Internet of Things system logic vulnerability mining system and method based on model learning
By building standard and abnormal business logic state machine for IoT systems and using TTT algorithms for differential analysis, the problem that existing technology cannot detect logical vulnerabilities in IoT systems is solved, and automated vulnerability detection and visual analysis are realized.
Patent Information
- Application Number
- CN202510225500.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-27
- Publication Date
- 2025-05-30
AI Technical Summary
The existing technology cannot detect memory-independent logic vulnerabilities in IoT systems, resulting in errors prone to design and implementing business logic, which may lead to serious consequences such as overprivileged access and information leakage.
Using a model-based learning method, a standard business logic state machine and an abnormal business logic state machine of the Internet of Things system is constructed, and a TTT algorithm is used to conduct state mechanism construction and differential analysis to automatically detect logical vulnerabilities.
It realizes relatively automated mining of business logic vulnerabilities in the Internet of Things system, supports business logic visualization, facilitates analysis and repair, and avoids complex binary analysis.
Smart Images

Figure CN120074924A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of Internet of Things systems, and particularly to an Internet of Things system logic vulnerability mining system and method. Background Art
[0002] With the rapid development of Internet of Things technology, more and more Internet of Things devices have emerged on the market. More and more research attempts to detect vulnerabilities existing in Internet of Things systems, which are divided into memory vulnerabilities and logical vulnerabilities. When existing technologies such as fuzz testing are used to mine vulnerabilities in Internet of Things systems, only memory vulnerabilities can be detected, such as device crashes caused by memory leaks. Some research is dedicated to mining vulnerabilities in Internet of Things device firmware, using fuzz testing methods to detect whether there are inputs that may cause the device to crash or exhibit abnormal behavior, such as Chinese invention patents CN118363854A, CN118153044A, CN117040854A, CN116743447A / CN116860598A, CN114328216A; some research uses static reverse analysis to assist in vulnerability mining, such as Chinese invention patents CN115525331A, CN116305152A; a small number of research is based on protocol state diagrams for vulnerability mining, such as Chinese invention patent CN106888209A.
[0003] However, the above-mentioned vulnerability mining work only mines memory vulnerabilities in Internet of Things device firmware and cannot detect logical vulnerabilities unrelated to memory. Some manufacturers are prone to errors when designing and implementing business logic, which may lead to serious consequences, such as unauthorized access (for example, including unauthorized control and failed permission revocation) and information leakage. Existing detection technologies for memory vulnerabilities cannot discover the above-mentioned logical vulnerabilities. The harm of these logical vulnerabilities is no less than that of memory vulnerabilities. There has been some research work in the academic community to detect logical vulnerabilities, but they are all based on manual detection, which is time-consuming and laborious, and the detection effect depends on manual experience.
[0004] The difficulties in detecting logical vulnerabilities are as follows: 1) There are various types of logical vulnerabilities and lack of a unified paradigm; 2) There are few logical vulnerability cases, and it is difficult to apply artificial intelligence technologies such as neural networks due to the lack of training samples; 3) The impact of logical vulnerabilities is difficult to monitor using methods similar to program crash detection, that is, there is a lack of effective monitoring means. Summary of the Invention
[0005] In view of the fact that the above-mentioned logical vulnerabilities cannot be detected by the prior art, the present invention proposes an Internet of Things system logic vulnerability mining system and method based on model learning, which uses the standard business logic state machine of the Internet of Things system constructed by model learning technology to perform logical fuzz testing on the system under test, so as to detect whether there are logical vulnerabilities in the system under test.
[0006] The present invention is implemented by the following technical solutions:
[0007] In a first aspect, an Internet of Things system logic vulnerability mining system based on model learning includes a manager, a learner, a mapper, and an Internet of Things system to be tested. Among them, the manager is responsible for performing logical analysis and processing on the Internet of Things manufacturer's companion application and calling the learner and the mapper; the learner is responsible for selecting a learning algorithm, generating an input symbol sequence, and constructing a standard business logic state machine and an abnormal business logic state machine using the TTT algorithm; the mapper consists of a repeater, an executor, and a listener. Among them, the repeater is responsible for receiving the input symbols from the learner, forwarding the input symbols to the executor, and sending the output symbols returned by the listener back to the learner; the executor is responsible for performing corresponding operations on the manufacturer's companion application in the Internet of Things system to be tested according to the received input symbols; the listener is responsible for monitoring the running state of the system to be tested, mapping the extracted core traffic clusters into output symbols, and feeding them back to the repeater; the Internet of Things system to be tested consists of an Internet of Things manufacturer's companion application to be tested, an Internet of Things manufacturer's cloud platform to be tested, and Internet of Things devices to be tested.
[0008] In some embodiments, the TTT algorithm further includes operations: managing the equivalence relationship between the constructed states in the finite state machine through a hierarchical tree structure, and locally adjusting the splitting and merging operations of the hierarchical tree according to the principle of dynamically maintaining the state equivalence class to achieve incremental state merging.
[0009] In some embodiments, when constructing a standard business logic state machine using the TTT algorithm, the TTT algorithm gradually infers the minimum deterministic finite automaton composed of the target input-output table through membership queries and equivalence queries. The input of the TTT algorithm is the input table and the output table, and the output is the finite state machine corresponding to the above input table and output table; the repeater receives the input symbols from the learner, forwards the input symbols to the executor, and sends the output symbols returned by the listener back to the learner; the executor performs corresponding operations on the Internet of Things manufacturer's companion application to be tested according to the received input symbols; the listener monitors the running state of the system to be tested, maps the extracted core traffic clusters into output symbols, and feeds them back to the repeater; the construction process of the standard business logic state machine performs the following operations: the learner interacts with the repeater by proposing input sequences, and the repeater determines whether the key operation sequences need to be optimized or executed.
[0010] In some embodiments, when constructing an abnormal service logic state machine using the TTT algorithm, a repeater determines whether a critical operation sequence needs to be optimized or executed. The basis for the repeater's determination is as follows: when the input sequence cannot bring new knowledge for the current state machine to learn, there is no need to execute; otherwise, the critical operation is forwarded to the executor, and the executor determines whether an abnormal data packet can be constructed, that is, if the current input sequence is consistent with the known operation sequence in the standard service logic state machine, the repeater directly uses the corresponding output sequence in the standard service logic state machine to reply to the learner; if the current input sequence causes an error state in the standard service logic state machine, the executor determines whether an abnormal data packet can be constructed. The basis for the executor's determination is as follows: if the critical operation that triggers the error state exists in the prefix of the current input sequence divided by this critical operation, an abnormal data packet is constructed using the selected abnormal data packet construction method and the control parameters obtained when executing this critical operation in the prefix, and is sent to the Internet of Things system under test. The core traffic cluster of the response of the system under test after executing this abnormal data packet is extracted and mapped to the entry in the output table; if the existing entry cannot be matched, a new entry is generated and the output table is updated; if the executor determines that an abnormal data packet cannot be constructed, the executor controls the listener to cause the abnormal service logic state machine to trigger an error state.
[0011] In some embodiments, the Internet of Things manufacturer companion application under test is responsible for controlling specific Internet of Things application operations, the Internet of Things manufacturer cloud platform under test is responsible for recording and forwarding specific Internet of Things application operations, and the Internet of Things device under test is responsible for executing specific Internet of Things application operations.
[0012] In a second aspect, a method for mining logic vulnerabilities in an Internet of Things system based on model learning includes:
[0013] Using a manager, based on the analysis of the business logic of the Internet of Things manufacturer, obtain the critical operations related to the Internet of Things manufacturer companion application, and construct an input table; read the input table, execute the critical operations in the input table multiple times in a man-in-the-middle environment, collect the network traffic generated when each critical operation is executed, and construct a traffic cluster; filter the noise traffic and extract the core traffic cluster from the traffic cluster, and construct an output table;
[0014] Using a manager to call a learner, and based on the input table and output table, construct a standard service logic state machine using the TTT algorithm;
[0015] Using a manager to perform reverse analysis on the implementation logic of the Internet of Things manufacturer companion application, obtain the implementation method of the business logic of the Internet of Things manufacturer companion application, so as to construct an abnormal data packet for critical operations;
[0016] The manager is used again to call the learner, and based on the input table, the output table, the standard business logic state machine, and the construction method of the abnormal data packet, the TTT algorithm is used to construct an abnormal business logic state machine;
[0017] Perform a difference analysis between the standard business logic state machine and the abnormal business logic state machine to detect logical vulnerabilities in the IoT system under test.
[0018] In some embodiments, the TTT algorithm further includes managing the equivalence relationship between the constructed states in the finite state machine through a hierarchical tree structure, and locally adjusting the split and merge operations of the hierarchical tree according to the principle of dynamically maintaining the state equivalence class to achieve incremental state merging.
[0019] In some embodiments, when constructing the standard business logic state machine using the TTT algorithm, the TTT algorithm gradually infers the minimum deterministic finite automaton composed of the target input-output table through membership queries and equivalence queries. The input of the TTT algorithm is the input table and the output table, and the output is the finite state machine corresponding to the above input table and output table; receive the input symbol of the learner through the repeater, forward the input symbol to the actuator, and send the output symbol returned by the listener back to the learner; the actuator performs corresponding operations on the IoT manufacturer companion application under test according to the received input symbol; the listener monitors the running state of the system under test, maps the extracted core traffic clusters to output symbols, and feeds them back to the repeater; the construction process of the standard business logic state machine performs the following operations: the learner interacts with the repeater by proposing key operation sequences, and the repeater determines whether the key operation sequences need to be optimized or executed.
[0020] In some embodiments, when constructing the abnormal service logic state machine using the TTT algorithm, the repeater determines whether the critical operation sequence needs to be optimized or executed. The basis for the repeater's determination is as follows: when the input sequence cannot bring new knowledge to the current state machine for learning, there is no need to execute; otherwise, the critical operation is forwarded to the executor, and the executor determines whether an abnormal data packet can be constructed: that is, if the current input sequence is consistent with the known operation sequence in the standard service logic state machine, the repeater directly uses the corresponding output sequence in the standard service logic state machine to reply to the learner; if the current input sequence causes an error state in the standard service logic state machine, it is determined by the executor whether an abnormal data packet can be constructed. The basis for the executor's determination is as follows: if the critical operation that triggers the error state exists in the prefix of the current input sequence divided by this critical operation, an abnormal data packet is constructed using the selected abnormal data packet construction method and the control parameters obtained when executing this critical operation in the prefix, and is sent to the Internet of Things system under test. The core traffic cluster of the response of the system under test after executing this abnormal data packet is extracted and mapped to the entry in the output table; if the existing entry cannot be matched, a new entry is generated and the output table is updated; if the executor determines that the abnormal data packet cannot be constructed, the executor controls the listener to cause the abnormal service logic state machine to trigger an error state.
[0021] In some embodiments, the abnormal data packet communicates with the cloud platform of the Internet of Things manufacturer under test or the Internet of Things device under test.
[0022] Compared with the prior art, the present invention has the following remarkable advantages:
[0023] 1. It can relatively automatically detect the business logic vulnerabilities of the Internet of Things system based on the difference comparison between the standard service logic state machine and the abnormal service logic state machine;
[0024] 2. It supports business logic visualization, thus facilitating analysts to understand the error location and cause and perform targeted repairs;
[0025] 3. There is no need to obtain and analyze the Internet of Things firmware, avoiding complex binary analysis. BRIEF DESCRIPTION OF THE DRAWINGS
[0026] Figure 1 It is the framework diagram of the Internet of Things system logic vulnerability detection system based on model learning of the present invention;
[0027] Figure 2 It is the overall flowchart of the method for detecting the logic vulnerability of the Internet of Things system based on model learning of the present invention;
[0028] Figure 3 It is the execution process diagram of the method for detecting the logic vulnerability of the Internet of Things system based on model learning of the present invention;
[0029] Figure 4 It is an engineering architecture of a logic vulnerability mining tool for an Internet of Things system based on model learning. Specific implementation manners
[0030] The present invention will be further described in detail below with reference to the accompanying drawings. It should be understood that the specific implementation manners described herein are only used to explain the present invention and are not used to limit the present invention.
[0031] As Figure 1 shown, the logic vulnerability mining system of the Internet of Things system based on model learning of the present invention is divided into four parts: a manager, a learner, a mapper, and an Internet of Things system to be tested. Among them, the manager is responsible for logical analysis and processing, and for calling the learner and the mapper. The learner is responsible for selecting a learning algorithm, generating an input symbol sequence, and constructing a state machine. The mapper is composed of a repeater, an executor, and a listener; the repeater is responsible for receiving the input symbols of the learner, judging whether optimization or execution is required, forwarding the input symbols that need to be executed to the executor, and sending the output symbols returned by the listener back to the learner; the executor is responsible for performing corresponding operations on the Internet of Things manufacturer's companion application to be tested according to the received input symbols; the listener is responsible for monitoring the running state of the system to be tested, mapping the extracted core traffic clusters into output symbols, and feeding them back to the repeater. The Internet of Things system to be tested is composed of an Internet of Things manufacturer's companion application to be tested, an Internet of Things manufacturer's cloud platform to be tested, and an Internet of Things device to be tested; among them, the Internet of Things manufacturer's companion application to be tested is an official application provided by the Internet of Things manufacturer for controlling the Internet of Things device, responsible for controlling specific Internet of Things application operations, the Internet of Things manufacturer's cloud platform to be tested is responsible for recording and forwarding specific Internet of Things application operations, the Internet of Things device to be tested is responsible for executing specific Internet of Things application operations, and the Internet of Things manufacturer's cloud platform to be tested and the Internet of Things device to be tested constitute the core detection objects of the entire framework.
[0032] As Figure 2 、 Figure 3 and Figure 4 shown, the specific content of the logic vulnerability mining method process of the Internet of Things system based on model learning of the present invention is as follows:
[0033] Step S1: Use the manager to perform business logic analysis on the Internet of Things manufacturer's companion application, obtain the key operations related to the Internet of Things manufacturer's companion application, and construct an input table; the input table specifically includes key operations such as operations provided by the manufacturer to the user regarding devices, permissions, etc., such as adding devices, device control, device sharing, inviting users into the home, etc., and each key operation is used as an entry in the input table;
[0034] Step S2: Use the manager to read the input table in step S1, execute the key operations in the input table multiple times in the man-in-the-middle environment, and collect the normal Internet of Things manufacturer business logic traffic clusters; the man-in-the-middle environment is as Figure 4 shown. This man-in-the-middle environment is built using Mitmproxy. Specifically, by using the Mitmproxy tool, an environment that can decrypt the manufacturer's TLS encrypted communication is built, so that the communication traffic is presented in plain text, facilitating subsequent classification and analysis. In this man-in-the-middle environment, simulate and execute key operations multiple times, such as the operation process of "adding a device - controlling a device - device sharing - the shared user agreeing to share - the shared user controlling the device - revocation of sharing permissions - deleting the device", etc. At the same time, use tools such as Wireshark to capture the complete traffic clusters of the companion application during the operation process. The traffic clusters include all network communication data sets generated when the key operations are executed;
[0035] Step S3: Use the manager to filter the noise traffic and extract the core traffic clusters from the traffic clusters in step S2, and build an output table; during the operation of the Internet of Things manufacturer companion application, noise traffic unrelated to key operations may be generated, such as advertisement loading, picture resource requests, background services, etc. These traffic not only do not help the key operation analysis, but will interfere with the analysis process and reduce efficiency. Therefore, it is necessary to clean and filter the traffic data. Specifically, first filter out the irrelevant traffic: that is, eliminate the traffic that appears more than 60% in multiple key operations. The high-frequency occurrence of such traffic indicates that it has nothing to do with the specific operation type and has no reference value for analysis; secondly, extract the relevant traffic: that is, retain the traffic that appears more than 80% in multiple executions of a certain key operation, and regard it as the specific traffic of this operation. Such traffic has a high degree of relevance and is the core data for analysis. After the above processing, the finally obtained core traffic clusters will be used as the basis for building the output table. The table entries of the output table are generated by extracting and splicing the key information of the data packets in the core traffic clusters. Specifically, the output table data includes the destination domain name, used protocol, destination port, protocol header fields (such as request method, domain field in the HTTP protocol, topic, header flag field in the MQTT protocol) and the payload part extracted from each data packet, and these information are spliced into a complete string in plain text to form the table entries in the output table;
[0036] Step S4: Invoke the learner using the manager, and based on the input table constructed in step S1 and the output table constructed in step S3, construct a standard business logic state machine using the latest model learning algorithm - the TTT algorithm. The TTT algorithm is an algorithm for finite state automaton learning that gradually infers the minimum deterministic finite automaton composed of the target input-output table through membership queries and equivalence queries. That is, the input of the TTT algorithm is the input table and the output table, and the output is the finite state machine corresponding to the above two tables. At the same time, this algorithm solves the bottlenecks in query efficiency and memory occupancy of previous learning algorithms through a hierarchical tree structure and an incremental state merging mechanism. The hierarchical tree structure is a classification tree with a three-layer tree structure, which is used to manage the equivalence relationship between the states already constructed in the state machine. The incremental state merging is based on the principle of dynamically maintaining state equivalence classes, and only locally adjusts the split and merge operations of the hierarchical tree when a new counterexample or suffix is triggered, avoiding global reconstruction of the observation table. Among them, the counterexample is a key operation sequence whose corresponding output sequence is inconsistent with the learned non-complete state machine. Specifically, the construction process of the standard business logic state machine performs the following operations: The learner sends a query request (i.e., an input sequence) to the repeater, and the repeater determines whether the input sequence needs to be optimized or executed. The query request is the union of the above membership queries and equivalence queries. The judgment basis of the repeater is: when the input sequence cannot bring new knowledge to the current state machine learning, there is no need to execute. In the state machine, "unable to generate new knowledge" means that the current input sequence has been learned but appears repeatedly or will enter an "error state". The "error state" is a special state, indicating that the input sequence cannot be executed normally in the current context. For example, when the corresponding operation button for a key operation does not exist, a special output symbol "N / A" will be generated. In this case, all subsequent operations in the sequence will output "N / A" and trigger the state machine to enter the "error state". For example, when the operation sequence generated by the learner is: "Invite user 2 to enter the home → User 1 controls the device → User 1 adds a device → User 2 agrees to enter the home", if when executing to "User 1 controls the device", since user 1 has no controllable devices at present, the output symbol of this key operation is "N / A", and all subsequent operations will also output "N / A", that is, the generated output sequence is: "Invitation successful - N / A - N / A - N / A". When a key operation needs to be executed, the executor controls the system under test to complete the specific operation (such as "Invite user 2 to enter the home"), and the monitor collects the traffic cluster and extracts the output table characters. The input sequence refers to the sequence composed of batch inputs of table items selected from the input table received by the repeater. The output sequence refers to the sequence of output symbols extracted by the listener after each input symbol in the input sequence is executed on the system under test.This process continues to iterate until the algorithm of the learner converges or reaches the preset upper limit of the learning time; combine the business logic and the logic that generates errors. These logics are spliced in one piece or multiple pieces and jointly construct a standard business logic state machine;
[0037] Step S5: Use the manager to perform reverse analysis on the business implementation logic of the Internet of Things manufacturer companion application, and write Hook code based on the business logic analysis results to construct abnormal data packets for key operations; specifically, each key operation of the Internet of Things manufacturer companion application will ultimately generate a data packet and send it to the target Internet of Things manufacturer cloud platform or Internet of Things device. To ensure that the format and encryption method of the constructed data packet meet the specification requirements of the Internet of Things manufacturer, the present invention uses reverse analysis technology to analyze the business implementation logic of the companion application, and writes an abnormal API call script through Hook technology to call the function used to construct the data packet in the Internet of Things manufacturer application, and uses this function to generate an abnormal data packet that meets the specification and communicate with the Internet of Things manufacturer platform or Internet of Things device to be tested, so as to support further analysis and verification; reverse analysis refers to restoring the application program to code and analyzing and understanding the running logic or execution process of the program from the perspective of the code;
[0038] Specifically, the specific process of constructing abnormal data packets through these two methods of abnormal API calls or data packet editing includes: 1) Writing abnormal API calls is one of the methods for constructing abnormal data packets, that is, using the function obtained through reverse analysis in the Internet of Things manufacturer companion application for constructing data packets; 2) For cases where abnormal API calls are not applicable or difficult to implement, directly create the corresponding abnormal key operation data packets. That is, the purpose of both is to construct abnormal data packets, and they only differ in the construction methods;
[0039] The purpose of reverse analysis is to analyze the implementation method of the business logic in the companion application, and then select the above method to construct the traffic packet in the business logic. Which method to choose can vary from person to person;
[0040] S6. Based on the input table constructed in step S1, the output table constructed in step S3, the standard business logic state machine constructed in step S4, and the abnormal data packet construction method selected in step S5, use the TTT algorithm to construct an abnormal business logic state machine; the standard business logic state machine exists as a guide in this process to optimize the construction efficiency of the abnormal business logic state machine. Specifically: when using the TTT algorithm to construct the abnormal business logic state machine, the repeater determines whether the critical operation sequence needs to be optimized or executed. The basis for the repeater's judgment is: when the input sequence cannot bring new knowledge to the current state machine for learning, there is no need to execute. Specifically, in this step, when the critical operation that causes the error state is the critical operation performed by User 1, then "no new knowledge can be generated"; conversely, if it is the critical operation performed by User 2, then the critical operation performed by User 2 needs to be forwarded to the executor, and the executor determines whether an abnormal data packet can be constructed. That is, if the current input sequence is the same as the known operation sequence in the standard business logic state machine, the repeater directly uses the corresponding output sequence in the standard business logic state machine to reply to the learner, avoiding redundant interactions and improving efficiency; if the current input sequence causes an "error state" in the standard business logic state machine, and the critical operation that triggers the "error state" is performed by User 2, then the executor determines whether an abnormal data packet can be constructed. The basis for the executor's judgment is: if the critical operation that triggers the "error state" exists in the prefix of the current input sequence divided by this critical operation, that is, this critical operation has been executed at least once in this query request, then try to use the abnormal data packet construction method selected in step S5 and the control parameters obtained when executing this critical operation in the prefix to construct an abnormal data packet and send it to the IoT system under test, extract the core traffic cluster of the response of the system under test after executing this abnormal data packet and map it to the entry in the output table; if no existing entry can be matched, then generate a new entry and update the output table; if the executor determines that the abnormal data packet cannot be constructed, the executor controls the listener to return "N / A", thereby causing the abnormal business logic state machine to trigger an "error state".
[0041] S7. Conduct a difference analysis between the standard business logic state machine and the abnormal business logic state machine to detect logical vulnerabilities; specifically, by comparing the standard business logic state machine and the abnormal business logic state machine, observe whether there are abnormal state transitions in the abnormal business logic state machine that are not defined in the standard business logic state machine. If an abnormal state transition is found, there may be a logical vulnerability and further manual analysis is required. These vulnerabilities may include, but are not limited to: unauthorized control, failed permission revocation, information leakage, and other issues.
[0042] In summary, the present invention uses model learning technology to detect whether there are logical vulnerabilities in the Internet of Things system. First, the key operations of the business logic in the system are analyzed to construct the input table required for model learning. Then, in the man-in-the-middle environment, the traffic clusters generated during normal operations are collected to construct a traffic database to build part of the output table required for model learning. Next, the model learning technology is used to construct the standard business logic state machine of the Internet of Things system, and based on this standard business logic state machine, a logic fuzz test is performed on the system under test to construct an abnormal business logic state machine that may have logical errors. Finally, a difference analysis is performed on the two state machines to detect whether there are logical vulnerabilities in the system under test.
[0043] As Figure 4 shown, the engineering architecture of the present invention consists of four mobile phones, two WiFi hotspots, a power supply socket, and several Internet of Things devices under test. Among them, all four mobile phones are installed with the companion applications of the devices under test, two for user 1 and two for user 2, which are respectively connected to the two WiFi hotspots to simulate the scenarios of home WiFi and remote public WiFi. To achieve plaintext traffic analysis, the two WiFi hotspots forward the TLS traffic to the Mitmproxy man-in-the-middle environment through Iptables for decryption and encryption operations. The power supply socket is used to automatically control the power supply and power off of the Internet of Things devices under test, preventing the devices from entering the standby mode due to being in the waiting-to-pair state for a long time, reducing manual intervention and improving the experimental efficiency.
[0044] It should be noted that the above content is only an embodiment of the present invention. Although the present invention has been shown and described with reference to specific exemplary embodiments of the present invention, its purpose is not to limit the systems and methods proposed by the present invention. The protection scope of the present invention is subject to the claims. However, those skilled in the art should understand that the present invention is not limited to the above embodiments. Any changes to the present invention fall within the protection scope of the present invention application. Those skilled in the art should make various obvious modifications or changes to its form and details without departing from the scope and spirit of the present invention, and such modifications or changes should fall within the protection scope of the present invention.
Claims
1. A logical vulnerability mining system for the Internet of Things system based on model learning, characterized in that: It includes a manager, a learner, a mapper and an IoT system to be tested, wherein the manager is responsible for performing logic analysis and processing on the IoT vendor companion application and calling the learner and the mapper; the learner is responsible for selecting a learning algorithm, generating an input symbol sequence and using the TTT algorithm to construct a standard business logic state machine and an abnormal business logic state machine; the mapper is composed of a repeater, an executor and a listener; wherein the repeater is responsible for receiving the input symbols of the learner and determining whether optimization or execution is required, forwarding the input symbols to be executed to the executor, and sending the output symbols returned by the listener back to the learner; the executor is responsible for performing corresponding operations on the vendor companion application in the IoT system to be tested according to the received input symbols; the listener is responsible for monitoring the operating status of the system to be tested, mapping the extracted core traffic clusters into output symbols, and feeding them back to the repeater; the IoT system to be tested is composed of an IoT vendor companion application to be tested, an IoT vendor cloud platform to be tested and an IoT device to be tested.
2. According to the model learning-based Internet of Things system logic vulnerability mining system according to claim 1, it is characterized in that: The TTT algorithm further includes operations: managing the equivalence relationship between states constructed in the finite state machine through a hierarchical tree structure, and locally adjusting the splitting and merging operations of the hierarchical tree based on the principle of dynamically maintaining state equivalence classes to achieve incremental state merging.
3. According to the model learning-based Internet of Things system logic vulnerability mining system according to claim 1, it is characterized in that: in, When the TTT algorithm is used to construct a standard business logic state machine, the TTT algorithm gradually infers the minimum deterministic finite automaton composed of the target input and output tables through member queries and equivalence queries. The input of the TTT algorithm is the input table and the output table, and the output is the finite state machine corresponding to the above input table and the output table; the input symbol of the learner is received through the repeater, the input symbol is forwarded to the executor, and the output symbol returned by the listener is sent back to the learner; the executor performs corresponding operations on the companion application of the IoT manufacturer to be tested according to the received input symbol; the listener monitors the operating status of the system to be tested, maps the extracted core traffic clusters into output symbols, and feeds them back to the repeater; The construction process of the standard business logic state machine performs the following operations: the learner interacts with the repeater by proposing key operation sequences, and the repeater determines whether the key operation sequences need to be optimized or executed.
4. According to the model learning-based Internet of Things system logic vulnerability mining system according to claim 1, it is characterized in that: in, When the TTT algorithm is used to construct an abnormal business logic state machine, the repeater determines whether the key operation sequence needs to be optimized or executed. The repeater's judgment basis is: when the input sequence cannot bring new knowledge to the current state machine learning, there is no need to execute; otherwise, the key operation is forwarded to the executor, and the executor determines whether the abnormal data packet can be constructed; that is, if the current input sequence is consistent with the known operation sequence in the standard business logic state machine, the repeater directly uses the corresponding output sequence in the standard business logic state machine to reply to the learner; if the current input sequence causes an error state in the standard business logic state machine, the executor determines whether the abnormal data packet can be constructed; the executor's judgment basis is: if the key operation that triggers the error state has the same key operation in the prefix divided by the key operation in the current input sequence, then the selected abnormal data packet construction method and the control parameters obtained when executing the key operation in the prefix are used to construct the abnormal data packet and send it to the Internet of Things system to be tested, extract the core traffic cluster responded by the system to be tested after the execution of the abnormal data packet and map it to the table item in the output table; if the existing table item cannot be matched, a new table item is generated and the output table is updated; If the executor determines that the abnormal data packet cannot be constructed, the executor controls the listener to cause the abnormal business logic state machine to trigger an error state.
5. According to the model learning-based IoT application logic vulnerability mining system of claim 1, it is characterized in that: The IoT vendor companion application to be tested is responsible for controlling specific IoT application operations, the IoT vendor cloud platform to be tested is responsible for recording and forwarding specific IoT application operations, and the IoT device to be tested is responsible for executing specific IoT application operations.
6. A method for mining logical vulnerabilities in an Internet of Things system based on model learning, characterized in that: include: The manager is used to analyze the business logic of the IoT manufacturer, obtain the key operations related to the IoT manufacturer's companion application, and construct an input table; Read the input table, execute key operations in the input table multiple times in a middleman environment, collect network traffic generated when each key operation is executed, and construct a traffic cluster; Perform noise traffic filtering and core traffic cluster extraction on the traffic cluster to construct an output table; Using the manager to call the learner, based on the input table and the output table, using the TTT algorithm to build a standard business logic state machine; Use the manager to reverse analyze the implementation logic of the IoT vendor's companion application, obtain the implementation method of the IoT vendor's companion application business logic, and construct abnormal data packets for key operations; The manager is used again to call the learner, and based on the input table, the output table, the standard business logic state machine and the abnormal data packet construction method, the abnormal business logic state machine is constructed using the TTT algorithm; Perform difference analysis between standard business logic state machine and abnormal business logic state machine to detect logical vulnerabilities of the IoT system under test.
7. The method for mining logical vulnerabilities in an Internet of Things system based on model learning according to claim 6 is characterized in that: The TTT algorithm further includes managing the equivalence relationship between states constructed in the finite state machine through a hierarchical tree structure, and locally adjusting the splitting and merging operations of the hierarchical tree based on the principle of dynamically maintaining state equivalence classes to achieve incremental state merging.
8. The method for mining logical vulnerabilities in an Internet of Things system based on model learning according to claim 6, characterized in that: in, When the TTT algorithm is used to construct a standard business logic state machine, the TTT algorithm gradually infers the minimum deterministic finite automaton composed of the target input and output tables through member queries and equivalence queries. The input of the TTT algorithm is the input table and the output table, and the output is the finite state machine corresponding to the above input table and the output table; the input symbol of the learner is received through the repeater, the input symbol is forwarded to the executor, and the output symbol returned by the listener is sent back to the learner; the executor performs corresponding operations on the companion application of the IoT manufacturer to be tested according to the received input symbol; the listener monitors the operating status of the system to be tested, maps the extracted core traffic clusters into output symbols, and feeds them back to the repeater; The construction process of the standard business logic state machine performs the following operations: the learner interacts with the repeater by proposing key operation sequences, and the repeater determines whether the key operation sequences need to be optimized or executed.
9. The method for mining logical vulnerabilities in an Internet of Things system based on model learning according to claim 6, characterized in that: in, When the TTT algorithm is used to construct an abnormal business logic state machine, the repeater determines whether the key operation sequence needs to be optimized or executed. The repeater's judgment basis is: when the input sequence cannot bring new knowledge to the current state machine learning, there is no need to execute; otherwise, the key operation is forwarded to the executor, and the executor determines whether the abnormal data packet can be constructed; that is, if the current input sequence is consistent with the known operation sequence in the standard business logic state machine, the repeater directly uses the corresponding output sequence in the standard business logic state machine to reply to the learner; if the current input sequence causes an error state in the standard business logic state machine, the executor determines whether the abnormal data packet can be constructed; the executor's judgment basis is: if the key operation that triggers the error state has the same key operation in the prefix divided by the key operation in the current input sequence, then the selected abnormal data packet construction method and the control parameters obtained when executing the key operation in the prefix are used to construct the abnormal data packet and send it to the Internet of Things system to be tested, extract the core traffic cluster responded by the system to be tested after the execution of the abnormal data packet and map it to the table item in the output table; if the existing table item cannot be matched, a new table item is generated and the output table is updated; If the executor determines that the abnormal data packet cannot be constructed, the executor controls the listener to cause the abnormal business logic state machine to trigger an error state.
10. The method for mining logical vulnerabilities in an Internet of Things system based on model learning according to claim 6, characterized in that: The abnormal data packet communicates with the cloud platform of the IoT manufacturer under test or the IoT device under test.
Citation Information
Patent Citations
Industrial control vulnerability mining method based on protocol state diagram depth traversal
CN106888209A
Vulnerability mining method and device
CN114328216A
Reverse analysis method for intelligent terminal firmware of power grid sensing layer
CN115525331A
Internet of Things equipment stack overflow vulnerability mining and utilizing method based on reverse analysis
CN116305152A
Fuzzy test-based power Internet of Things equipment vulnerability mining method and system
CN116743447A
Cited By
Intelligent detection method for business logic vulnerabilities
CN120744930A