Distributed kernel vulnerability mining method and device, storage medium and server
Through the distributed kernel vulnerability mining method, multiple servers are used to jointly handle kernel vulnerability testing tasks, solving the problems of extended test cycles and low vulnerability mining efficiency in the existing technology, and achieving more efficient kernel vulnerability detection.
Patent Information
- Application Number
- CN202510174639.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-17
- Publication Date
- 2025-06-06
AI Technical Summary
When existing kernel vulnerability mining tools face complex and large-scale kernels, the test cycle is extended, the vulnerability mining efficiency is reduced, making it difficult to adapt to large-scale testing needs.
Using the distributed kernel vulnerability mining method, the first server responds to the vulnerability mining request, creates test tasks and allocates test resources, determines and transmits task resources to multiple second servers, creates a virtual machine and executes test corpus, and receives and analyzes test results.
Through distributed processing, the overall test computing power can be improved, more test tasks can be handled at the same time, speeding up the kernel vulnerability mining and shortening the test cycle.
Smart Images

Figure CN120104488A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of computer technology, and in particular to a method, device, storage medium and server for distributed kernel vulnerability mining. Background Art
[0002] Computer devices all run operating system kernels, which support the functions of computer devices and the execution of applications. Due to the characteristics of modern programming languages, some memory safety issues are inevitably faced in the process of using programming languages to build kernels. Some common kernel vulnerability mining tools can automatically input various parameters and data into the kernel and monitor the running status of the kernel, so as to obtain code coverage path information and capture the first-hand information of vulnerability triggering, which helps to discover vulnerabilities hidden in complex code paths. However, with the continuous development of technology, the complexity and scale of kernels are also increasing, which has extended the test cycle of existing mining tools, reduced the efficiency of vulnerability mining, and made it difficult to adapt to large-scale testing needs. Summary of the invention
[0003] The present application provides a distributed kernel vulnerability mining method, device, storage medium and server to solve the above-mentioned problems of extended test cycle and reduced vulnerability mining efficiency.
[0004] In a first aspect, an embodiment of the present application provides a distributed kernel vulnerability mining method, which is applied to a first server, and the method includes:
[0005] In response to a vulnerability mining request for a target kernel, a test task is created according to test information corresponding to the vulnerability mining request, a test resource is allocated to the test task, and task resources corresponding to the test task are obtained;
[0006] Determine multiple second servers corresponding to the test tasks according to the test resources, and transmit the task resources to the corresponding second servers respectively;
[0007] A virtual machine corresponding to the target kernel is created on each second server, the virtual machine in each second server is instructed to execute the test corpus sent by the first server, and the test results returned by each virtual machine are received.
[0008] In a second aspect, an embodiment of the present application provides a distributed kernel vulnerability mining device, which is applied to a first server, and the device includes:
[0009] A resource configuration module, for responding to a vulnerability mining request for a target kernel, creating a test task according to the test information corresponding to the vulnerability mining request, allocating test resources to the test task, and obtaining task resources corresponding to the test task;
[0010] A resource transmission module, used to determine multiple second servers corresponding to the test tasks according to the test resources, and transmit the task resources to the corresponding second servers respectively;
[0011] The task execution module is used to create a virtual machine corresponding to the target kernel on each second server, instruct the virtual machine in each second server to execute the test corpus sent by the first server, and receive the test results returned by each virtual machine.
[0012] In a third aspect, an embodiment of the present application provides a computer storage medium, wherein the computer storage medium stores a plurality of instructions, and the instructions are suitable for being loaded by a processor and executing the steps of the method.
[0013] In a fourth aspect, an embodiment of the present application provides a server, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the computer program is suitable for being loaded by the processor and executing the steps of the method.
[0014] The beneficial effects brought about by the technical solutions provided by some embodiments of the present application include at least:
[0015] The present application provides a distributed kernel vulnerability mining method, which is applied to a first server, responds to a vulnerability mining request for a target kernel, creates a test task according to test information corresponding to the vulnerability mining request, allocates test resources to the test task, and obtains task resources corresponding to the test task; determines multiple second servers corresponding to the test task according to the test resources, and transmits the task resources to the corresponding second servers respectively; creates a virtual machine corresponding to the target kernel on each second server, instructs the virtual machine in each second server to execute the test corpus sent by the first server, and receives the test results returned by each virtual machine. When a vulnerability mining request for the target kernel is triggered, the test resources required for executing the vulnerability mining can be configured according to the test information corresponding to the request, and the task resources corresponding to the test task can be obtained. This step can allocate the test resources according to the actual performance of each second server, so that the second server used to perform the test is more efficiently utilized; then, multiple second servers running the test task are determined according to the test resources, and the task resources corresponding to the test task are transmitted to the corresponding second servers respectively, which can ensure that the task resources are reasonably and accurately allocated to each second server, and prepare for the subsequent second servers to execute the test tasks respectively; the next step is to create a virtual machine corresponding to the target kernel on each second server, execute the received test corpus through each virtual machine, and receive the test results after execution, so as to judge the existence of vulnerabilities in the target kernel according to the test results. The embodiment of the present application improves the overall test computing power by unifying the test tasks of kernel vulnerability mining and executing them in a distributed manner in each second server, and can process more test tasks at the same time, thereby speeding up the kernel vulnerability mining. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For those skilled in the art, other drawings can be obtained based on these drawings without paying any creative work.
[0017] Figure 1 An exemplary system architecture diagram of a distributed kernel vulnerability mining method provided in an embodiment of the present application;
[0018] Figure 2 A schematic diagram of a process flow of a distributed kernel vulnerability mining method provided in an embodiment of the present application;
[0019] Figure 3 A schematic diagram of a process flow of a distributed kernel vulnerability mining method provided in an embodiment of the present application;
[0020] Figure 4 A structural diagram of a distributed kernel vulnerability mining method provided in an embodiment of the present application;
[0021] Figure 5 A schematic diagram of a process flow of a distributed kernel vulnerability mining method provided in an embodiment of the present application;
[0022] Figure 6 A structural block diagram of a distributed kernel vulnerability mining device provided in an embodiment of the present application;
[0023] Figure 7 A schematic diagram of the structure of a server provided in an embodiment of the present application. DETAILED DESCRIPTION
[0024] In order to make the features and advantages of the present application more obvious and easy to understand, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative work are within the scope of protection of the present application.
[0025] When the following description refers to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present application. Instead, they are only examples of devices and methods consistent with some aspects of the present application as detailed in the attached claims.
[0026] In the field of modern computer science, the operating system kernel is the cornerstone of computer equipment operation, and the stability and security of the kernel are crucial to the normal operation of computer equipment. As the basic tool for kernel development, the characteristics of programming language directly affect the security of the kernel. Since modern programming languages (such as C language, C++, etc.) provide powerful functions and flexibility, they are also accompanied by some inherent defects. Therefore, in the process of building the kernel, we will inevitably face some memory safety issues. For example, the Linux kernel is built by C language, and there will be memory safety issues such as Use-After-Free (UAF) and Out-Of-Bound (OOB). This will cause users with ordinary permissions to trigger vulnerabilities in the Linux kernel through the system call interface, thereby elevating privileges to root privileges, and even having the ability to execute arbitrary code in the kernel. At present, some common kernel vulnerability mining tools can automatically input various parameters and data into the kernel and monitor the running status of the kernel, so as to obtain code coverage path information and capture the first-hand information of vulnerability triggering, which helps to discover vulnerabilities hidden in complex code paths. For example, for Linux kernel vulnerability issues, you can use the syzkaller tool to obtain code coverage path information and capture first-hand information about vulnerability triggering through kernel compilation configuration CONFIG_KCOV and CONFIG_KASAN.
[0027] However, with the continuous advancement of technology, the complexity and scale of the kernel are also showing an increasing trend, which makes the amount of data and logical complexity that mining tools need to process in the process of kernel vulnerability mining also increase. When the test scale is large or complex test cases need to be processed, a single server may not be able to provide enough computing power to support efficient testing, which directly leads to the extension of the test cycle and reduces the efficiency of vulnerability mining. This makes the performance of the tool a limiting factor for vulnerability mining under large-scale testing requirements.
[0028] Therefore, the present application provides a distributed kernel vulnerability mining method to solve the problem of reduced vulnerability mining efficiency due to insufficient performance on the above-mentioned single server.
[0029] See also Figure 1 , Figure 1 An exemplary system architecture diagram of a distributed kernel vulnerability mining method provided in an embodiment of the present application.
[0030] like Figure 1As shown, the system architecture may include a first server 10, a second server 20, and a network 30. The network 30 is used to provide a medium for a communication link between the first server 10 and the second server 20. The network 30 may include various types of wired communication links or wireless communication links, for example, the wired communication link includes an optical fiber, a twisted pair, or a coaxial cable, and the wireless communication link includes a Bluetooth communication link, a Wireless-Fidelity (Wi-Fi) communication link, or a microwave communication link.
[0031] The first server 10 may interact with the second server 20 through the network 30 to receive a message from the second server 20 or send a message to the second server 20 .
[0032] Exemplarily, in the embodiment of the present application, the first server 10 is the first server, and the second server 20a and the second server 20b are the second servers. When implementing the distributed kernel vulnerability mining method, the first server 10 first responds to the vulnerability mining request for the target kernel, creates a test task according to the test information corresponding to the vulnerability mining request, allocates test resources for the test task, and obtains the task resources corresponding to the test task; then, the first server 10 determines the multiple second servers 20 corresponding to the test task according to the test resources, that is, the second server 20a and the second server 20b, and transmits the task resources to the corresponding second server 20a and the second server 20b respectively; finally, the first server 10 creates a virtual machine corresponding to the target kernel on the second server 20a and the second server 20b, instructs the virtual machines in the second server 20a and the second server 20b to execute the test corpus sent by the first server 10, and receives the test results returned by each virtual machine.
[0033] It should be understood that Figure 1 The number of the first server 10, the network and the second server 20 is only illustrative, and any number of the first server, the network and the second server may be used according to implementation requirements.
[0034] See also Figure 2 , Figure 2 A flow chart of a distributed kernel vulnerability mining method provided in an embodiment of the present application. The execution subject of the embodiment of the present application can be a server that executes distributed kernel vulnerability mining, or a processor in a server that executes the distributed kernel vulnerability mining method, or a distributed kernel vulnerability mining service in a server that executes the distributed kernel vulnerability mining method. For the convenience of description, the specific execution process of the distributed kernel vulnerability mining method is introduced below by taking the execution subject being a processor in a server as an example.
[0035] like Figure 2As shown, the distributed kernel vulnerability mining method, applied to the first server, may at least include:
[0036] S202 , in response to a vulnerability mining request for a target kernel, creating a test task according to test information corresponding to the vulnerability mining request, allocating test resources to the test task, and obtaining task resources corresponding to the test task.
[0037] Alternatively, as a complex system, the internal structure and functional characteristics of the operating system kernel may vary due to factors such as version, configuration, patch status, etc. Therefore, when it is necessary to perform vulnerability mining on the target kernel of the operating system, it is first necessary to provide test information containing relevant information of the target kernel, such as kernel version, kernel compilation configuration file, kernel image, etc., based on the actual situation of the target kernel or the security requirements to be met. Such test information helps to determine the focus and direction of vulnerability mining, ensuring that the mining work can be carried out on the potential vulnerabilities of the target kernel, thereby improving the pertinence and effectiveness of the test.
[0038] Optionally, the vulnerability mining request for the target kernel is triggered by the user, and correspondingly, the test information of the target kernel may come from multiple aspects, including but not limited to user input, system configuration, historical test data, etc. Exemplarily, when the user wants to mine vulnerabilities for the target kernel, the user can fill in the task name, test target time, test target crash number, test target kernel type, and test information such as the template library and test machine node used in the test on the relevant interface, and trigger the vulnerability mining request by clicking the relevant control on the interface.
[0039] Optionally, a stable and controllable test environment is required to perform vulnerability mining tasks on the target kernel, and this environment needs to simulate the real operation scenario of the target kernel, while ensuring safety, isolation and recoverability. Such a test environment can be constructed through the test information of the kernel. Specifically, in the embodiment of the present application, considering the kernel vulnerability test scenario with large scale and complex tasks, the computing power of multiple servers can be used at the same time to perform kernel vulnerability test tasks in a distributed manner, thereby accelerating the speed of vulnerability mining and shortening the test cycle. At the same time, since different servers may have different configurations and performance characteristics, correspondingly, in distributed execution, it is necessary to consider that the vulnerability mining tasks performed on different execution servers may also require different resource combinations and configurations. Based on this, the test information of the target kernel corresponding to the vulnerability mining request is first parsed, and the detailed information and specific test requirements of the target kernel are understood based on these test information, and physical test resources are allocated accordingly, and necessary software, hardware and network resources are configured, which may include the number of virtual machines allocated for the test task, the memory size on each virtual machine, the address information of the server performing the test task and other test parameters and conditions. When allocating test resources, the vulnerability mining tasks (that is, test tasks) that need to be executed on each execution server can be allocated according to the specific needs of vulnerability mining and the performance of each execution server, ensuring that the vulnerability mining tasks for the target kernel can obtain sufficient resource support and build the required test environment in a targeted manner.
[0040] Optionally, in addition to the allocation of physical resources, corresponding task resources are also required to build a test environment on each server that executes the test. For example, each server that executes the test needs to use the target kernel image and disk image to build a test environment when executing the task. Therefore, it is also necessary to obtain the task resources corresponding to the current test task based on the test information, so that the task resources can be subsequently transmitted to each server that executes the test, so that each execution server can build a corresponding test environment based on the task resources.
[0041] S204. Determine multiple second servers corresponding to the test tasks according to the test resources, and transmit the task resources to the corresponding second servers respectively.
[0042] Optionally, in the distributed execution vulnerability mining, each server (that is, the second server) that specifically executes the test task needs to have complete task resources and build a corresponding test environment to simulate the operation scenario of the target kernel to execute the test corpus assigned to it and conduct in-depth vulnerability mining on the target kernel. Therefore, transmitting the task resources to the second server is the basis for realizing distributed kernel vulnerability mining. Specifically, after the test resources corresponding to the test task are dynamically allocated according to the test information, it is also necessary to determine the second server corresponding to the test task according to the test resources, and then transmit the task resources of the test task to the corresponding second server, so that the test environment required for executing the test task can be constructed on each second server accordingly.
[0043] S206: Create a virtual machine corresponding to the target kernel on each second server, instruct the virtual machine in each second server to execute the test corpus sent by the first server, and receive the test results returned by each virtual machine.
[0044] Optionally, when performing vulnerability mining on the target kernel, the second server that performs the test task must be able to truly reflect the behavior and performance of the target kernel in actual operation. If the test environment in the second server is inconsistent with the actual operating environment in the target kernel, the test results may be affected by the environmental differences, resulting in the test being unable to accurately evaluate the security and stability of the target kernel; at the same time, due to differences in hardware configurations, operating system versions and other factors of different servers, these differences may lead to deviations in the test results. Therefore, when performing vulnerability mining on the same target kernel through multiple second servers, it is possible to consider building a test environment consistent with the operating state of the target kernel on each second server to reduce errors caused by server differences and improve the accuracy and reliability of the test.
[0045] Optionally, in order to build a test environment consistent with the running state of the target kernel on each second server, we can create a virtual machine matching the target kernel on each second server. Specifically, after each second server receives the task resources transmitted by the first server, it can select the corresponding operating system image for deployment based on the task resources and according to the type (such as Ubuntu, CentOS, etc.) and version of the target kernel, and configure the necessary hardware resources (such as CPU, memory, disk space, etc.) to meet the test requirements. In other words, the task resources obtained according to the test information include at least the target kernel image file and the disk image file.
[0046] Optionally, after configuring the virtual machines, each virtual machine can be instructed to execute the test corpus assigned to it. When the virtual machine executes the test corpus, observe whether it will crash, exit abnormally, or have error behaviors such as abnormal exit. At the same time, the virtual machine will also collect test results in real time, which may include abnormal kernel logs of the virtual machine, coverage path information corresponding to the test corpus, etc. Once the test is completed, the virtual machine will return these test results to the first server so that the first server can perform further analysis and processing. It should be noted that distributed execution can run complementary test corpora on multiple virtual machines at the same time to increase the code coverage of vulnerability mining; it can also run the same test corpus to verify the accuracy and reliability of the test by comparing the test results on different virtual machines.
[0047] In an embodiment of the present application, a distributed kernel vulnerability mining method is provided, which is applied to a first server, responds to a vulnerability mining request for a target kernel, creates a test task according to test information corresponding to the vulnerability mining request, allocates test resources to the test task, and obtains task resources corresponding to the test task; determines multiple second servers corresponding to the test task according to the test resources, and transmits the task resources to the corresponding second servers respectively; creates a virtual machine corresponding to the target kernel on each second server, instructs the virtual machine in each second server to execute the test corpus sent by the first server, and receives the test results returned by each virtual machine. When a vulnerability mining request for the target kernel is triggered, the test resources required for executing the vulnerability mining can be configured according to the test information corresponding to the request, and the task resources corresponding to the test task can be obtained. This step can allocate the test resources according to the actual performance of each second server, so that the second server used to perform the test is more efficiently utilized; then, multiple second servers running the test task are determined according to the test resources, and the task resources corresponding to the test task are transmitted to the corresponding second servers respectively, which can ensure that the task resources are reasonably and accurately allocated to each second server, and prepare for the subsequent second servers to execute the test tasks respectively; the next step is to create a virtual machine corresponding to the target kernel on each second server, execute the received test corpus through each virtual machine, and receive the test results after execution, so as to judge the existence of vulnerabilities in the target kernel according to the test results. The embodiment of the present application improves the overall test computing power by unifying the test tasks of kernel vulnerability mining and executing them in a distributed manner in each second server, and can process more test tasks at the same time, thereby speeding up the kernel vulnerability mining.
[0048] See also Figure 3 , Figure 3 A flowchart of a distributed kernel vulnerability mining method provided in an embodiment of the present application.
[0049] like Figure 3 The distributed kernel vulnerability mining method is applied to the first server and may at least include:
[0050] S302, in response to a vulnerability mining request for a target kernel, creating a test task according to test information corresponding to the vulnerability mining request, allocating test resources to the test task, and obtaining task resources corresponding to the test task.
[0051] Alternatively, if Figure 4 The structure diagram of a distributed kernel vulnerability mining method provided by an embodiment of the present application is shown. When a vulnerability mining request for a target kernel is triggered, the first thing to do is to configure the test resources according to the corresponding test information and obtain the task resources corresponding to the test task. Specifically, for step S302, please refer to the detailed record in step S202, which will not be repeated here.
[0052] S304: Determine the IP addresses of the second servers for executing the test tasks according to the test resources, and transmit the task resources to the corresponding second servers according to the IP addresses.
[0053] Optionally, since the test tasks are executed on each second server respectively, it is necessary to first transfer the task resources used to build the test environment to each second server, and configure the corresponding test environment accordingly to execute the specific task. Therefore, when allocating physical test resources to each test task, it is also necessary to clarify the relevant information of the second server that executes each test task, so as to smoothly transfer each task resource to the corresponding second server.
[0054] Specifically, Figure 4 The structure diagram of a distributed kernel vulnerability mining method provided by the embodiment of the present application shown in the figure clarifies the vulnerability mining requirements of the target kernel by parsing the test information. According to the requirements of the test task, the current load and available resources of each second server, the user can manually match different second servers for the test task. And it is necessary to determine the IP address of each second server, package the task resources required to execute the test task into data packets, and transmit them to the corresponding second servers according to the IP addresses. During the transmission process, data encryption and integrity verification can be implemented to ensure the security and accuracy of the data.
[0055] S306: Fill in an engine configuration file according to the test resources, where the engine configuration file at least includes the IP addresses of each second server.
[0056] Optionally, when large-scale kernel vulnerability mining is performed through each second server, if the test tasks in each second server are not managed in a unified manner, it may lead to uneven distribution of resources, thereby affecting the execution of the test tasks and the overall test progress. Based on this, it is possible to consider configuring a test engine in the first server and managing the test tasks in a unified manner through this test engine. Specifically, to configure the test engine, it is first necessary to fill in the relevant engine configuration file based on the test resources. This engine configuration file contains the key information required to perform vulnerability mining, including the IP addresses of each second server, which ensures that the test engine can accurately locate and connect to each second server involved in the test task execution process.
[0057] S308: Start the test engine corresponding to the target kernel based on the engine configuration file, and create a virtual machine for executing the test corpus on each second server through the test engine.
[0058] Alternatively, if Figure 4 The structure diagram of a distributed kernel vulnerability mining method provided by an embodiment of the present application is shown in FIG. 1 . Based on the above engine configuration file, a test engine (e.g. Figure 4 The test fuzz engine shown in ), which is responsible for managing and scheduling the execution of the test corpus distributed on each second server. Then, the test engine will create a virtual machine (for example, Figure 4 The QEMU virtual machines shown in ), which are specially designed to execute specific test corpora, will load the target kernel image and disk image, and receive test instructions from the test engine.
[0059] S310: Instruct each virtual machine to open a management port through the test engine, and establish a communication connection between the test engine and the management port of each virtual machine.
[0060] Alternatively, if Figure 4 The structure diagram of a distributed kernel vulnerability mining method provided by an embodiment of the present application is shown. In order to ensure that the test tasks can be executed efficiently and orderly on these virtual machines, the embodiment of the present application distinguishes the management and data transmission processes on the virtual machines. That is, a management port (such as Figure 4 SSH port) and transport port (as shown in Figure 4 The RPC ports shown in the figure are used to handle the virtual machine management and data transmission processes instructed by the test engine.
[0061] Optionally, the test engine instructs each virtual machine to open a management port, and a direct communication connection is established between the test engine and the management port of each virtual machine. Through this management port, the test engine can monitor the status of the virtual machine in real time and send management instructions.
[0062] S312: Send a test instruction to each management port through the test engine, and instruct the virtual machine in each second server to execute the test corpus sent by the first server, and receive the test result returned by each virtual machine.
[0063] Optionally, after establishing a communication connection through the management port, the test engine will send test instructions to the management port of each virtual machine according to the test strategy and process generated in the test resources. After receiving the test instructions, the virtual machines on each second server will parse and execute the test corpus received by the transmission port, and finally return the corresponding test results to the first server so that the first server can perform subsequent vulnerability analysis and processing.
[0064] In an embodiment of the present application, a distributed kernel vulnerability mining method is provided. After the corresponding test resources are configured according to the test information corresponding to the vulnerability mining request and the corresponding task resources are obtained, by determining the IP addresses of multiple second servers corresponding to each test resource, and sending the task resources to each second server according to the IP address, the test task can be distributed to multiple second servers for parallel execution, which significantly improves the efficiency of kernel vulnerability mining; at the same time, by filling in an engine configuration file and starting the test engine corresponding to the target kernel based on the engine configuration file, the virtual machine can be quickly created and configured according to the test engine, and the virtual machine resources can be uniformly managed and scheduled through the test engine to ensure the continuous stability of the test environment; the test engine and the management port of the virtual machine are connected, so that the first server can monitor the status and test progress of each virtual machine in real time through the management port based on the test engine, and perform corresponding management to ensure the smooth progress of the test task.
[0065] See also Figure 5 , Figure 5 A flowchart of a distributed kernel vulnerability mining method provided in an embodiment of the present application.
[0066] like Figure 5 As shown, the distributed kernel vulnerability mining method, applied to the first server, may at least include:
[0067] S502. In response to a vulnerability mining request for a target kernel, a test task is created according to the test information corresponding to the vulnerability mining request, test resources are allocated to the test task, and task resources corresponding to the test task are obtained; multiple second servers corresponding to the test task are determined according to the test resources, and the task resources are transmitted to the corresponding second servers respectively.
[0068] Optionally, regarding step S502, see Figure 2 The detailed description in the illustrated embodiments will not be repeated here.
[0069] S504. Fill in the engine configuration file according to the test resources, the engine configuration file at least including the IP address of each second server, and start the test engine corresponding to the target kernel based on the engine configuration file, and create a virtual machine for executing the test task on each second server through the test engine.
[0070] Optionally, regarding step S504, see Figure 3 The detailed description in the illustrated embodiments will not be repeated here.
[0071] S506: Generate multiple test corpora for executing tests based on the test information.
[0072] Optionally, in addition to configuring the test environment on each second server, a test corpus (i.e., input data or operation sequence used to trigger potential vulnerabilities) is also required to complete the specific execution of the test task. Therefore, based on the target kernel status and vulnerability mining requirements parsed in the aforementioned process, multiple test corpora can be generated in a targeted manner. These test corpora can act on the target kernel in a specific way in the virtual machine, covering various functional modules of the kernel and possible input scenarios, so as to maximize the efficiency and accuracy of vulnerability detection.
[0073] S508: Instruct each virtual machine to open a transmission port through the test engine, and establish a communication connection based on the transmission port between the test engine and each virtual machine.
[0074] Alternatively, if Figure 4 The structural diagram of a distributed kernel vulnerability mining method provided by an embodiment of the present application is shown. The test engine instructs each virtual machine to open a transmission port, and establishes a direct communication connection between the test engine and the transmission port of each virtual machine. Through this transmission port, the test engine can transmit data with the virtual machine in real time and accurately.
[0075] S510 . Send each test corpus to each virtual machine through the transmission port of each virtual machine by the test engine.
[0076] Optionally, after establishing a communication connection through the transmission port, the first server may send each test corpus to each virtual machine through the transmission port based on the test engine to ensure smooth progress of the test task.
[0077] S512, instructing the virtual machines in each second server to execute the test corpus sent by the first server, and receiving the test results returned by the transmission port of each virtual machine through the test engine, wherein the test results at least include coverage path information and kernel logs corresponding to the executed test corpus.
[0078] Alternatively, if Figure 4 The structural diagram of a distributed kernel vulnerability mining method provided by an embodiment of the present application is shown. After the test environment and test corpus have been configured, the test engine can instruct the virtual machines in each second server to execute the received test corpus. After each virtual machine executes the test corpus, it will generate corresponding test results, which will be returned to the test engine through the transmission port of the virtual machine.
[0079] Alternatively, if Figure 4 The structural diagram of a distributed kernel vulnerability mining method provided by an embodiment of the present application is shown. The test results received by the test engine include at least coverage path information and kernel logs corresponding to the executed test corpus. Among them, the coverage path information reflects the execution of the target kernel code during the test process, which helps to evaluate whether the test corpus effectively covers all or most of the code paths of the target kernel; the kernel log is a collection of various events and status information recorded by the target kernel during operation, which helps users understand the specific behavior of the kernel during the execution of the test corpus, and is an important source of information for analyzing the behavior of the target kernel and detecting anomalies or potential vulnerabilities.
[0080] In an embodiment of the present application, a distributed kernel vulnerability mining method is provided, in which test corpus is sent to the virtual machine through the transmission port of each virtual machine, so that the virtual machine can perform the test task according to the test corpus, thereby ensuring the smooth progress of the test task; at the same time, the test results after execution are received through the transmission port, and the test results are analyzed, so as to capture the potential vulnerabilities of the target kernel in time.
[0081] See also Figure 6 , Figure 6 A structural block diagram of a distributed kernel vulnerability mining device provided in an embodiment of the present application.
[0082] like Figure 6 As shown, the distributed kernel vulnerability mining device 600 is applied to the first server and includes:
[0083] The resource configuration module 610 is used to respond to the vulnerability mining request for the target kernel, create a test task according to the test information corresponding to the vulnerability mining request, allocate test resources to the test task, and obtain the task resources corresponding to the test task;
[0084] A resource transmission module 620, configured to determine a plurality of second servers corresponding to the test tasks according to the test resources, and transmit the task resources to the corresponding second servers respectively;
[0085] The task execution module 630 is used to create a virtual machine corresponding to the target kernel on each second server, instruct the virtual machine in each second server to execute the test corpus sent by the first server, and receive the test results returned by each virtual machine.
[0086] Optionally, the resource transmission module 620 is further used to determine the IP addresses of the second servers used to execute the test tasks according to the test resources, and transmit the task resources to the corresponding second servers according to the IP addresses.
[0087] Optionally, the task execution module 630 is also used to fill in the engine configuration file according to the test resources, and the engine configuration file includes at least the IP address of each second server; based on the engine configuration file, the test engine corresponding to the target kernel is started, and a virtual machine for executing the test corpus is created on each second server through the test engine.
[0088] Optionally, the distributed kernel vulnerability mining device 600 also includes: a connection management port module, which is used to instruct each virtual machine to open a management port through the test engine, and establish a communication connection between the test engine and the management port of each virtual machine; a task execution module 630, which is also used to send test instructions to each management port through the test engine, and instruct the virtual machines in each second server to execute the test corpus sent by the first server.
[0089] Optionally, the distributed kernel vulnerability mining device 600 also includes: a test corpus generation module, which is used to generate multiple test corpora for executing tests based on test information; the distributed kernel vulnerability mining device 600 also includes a transmission port connection module, which is used to instruct each virtual machine to open a transmission port through the test engine after the task execution module 630 creates a virtual machine for executing the test corpus on each second server through the test engine, and establish a communication connection based on the test engine and the transmission port of each virtual machine; and send each test corpus to each virtual machine through the transmission port of each virtual machine through the test engine.
[0090] Optionally, the task execution module 630 is further used to receive the test results returned by the transmission port of each virtual machine through the test engine, and the test results at least include coverage path information and kernel logs corresponding to the executed test corpus.
[0091] Optionally, the task resources include at least a target kernel image file and a disk image file.
[0092] In an embodiment of the present application, a distributed kernel vulnerability mining device is provided, which is applied to a first server, wherein a resource configuration module is used to respond to a vulnerability mining request for a target kernel, create a test task according to test information corresponding to the vulnerability mining request, allocate test resources to the test task, and obtain task resources corresponding to the test task; a resource transmission module is used to determine multiple second servers corresponding to the test task according to the test resources, and transmit the task resources to the corresponding second servers respectively; a task execution module is used to create a virtual machine corresponding to the target kernel on each second server, instruct the virtual machine in each second server to execute the test corpus sent by the first server, and receive the test results returned by each virtual machine. When a vulnerability mining request for the target kernel is triggered, the resource configuration module can configure the test resources required to execute the test task according to the test information of the target kernel and obtain the task resources corresponding to the test task; then the resource transmission module can determine the multiple second servers corresponding to the test task according to the test resources, and transmit the aforementioned task resources to each second server respectively, to prepare for the subsequent distributed execution of the test task by the second server; finally, a virtual machine is created on each second server through the task execution module, and the received test corpus is executed in a distributed manner, so that the vulnerabilities of the target kernel can be analyzed and processed according to the test results after execution. This distributed execution of kernel vulnerability mining tasks can handle more test tasks at the same time, thereby speeding up the kernel vulnerability mining.
[0093] An embodiment of the present application further provides a computer storage medium, which can store multiple instructions, and the instructions are suitable for being loaded by a processor and executing the steps of any method in the above embodiments.
[0094] See also Figure 7 , Figure 7 A schematic diagram of the structure of a server provided in an embodiment of the present application. Figure 7 As shown, the server 700 may include: at least one processor 701 , at least one network interface 704 , a user interface 703 , a memory 705 , and at least one communication bus 702 .
[0095] The communication bus 702 is used to realize the connection and communication between these components.
[0096] The user interface 703 may include a display screen (Display) and a camera (Camera), and the optional user interface 703 may also include a standard wired interface and a wireless interface.
[0097] The network interface 704 may optionally include a standard wired interface or a wireless interface (such as a WI-FI interface).
[0098] Among them, the processor 701 may include one or more processing cores. The processor 701 uses various interfaces and lines to connect various parts within the entire server 700, and executes various functions and processes data of the server 700 by running or executing instructions, programs, code sets or instruction sets stored in the memory 705, and calling data stored in the memory 705. Optionally, the processor 701 can be implemented in at least one hardware form of digital signal processing (Digital Signal Processing, DSP), field programmable gate array (Field-Programmable Gate Array, FPGA), and programmable logic array (Programmable Logic Array, PLA). The processor 701 can integrate one or a combination of a central processing unit (Central Processing Unit, CPU), a graphics processing unit (Graphics Processing Unit, GPU) and a modem. Among them, the CPU mainly processes the operating system, user interface and application programs; the GPU is responsible for rendering and drawing the content to be displayed on the display screen; the modem is used to process wireless communications. It can be understood that the above-mentioned modem may not be integrated into the processor 701, and it can be implemented by a single chip.
[0099] Among them, the memory 705 may include a random access memory (Random Access Memory, RAM) and may also include a read-only memory (Read-Only Memory, ROM). Optionally, the memory 705 includes a non-transitory computer-readable storage medium. The memory 705 can be used to store instructions, programs, codes, code sets or instruction sets. The memory 705 may include a program storage area and a data storage area, wherein the program storage area may store instructions for implementing an operating system, instructions for at least one function (such as a touch function, a sound playback function, an image playback function, etc.), instructions for implementing the above-mentioned various method embodiments, etc.; the data storage area may store data involved in the above-mentioned various method embodiments, etc. The memory 705 may also be optionally at least one storage device located away from the aforementioned processor 701. As Figure 7 As shown, the memory 705 as a computer storage medium may include an operating system, a network communication module, a user interface module, and a distributed kernel vulnerability mining program.
[0100] exist Figure 7In the server 700 shown, the user interface 703 is mainly used to provide an input interface for the user and obtain the data input by the user; and the processor 701 can be used to call the distributed kernel vulnerability mining program stored in the memory 705, and specifically perform the following operations:
[0101] In response to a vulnerability mining request for a target kernel, a test task is created according to test information corresponding to the vulnerability mining request, a test resource is allocated to the test task, and task resources corresponding to the test task are obtained;
[0102] Determine multiple second servers corresponding to the test tasks according to the test resources, and transmit the task resources to the corresponding second servers respectively;
[0103] A virtual machine corresponding to the target kernel is created on each second server, the virtual machine in each second server is instructed to execute the test corpus sent by the first server, and the test results returned by each virtual machine are received.
[0104] In some embodiments, when the processor 701 determines multiple second servers corresponding to the test tasks according to the test resources and transmits the task resources to the corresponding second servers respectively, it specifically performs the following steps: determines the IP addresses of the second servers used to execute the test tasks according to the test resources, and transmits the task resources to the corresponding second servers according to each IP address.
[0105] In some embodiments, when the processor 701 creates a virtual machine corresponding to the target kernel on each second server, it specifically performs the following steps: fills in an engine configuration file according to the test resources, and the engine configuration file includes at least the IP address of each second server; starts the test engine corresponding to the target kernel based on the engine configuration file, and creates a virtual machine for executing the test corpus on each second server through the test engine.
[0106] In some embodiments, after executing the creation of a virtual machine for executing the test corpus on each second server through the test engine, the processor 701 further specifically performs the following steps: instructing each virtual machine to open a management port through the test engine, and establishing a communication connection based on the test engine and the management port of each virtual machine; when the processor 701 executes the instruction to instruct the virtual machine in each second server to execute the test corpus sent by the first server, the processor 701 specifically performs the following steps: sending a test instruction to each management port through the test engine, and instructing the virtual machine in each second server to execute the test corpus sent by the first server.
[0107] In some embodiments, the processor 701 further specifically performs the following steps: generating multiple test corpora for executing tests based on the test information; after the processor 701 creates a virtual machine for executing the test corpora on each second server through the test engine, it further specifically performs the following steps: instructing each virtual machine to open a transmission port through the test engine, and establishing a communication connection based on the transmission port between the test engine and each virtual machine; and sending each test corpus to each virtual machine through the transmission port of each virtual machine through the test engine.
[0108] In some embodiments, when the processor 701 executes to receive the test results returned by each virtual machine, it specifically performs the following steps: receiving the test results returned by the transmission port of each virtual machine through the test engine, and the test results at least include the coverage path information and kernel log corresponding to the executed test corpus.
[0109] In some embodiments, the task resources include at least a target kernel image file and a disk image file.
[0110] In the several embodiments provided in the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are only schematic. For example, the division of modules is only a logical function division. There may be other division methods in actual implementation, such as multiple modules or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or modules, which can be electrical, mechanical or other forms.
[0111] The modules described as separate components may or may not be physically separated, and the components shown as modules may or may not be physical modules, that is, they may be located in one place or distributed on multiple network modules. Some or all of the modules may be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0112] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The above computer program product includes one or more computer instructions. When the above computer program instructions are loaded and executed on a computer, the above process or function according to the embodiment of this specification is generated in whole or in part. The above computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The above computer instructions can be stored in a computer-readable storage medium or transmitted by the above computer-readable storage medium. The above computer instructions can be transmitted from a website site, computer, server or data center to another website site, computer, server or data center by wired (e.g., coaxial cable, optical fiber, digital subscriber line (Digital Subscriber Line, DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) mode. The above computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server, data center, etc. that contains one or more available media integrated. The above-mentioned available media can be magnetic media (for example, floppy disks, hard disks, tapes), optical media (for example, digital versatile discs (DVD)), or semiconductor media (for example, solid state drives (SSD)), etc.
[0113] It should be noted that, for the above-mentioned method embodiments, for the sake of simplicity of description, they are all expressed as a series of action combinations, but those skilled in the art should be aware that the present application is not limited by the described action sequence, because according to the present application, certain steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily required by the present application.
[0114] In the above embodiments, the description of each embodiment has its own emphasis. For parts that are not described in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0115] The above is a description of a distributed kernel vulnerability mining method, device, storage medium and server provided by the present application. For technicians in this field, according to the ideas of the embodiments of the present application, there may be changes in the specific implementation methods and application scopes. In summary, the content of this specification should not be understood as a limitation on the present application.
Claims
1. A distributed kernel vulnerability mining method, characterized in that: Applied to a first server, the method comprises: In response to a vulnerability mining request for a target kernel, creating a test task according to test information corresponding to the vulnerability mining request, allocating test resources to the test task, and obtaining task resources corresponding to the test task; Determine a plurality of second servers corresponding to the test tasks according to the test resources, and transmit the task resources to the corresponding second servers respectively; A virtual machine corresponding to the target kernel is created on each second server, the virtual machine in each second server is instructed to execute the test corpus sent by the first server, and the test results returned by each virtual machine are received.
2. The method according to claim 1, characterized in that: The step of respectively determining a plurality of second servers corresponding to the test tasks according to the test resources, and respectively transmitting the task resources to the corresponding second servers comprises: The IP addresses of the second servers for executing the test tasks are determined respectively according to the test resources, and the task resources are transmitted to the corresponding second servers respectively according to the IP addresses.
3. The method according to claim 1, characterized in that The step of creating a virtual machine corresponding to the target kernel on each second server includes: Fill in an engine configuration file according to the test resources, wherein the engine configuration file at least includes the IP address of each second server; A test engine corresponding to the target kernel is started based on the engine configuration file, and a virtual machine for executing the test corpus is created on each second server through the test engine.
4. The method according to claim 3, characterized in that After the test engine creates a virtual machine for executing the test corpus on each second server, the method further includes: Instructing each virtual machine to open a management port through the test engine, and establishing a communication connection between the test engine and the management port of each virtual machine; The step of instructing the virtual machines in the second servers to execute the test corpus sent by the first server includes: The test engine sends a test instruction to each management port, and instructs the virtual machine in each second server to execute the test corpus sent by the first server.
5. The method according to claim 3, characterized in that: The method further comprises: Generating a plurality of test corpora for executing the test based on the test information; After the test engine creates a virtual machine for executing the test corpus on each second server, the method further includes: Instructing each virtual machine to open a transmission port through the test engine, and establishing a communication connection based on the transmission port between the test engine and each virtual machine; The test engine sends each test corpus to each virtual machine through the transmission port of each virtual machine.
6. The method according to claim 5, characterized in that The receiving of the test results returned by each virtual machine includes: The test engine receives the test results returned by the transmission port of each virtual machine, wherein the test results at least include coverage path information and kernel logs corresponding to the executed test corpus.
7. The method according to claim 1, characterized in that The task resources include at least a target kernel image file and a disk image file.
8. A kernel vulnerability testing device, characterized in that: Applied to a first server, the device comprises: A resource configuration module, for responding to a vulnerability mining request for a target kernel, creating a test task according to the test information corresponding to the vulnerability mining request, allocating test resources to the test task, and obtaining task resources corresponding to the test task; A resource transmission module, used to determine a plurality of second servers corresponding to the test task according to the test resources, and transmit the task resources to the corresponding second servers respectively; The task execution module is used to create a virtual machine corresponding to the target kernel on each second server, instruct the virtual machine in each second server to execute the test corpus sent by the first server, and receive the test results returned by each virtual machine.
9. A computer storage medium, characterized in that: The computer storage medium stores a plurality of instructions, and the instructions are suitable for being loaded by a processor and executing the steps of the method according to any one of claims 1 to 7.
10. A server, characterized in that: The method comprises a memory, a processor and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps of the method according to any one of claims 1 to 7 when executing the program.