A protocol specification state machine-based vulnerability automatic analysis method

By using a method based on the protocol specification state machine, a finite state machine model of the target system and protocol specification is generated to automatically detect vulnerabilities in the network protocol, solving the problems of low efficiency and easy omissions in the existing technology and improving the efficiency of vulnerability detection and system security.

CN120263568BActive Publication Date: 2025-10-10TSINGHUA UNIVERSITY +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510750480.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-06-06
Publication Date
2025-10-10
Estimated Expiration
2045-06-06

AI Technical Summary

Technical Problem

In the existing technology, the inconsistency between the implementation of network protocols and protocol specifications may lead to security vulnerabilities. Existing vulnerability detection methods are inefficient and prone to missing problems, and require a lot of manual intervention and repeated detection.

Method used

By using a method based on the protocol specification state machine, a finite state machine model of the target system and protocol specification is generated, and vulnerabilities in the network protocol are automatically detected using mapping relationships and consistency verification.

Benefits of technology

It improves the efficiency and accuracy of vulnerability detection, reduces the need for manual intervention, reduces the workload of repeated detection, and improves system security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120263568B_ABST
    Figure CN120263568B_ABST
Patent Text Reader

Abstract

The application provides a vulnerability automatic analysis method based on a protocol specification state machine, and relates to the technical field of Internet, wherein the method comprises the following steps: mapping an input symbol sequence according to a mapping relationship to generate first mapping data, inputting the first mapping data into a target system for processing to obtain a first output symbol sequence, and determining a first finite state machine model; mapping the input symbol sequence according to a protocol specification to generate second mapping data, and determining a second finite state machine model directory; generating a first state diagram and a second state diagram, comparing the first state diagram with the second state diagram to determine a target path, and analyzing the target path to determine a vulnerability. The target system and the protocol specification are analyzed to generate state diagrams, and the state diagrams are compared, so that the detection and comparison of system vulnerabilities are realized, the probability of system security problems caused by system vulnerabilities is reduced, and the efficiency of system vulnerability detection and the security of the system are improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of Internet, and particularly relates to a vulnerability automatic analysis method based on a protocol specification state machine. BACKGROUND

[0002] With the development of Internet technology, network security problems also arise, and vulnerability analysis of network protocols has become a research hotspot in the field of information security. The implementation of network protocols should be consistent with the protocol specification, and any deviation or violation of the implementation logic specified in the protocol specification may lead to some security vulnerabilities, or even unable to work normally. For example, such implementation errors may be exploited to establish an insecure connection. SUMMARY

[0003] The present application aims to at least solve one of the technical problems in the related art to some extent.

[0004] To this end, a first object of the present application is to provide a vulnerability automatic analysis method based on a protocol specification state machine.

[0005] A second object of the present application is to provide an apparatus.

[0006] A third object of the present application is to provide an electronic device.

[0007] A fourth object of the present application is to provide a computer-readable storage medium.

[0008] A fifth object of the present application is to provide a computer program product.

[0009] To achieve the above objects, a vulnerability automatic analysis method based on a protocol specification state machine is provided in an embodiment of the first aspect of the present application, comprising:

[0010] mapping an input symbol sequence according to a mapping relationship to generate first mapping data, inputting the first mapping data into a target system for processing to obtain feedback data, wherein the first mapping data is accurate data for the target system;

[0011] mapping the feedback data according to the mapping relationship to generate a first output symbol sequence, and determining a first finite state machine model according to the input symbol sequence and the first output symbol sequence, wherein the first finite state machine model is a finite state machine model of the target system;

[0012] Mapping the input symbol sequence according to a protocol specification to generate second mapping data, and determining a second finite state machine model directory based on the input symbol sequence and the second output symbol sequence, wherein the second finite state machine model directory includes a plurality of second sub-finite state machine models corresponding to the protocol specification, and wherein the second mapping data is a symbol for the protocol specification;

[0013] Generate a first state diagram corresponding to the first finite state machine model and a second state diagram corresponding to the second finite state machine model directory, compare the first state diagram and the second state diagram to determine a target path, and analyze the target path to determine vulnerabilities.

[0014] Optionally, the step of generating the input symbol sequence includes:

[0015] According to the protocol interaction characteristics, set the input symbol table and output symbol table of the protocol;

[0016] A plurality of input symbols are selected from the input symbol table and an order of the input symbols is determined to generate the input symbol sequence.

[0017] Optionally, the step of inputting the first mapping data into a target system for processing and then obtaining feedback data includes:

[0018] generating a communication data packet recognizable by the target system according to the first mapping data;

[0019] The communication data packet is input into the target system.

[0020] Optionally, determining a first finite state machine model according to the input symbol sequence and the first output symbol sequence includes:

[0021] generating a first hypothetical state machine model according to all the input symbol sequences and the corresponding first output symbol sequences, and performing consistency verification on the first hypothetical state machine model;

[0022] If the behavior of the first hypothetical state machine model is inconsistent with the expected behavior, continue to input the input symbol sequence and the first output symbol sequence to update the first hypothetical state machine model; or

[0023] If the behavior of the first hypothetical state machine model is consistent with the expected behavior, the current first hypothetical state machine model is determined to be the first finite state machine model.

[0024] Optionally, determining a second finite state machine model catalog according to the input symbol sequence and the second output symbol sequence includes:

[0025] generating a second hypothetical state machine model according to a portion of the input symbol sequence and the corresponding second output symbol sequence, and performing consistency verification on the second hypothetical state machine model;

[0026] If the behavior of the second hypothetical state machine model is inconsistent with the expected behavior, continue to input the input symbol sequence and the second output symbol sequence to update the second hypothetical state machine model; or

[0027] If the behavior of the second hypothetical state machine model is consistent with the expected behavior, the current second hypothetical state machine model is determined to be the sub-second finite state machine model, and the second finite state machine model directory is generated according to all the sub-second finite state machine models.

[0028] Optionally, generating a first state diagram corresponding to the first finite state machine model and a second state diagram corresponding to the second finite state machine model directory includes:

[0029] Read each first state in the first finite state machine model and the second finite state machine model directory, as well as the input and output corresponding to the first state;

[0030] Determine the second state corresponding to each of the inputs and outputs in the finite automaton model, and generate the first state diagram and the second state diagram according to each of the second states.

[0031] Optionally, comparing the first state diagram and the second state diagram to determine a target path, and analyzing the target path to determine a vulnerability includes:

[0032] comparing a state path in the first state diagram with each state path in the second state diagram;

[0033] determining the different state paths as the target paths;

[0034] The input sequence corresponding to the target path is re-input into the target system to check for vulnerabilities.

[0035] To achieve the above objectives, the second embodiment of the present application proposes an automated vulnerability analysis device based on a protocol specification state machine, comprising:

[0036] a data processing module, configured to map the input symbol sequence according to the mapping relationship to generate first mapping data, input the first mapping data into a target system for processing, and obtain feedback data, wherein the first mapping data is accurate data for the target system;

[0037] a first state machine model generating module, configured to map the feedback data according to the mapping relationship to generate a first output symbol sequence, and determine a first finite state machine model according to the input symbol sequence and the first output symbol sequence, wherein the first finite state machine model is a finite state machine model of the target system;

[0038] a second state machine model generating module, configured to map the input symbol sequence according to a protocol specification to generate second mapping data, and determine a second finite state machine model directory according to the input symbol sequence and the second output symbol sequence, wherein the second finite state machine model directory includes a plurality of second sub-finite state machine models corresponding to the protocol specification, and wherein the second mapping data is a symbol for the protocol specification;

[0039] A vulnerability detection module is used to generate a first state diagram corresponding to the first finite state machine model and a second state diagram corresponding to the second finite state machine model directory, compare the first state diagram and the second state diagram to determine the target path, and analyze the target path to determine the vulnerability.

[0040] To achieve the above-mentioned purpose, a third embodiment of the present application provides an electronic device, comprising: a processor, and a memory communicatively connected to the processor;

[0041] The memory stores computer-executable instructions;

[0042] The processor executes the computer-executable instructions stored in the memory to implement the method as described in any one of the first aspects.

[0043] To achieve the above-mentioned purpose, the fourth embodiment of the present application proposes a computer-readable storage medium, which stores computer-executable instructions. When the computer-executable instructions are executed by a processor, they are used to implement the method as described in any one of the first aspects.

[0044] To achieve the above-mentioned objectives, the fifth embodiment of the present application proposes a computer program product, which implements any one of the methods in the first aspect when executed by a processor.

[0045] The automated vulnerability analysis method, device, electronic device, and storage medium based on the protocol specification state machine provided in this application parse the target system and protocol specification to generate a state diagram, and compare the state diagrams, thereby realizing the detection and comparison of system vulnerabilities, reducing the probability of system security issues caused by system vulnerabilities, and improving the efficiency of system vulnerability detection and the security of the system.

[0046] Additional aspects and advantages of the present application will be given in part in the description below, and in part will become apparent from the description below, or will be learned through practice of the present application. BRIEF DESCRIPTION OF THE DRAWINGS

[0047] The above and / or additional aspects and advantages of the present application will become apparent and easily understood from the following description of the embodiments in conjunction with the accompanying drawings, in which:

[0048] Figure 1 A flowchart of an automated vulnerability analysis method based on a protocol specification state machine provided in an embodiment of the present application;

[0049] Figure 2 A schematic diagram of the structure of an automated vulnerability analysis device based on a protocol specification state machine provided in an embodiment of the present application;

[0050] Figure 3 A schematic diagram of the structure of an automated vulnerability analysis device based on a protocol specification state machine provided in an embodiment of the present application;

[0051] Figure 4 A schematic diagram of a first finite state machine model proposed in an embodiment of the present application;

[0052] Figure 5 This is a schematic diagram of a first state diagram proposed in an embodiment of the present application. DETAILED DESCRIPTION

[0053] The following describes in detail embodiments of the present application, examples of which are shown in the accompanying drawings, wherein the same or similar reference numerals throughout represent the same or similar elements or elements having the same or similar functions. The embodiments described below with reference to the accompanying drawings are exemplary and are intended to be used to explain the present application, and should not be construed as limiting the present application.

[0054] With the development of internet technology, network security issues have also arisen. Vulnerability analysis of network protocols has become a hot topic in information security research. Network protocol implementations must conform to protocol specifications. Any deviation from or violation of the implementation logic specified in the protocol specifications can lead to security vulnerabilities and even prevent normal operation. For example, such implementation errors can be exploited to establish insecure connections.

[0055] The implementation process of network protocol can be represented by state diagram, and the detection of state machine model becomes the mainstream method of protocol vulnerability analysis, and the part that violates the protocol specification is called state machine error. The state machine model of protocol implementation is automatically inferred by model learning. Model learning is a black box technology that automatically generates state machine model, which describes the message flow in the implementation process of protocol by giving input test sequence and receiving response. Based on the learned state machine model, the defects or errors in the implementation process of protocol are found.

[0056] Existing state machine vulnerability detection methods mainly fall into several categories: manual inspection, model difference comparison, formal verification of linear temporal logic (LTL) codes, and automated vulnerability detection of deterministic finite state automata (DFA) codes. Manual inspection requires strong expertise. Some models have a large number of states and are large and complex, making visual inspection time-consuming and prone to missing errors. Furthermore, once an error is discovered and fixed, the inspection process must be repeated after the model is updated, significantly increasing the workload. Model difference comparison methods use model learning to generate multiple models of different implementations of the same protocol, then compare these models to identify anomalies. This vulnerability detection approach analyzes the model rather than testing input and output behavior. Difference testing requires comparing at least two implementations of a protocol. Fundamentally, this method cannot traverse all model differences, resulting in missed issues. Property verification methods for linear temporal logic codes, based on finite state machine systems, can determine whether system-level behavior meets the protocol design specifications corresponding to a given temporal logic formula. If violations occur, counterexamples are generated. The DFA-encoded automated vulnerability detection method first extracts a vulnerability catalog from protocol specifications, reported vulnerabilities, and empirical evidence. These vulnerabilities are then encoded using DFAs to form vulnerability templates. DFA encoding is more expressive of protocol properties than LTL. As vulnerability detection results accumulate, the vulnerability template catalog gradually fills in. In computational theory, a Mealy machine is a finite state automaton (more precisely, a finite state transducer) that generates an output based on its current state and input. This means that its state graph includes both an input and an output for each transition edge, with the output being dependent on both the current state and the input. The finite Mealy state machine model generated through model learning is converted into a DFA state graph, which is then automatically checked to see if it contains a defined vulnerability template. If a vulnerability exists, the test stimulus that triggers it is recorded, and the vulnerability is verified in a real-world system. This method effectively achieves automated vulnerability detection and validation. However, vulnerability definition requires analyzing protocol violations based on the normal behavior or communication mechanisms specified in the official protocol documentation and converting these into vulnerability templates. Vulnerabilities specified based on empirical evidence or reported vulnerabilities require a deep understanding of the protocol.

[0057] To address the above issues, the present invention provides an automated vulnerability analysis method based on a protocol specification state machine. Figure 1 The flowchart of the vulnerability automatic analysis method based on the protocol specification state machine provided in the embodiment of the present application is as follows. Figure 1As shown, the method includes the following steps:

[0058] Step 101: Mapping an input symbol sequence according to a mapping relationship to generate first mapping data, inputting the first mapping data into a target system for processing to obtain feedback data, wherein the first mapping data is accurate data for the target system;

[0059] Step 102: Map the feedback data according to the mapping relationship to generate a first output symbol sequence, and determine a first finite state machine model according to the input symbol sequence and the first output symbol sequence, wherein the first finite state machine model is a finite state machine model of the target system;

[0060] Step 103: Map the input symbol sequence according to the protocol specification to generate second mapping data, and determine a second finite state machine model directory based on the input symbol sequence and the second output symbol sequence, wherein the second finite state machine model directory includes multiple sub-second finite state machine models corresponding to the protocol specification, and wherein the second mapping data is a symbol for the protocol specification;

[0061] Step 104: Generate a first state diagram corresponding to the first finite state machine model and a second state diagram corresponding to the second finite state machine model directory, compare the first state diagram and the second state diagram to determine a target path, and analyze the target path to determine vulnerabilities.

[0062] In this embodiment, we address the aforementioned issues by directly extracting reasonable behaviors from the protocol specification and establishing a protocol specification behavior simulator with input-output mappings that conform to the specification. Based on a model learning framework, behaviors that conform to the protocol specification are converted into a finite state machine (FSM) format, resulting in a second FSM model catalog. This catalog is then compared with the first FSM model derived from learning the target system's behavior. Any inconsistencies in the models are further analyzed and verified to identify potential vulnerabilities in the protocol specification within the target system.

[0063] This embodiment provides a vulnerability automated analysis device based on a protocol specification state machine. Figure 2 This is a schematic diagram of the structure of a vulnerability automatic analysis device based on a protocol specification state machine provided in an embodiment of the present application. Figure 2 As shown, the apparatus may include: a first state machine generating module 210 , a second state machine generating module 220 and a vulnerability analysis and detection module 230 .

[0064] The first state machine generation module 210 is used to execute the behaviors in step 101 and step 102 , the second state machine generation module 220 is used to execute the behavior in step 103 , and the vulnerability analysis and detection module 230 is used to execute the behavior in step 104 .

[0065] Optionally, the first state machine generation module 210 includes a learner 211, a mapper 212 and a target system 213. The learner 211 generates an input symbol sequence for model learning and provides an automatic learning framework, which includes a learning algorithm and a consistency algorithm. The mapper 212 is responsible for the conversion between input and output symbols and precise data information, and generates actual data packets based on the precise data information. After receiving the converted input data packet, the target system 213 outputs a response data packet. It is then reversely converted into an output abstract symbol through the mapper 212 and sent to the learner 211. The learner 211 automatically infers the first state machine model of the target system based on the input and output symbols and the selected learning algorithm and consistency algorithm.

[0066] Optionally, the step of generating the input symbol sequence includes:

[0067] According to the protocol interaction characteristics, set the input symbol table and output symbol table of the protocol;

[0068] A plurality of input symbols are selected from the input symbol table and an order of the input symbols is determined to generate the input symbol sequence.

[0069] In this embodiment, the learner 211 combines the input symbols of the symbol table into multiple input symbol sequences of different orders and elements as test stimuli for the target system. Each input symbol in the input symbol sequence is sent to the mapper 212 in sequence. The learner 211 uses the open source automaton learning library LearnLib, which supports multiple learning algorithms such as L*, TTT and consistency algorithms such as Wp and Wp-Random. During the learning process, for the input requests issued, the learner 211 needs to be able to receive a certain output response. However, the target system may not respond to some given input stimuli, and the response will time out if the set time threshold is exceeded.

[0070] Optionally, step 102 of determining a first finite state machine model according to the input symbol sequence and the first output symbol sequence includes:

[0071] generating a first hypothetical state machine model according to all the input symbol sequences and the corresponding first output symbol sequences, and performing consistency verification on the first hypothetical state machine model;

[0072] If the behavior of the first hypothetical state machine model is inconsistent with the expected behavior, continue to input the input symbol sequence and the first output symbol sequence to update the first hypothetical state machine model; or

[0073] If the behavior of the first hypothetical state machine model is consistent with the expected behavior, the current first hypothetical state machine model is determined to be the first finite state machine model.

[0074] In this embodiment, learner 211 generates a hypothetical finite Mealy state machine model (a first hypothetical state machine model) based on a learning algorithm, combining the input symbol sequence and the received first output symbol sequence. A Mealy state machine consists of inputs, outputs, states, initial states, and transition relationships. These five elements describe the interactive logic process implemented by the protocol. For a given state, if a symbol is input, the state machine model indicates the next state to jump to and the corresponding output information.

[0075] The learning algorithm follows the MAT framework. In the MAT framework, the input and output of the deterministic Mealy state machine model M are known. The learner will learn the model M through question-answering and infer the unknown automaton. During the learning process, in a member sequence, the learner will ask what the output response is for an input. In the equivalence query process, the learner asks whether the learned first hypothesis state machine model is correct. If it is equivalent to the model M, the correct response is received. Otherwise, a counterexample is provided, indicating that the first hypothesis state machine model is inconsistent with the model M. In the method of this article, the task of answering the learner's output response is performed by the target system, and the validity of the first hypothesis state machine model is tested by a consistency testing tool and verified using several test sequences.

[0076] Optionally, step 101 of inputting the first mapping data into a target system for processing and obtaining feedback data includes:

[0077] generating a communication data packet recognizable by the target system according to the first mapping data;

[0078] The communication data packet is input into the target system.

[0079] In this embodiment, in the protocol implementation, there are many data information of interaction, and it is difficult to learn the data information directly. Therefore, the conversion of learning elements is needed through the mapper 212. The mapper 212 is responsible for the bidirectional conversion between the precise data information (first mapping data) and the abstract symbol information (input symbol sequence). The abstract symbol and the precise data information are generally in a one-to-many relationship, so the number of abstract symbols is less. The mapper 212 is located between the learner 211 and the target system 213. The mapper 212 interacts with the learner 211 through the abstract symbol information, instead of learning the precise data directly, which reduces the complexity of learning. The mapper 212 interacts with the target system 213 through the precise data information. In the process of communication, the precise data information is converted into an actual data packet and sent to the target system, and the response data packet output by the target system is converted into precise data information and sent to the mapper.

[0080] The overall learning process in the first state machine generation module 210 is as follows:

[0081] (1) According to the protocol interaction characteristics, set the input and output symbol table of the protocol, and provide the input and output content for the learner 211.

[0082] (2) The learner 211 combines the input symbol based on the symbol table into a plurality of input symbol sequences with different sequences and elements, as the test stimulus of the target system, and sends each input symbol to the mapper 212 in sequence.

[0083] (3) The mapper 212 converts the abstract message covered by the received input symbol sequence into precise input data information (first mapping data), and then forms a communication data packet recognizable by the target system according to the first mapping data.

[0084] (4) Establish a path between the mapper 212 and the target system 213, and send the converted communication data packet to the target system 213 and wait for the system response.

[0085] (5) The mapper 212 receives the response data packet (feedback data) sent by the target system 213, and converts the feedback data into precise output data information, and then converts the precise data information through the mapper 212 into the first output symbol sequence in reverse, and sends it back to the learner 211.

[0086] (6) Learner 211 continuously sends input symbol sequences and receives the first output symbol sequence. After a period of learning, an automatically inferred hypothetical state machine model is generated. For the hypothetical state machine model, a consistency algorithm is used to verify whether the behavior of the hypothetical state machine is completely consistent with the expected behavior. If not, the verification fails and learning continues until there are no counterexamples. Otherwise, the final first finite state machine model is obtained.

[0087] Optionally, the second state machine generation module 220 includes two parts: a learner 221 and a protocol specification behavior simulator 222. The protocol specification gives the communication rules of the target protocol and constrains the content and interaction logic of the protocol. Content that violates the protocol specification behavior is considered to be problematic. After generating the first finite state machine model corresponding to the target system, the input, output and jump state of the first finite state machine model can be compared and checked based on the protocol specification. If there are certain behaviors in the model that are inconsistent with the protocol specification, they are considered to be suspicious actions. However, protocol specifications are usually some descriptive languages. The manual analysis of the model will become time-consuming and easy to overlook certain problems as the model grows. It is inefficient and the accuracy cannot be guaranteed. This section imitates the MAT framework to express the protocol specification in the form of a Mealy state machine through model learning, so that problems in the target system learning model can be more automatically detected in the subsequent vulnerability analysis process.

[0088] Optionally, step 103 of determining a second finite state machine model catalog according to the input symbol sequence and the second output symbol sequence includes:

[0089] generating a second hypothetical state machine model according to a portion of the input symbol sequence and the corresponding second output symbol sequence, and performing consistency verification on the second hypothetical state machine model;

[0090] If the behavior of the second hypothetical state machine model is inconsistent with the expected behavior, continue to input the input symbol sequence and the second output symbol sequence to update the second hypothetical state machine model; or

[0091] If the behavior of the second hypothetical state machine model is consistent with the expected behavior, the current second hypothetical state machine model is determined to be the sub-second finite state machine model, and the second finite state machine model directory is generated according to all the sub-second finite state machine models.

[0092] In this embodiment, learner 221 performs the same function as learner 211. Based on the learning algorithm, it inputs test stimuli, finds corresponding output results, and returns them to the learner. Based on the input and learned output, the learner automatically learns and performs model consistency verification. Using a consistency algorithm, the learner verifies that the behavior of the second hypothetical state machine model is completely consistent with the expected behavior. If not, verification fails. Learning continues until there are no counterexamples. Otherwise, the final state machine model (the second finite state machine model catalog) that reflects the protocol specification behavior is obtained.

[0093] Protocol specification behavior simulator 222 describes the correspondence between input and output symbol sequences. Unlike first state machine generation module 210, it does not interact with the target system and therefore does not require conversion between symbol information and precise data. Based on the protocol specification, it abstracts the correspondence between input and output symbol sequences that conform to the protocol specification and reflects this relationship in protocol specification behavior simulator 222. Learner 221 sends an input symbol, and protocol specification behavior simulator 222 searches for it and responds with an output symbol to learner 221. This learning process repeats, completing the learning of a sequence of input and output behaviors.

[0094] Optionally, to reduce the complexity of the generated state diagram and facilitate model comparison and vulnerability analysis during protocol specification learning, each time a portion of the input and output behavior (the input symbol sequence and the corresponding second output symbol sequence) in the protocol specification simulator 222 is learned, multiple sub-learning models (sub-second finite state machine models) of the protocol specification are generated. Ultimately, all input symbol sequences are traversed to generate multiple sub-second finite state machine models representing the protocol specification behavior, forming a second finite state machine model directory.

[0095] It should be noted that the protocol specification behavior simulator 222 and the mapper 212 share the same input and output symbol table. The symbol sequence input by learner 221 into the protocol specification behavior simulator 222 must be identical to the symbol sequence input by learner 211 during the model learning process. This ensures that the target system and protocol specification learning models are generated based on the same input stimulus, facilitating subsequent model comparison.

[0096] Optionally, the vulnerability analysis and detection module 230 includes a state diagram conversion module 231 , a state path comparison module 232 and a vulnerability analysis module 233 .

[0097] The first state machine generation module 210 and the second state machine generation module 220 respectively generate Mealy state machine models representing the target system's protocol implementation process and protocol specifications. The vulnerability analysis and detection module 230 can automatically search for inclusion of content from another DFA state machine within a model based on the DFA-encoded state diagram and generate a search report. Therefore, the first finite state machine model corresponding to the target system and the second finite state machine model corresponding to the protocol specification are automatically converted into DFA-encoded state diagrams (first state diagram and second state diagram). A Mealy state machine specifies the relationship between input and output symbols during transmission. Starting from an initial state, each input symbol triggers a sequence of output symbols, bringing the state machine to a new state, where the next input symbol will be processed. A finite automaton is a recognizer that identifies and judges each input character to determine the final state, set of states, and path it can reach. The DFA does not distinguish between input and output; it only defines the set of acceptable symbols.

[0098] Optionally, step 104 generates a first state diagram corresponding to the first finite state machine model and a second state diagram corresponding to the second finite state machine model directory, including:

[0099] Read each first state in the first finite state machine model and the second finite state machine model directory, as well as the input and output corresponding to the first state;

[0100] Determine the second state corresponding to each of the inputs and outputs in the finite automaton model, and generate the first state diagram and the second state diagram according to each of the second states.

[0101] In this embodiment, the concept behind converting a Mealy state machine model into a DFA encoding is as follows: Reading the input of a Mealy state machine jumps to the next state. In the new DFA state, the output symbol generated by the Mealy state machine in the previous state is used as input, read again, and jumps to the next state. This continues in this manner, completing the conversion from the Mealy model to the DFA.

[0102] Optionally, comparing the first state diagram and the second state diagram to determine a target path, and analyzing the target path to determine a vulnerability includes:

[0103] comparing a state path in the first state diagram with each state path in the second state diagram;

[0104] determining the different state paths as the target paths;

[0105] The input sequence corresponding to the target path is re-input into the target system to check for vulnerabilities.

[0106] In this embodiment, after all sub-second finite state machine models of the protocol specification are converted into the second state graphs encoded by DFA, a protocol specification template directory is formed; all first finite state machine models of the target system are converted into the first state graphs encoded by DFA. Then, the first state graph corresponding to the target system is intersected with each second state graph in the protocol specification template directory. If the same path behavior is detected in the first state graph of the target system, it means that the intersecting part is reasonable. Otherwise, it is regarded as suspicious behavior and a detection report is generated. After traversing all the second state graphs, the second state graphs with consistent behavior are counted according to the detection report, and these consistent behavior parts are deleted in the first state graph of the target system, highlighting the inconsistent behavior areas and the state paths not covered by the protocol template, and further manually analyzing these remaining state paths to determine whether they are vulnerabilities, and recording the input sequence that triggers the vulnerability. The validity of the vulnerability is verified on the target system based on the input sequence.

[0107] In one possible embodiment, the host computer software of the Modbus protocol slave is simulated by simulation software, which can perform Modbus communication with other devices. The method of the present invention is described below with respect to the tested software Modbus Slave (target system) and the target protocol Modbus.

[0108] The Modbus protocol state machine generation process of the tested software Modbus Slave includes:

[0109] (1) Based on the different function codes of the Modbus protocol, a Modbus input and output symbol table is developed to represent various Modbus data packets as input and output elements for learners. For example, the request PDU of the Modbus function code 05 contains three parts of information: function code, output address, and output value. The request data packet containing function code 05 corresponds to an input symbol element, defined as FUNC05_REQ(). The output address and output value corresponding to function code 05 are precise data information, which is converted into abstract information corresponding to {valid "V", invalid "UV"}. The output address must be between 0x0000 and 0xFFFF, as the first sub-element of function code 05. The output value is 0xFF00 or 0x0000, as the second sub-element of function code 05. When the output address is within the valid range, it is converted to a valid "V", otherwise it is invalid "UV"; when the output value is a reasonable value, it is converted to a valid "V", otherwise it is invalid "UV". Then a reasonable request information of Modbus function code 05 is represented by input symbols as FUNC05_REQ(V, V). The response data for function code 05 is divided into two categories: a normal response includes function code 05, output address, and output value; an error response includes error code 0x85 and exception codes 01, 02, 03, or 04, corresponding to the four error responses. The output symbol for function code 05 is defined as FUNC05_RES(). The possible values ​​for the first sub-element of FUNC05_RES() are {function code 05 "FC", error code 85 "ERC", other invalid codes "UC"}, and the possible values ​​for the second sub-element are {valid output value "V", exception code 01 "EXC01", exception code 02 "EXC02", exception code 03 "EXC03", exception code 04 "EXC04", other invalid values ​​"UV"}.

[0110] (2) The mapper converts Modbus input and output symbols into precise data information. When a learner issues an input symbol FUNC05_REQ(V, V) based on the defined input and output symbol table, the mapper converts the input symbol into a function code of 05, an output address of a value between 0x0000 and 0xFFFF, and an output value of 0xFF00 or 0x0000. This precise address information is then encapsulated into a complete data packet and sent to the Modbus Slave server.

[0111] (3) After receiving the data packet, the Modbus Slave server responds to it and generates an output data packet.

[0112] (4) The output data packet is first parsed to obtain the precise function code, output address, output value and other information, and then sent back to the mapper.

[0113] (5) The mapper inversely converts the precise data information into output symbols and then sends them back to the learner.

[0114] (6) Repeat the above (2)-(5) process. The learner automatically infers the state machine model based on the input and output information, performs consistency detection, and finally generates the Mealy state machine model of the Modbus Slave.

[0115] The Modbus protocol specification state machine generation process includes:

[0116] (1) According to the Modbus protocol specification, a protocol specification behavior simulator is constructed. The input and output symbol table is consistent with the symbols used in the state machine learning process of ModbusSlave. The protocol specification behavior simulator sets the output symbol information for each input symbol information according to the specification requirements, establishes the corresponding relationship between input and output, and is used to represent the behavior that complies with the Modbus protocol specification. For example, the request information of the Modbus protocol function code 05 can be abstracted as an input symbol FUNC05_REQ(), and FUNC05_REQ(V, UV) indicates that the output address is reasonable and the output value is unreasonable. The response information of the Modbus protocol function code 05 can be abstracted as an output symbol FUNC05_RES(), and ERC in FUNC05_RES(ERC, EXC03) indicates error code 85, and EXC03 indicates that the output value information in the requested data packet is invalid. Then, in the protocol specification behavior simulator, assuming that the input is FUNC05_REQ(V, UV), the output is FUNC05_RES(ERC, EXC03) based on the protocol specification.

[0117] (2) The state machine learning process for the learner is the same as that for the Modbus Slave. During the learning process, the Modbus protocol specification behavior simulator learns a portion of the protocol specification behavior each time, and then learns multiple times to cover all the behaviors of the protocol specification behavior simulator. The segmented learning is to facilitate the subsequent state diagram comparison and analysis. The learner sends an input sequence to the protocol specification behavior simulator, and the protocol specification behavior simulator returns the output. The learner automatically learns and verifies the consistency. After multiple learnings, multiple sub-state machine models are generated, forming a Mealy state machine model directory representing the Modbus protocol specification behavior.

[0118] The vulnerability analysis and detection process includes:

[0119] Convert the Modbus Slave state machine and protocol specification state machine directory generated in the above two steps into a DFA-encoded state diagram.

[0120] Figure 4 Schematic diagram of a first finite state machine model proposed in an embodiment of the present application, Figure 5 This is a schematic diagram of a first state diagram proposed in an embodiment of the present application.

[0121] like Figure 4 、 Figure 5 As shown, for the input and output symbols corresponding to the Modbus function code 05 defined above, a sequence of FUNC05_REQ(V, V) + FUNC05_REQ(V, UV) is input. FUNC05_REQ(V, V) indicates that both the output address and output value are valid. FUNC05_REQ(V, UV) indicates that the output address is valid but the output value is invalid. Therefore, when the input request is valid, the input is FUNC05_REQ(V, V), and according to the protocol specification, the output is FUNC05_RES(FC, V). When the input request output value is invalid, the input is FUNC05_REQ(V, UV), and according to the protocol specification, the output is FUNC05_RES(ERC, EXC03).

[0122] Based on existing methods, this approach automatically detects the presence of each template in the protocol specification's DFA template directory within the Modbus Slave state model. The detection results indicate whether the template exists and, if so, list the input sequences that trigger this path within the Modbus Slave state model. Based on the generated detection results, the matching protocol specification state path is deleted from the Modbus Slave's Mealy state model, filtering out any inconsistencies. The input and output behavior of this portion of the model is then manually analyzed and verified to determine if it represents a vulnerability.

[0123] In order to implement the above embodiments, the present application also proposes an automated vulnerability analysis device based on a protocol specification state machine. Figure 3 This is a schematic diagram of the structure of a vulnerability automatic analysis device based on a protocol specification state machine provided in an embodiment of the present application. Figure 3 As shown, the device includes:

[0124] A data processing module 310 is configured to map the input symbol sequence according to the mapping relationship to generate first mapping data, and input the first mapping data into a target system for processing to obtain feedback data;

[0125] a first state machine model generating module 320, configured to map the feedback data according to the mapping relationship to generate a first output symbol sequence, and determine a first finite state machine model according to the input symbol sequence and the first output symbol sequence, wherein the first finite state machine model is a finite state machine model of the target system;

[0126] a second state machine model generating module 330, configured to map the input symbol sequence according to a protocol specification to generate second mapping data, and determine a second finite state machine model directory according to the input symbol sequence and the second output symbol sequence, wherein the second finite state machine model directory includes a plurality of second sub-finite state machine models corresponding to the protocol specification;

[0127] The vulnerability detection module 340 is used to generate a first state diagram corresponding to the first finite state machine model and a second state diagram corresponding to the second finite state machine model directory, compare the first state diagram and the second state diagram to determine the target path, and analyze the target path to determine the vulnerability.

[0128] In order to implement the above embodiments, the present application also proposes an electronic device, comprising: a processor, and a memory communicatively connected to the processor; the memory stores computer-executable instructions; the processor executes the computer-executable instructions stored in the memory to implement the method provided by the above embodiments.

[0129] In order to implement the above embodiments, the present application also proposes a computer-readable storage medium, in which computer-executable instructions are stored. When the computer-executable instructions are executed by a processor, they are used to implement the methods provided by the above embodiments.

[0130] In order to implement the above embodiments, the present application also proposes a computer program product, including a computer program, which implements the methods provided by the above embodiments when executed by a processor.

[0131] The collection, storage, use, processing, transmission, provision and disclosure of user personal information involved in this application are in compliance with relevant laws and regulations and do not violate public order and good morals.

[0132] It is important to note that personal information collected from users should be used for legitimate and reasonable purposes and should not be shared or sold beyond these legitimate uses. Furthermore, such collection / sharing should be conducted only after receiving the user's informed consent, including but not limited to notifying the user to read the user agreement / user notice and sign an agreement / authorization that includes the relevant user information before using the feature. Furthermore, any necessary steps must be taken to safeguard and secure access to such personal information and ensure that others with access to personal information comply with its privacy policy and procedures.

[0133] This application contemplates providing implementations that allow users to selectively block the use or access of personal information data. Specifically, this disclosure contemplates providing hardware and / or software to prevent or block access to such personal information data. Risks can be minimized by limiting data collection and deleting data once it is no longer needed. Furthermore, where applicable, such personal information can be de-identified to protect user privacy.

[0134] In the descriptions of the foregoing embodiments, the reference terms "one embodiment", "some embodiments", "example", "specific example", or "some examples" mean that the specific features, structures, materials or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present application. In this specification, the schematic expressions of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described may be combined in any one or more embodiments or examples in a suitable manner. In addition, those skilled in the art may combine and combine different embodiments or examples described in this specification and features of different embodiments or examples, unless they are mutually inconsistent.

[0135] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of the technical features being referred to. Thus, a feature defined as "first" or "second" may explicitly or implicitly include at least one of such features. Throughout the description of this application, "plurality" means at least two, for example, two, three, etc., unless otherwise specifically defined.

[0136] Any process or method description in a flowchart or otherwise described herein may be understood to represent a module, segment or portion of code comprising one or more executable instructions for implementing the steps of a custom logical function or process, and the scope of the preferred embodiments of the present application includes alternative implementations in which functions may be performed out of the order shown or discussed, including performing functions in a substantially simultaneous manner or in the reverse order depending on the functions involved, which should be understood by those skilled in the art to which the embodiments of the present application belong.

[0137] The logic and / or steps represented in a flowchart or otherwise described herein, for example, can be considered a sequenced list of executable instructions for implementing the logical functions, and can be embodied in any computer-readable medium for use by, or in conjunction with, an instruction execution system, apparatus, or device (e.g., a computer-based system, a system including a processor, or other system that can fetch and execute instructions from an instruction execution system, apparatus, or device). For purposes of this specification, a "computer-readable medium" is any device that can contain, store, communicate, propagate, or transport a program for use by, or in conjunction with, an instruction execution system, apparatus, or device. More specific examples (not exhaustive) of computer-readable media include: an electrical connection with one or more wires (electronic devices), a portable computer disk cartridge (magnetic device), random access memory (RAM), read-only memory (ROM), erasable and programmable read-only memory (EPROM or flash memory), fiber optic devices, and a portable compact disc read-only memory (CDROM). Furthermore, the computer-readable medium may even be paper or other suitable medium on which the program is printed, since the program may be obtained electronically, for example, by optically scanning the paper or other medium and then editing, interpreting or processing it in another suitable manner if necessary, and then storing it in a computer memory.

[0138] It should be understood that various parts of this application can be implemented using hardware, software, firmware, or a combination thereof. In the above-described embodiments, multiple steps or methods can be implemented using software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented using hardware, as in another embodiment, any one of the following technologies known in the art or a combination thereof can be used: a discrete logic circuit having logic gate circuits for implementing logical functions on data signals, an application-specific integrated circuit having suitable combinational logic gate circuits, a programmable gate array (PGA), a field-programmable gate array (FPGA), etc.

[0139] Those skilled in the art will understand that all or part of the steps in the method of the above embodiment can be completed by instructing related hardware through a program, and the program can be stored in a computer-readable storage medium. When the program is executed, it includes one or a combination of the steps of the method embodiment.

[0140] In addition, the functional units in the various embodiments of the present application may be integrated into a processing module, or each unit may exist physically separately, or two or more units may be integrated into a module. The above-mentioned integrated module may be implemented in the form of hardware or in the form of a software functional module. If the integrated module is implemented in the form of a software functional module and sold or used as an independent product, it may also be stored in a computer-readable storage medium.

[0141] The storage medium mentioned above may be a read-only memory, a magnetic disk, or an optical disk, etc. Although the embodiments of the present application have been shown and described above, it is understood that the above embodiments are exemplary and should not be construed as limiting the present application. Persons skilled in the art may make changes, modifications, substitutions, and variations to the above embodiments within the scope of the present application.

Claims

1. A vulnerability automated analysis method based on a protocol specification state machine, characterized in that: The following steps are involved: Mapping the input symbol sequence according to the mapping relationship to generate first mapping data, inputting the first mapping data into a target system for processing to obtain feedback data, wherein the first mapping data is accurate data for the target system; Mapping the feedback data according to the mapping relationship to generate a first output symbol sequence, and determining a first finite state machine model according to the input symbol sequence and the first output symbol sequence, wherein the first finite state machine model is a finite state machine model of the target system; Mapping the input symbol sequence according to the protocol specification to generate second mapping data, inputting the second mapping data into a protocol specification behavior simulator to generate a second output symbol sequence, and determining a second finite state machine model directory based on the input symbol sequence and the second output symbol sequence, wherein the second finite state machine model directory includes a plurality of sub-second finite state machine models corresponding to the protocol specification, wherein the second mapping data is a symbol for the protocol specification, and the protocol specification behavior simulator has a correspondence between the input symbol sequence and the output symbol sequence that conforms to the protocol specification; Generate a first state diagram corresponding to the first finite state machine model and a second state diagram corresponding to the second finite state machine model directory, compare the first state diagram and the second state diagram to determine a target path, and analyze the target path to determine vulnerabilities.

2. The method according to claim 1, characterized in that The step of generating the input symbol sequence comprises: According to the protocol interaction characteristics, set the input symbol table and output symbol table of the protocol; A plurality of input symbols are selected from the input symbol table and an order of the input symbols is determined to generate the input symbol sequence.

3. The method according to claim 2, characterized in that The step of inputting the first mapping data into a target system for processing and then obtaining feedback data includes: generating a communication data packet recognizable by the target system according to the first mapping data; The communication data packet is input into the target system.

4. The method according to claim 3, characterized in that The determining a first finite state machine model according to the input symbol sequence and the first output symbol sequence includes: generating a first hypothetical state machine model according to all the input symbol sequences and the corresponding first output symbol sequences, and performing consistency verification on the first hypothetical state machine model; If the behavior of the first hypothetical state machine model is inconsistent with the expected behavior, continue to input the input symbol sequence and the first output symbol sequence to update the first hypothetical state machine model; or If the behavior of the first hypothetical state machine model is consistent with the expected behavior, the current first hypothetical state machine model is determined to be the first finite state machine model.

5. The method according to claim 1, wherein Determining a second finite state machine model catalog according to the input symbol sequence and the second output symbol sequence includes: generating a second hypothetical state machine model according to part of the input symbol sequence and the corresponding second output symbol sequence, and performing consistency verification on the second hypothetical state machine model; If the behavior of the second hypothetical state machine model is inconsistent with the expected behavior, continue to input the input symbol sequence and the second output symbol sequence to update the second hypothetical state machine model; or If the behavior of the second hypothetical state machine model is consistent with the expected behavior, the current second hypothetical state machine model is determined to be the sub-second finite state machine model, and the second finite state machine model directory is generated according to all the sub-second finite state machine models.

6. The method according to any one of claims 1 to 5, characterized in that The generating of a first state diagram corresponding to the first finite state machine model and a second state diagram corresponding to the second finite state machine model directory includes: Read each first state in the first finite state machine model and the second finite state machine model directory, as well as the input and output corresponding to the first state; Determine the second state corresponding to each of the inputs and outputs in the finite automaton model, and generate the first state diagram and the second state diagram according to each of the second states.

7. The method according to claim 6, characterized in that The comparing the first state diagram and the second state diagram to determine a target path, and analyzing the target path to determine a vulnerability, includes: comparing a state path in the first state diagram with each state path in the second state diagram; determining the different state paths as the target paths; The input sequence corresponding to the target path is re-input into the target system to check for vulnerabilities.

8. A vulnerability automated analysis device based on a protocol specification state machine, characterized in that: include: a data processing module, configured to map the input symbol sequence according to the mapping relationship to generate first mapping data, input the first mapping data into a target system for processing, and obtain feedback data, wherein the first mapping data is accurate data for the target system; a first state machine model generating module, configured to map the feedback data according to the mapping relationship to generate a first output symbol sequence, and determine a first finite state machine model according to the input symbol sequence and the first output symbol sequence, wherein the first finite state machine model is a finite state machine model of the target system; a second state machine model generation module, configured to map the input symbol sequence according to the protocol specification to generate second mapping data, input the second mapping data into a protocol specification behavior simulator to generate a second output symbol sequence, and determine a second finite state machine model directory based on the input symbol sequence and the second output symbol sequence, wherein the second finite state machine model directory includes a plurality of second sub-finite state machine models corresponding to the protocol specification, wherein the second mapping data is a symbol for the protocol specification, and the protocol specification behavior simulator has a correspondence between the input symbol sequence and the output symbol sequence that conforms to the protocol specification; A vulnerability detection module is used to generate a first state diagram corresponding to the first finite state machine model and a second state diagram corresponding to the second finite state machine model directory, compare the first state diagram and the second state diagram to determine the target path, and analyze the target path to determine the vulnerability.

9. An electronic device, characterized in that: include: a processor, and a memory communicatively connected to the processor; The memory stores computer-executable instructions; The processor executes the computer-executable instructions stored in the memory to implement the method according to any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer-executable instructions, which are used to implement the method according to any one of claims 1 to 7 when executed by a processor.

11. A computer program product, characterized in that The invention comprises a computer program, which implements the method according to any one of claims 1 to 7 when being executed by a processor.

Citation Information

Patent Citations

  • Regularization state machine model design method with stateful protocol

    CN104142888A

  • Network protocol security test evaluation method based on model learning

    CN111092775A