Automatic fault injection method and system of C language system
Through command line tools and C language support modules, the fault injection instructions are parsed, combined with C language chaos tools and Frida-core-devkit toolkit, automated fault injection into the C language system is achieved, solving the inefficiency problem in traditional methods, and improving the efficiency and security of fault detection.
Patent Information
- Application Number
- CN202510385218.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-28
- Publication Date
- 2025-07-18
AI Technical Summary
It is difficult to realize automated fault injection into C language systems in the prior art, resulting in inefficient fault detection, and traditional methods such as GDB in production environments have performance impacts, security risks and unpredictability.
The command line tool and C language support module are used to parse fault injection instructions, combine C language chaos tools and Frida-core-devkit toolkit to automatically inject fault code into the target process, and achieve fast and batch fault injection through inline hooks and FIFO communication queues.
It realizes automatic fault injection into the C language system, improves fault detection efficiency, reduces manpower consumption, ensures operation safety and stability, and reduces the error rate of manual operation.
Smart Images

Figure CN120336054A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of fault detection, and more specifically, to an automated fault injection method and system for a C language system. Background Art
[0002] With the rise of microservices and distributed architectures, the increasing complexity of system architectures and the introduction of new technologies are challenging system stability. In a real production environment, various unpredictable events are inevitable, and the stable operation ability of the system needs to be verified. For example: when abnormalities occur in the basic environment, such as delays or lags in disk input / output operations, full memory occupancy, unstable network, etc., can each layer of services handle it normally? When the scale of a distributed system exceeds a certain level, will a failure of any node, component, or sub-service cause an avalanche of the entire system? When a connection timeout occurs, is there a suitable connection retry mechanism to ensure the stable operation of the service? When the system undergoes upgrades, restarts, or switches, will there be accumulated messages, incorrect long connections, etc. that cannot be processed? When a system failure occurs, are the effectiveness and timeliness of the operation and maintenance personnel's disposal plans in line with expectations? Can various platform tools effectively support it? Facing such problems, traditional testing and rehearsal methods cannot meet the requirements, and means for discovering system hidden dangers in advance need to be further improved. Currently, chaos engineering has gradually become an effective method recognized in the industry for improving system stability.
[0003] Chaos Engineering is to actively inject abnormal states or disturbances of software or hardware into the system by designing and executing a series of experiments, helping us discover potential vulnerable links in the system that may lead to disasters, and driving us to actively solve the problems existing in these links.
[0004] The implementation of chaos engineering needs to solve two basic problems: how to find vulnerable points for fault injection? How to perform fault injection? The same is true for the chaos implementation of many business systems: for important business systems, the system code volume is large, the business is complex, and the average number of system transaction types is 100+. How to quickly find possible vulnerable points? What kind of faults should be injected into the vulnerable points for verification? Currently, many important systems are developed in C language, and the industry currently does not support fault injection for C language. How to achieve automated fault injection for C language systems is a difficult problem that urgently needs to be solved.
[0005] Currently, there is no open-source solution for the fault injection ability of C language systems in the industry. There is a basic solution for a similar C++ language: Chaosblade-Exec-CPlus.
[0006] Chaosblade-Exec-CPlus is a chaos engineering experiment framework for the C++ language in the chaostool community. It provides a set of tools and libraries for injecting faults and exceptions into C++ programs to simulate instability and abnormal situations in various scenarios, including line delays, variable modifications, and error returns. Among them, the C++ language fault injection solution of Chaosblade-Exec-CPlus uses the Expect tool for automated interactive tasks, attaches to the process through the GDB tool, and then injects faults into the program by setting breakpoints and modifying the program state during runtime.
[0007] When performing injection, first determine the type of operation, then specify the target process to attach to, the location of the injection breakpoint, and related parameters, combine the except script to be executed, and execute it. The Execpt script will start GDB and sequentially execute the script to achieve fault injection.
[0008] However, using GDB for fault injection in a production environment is generally highly discouraged because GDB is a debugger and it is not designed to run in a production environment. Using GDB for fault injection in a production environment may cause the following problems:
[0009] 1. GDB will monitor and intervene in the execution of the program in real time during program execution, which will introduce additional overhead and delays and affect the performance in the production environment.
[0010] 2. GDB's intervention in the execution of the program may cause the program to exhibit unexpected behaviors, including crashes or data corruption, which will have a serious impact on the stability of the production environment.
[0011] 3. Using GDB in a production environment increases the security risk of the system because it requires embedding debugging information by specifying compilation parameters during the compilation stage. The resulting binary program may expose the internal state and sensitive information of the program, which can be exploited by attackers for malicious operations.
[0012] 4. The way GDB intervenes in program execution is manual and interactive, and requires intervention while observing the program execution in real time. So when using a script for automated sequential execution, once a certain command fails or encounters an exception, the entire operation process will become unpredictable and prone to unexpected situations.
[0013] 5. It is necessary to set up GDB and Execpt in the production environment in advance, resulting in extra work and load.
[0014] In addition, it is required that the program to be injected is in debug mode. For many old business systems, the cost of packaging the debug version is too high.
[0015] Secondly, the current automated fault injection solutions are mainly for classic scenarios such as high-availability scenarios, databases, and middleware. Rules are matched according to the system architecture layout, and then scenarios are automatically executed in batches. For code-level fault injection in application systems, in terms of basic capabilities, Java classes are relatively mature, but the injection execution is mainly manual. There is no mature solution for automatic fault injection, especially for C language systems.
[0016] Moreover, there are the following disadvantages in manually executing code-level fault injection in business systems:
[0017] 1. It consumes manpower and requires complete manual analysis of where in the system fault injection should be performed. When the complexity of a business system reaches a certain level, this task is almost impossible to achieve.
[0018] 2. After manually analyzing where to perform fault injection, it is also necessary to manually determine what type of fault to inject. This requires people to continuously perform manual attempts, verification, and optimization, resulting in low efficiency.
[0019] In summary, there is a problem in the related art that it is difficult to achieve automated fault injection for C language systems. Summary of the Invention
[0020] The embodiments of the present invention provide an automated fault injection method and system for a C language system, which at least solve the problem in the related art that it is difficult to achieve automated fault injection for a C language system.
[0021] According to an embodiment of the present invention, an automated fault injection method for a C language system is provided, including:
[0022] Obtaining a fault injection instruction based on a command-line tool;
[0023] Parsing the fault injection instruction based on a C language support module, and based on the parsing result, passing a target process written in C language through the command-line tool and calling a C language chaos tool to create a C language chaos tool process; wherein, the C language chaos tool process contains fault codes;
[0024] Injecting the fault code into the target process by loading the Frida-core-devkit tool package based on the C language chaos tool.
[0025] According to another embodiment of the present invention, an automated fault injection device for a C language system is provided, including:
[0026] A command-line tool for obtaining fault injection instructions;
[0027] A C language support module for parsing the fault injection instructions, enabling the command-line tool to pass a target process written in C language based on the parsing result and call a C language chaos tool to create a C language chaos tool process; wherein, the C language chaos tool process contains fault codes;
[0028] The C language chaos tool is used to load the Frida-core-devkit toolkit to inject the fault code into the target process.
[0029] According to another embodiment of the present invention, there is also provided a computer-readable storage medium, in which a computer program is stored, and wherein the computer program is set to execute the steps in any one of the above method embodiments when running.
[0030] According to another embodiment of the present invention, there is also provided an electronic device, including a memory and a processor, a computer program is stored in the memory, and the processor is set to run the computer program to execute the steps in any one of the above method embodiments.
[0031] According to another embodiment of the present invention, there is also provided a computer program product, including computer instructions, and the steps in any one of the above method embodiments are implemented when the computer instructions are executed by a processor.
[0032] Through one of the embodiments of the present invention, due to the technical means of effectively integrating the command-line tool and the C language support module, the C language support module can be used to automatically interpret and analyze the fault injection instructions written in C language, so that the command-line tool can quickly and batch-interpret the fault injection instructions, and then combine the capabilities of the C language chaos tool and the Frida-core-devkit toolkit to achieve automatic fault injection into the C language system. Therefore, the problem of difficult automatic fault injection into the C language system in the related art is solved, and the efficiency of fault detection of the C language system is improved. BRIEF DESCRIPTION OF THE DRAWINGS
[0033] The drawings described herein are used to provide a further understanding of the present invention, form a part of the present invention, and the schematic embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute an improper limitation to the present invention. In the drawings:
[0034] Figure 1 It is a schematic structural diagram of a computer terminal for executing the automatic fault injection method of the C language system in an embodiment of the present invention;
[0035] Figure 2 It is a flowchart of an automated fault injection method for a C language system according to an embodiment of the present invention;
[0036] Figure 3 It is a schematic diagram of a simulation scenario of the flow process of information involved in the automated fault injection method for a C language system according to an embodiment of the present invention in an exemplary system structure;
[0037] Figure 4 It is a flowchart of a method for establishing communication between a C language chaos tool process and a target process according to an embodiment of the present invention;
[0038] Figure 5 It is a schematic diagram of the structure of the code stack of a C language chaos tool process and a target process according to an embodiment of the present invention;
[0039] Figure 6 It is a schematic diagram of the code stack when a target function without injected fault code is normally called according to an embodiment of the present invention;
[0040] Figure 7 It is a flowchart of a method for injecting fault code into a target function based on a target process according to an embodiment of the present invention;
[0041] Figure 8 It is a schematic diagram of the code stack of a target function of a target process injected with fault code according to an embodiment of the present invention;
[0042] Figure 9 It is a schematic diagram of the process of generating a fault code with a basic sleep function according to an embodiment of the present invention;
[0043] Figure 10 It is a schematic diagram of the process of injecting a fault code with a basic sleep function into a target process according to an embodiment of the present invention;
[0044] Figure 11 It is a flowchart of a method for closing and deleting a C language chaos tool process according to an embodiment of the present invention;
[0045] Figure 12 It is a schematic diagram of the process of closing and deleting a C language chaos tool process according to an embodiment of the present invention;
[0046] Figure 13 It is a schematic diagram of recommending an experimental scenario for a target process through a scenario recommendation model according to an embodiment of the present invention;
[0047] Figure 14 It is a schematic diagram of the structure of an automated fault injection system for a C language system according to an embodiment of the present invention Figure 1 ;
[0048] Figure 15Schematic structure of the automated fault injection system for the C language system according to an embodiment of the present invention Figure 2 。 Detailed implementation manners
[0049] The present invention will be described in detail below with reference to the accompanying drawings and in conjunction with embodiments. It should be noted that, without conflict, the embodiments in the present invention and the features in the embodiments may be combined with each other.
[0050] It should be noted that the terms "first", "second", etc. in the description and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily need to describe a specific order or sequence.
[0051] The method embodiments provided by the embodiments of the present invention can be executed on a mobile terminal, a computer terminal or a similar computing device. Taking running on a computer terminal as an example, Figure 1 is a schematic structural diagram of a computer terminal for executing the automated fault injection method of the C language system according to an embodiment of the present invention, as Figure 1 shown. The computer terminal may include one or more ( Figure 1 only one is shown in Figure 1 ) processors 102 (the processors 102 may include, but are not limited to, processing devices such as a microprocessor MCU or a programmable logic device FPGA) and a memory 104 for storing data. Optionally, the above computer terminal may further include a transmission device 106 for communication functions and an input / output device 108. Those of ordinary skill in the art can understand that Figure 1 the structure shown in Figure 1 is only schematic and does not limit the structure of the above computer terminal. For example, the computer terminal may further include more or fewer components than those shown in
[0052] or have a different configuration from that shown in
[0053] The memory 104 can be used to store computer programs, for example, software programs and modules of application software, such as the computer program corresponding to the automated fault injection method for executing the C language system in the embodiments of the present invention. The processor 102 executes various functional applications and data processing by running the computer program stored in the memory 104, that is, implements the above method. The memory 104 may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memories, or other non-volatile solid-state memories. In some instances, the memory 104 may further include a memory remotely disposed relative to the processor 102, and these remote memories may be connected to the computer terminal through a network. Examples of the above network include, but are not limited to, the Internet, an enterprise intranet, a local area network, a mobile communication network, and their combinations.
[0053] The transmission device 106 is used to receive or send data via a network. Specific examples of the above network may include a wireless network provided by a communication provider of a computer terminal. In one example, the transmission device 106 includes a network adapter (Network Interface Controller, abbreviated as NIC), which can be connected to other network devices through a gateway to communicate with the Internet. In one example, the transmission device 106 can be a Radio Frequency (RF) module, which is used to communicate with the Internet wirelessly.
[0054] In this embodiment, an automated fault injection method for a C language system is provided. Figure 2 It is a flowchart of the automated fault injection method for a C language system according to an embodiment of the present invention. Figure 3 It is a schematic diagram of a simulation scenario of the information flow process involved in the automated fault injection method for a C language system according to an embodiment of the present invention in an exemplary system structure, as Figure 2 and Figure 3 shown. The process includes:
[0055] Step S201, obtaining a fault injection instruction based on a command-line tool;
[0056] In one implementation, the command-line tool is Blade.
[0057] In an exemplary implementation, a user can input a fault injection instruction through the command-line tool Blade of the chaos tool chaostool, so that the command-line tool Blade obtains the fault injection instruction and sends the fault injection instruction to the C language support module. Among them, the fault injection instruction contains the code for creating a C language chaos tool process and the address information of the target process.
[0058] Step S202, parsing the fault injection instruction based on the C language support module, and passing the target process written in C language and calling the C language chaos tool to create a C language chaos tool process based on the parsing result; wherein, the C language chaos tool process contains fault codes;
[0059] In an exemplary implementation, the C language support module receives the fault injection instruction and parses the fault injection instruction to obtain a parsing result in a format that can be recognized by the command-line tool Blade. The command-line tool Blade then passes the information of the target process written in C language to the C language chaos tool (Chaos_C tool) and the Frida-core-devkit toolkit based on the parsing result, and calls the C language chaos tool to create a C language chaos tool process based on the parsing result.
[0060] Step S203: Based on the C language chaos tool, load the Frida-core-devkit toolkit to inject fault codes into the target process.
[0061] In an exemplary embodiment, the C language chaos tool creates and executes a C language chaos tool process, and loads the Frida-core-devkit toolkit to inject fault codes into the target process.
[0062] Through the above steps S201 to S203, due to the technical means of effectively integrating the command-line tool and the C language support module, the C language support module can be used to automatically interpret and analyze the fault injection instructions written in C language, so that the command-line tool can quickly and batch-interpret the fault injection instructions, and then combine the capabilities of the C language chaos tool and the Frida-core-devkit toolkit to achieve automatic fault injection into the C language system. Therefore, the problem of difficult to achieve automatic fault injection into the C language system in the related technology is solved, and the efficiency of fault detection of the C language system is improved.
[0063] Figure 4 It is a flowchart of a method for establishing communication between a C language chaos tool process and a target process according to an embodiment of the present invention. Figure 5 It is a schematic structural diagram of the code stacks of a C language chaos tool process and a target process according to an embodiment of the present invention. As Figure 4 and Figure 5 shown, in one embodiment, after passing the target process written in C language through the command-line tool based on the parsing result and calling the C language chaos tool to create a C language chaos tool process, it further includes:
[0064] Step S401: Configure memory with a preset length in the target process, load and execute the code of a preset dynamic library in the memory to create a thread.
[0065] In an exemplary embodiment, as Figure 5 shown, for example, configure memory with a preset length between pthread and heap in the code stack of the target process, and load and execute Frida_agent (the code of Frida_agent.so) of Frida_agent.so (preset dynamic library) at this memory location, then the thread Frida is created.
[0066] Step S402: Based on the first-in-first-out (FIFO) communication queue, use the thread to establish communication between the C language chaos tool process and the target process.
[0067] In an exemplary embodiment, as Figure 5As shown, the C language chaos tool process establishes communication with the target process using the FIFO communication queue and the thread Frida, that is, the FIFO communication queue and the thread Frida can be used to inject fault codes into the target process.
[0068] In one implementation, injecting fault codes into the target process based on the C language chaos tool by loading the Frida-core-devkit toolkit includes:
[0069] Obtain the target function of the target process to inject fault codes based on the target function.
[0070] Figure 6 It is a schematic diagram of the code stack when the target function according to an embodiment of the present invention is normally called without being injected with fault codes, as Figure 6 shown. In one exemplary implementation, the encoding of the call print method is e8 04 03 01 01. Its function is to call the target function print (in x86 assembly, the machine code encoding of the call instruction is usually E8, followed by a relative offset indicating the offset of the target address to be called relative to the current instruction. For example, E8 xx xx xxxx, where xx xx xx xx is a 32-bit offset address used to indicate the position of the target address relative to the current instruction).
[0071] Figure 7 It is a flowchart of the method for injecting fault codes based on the target function of the target process according to an embodiment of the present invention. Figure 8 It is a schematic diagram of the code stack of the target function of the target process injected with fault codes according to an embodiment of the present invention, as Figure 7 and Figure 8 shown. In one implementation, obtaining the target function of the target process to inject fault codes based on the target function includes:
[0072] Step S701, install an inline hook at the entry address of the target function based on the Frida-core-devkit toolkit, so that the starting position of the target function of the target process is replaced with a jump instruction pointing to the hook function;
[0073] In one exemplary implementation, as Figure 8 shown, install an inline hook at the entry address of print (the target function) based on the Frida-core-devkit toolkit, so that the starting position of the target function of the target process is replaced with a jump instruction pointing to trampoline (the hook function).
[0074] Step S702, inject fault codes into the hook function;
[0075] In an exemplary embodiment, as Figure 8 shown, inject the on_enter_callback function (fault code) into the trampoline (hook function).
[0076] Step S703, when the target process calls the hooked target function, transfer the execution flow to the hook function to run the hook function injected with the fault code.
[0077] In an exemplary embodiment, when the target process runs to the code of "Jumptrampoline" in print (target function), jump to run the trampoline (hook function) to run the trampoline (hook function) injected with the on_enter_callback function (fault code).
[0078] In one embodiment, after injecting the fault code into the hook function, it further includes:
[0079] After the fault code is executed, jump back to the execution position of the target function to continue executing the target function.
[0080] In an exemplary embodiment, as Figure 8 shown, when the hook function injected with the fault code finishes running, jump back to the "next_instruction" code segment of the target function based on the "Jump next_instruction" code in the hook function to continue running the target function print.
[0081] Figure 9 is a schematic diagram of the process of generating a fault code with a basic sleep function according to an embodiment of the present invention, as Figure 9 shown, which shows the implementation of the callback function using the JavaScript script of Frida and the injection function logic is automatically generated through the parameter matching injection scheme of the chaosblade command-line tool. By defining the basic script template and parametric substitution, the code for different fault injection requirements can be generated flexibly and efficiently, improving the efficiency and accuracy of fault injection.
[0082] Specifically, it includes:
[0083] 1. Select the defined basic script template for the injection fault according to the injection type:
[0084] Implementation method:
[0085] Define the basic script template: For different types of fault injection, define the basic JavaScript script template. Placeholders are used in these templates to represent the parameters that will be dynamically replaced.
[0086] For example, the basic template could be:
[0087] JavaScript copy
[0088]
[0089] Where %s and %f are placeholders for the injected function name and sleep time respectively.
[0090] Achieved effects:
[0091] Flexibility: By defining the basic template, it is possible to flexibly support various types of fault injection, such as delays, return value replacement, parameter replacement, etc.
[0092] Maintainability: Centralized management of the templates makes it easier to maintain and update the injection logic.
[0093] 2. Combine into the target injection code through formatted parameter injection based on the template:
[0094] Implementation method:
[0095] Parameter matching and replacement: According to the parameters input by the user through the chaosblade command-line tool, match these parameters to the corresponding placeholders in the basic template to generate the final injection code.
[0096] For example, if the user specifies that the injected function is print and the sleep time is 3000, then %s in the template will be replaced by print and %f will be replaced by 3000, and the generated code will be as follows:
[0097] JavaScript copy
[0098]
[0099]
[0100] Achieved effects:
[0101] Automation: Through parameterization, it is possible to automatically generate code for different injection requirements, reducing the workload and error rate of manual code writing.
[0102] Efficiency: The generation process is fast and accurate, improving the efficiency of fault injection.
[0103] For example, to generate an injection script for a basic sleep function, the specific steps are as follows:
[0104] Select the basic template:
[0105] JavaScript copy
[0106]
[0107] Parameter matching and replacement:
[0108] Parameter 1: print (injection function)
[0109] Parameter 2: 3000 (sleep time)
[0110] The code after replacement:
[0111] JavaScript copy
[0112]
[0113] Figure 10 It is a schematic diagram of the process of injecting a fault code with a basic sleep function into a target process according to an embodiment of the present invention, as Figure 10 shown, which shows the complete process of creating a fault injection task using the blade command. The chaos_c process is created through the blade command. The chaos_c process parses the parameters to generate an injection script, and uses the API of Frida to inject the fault into the target process. The whole process is efficient and automated, ensuring the accuracy and reliability of the fault injection task. At the same time, the relevant information is saved through the database for subsequent management and monitoring.
[0114] Specifically, it includes:
[0115] 1. Use the blade create c command to create a fault injection task:
[0116] Implementation method: The user creates a fault injection task through the blade create c command and specifies the detailed configuration of the fault injection through command-line parameters. For example:
[0117] bash copy
[0118] blade create c delay--process hello--lib libc.so--function print--delaytype enter--time 3000
[0119] --process hello: Specify the target process as hello.
[0120] --lib libc.so: Specify the dynamic library where the target function is located as libc.so.
[0121] --function print: Specify the target function as print.
[0122] --delaytype enter: Specify the delay type as when the function enters.
[0123] --time 3000: Specify the delay time as 3000 milliseconds.
[0124] Achieved effects:
[0125] Command-line interface: Through the command-line tool, users can flexibly configure the fault injection task without the need for complex graphical interface operations.
[0126] Parameterized configuration: Command-line parameters make the configuration of the fault injection task more precise and controllable.
[0127] 2. Create the chaos_c process to execute the injection of C language faults:
[0128] Implementation method: After receiving the command, the blade tool will create a chaos_c process to specifically execute the injection task of C language faults. This process is responsible for all subsequent injection operations.
[0129] Achieved effects:
[0130] Dedicated process: By creating a dedicated chaos_c process, the fault injection task is separated from the user's command-line operations, improving the security and stability of the operations.
[0131] Centralized management: The chaos_c process can centrally manage the fault injection task, facilitating subsequent monitoring and destruction.
[0132] 3. The chaos_c command generates a callback script by parsing parameters:
[0133] Implementation method: The chaos_c process generates the corresponding injection script by parsing the incoming parameters. The script specifies the function to be intercepted and the delay operation to be executed when the function enters. For example:
[0134] bash copy
[0135] chaos_c --type delay --process hello --lib libc.so --function print --delaytype enter --value 3000
[0136] --type delay: Specify the fault type as delay.
[0137] --process hello: Specify the target process as hello.
[0138] --lib libc.so: Specify the dynamic library where the target function is located as libc.so.
[0139] --function print: Specify the target function as print.
[0140] --delaytype enter: Specify the delay type as when the function enters.
[0141] --value 3000: Specify the delay time as 3000 milliseconds.
[0142] Achieved effects:
[0143] Automated script generation: Automatically generate injection scripts through parameter parsing, reducing the workload and error rate of manual script writing.
[0144] Flexible configuration: Users can generate multiple fault injection scripts through different parameter combinations to meet different test requirements.
[0145] 4. chaos_c calls the Frida API to inject faults:
[0146] Implementation method: The chaos_c process uses the API provided by Frida to apply the generated injection script to the target process hello. Specifically, intercept the call of the print function through the Interceptor.attach method and perform a delay operation when the function enters. For example:
[0147] JavaScript copy
[0148]
[0149] Achieved effects:
[0150] Dynamic injection: Through the Frida API, fault code can be dynamically injected while the target process is running, without the need to recompile or restart the target process.
[0151] Precise control: The location and behavior of fault injection can be precisely controlled, for example, performing specific operations when the function enters or returns.
[0152] 5. After creating the chaos_c process, blade will save relevant information to the database and output relevant information:
[0153] Implementation method: After the blade tool creates the chaos_c process, it will save the relevant fault information to the database for subsequent query and management. Meanwhile, blade will output relevant confirmation information to prompt the user that the fault injection task has been successfully created.
[0154] Achieved effect:
[0155] Information saving: Save the relevant information of the fault injection task to the database for subsequent query, monitoring, and management.
[0156] User feedback: By outputting confirmation information, users can timely understand the creation status of the task, improving the transparency of operations and the user experience.
[0157] Figure 11 It is a flowchart of the method for closing and deleting the C language chaos tool process according to an embodiment of the present invention. Figure 12 It is a schematic diagram of the process for closing and deleting the C language chaos tool process according to an embodiment of the present invention. As Figure 11 and Figure 12 shown, in one implementation, when the target process calls the hooked target function, the execution flow is transferred to the hook function. After running the hook function injected with the fault code, it further includes:
[0158] Step S1101, obtain the destruction request. Among them, the parsing result includes the destruction request, and the destruction request is set with the mapping relationship between the C language chaos tool process and the target process.
[0159] In an exemplary implementation, as Figure 12 shown, the destruction request can be "blade destroy uuid". Among them, uuid is included in the parsing result, and this parsing result can be stored in the database. Therefore, uuid can be obtained from the database. The parsing result includes the mapping relationship between the destruction request and the C language chaos tool process and the target process.
[0160] Step S1102, send a shutdown signal based on the destruction request.
[0161] In an exemplary implementation, as Figure 12 shown, generate and send a SIGTERM signal (shutdown signal) based on the destruction request "blade destroy uuid".
[0162] Step S1103, close and delete the C language chaos tool process based on the shutdown signal.
[0163] In an exemplary implementation, as Figure 12As shown, the Chaos_C tool process (C language chaos tool process) is closed and deleted based on the SIGTERM signal (shutdown signal).
[0164] The following uses examples to explain the usage scenarios of the above-mentioned automated fault injection method for the C language system:
[0165] In one implementation, before obtaining the fault injection instruction, an experimental scenario is recommended for the target process through a scenario recommendation model.
[0166] Figure 13 It is a schematic diagram of recommending an experimental scenario for the target process through a scenario recommendation model according to an embodiment of the present invention, as Figure 13 shown, in an exemplary implementation, an experimental scenario is recommended for the target process through a scenario recommendation model:
[0167] Based on the scenario recommendation model for a single fault, the recommended sorting results for each single fault are obtained;
[0168] The scenario recommendation results of multiple faults are sorted together to obtain the global fault scenario sorting result;
[0169] Based on the requirements of the business scenario, the aggregated sorting results are filtered to obtain experimental scenarios under different business requirements, and specific business requirements can produce fault scenarios to be experimented.
[0170] Specifically, first, the Failure Mode and Effects Criticality Analysis method (FMECA model) is used. Among them, the critical factor analysis method is expressed by the formula: CA = SEV * PRO * DET.
[0171] The specific dimension table is designed as follows. The values within the sub-dimensions are summed according to the weights, and the sub-dimensions are multiplied. After obtaining the priority value, they are sorted to obtain the recommended sorting of each experimental scenario under this fault category.
[0172]
[0173] Among them, the goal of the screening strategy is to filter the aggregated sorted pool according to a certain current situation and select the fault scenarios that are really to be executed. It mainly includes the following categories:
[0174] If this scenario has been executed recently, is in a passed state, and the code has not been updated recently, this scenario can be skipped;
[0175] If this scenario has been executed recently, is in a failed state, but is still under repair, this scenario can be skipped;
[0176] Other scenarios that need to be temporarily skipped can also be added through configuration.
[0177] Through the description of the above embodiments, those skilled in the art can clearly understand that the method according to the above embodiments can be implemented by means of software to add a necessary general hardware platform. Of course, it can also be implemented by hardware, but in many cases the former is a better implementation. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), and includes several instructions for causing a terminal device (which can be a mobile phone, computer, server, or network device, etc.) to execute the methods described in various embodiments of the present invention.
[0178] In this embodiment, an automated fault injection system for a C language system is also provided. This system is used to implement the above embodiments and preferred implementation manners, and those that have been described will not be repeated. As used below, the term "module" can be a combination of software and / or hardware that can achieve a predetermined function. Although the devices described in the following embodiments are preferably implemented in software, implementation in hardware, or a combination of software and hardware is also possible and contemplated.
[0179] Figure 14 is a structural schematic diagram of the automated fault injection system for a C language system according to an embodiment of the present invention Figure 1 , as Figure 14 shown, this system includes:
[0180] A command-line tool 141, which is used to obtain a fault injection instruction;
[0181] In one implementation, the command-line tool is Blade.
[0182] A C language support module 142, which is used to parse the fault injection instruction, so that the command-line tool 141 passes a target process written in C language based on the parsing result;
[0183] A C language chaos tool 143, which is used to create a C language chaos tool process based on the fault injection instruction;
[0184] A Frida-core-devkit toolkit 144, which is used to inject fault codes into the target process based on the C language chaos tool process.
[0185] By adopting the above technical solution, since the technical means of effectively integrating the command-line tool and the C language support module is adopted, the C language support module can be used to automatically interpret and analyze the fault injection instructions written in C language, so that the command-line tool can quickly and batch-interpret the fault injection instructions, and then combine the capabilities of the C language chaos tool and the Frida-core-devkit toolkit to realize the automatic fault injection of the C language system. Therefore, the problem that it is difficult to realize the automatic fault injection of the C language system in the related technology is solved, and the efficiency of fault detection of the C language system is improved.
[0186] Figure 15 is a structural schematic diagram of an automatic fault injection system for a C language system according to an embodiment of the present invention Figure 2 , such as Figure 15 shown, in one embodiment, the system further includes:
[0187] SQLite database 145, used to store the parsing results.
[0188] In one embodiment, the system is further configured to: obtain the target function of the target process, so as to inject fault codes based on the target function.
[0189] In one embodiment, the system is further configured to:
[0190] Install an inline hook at the entry address of the target function based on the Frida-core-devkit toolkit, so that the starting position of the target function of the target process is replaced with a jump instruction, pointing to the hook function;
[0191] Inject fault codes in the hook function;
[0192] In the case where the target process calls the hooked target function, transfer the execution flow to the hook function to run the hook function injected with fault codes.
[0193] In one embodiment, the system is further configured to: jump back to the execution position of the target function after the fault code is executed to continue executing the target function.
[0194] In one embodiment, the system is further configured to:
[0195] Obtain a destruction request, wherein the parsing result includes the destruction request, and the destruction request is set with a mapping relationship between the C language chaos tool process and the target process;
[0196] Send a close signal based on the destruction request;
[0197] Close and delete the C language chaos tool process based on the close signal.
[0198] In one embodiment, the system is further configured to: configure memory of a preset length in a target process, load and execute code of a preset dynamic library in the memory to create a thread;
[0199] Establish communication between a C language chaos tool process and the target process by using the thread based on a first-in first-out (FIFO) communication queue.
[0200] It should be noted that the above-mentioned modules can be implemented by software or hardware. For the latter, it can be implemented in the following ways, but not limited to this: all the above-mentioned modules are located in the same processor; or, the above-mentioned modules are respectively located in different processors in any combination form.
[0201] An embodiment of the present invention further provides a computer-readable storage medium, in which a computer program is stored, and the computer program is configured to execute the steps in any one of the above method embodiments when running.
[0202] In an exemplary embodiment, the above computer-readable storage medium may include, but is not limited to: various media such as a USB flash drive, a read-only memory (ROM), a random access memory (RAM), a mobile hard disk, a magnetic disk, or an optical disc that can store a computer program.
[0203] An embodiment of the present invention further provides an electronic device, including a memory and a processor. A computer program is stored in the memory, and the processor is configured to run the computer program to execute the steps in any one of the above method embodiments.
[0204] In an exemplary embodiment, the above electronic device may further include a transmission device and an input / output device, where the transmission device is connected to the above processor, and the input / output device is connected to the above processor.
[0205] An embodiment of the present invention further provides a computer program product, including a computer program, and the computer program implements the steps in any one of the above method embodiments when executed by a processor.
[0206] Specific examples in this embodiment may refer to the examples described in the above embodiments and exemplary embodiments, and will not be repeated here.
[0207] In summary, the embodiments of the present application can be applied to the following experiments:
[0208] Experiment 1: Simulate the delay experiment of a specified dynamic library function call.
[0209] Scenario introduction:
[0210] When calling a function in the target dynamic library for a specified process, a call delay occurs.
[0211] Parameters:
[0212]
[0213]
[0214] Example:
[0215] The following example injects a delay of 3000 milliseconds for the print function in libc.so for the process hello after execution.
[0216]
[0217] Experiment 2: Simulate the experiment of delaying the call of a function in the specified process.
[0218] Scenario Introduction:
[0219] When calling a function inside the specified process, a call delay occurs.
[0220] Parameters:
[0221]
[0222]
[0223] Example:
[0224] The following example injects a delay of 3000 milliseconds for the print function in libc.so for the process hello after execution.
[0225]
[0226]
[0227] Experiment 3: Simulate the experiment of returning the value of a specified dynamic library function.
[0228] Scenario Introduction:
[0229] When calling a function in the target dynamic library for a specified process, replace the return value of the function. Parameters:
[0230]
[0231]
[0232] Example:
[0233] The following example is to inject a return value change for the print function in libc.so for the process hello. After execution, the return value becomes 0.
[0234]
[0235] Experiment 4: Simulate the experiment of specifying the return value of a function in this process.
[0236] Scenario introduction:
[0237] For a specified process, when calling a function in this process, replace the return value of the function.
[0238] Parameters:
[0239]
[0240]
[0241] Example:
[0242] The following example is to inject a return value change for the cat_log_show_int function in the process testone for the process testone. After execution, the return value becomes 0.
[0243]
[0244] Experiment 5: Simulate the experiment of specifying parameter replacement for a dynamic library function.
[0245] Scenario introduction:
[0246] For a specified process, when calling a function of the target dynamic library, replace the parameters of the function. Parameters:
[0247]
[0248]
[0249] Example:
[0250] The following example is to inject a parameter change for the cat_log_show_int function in libcatlog.so for the process test. After execution, the first parameter of the function call becomes 15.
[0251]
[0252] Experiment 6: Simulate the experiment of specifying parameter replacement for a function in this process.
[0253] Scenario introduction:
[0254] For a specified process, when calling a function in this process, replace the parameters of the function.
[0255] Parameter:
[0256]
[0257]
[0258] Example:
[0259] The following example is for the process testone. When injecting parameter changes into the cat_log_show_int function in the process testone, the first parameter becomes 151111 after execution.
[0260]
[0261] Experiment 7: Experiment on simulating the insertion of a hook script into a specified dynamic library function.
[0262] Scenario introduction:
[0263] For a specified process, when calling a function of the target dynamic library, call the inserted hook script. Parameter:
[0264]
[0265] Example:
[0266]
[0267] Experiment 8: Experiment on simulating the insertion of a hook script into a specified function of the current process.
[0268] Scenario introduction:
[0269] For a specified process, when calling a function of the current process, call the inserted hook script. Parameter:
[0270]
[0271] Example:
[0272]
[0273]
[0274] Obviously, those skilled in the art should understand that the above-mentioned modules or steps of the present invention can be implemented by a general-purpose computing device. They can be concentrated on a single computing device or distributed on a network composed of multiple computing devices. They can be implemented by program codes executable by the computing device. Thus, they can be stored in a storage device and executed by the computing device. And in some cases, the steps shown or described can be executed in a sequence different from that here, or they can be separately fabricated into individual integrated circuit modules, or multiple modules or steps among them can be fabricated into a single integrated circuit module for implementation. In this way, the present invention is not limited to any specific combination of hardware and software.
[0275] The above are only the preferred embodiments of the present invention and are not used to limit the present invention. For those skilled in the art, the present invention can have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. An automated fault injection method for a C language system, characterized in that, Including: Obtaining a fault injection instruction based on a command-line tool; Parsing the fault injection instruction based on a C language support module, and based on the parsing result, passing a target process written in C language through the command-line tool and calling a C language chaos tool to create a C language chaos tool process; wherein, the C language chaos tool process contains fault codes; Injecting the fault code into the target process by loading the Frida-core-devkit toolkit based on the C language chaos tool.
2. The method according to claim 1, wherein Injecting the fault code into the target process by loading the Frida-core-devkit toolkit based on the C language chaos tool, including: Obtaining the target function of the target process to inject the fault code based on the target function.
3. The method according to claim 2, wherein Obtaining the target function of the target process to inject the fault code based on the target function, including: Installing an inline hook at the entry address of the target function based on the Frida-core-devkit toolkit, so that the starting position of the target function of the target process is replaced with a jump instruction pointing to a hook function; Injecting the fault code into the hook function; In the case where the target process calls the hooked target function, transferring the execution flow to the hook function to run the hook function injected with the fault code.
4. The method according to claim 3, characterized in that, After injecting the fault code into the hook function, further including: Jumping back to the execution position of the target function after the fault code is executed to continue executing the target function.
5. The method according to claim 3, characterized in that, After transferring the execution flow to the hook function to run the hook function injected with the fault code in the case where the target process calls the hooked target function, further including: Obtaining a destruction request, wherein the parsing result includes the destruction request, and the destruction request is set with a mapping relationship with the C language chaos tool process and the target process; Sending a close signal based on the destruction request; Closing and deleting the C language chaos tool process based on the close signal.
6. The method according to claim 1, characterized in that After passing a target process written in C language through the command-line tool and calling a C language chaos tool to create a C language chaos tool process based on the parsing result, further including: Configuring memory of a preset length in the target process, loading and executing the code of a preset dynamic library in the memory to create a thread; Establishing communication between the C language chaos tool process and the target process by using the thread based on a first-in-first-out (FIFO) communication queue.
7. The method according to claim 1, wherein The command-line tool is Blade.
8. An automated fault injection system for a C language system, characterized in that, Including: A command-line tool for obtaining a fault injection instruction; A C language support module for parsing the fault injection instruction, so that the command-line tool transfers a target process written in C language and calls a C language chaos tool to create a C language chaos tool process based on the parsing result; wherein, the C language chaos tool process contains fault codes; The C language chaos tool for injecting the fault code into the target process by loading the Frida-core-devkit toolkit.
9. The system according to claim 8, wherein Further including: An SQLite database for storing the parsing result.
10. A computer-readable storage medium, characterized in that, A computer program is stored in the storage medium, wherein the computer program, when run by a processor, executes the method described in any one of claims 1 to 7.
11. An electronic device, comprising a memory and a processor, characterized in that, A computer program is stored in the memory, and the processor is configured to run the computer program to execute the method described in any one of claims 1 to 7.
12. A computer program product comprising computer instructions, characterized in that, When the computer instructions are executed by a processor, the steps of the method described in any one of claims 1 to 7 are implemented.