target position on the inter-procedural control flow graph, and conditions are transferred and derived between program variables according to program instructions and predicate conversions; Step 23, when deriving the precondition, first convert the conditional expression into an interval domain representation according to the interval abstraction function, then perform calculation according to the interval operation rule, and finally convert the derived interval domain into a conditional expression; Step 24, during the precondition analysis process, the preconditions of multiple targets are saved separately, and when reverse analysis reaches a program instruction, multiple preconditions are derived simultaneously; Disjunct the preconditions of multiple targets; to ensure that the final precondition does not reject input that can reach any target.
4. The method according to claim 3, characterized in that: Step three includes: Perform precondition stubbing, determine the program variables to be stubbing according to the preconditions analyzed in step 2, and convert the interval domain of the program variables into a conditional expression; Determine the code position where the program variable to be inserted is first defined in the program on the intermediate code in the static single assignment form; Use the conditional expression of the program variable as the condition of the assert statement, and then insert the assert statement after the program variable is first defined in the program; Perform reachability information instrumentation, and write the reachability information analyzed in step 2 into the corresponding basic block as a parameter of the function of statistical execution information; The following principles are followed when selecting basic block reachability information stubs: for basic blocks with the same reachability information, only the basic block closest to the program entry is selected for stubs; Coverage instrumentation inserts statements for statistical code coverage and path coverage into basic blocks in the program, and collects coverage information during the test.
5. The method according to claim 4, characterized in that Step 4 includes: Mutate the seed to generate test cases and execute the program under test; Since the test cases that do not meet the preconditions cannot be executed to the target position, all the test cases that do not meet the preconditions are terminated early according to the assertion statements inserted in step 3; Collect the reachability and coverage information of the test case execution process, and add the test case as a new seed to the seed pool; The seeds are scheduled according to the collected reachability information; wherein the scores are calculated according to the reachability information of the seed execution, and energy is allocated to the seeds accordingly, as follows: Among them, #Target is the number of targets in a single multi-target directional fuzz test, Num represents the number of targets that the seed can reach during the execution process; Num reflects the execution status of the test case, which is calculated based on the reachability information of the execution path. The determination method is as follows: Num=|S b ΛS all | Where S b Represents the reachability information of the basic blocks on the execution path, and the execution status fed back by the instrumentation code during the execution of the tested program. all Indicates the number of targets that still need to be reproduced.
6. The method according to claim 3, characterized in that: The interval domain abstraction in step 2 is as follows: In precondition analysis, the function α for converting the conditional expression into the interval domain is as follows: Where Γ(v) represents the conditional expression of the program variable v, T represents the entire set, and ⊥ represents the empty set; The function β that converts the interval domain into a conditional expression is as follows: Among them, Λ(v) represents the interval domain of the program variable v, true means that the condition is true, and false means that the condition is false.
7. The method according to claim 5, characterized in that Seed scheduling strategies, including: At the beginning of the fuzz test, a global set of identifiers of all targets is generated. This set represents all the targets that need to be reproduced in this fuzz test. During the fuzz testing process, when a target vulnerability is triggered, the fuzzer synchronously collects the vulnerability identifier and removes the identifier from the global set, indicating that the target vulnerability is no longer of interest; The smaller the test case Num is, the closer it is to the target position, and the higher the score will be given when it is added to the seed pool; In addition, for test cases where Num is 0, it means that no target position can be reached, so a minimum score is assigned; When a target is reproduced, the information of the global set is changed, which will also affect the scores of some seeds.