A seed scheduling directional fuzz testing method based on semantic targeted ranging
Patent Information
- Application Number
- CN202610895693.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2026-06-22
- Publication Date
- 2026-09-29
- Estimated Expiration
- 2046-06-22
AI Technical Summary
[0006]但是,现有定向模糊测试方案的目标距离大多仍建立在调用图、控制流图或其图论最短路径基础上,本质上偏向物理拓扑距离,缺乏对数据流依赖、分支约束强度及上下文语义状态的深层刻画
1、本发明构建融合控制流图、数据流图与抽象语法树的代码属性图,并引入分支约束障碍系数形成语义靶向图,在目标漏洞区域定位和距离度量过程中同时考虑控制流拓扑结构、数据依赖层级及分支约束强度,能够比仅基于调用图或控制流图的距离度量方式更准确地表征程序位置与目标漏洞区域之间的语义关联,有利于降低定向模糊测试的路径探索盲目性。
Smart Images

Figure CN122432054B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of fuzz testing technology, specifically to a seed scheduling directional fuzz testing method based on semantic target ranging. Background Technology
[0002] Fuzzing is a software testing technique that continuously inputs mutated test data into the program under test and discovers abnormal behavior or potential vulnerabilities based on the program execution results. Current mainstream solutions typically include black-box fuzzing, gray-box fuzzing, and hybrid fuzzing combined with symbolic execution.
[0003] In gray-box fuzz testing, the testing system typically uses compiler instrumentation or runtime monitoring to obtain feedback information such as path coverage and branch hits, and then uses this information to select seeds, allocate energy, and mutate test cases to improve the ability to explore effective paths.
[0004] As complex software systems continue to grow in scale, program control flow and data dependencies become increasingly complex. Traditional coverage-guided fuzzing tends to consume a large amount of computing resources in code areas unrelated to the target vulnerability, resulting in problems such as blind path exploration, slow access to deep targets, and low utilization of test resources.
[0005] To address this issue, a targeted gray-box fuzzing scheme has emerged in the existing technology. It attempts to adjust the priority of the seed based on the distance between the target location and the current execution location, so as to reach the location of the vulnerability to be verified or the code area related to the patch more quickly.
[0006] However, most existing targeted fuzzy testing schemes still rely on call graphs, control flow graphs, or graph theory shortest paths, which are essentially biased towards physical topological distances and lack a deep characterization of data flow dependencies, branch constraint strength, and contextual semantic states.
[0007] Therefore, when the target vulnerability is located in a deep path with complex verification logic, sensitive API call sequences, specific memory operation states, or multi-layered data dependencies, existing solutions can approximate the target area in a topological sense, but the generated test cases are still easily intercepted by shallow semantic checks, resulting in a large number of invalid executions.
[0008] To address this, a seed scheduling directional fuzzy testing method based on semantic target ranging is proposed. Summary of the Invention
[0009] The purpose of this invention is to provide a seed scheduling-oriented fuzzy testing method based on semantic targeting ranging, comprising: firstly, extracting the control flow graph and data flow graph of the target program and fusing them to construct a code attribute graph, and calculating the branch constraint obstacle coefficient according to the constraint predicate type and variable dependency range to obtain a semantic targeting graph; for each program location, calculating its semantic distance to the target vulnerability region based on the control flow jump cost, data flow dependency level, and total path constraint obstacle coefficient; dynamically instrumenting the seeds, executing candidate value derivation rules according to the branch constraint type, generating and replacing corresponding bytes to obtain mutation test cases; using the weighted sum of semantic distance decay and coverage increment as the base score, combined with the nonlinear reward score of constraint breakthrough events to obtain a hybrid score, adjusting the mutation energy allocation of the seeds, and removing stagnant seeds from the queue. This invention can improve the detection efficiency of deep vulnerabilities.
[0010] To achieve the above objectives, the present invention provides the following technical solution: 1. A seed scheduling directional fuzzy testing method based on semantic target ranging, comprising: S1. Extract the control flow graph and data flow graph of the target program and merge them to construct a code attribute graph; calculate the branch constraint obstacle coefficient of each branch node in the code attribute graph according to the constraint predicate type and variable dependency range to obtain the semantic target graph; S2. For each program location in the semantic targeting graph, calculate the semantic distance from that location to the target vulnerability region by weighted summation of control flow jump cost, data flow dependency level, and total coefficient of path constraint barriers. S3. Perform dynamic instrumentation on the seed under test, record the actual execution path and the constraint predicate hit status of each branch node; execute the candidate value derivation rule according to the constraint type of the corresponding branch node to generate a set of candidate mutation values; select a target mutation value to replace the corresponding byte position in the seed under test to generate mutation test cases. S4. Input the mutation test cases into the target program and collect feedback; use the weighted sum of semantic distance decay and coverage increment as the base score, and when a constraint breach event is detected, add nonlinear reward points based on the branch constraint obstacle coefficient of the breached branch node to obtain a mixed score and adjust the mutation energy allocation of the test seeds; remove seeds with no semantic distance decay and no constraint breach events from the main test queue within a consecutive preset round. S5. Repeat steps S3 to S4 until the target program triggers an exception. Record the variant test cases that trigger the exception and terminate the test.
[0011] Preferably, the process of obtaining the code attribute graph includes: performing syntax parsing on the source code of the target program to obtain an abstract syntax tree; constructing a control flow graph and a data flow graph based on the abstract syntax tree, associating nodes that point to the same statement in both to obtain an initial graph structure containing control flow edges and data flow edges; adding node type label, source code line number, function name, and variable name information to each node in the initial graph structure to obtain a code attribute graph with semantic labels.
[0012] Preferably, the process of obtaining the semantic targeting graph includes: reading the target function name, target variable name, and target constraint predicate form corresponding to the target vulnerability type from the vulnerability pattern dictionary; searching for nodes that match the target function name, target variable name, and target constraint predicate form in the code attribute graph, and marking these nodes as nodes related to the target vulnerability region; calculating the branch constraint barrier coefficient for all branch nodes in the code attribute graph according to the constraint predicate type on the branch node and the variable dependency range involved in the constraint predicate, and writing the calculation result into the branch node attribute to obtain the semantic targeting graph.
[0013] Preferably, the semantic distance acquisition process includes: in the semantic targeting graph, starting from the relevant nodes of the target vulnerability region, traversing backwards through all reachable program locations on the control flow graph, assigning corresponding jump weights to each jump edge on each control flow path based on whether it is a cross-function jump, and accumulating the jump weights of each path to obtain the control flow jump cost; starting from the sensitive variables involved in the target vulnerability region, traversing backwards along the variable definition usage chain on the data flow graph, counting the number of variable definition usage chain edges from the relevant nodes of the target vulnerability region to each program location, and using this number of edges as the data flow dependency level of each program location; for each control flow path from each program location to the target vulnerability region, accumulating the branch constraint obstacle coefficients of all branch nodes on the path to obtain the total path constraint obstacle coefficient of each path; for each program location, according to the preset control flow weight coefficient, data flow weight coefficient, and constraint weight coefficient, weighting and summing the control flow jump cost, data flow dependency level, and minimum path constraint obstacle total coefficient of the program location, and using the summation result as the semantic distance from the program location to the target vulnerability region.
[0014] Preferably, the process of generating the mutation test cases includes: inputting the seed to be tested into the target program and enabling the instrumentation module, recording the actual execution path of the seed to be tested in the program, and recording the constraint predicate hit results of each branch node on the execution path; for the hit branch node, reading the constraint type of the corresponding branch node in the semantic targeting graph, calling the corresponding candidate value derivation rule according to the constraint type, generating multiple candidate mutation values and writing them into the candidate mutation value set; selecting a target mutation value from the candidate mutation value set, determining the writing start position and writing length of the target mutation value in the input byte sequence; writing the target mutation value into the corresponding byte position of the seed to be tested to form a new input byte sequence, and using this input byte sequence as the mutation test case.
[0015] Preferably, the process of obtaining the hybrid score includes: before executing the mutation test case, reading the semantic distance from each program position on the previous execution path of the seed to be tested to the target vulnerability area from the semantic distance table, and calculating the average semantic distance of the execution path as the initial semantic distance; inputting the mutation test case into the target program for execution, recording the execution path of the mutation test case, and reading the semantic distance of each program position on the execution path from the semantic distance table, and calculating the average semantic distance of the execution path as the current semantic distance; subtracting the current semantic distance from the initial semantic distance to obtain the semantic distance decay, and weighting and summing the semantic distance decay with the coverage increment to obtain the base score; wherein, the coverage increment represents the number of newly added basic blocks in the current execution path; on the current execution path, detecting whether there are previously missed branch nodes that have been successfully passed, recording the branch node as the breached branch node, reading the branch constraint obstacle coefficient of the branch node, calculating the bonus score based on the coefficient, and adding the bonus score to the base score to obtain the hybrid score.
[0016] Preferably, the specific adjustment process of the mutation energy allocation includes: setting an initial mutation energy value for each seed to be tested, the initial mutation energy value corresponding to the initial number of mutations; after each mutation test case is executed and a mixed score is obtained, comparing the current mixed score with a first preset threshold and a second preset threshold; when the mixed score is greater than the second preset threshold, setting the mutation energy value of the seed to the product of the current mutation energy value and the amplification coefficient; when the mixed score is not greater than the second preset threshold and not less than the first preset threshold, keeping the mutation energy value of the seed unchanged; when the mixed score is less than the first preset threshold, setting the mutation energy value of the seed to the product of the current mutation energy value and the attenuation coefficient; and determining the number of mutations that the seed can be allocated in the next round based on the updated mutation energy value.
[0017] Preferably, the logic for removing a seed from the main test queue includes: setting a round counter for each seed and initializing it to zero; after each round of execution, comparing the current semantic distance of the seed with the semantic distance of the previous round; if the current semantic distance of the seed is not less than the semantic distance of the previous round and no constraint breach event is detected in this round, incrementing the round counter of the seed by one; if the round counter of the seed is less than a preset round threshold, retaining it in the main test queue to participate in the next round of testing; if the round counter of the seed is not less than the preset round threshold, deleting it from the main test queue and no longer allocating mutation energy to it.
[0018] Preferably, repeating steps S3 to S4 until the target program triggers an exception, recording the mutated test cases that trigger the exception, and terminating the test includes: monitoring the process status and exception signals of the target program each time a mutated test case is executed; when a program crash, out-of-bounds access, and / or uncaught exception is detected, marking the current test case as a mutated test case that triggers the exception; writing the mutated test case that triggers the exception, along with the corresponding seed's input byte sequence, execution path information, and exception type, into the exception test case database; counting the number of mutated test cases that trigger the same target vulnerability area in the exception test case database; when this number reaches a preset upper limit, marking the current target as detected and ceasing to execute steps S3 and S4 for that target; and terminating the fuzzing process when all preset target vulnerability areas have been marked as detected.
[0019] Compared with the prior art, the beneficial effects of the present invention are as follows: 1. This invention constructs a code attribute graph that integrates control flow graph, data flow graph, and abstract syntax tree, and introduces branch constraint barrier coefficients to form a semantic targeting graph. In the process of locating the target vulnerability region and measuring distance, it simultaneously considers the control flow topology, data dependency level, and branch constraint strength. It can more accurately represent the semantic relationship between the program location and the target vulnerability region than distance measurement methods based solely on call graph or control flow graph, which is beneficial to reducing the blindness of path exploration in targeted fuzz testing.
[0020] 2. This invention calculates the semantic distance from each program location to the target vulnerability region based on the semantic targeting graph, and generates and writes the target mutation value according to the candidate value inference rule based on the branch constraint type during dynamic execution, combined with byte influence analysis. This allows the input changes of the mutation test cases to be finely adjusted around the target vulnerability-related constraints, which can enhance the approximation ability of deep target paths and complex verification logic paths. This helps to reduce invalid executions blocked by shallow semantic checks and improve the efficiency of reaching deep vulnerabilities.
[0021] 3. This invention uses the weighted sum of semantic distance decay and coverage increment as the base score, and adds nonlinear reward scores according to the branch constraint barrier coefficient when a constraint breach event is detected to construct a hybrid score that reflects the effectiveness of the seed. Then, the seed mutation energy is dynamically adjusted according to the hybrid score, and stagnant seeds that have not made semantic progress and have no constraint breach events for multiple consecutive rounds are removed. This allows test resources to be preferentially allocated to seeds that are closer to the target vulnerability area and have exploration value, which is conducive to improving the resource utilization efficiency and target vulnerability detection efficiency of the fuzzing process. Attached Figure Description
[0022] Figure 1 A flowchart illustrating a seed scheduling directional fuzzy testing method based on semantic target ranging provided in an embodiment of the present invention; Figure 2 This is a flowchart illustrating a semantic distance calculation process provided in an embodiment of the present invention. Detailed Implementation
[0023] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0024] Example 1: This embodiment uses semantic-targeted ranging-based directional fuzzing testing of the open-source C program libpng-1.6.37 as a specific scenario. The target vulnerability area is the integer overflow path in the png_handle_IHDR function involving width and height out-of-bounds checks. The system uses an Ubuntu 22.04 x86_64 platform, LLVM 14 compilation environment, Python 3.10, and AFL++ 4.0c framework. Specifically, it applies a seed-scheduled directional fuzzing testing method based on semantic-targeted ranging, including: S1. Extract the control flow graph and data flow graph of the target program and merge them to construct a code attribute graph; calculate the branch constraint obstacle coefficient of each branch node in the code attribute graph according to the constraint predicate type and variable dependency range to obtain the semantic target graph; S2. For each program location in the semantic targeting graph, calculate the semantic distance from that location to the target vulnerability region by weighted summation of control flow jump cost, data flow dependency level, and total coefficient of path constraint barriers. S3. Perform dynamic instrumentation on the seed under test, record the actual execution path and the constraint predicate hit status of each branch node; execute the candidate value derivation rule according to the constraint type of the corresponding branch node to generate a set of candidate mutation values; select a target mutation value to replace the corresponding byte position in the seed under test to generate mutation test cases. S4. Input the mutation test cases into the target program and collect feedback; use the weighted sum of semantic distance decay and coverage increment as the base score, and when a constraint breach event is detected, add nonlinear reward points based on the branch constraint obstacle coefficient of the breached branch node to obtain a mixed score and adjust the mutation energy allocation of the test seeds; remove seeds with no semantic distance decay and no constraint breach events from the main test queue within a consecutive preset round. S5. Repeat steps S3 to S4 until the target program triggers an exception. Record the variant test cases that trigger the exception and terminate the test.
[0025] Furthermore, the process of obtaining the code attribute graph includes: performing syntax parsing on the source code of the target program to obtain an abstract syntax tree; constructing a control flow graph and a data flow graph based on the abstract syntax tree, associating nodes that point to the same statement in both to obtain an initial graph structure containing control flow edges and data flow edges; adding node type label, source code line number, function name, and variable name information to each node in the initial graph structure to obtain a code attribute graph with semantic labels.
[0026] The specific process includes: (1) Syntax parsing and abstract syntax tree generation All .c and .h source files of libpng-1.6.37 were submitted to the static analysis frontend. ClangLibTooling was used to perform lexical and syntactic analysis on each translation unit, traversing the root node TranslationUnitDecl and recording the node types (e.g., FunctionDecl, IfStmt, WhileStmt, BinaryOperator, CallExpr) one by one: node type (NodeType), source file path and line number (FileLoc), and the name of the function (FuncName). If it was an expression node, the operator and the types of its left and right subexpressions were also recorded. Finally, the AST nodes of all translation units were written to the SQLite database table ast_nodes(id, node_type, file, line, func_name, var_name, detail), generating approximately 42,000 node records.
[0027] (2) Construction of Control Flow Graph (CFG) CFGs are extracted at the function level. For each FunctionDecl node, the function body is divided into basic blocks (BasicBlock) using the Clang CFG::buildCFG interface. Each basic block corresponds to a CFGBlock object, containing a sequence of ordered statements. Directed control flow edges are extracted based on the Succs (successors) and Preds (predecessors) sets of the CFGBlock. Edge types are categorized as: sequential edges (SEQ), true-value branch edges (BRANCH_TRUE), false-value branch edges (BRANCH_FALSE), function call edges (CALL), and function return edges (RET). The control flow edges are then written to the database table cfg_edges(src_block_id, dst_block_id, edge_type, func_name).
[0028] (3) Data Flow Graph (DFG) Construction Based on CFG, perform in-process definition reach analysis. For each variable v within a function, for all definition points d and usage points u, if the definition of d at the entry point of the basic block containing u is reachable (i.e., no other redefinition of v will overwrite d), then establish a definition-use edge between d and u. For cross-function scenarios, extract the data flow edges (ARG_PARAM) from actual parameters to formal parameters in each CallExpr. Write the data flow edges to the database table dfg_edges(def_node_id, use_node_id, var_name, edge_type).
[0029] (4) Graph structure fusion and semantic tag addition Using source code line numbers as the association key, CFG nodes and AST nodes are merged: For each edge in cfg_edges, the src_block_id and dst_block_id are used to query the ast_nodes records corresponding to all statements within that basic block, and the AST nodes of the same statement are associated with the CFG basic block nodes through the edge attribute IS_STMT. Similarly, the def_node_id and use_node_id in dfg_edges are associated with their corresponding basic block nodes. Finally, all node attributes (NodeType, FileLoc, FuncName, VarName) are written to the node attribute table cpg_nodes, and all edges (control flow edges + data flow edges + AST belonging edges) are written to cpg_edges, resulting in the complete code attribute graph (CPG).
[0030] Furthermore, the process of obtaining the semantic targeting graph includes: reading the target function name, target variable name, and target constraint predicate form corresponding to the target vulnerability type from the vulnerability pattern dictionary; searching for nodes that match the target function name, target variable name, and target constraint predicate form in the code attribute graph, and marking these nodes as nodes related to the target vulnerability region; calculating the branch constraint barrier coefficient for all branch nodes in the code attribute graph according to the constraint predicate type on the branch node and the variable dependency range involved in the constraint predicate, and writing the calculation result into the branch node attribute to obtain the semantic targeting graph.
[0031] The specific process includes: (1) Read the vulnerability pattern dictionary The vulnerability pattern dictionary is stored in JSON format, with the format {"vuln_type":"integer_overflow","target_funcs":["png_handle_IHDR","png_set_IHDR"],"target_vars":["width","height","bit_depth"],"target_predicates":[">","==","!="]}. Testers load this dictionary and extract the target function name set TF, the target variable name set TV, and the target constraint predicate set TP.
[0032] The vulnerability pattern dictionary is stored in JSON format and is pre-maintained by security analysts based on publicly available vulnerability databases and the SAST rule set. The specific construction rules are as follows: extract code patch files described in publicly available vulnerability databases (such as CVEs), use abstract syntax tree comparison tools to extract deleted or modified branch predicates, and abstract them into target constraint predicate forms; for target functions with duplicate names, disambiguation is performed based on their file paths or namespace attributes. For vulnerability types not included in the dictionary, testers should manually specify the target function name, target variable name, and target constraint predicate form; when there is no matching entry in the dictionary, the system uses manually input parameters instead of dictionary lookup to ensure the method's generality.
[0033] (2) Mark the relevant nodes in the target vulnerability area. In `cpg_nodes`, a query is executed with the condition `FuncName∈TF` and `VarName∈TV`, and a joint query is performed on nodes with `NodeType=BinaryOperator` and `operator∈TP`. All hit nodes are added to `cpg_nodes` with the attribute `is_target=1`, denoted as the set of nodes related to the target vulnerability area, `T_nodes`. In this example, 6 `BinaryOperator` nodes and 2 `CallExpr` nodes involved in width and height comparisons within the `png_handle_IHDR` function are marked, for a total of 8 target nodes.
[0034] (3) Calculate the branch constraint obstacle coefficient For all branch nodes B in cpg_nodes with NodeType∈{IfStmt, WhileStmt, ForStmt, SwitchStmt}, calculate the branch constraint obstacle coefficient CB(B) according to the following rules: ① If the constraint predicate type of B belongs to {==, !=} (equivalence constraint), the basic coefficient is assigned a value of 3.0; ② If the constraint predicate type of B belongs to {<, >, <=, >=} (range constraint), the basic coefficient is assigned a value of 2.0; ③ If the constraint predicate type of B is a logical compound expression (&&, || nested), the basic coefficient is assigned a value of 4.0; ④ Calculate the length L of the ancestor chain of the variables involved in the constraint predicate in cpg_nodes (i.e., the maximum number of steps required to traverse backwards along the DEF_USE edge to the node with no in-degree). ⑤ The final CB(B) = base coefficient × (1 + 0.3 × L); if the constraint predicate of B involves pointer dereferencing or array subscript operations, multiply by an additional coefficient of 1.5. The coefficient 0.3 is an empirical parameter, determined as follows: during the preliminary research phase, for multiple open-source C projects such as libpng, openssl, and binutils, with the vulnerability trigger time (Time-to-Exposure) as the optimization target, a grid search was performed in the range [0.1, 0.5] with a step size of 0.1 to obtain the result. Experiments show that when the coefficient is set to 0.3, it can balance data flow tracing depth and computational overhead, achieving the optimal trigger time. When L exceeds 10, the CB value adopts an upper limit cutoff mechanism, i.e., CB(B) = min(base coefficient × (1 + 0.3 × L), 20.0), to prevent extreme chain lengths from causing distortion of the distance value; testers can adjust this coefficient within the range [0.1, 0.5] according to the data flow complexity of the target program.
[0035] Write CB(B) into the constraint_barrier attribute field of the corresponding node in cpg_nodes to complete the construction of the semantic target graph (STG). For example, in png_handle_IHDR, for the IfStmt node where width > PNG_USER_WIDTH_MAX, the constraint is a range constraint with a base coefficient of 2.0. The ancestor chain length of the data flow involving the variable width is L=2 (width←read_uint32←fread), so CB=2.0×(1+0.3×2)=3.2.
[0036] Further, the semantic distance acquisition process includes: in the semantic targeting graph, starting from the relevant nodes of the target vulnerability region, traversing backwards through all reachable program locations on the control flow graph, assigning corresponding jump weights to each jump edge on each control flow path based on whether it is a cross-function jump, and accumulating the jump weights of each path to obtain the control flow jump cost; starting from the sensitive variables involved in the target vulnerability region, traversing backwards along the variable definition usage chain on the data flow graph, counting the number of variable definition usage chain edges from the relevant nodes of the target vulnerability region to each program location, and using this number of edges as the data flow dependency level of each program location; for each control flow path from each program location to the target vulnerability region, accumulating the branch constraint obstacle coefficients of all branch nodes on the path to obtain the total path constraint obstacle coefficient of each path; for each program location, according to the preset control flow weight coefficient, data flow weight coefficient, and constraint weight coefficient, weighting and summing the control flow jump cost, data flow dependency level, and minimum path constraint obstacle total coefficient of the program location, and using the summation result as the semantic distance from the program location to the target vulnerability region. Figure 2 This is a flowchart illustrating a semantic distance calculation process provided in an embodiment of the present invention.
[0037] The specific process includes: (1) Calculation of control flow jump cost Starting with the basic blocks in the CFG corresponding to each target node in T_nodes, a reverse BFS (i.e., BFS reversed along the edge direction) is performed on cfg_edges to traverse all reachable basic blocks in the entire program. During the traversal, a list of visited nodes is maintained. When a circular back edge or a visited node is encountered, branch expansion of that path is stopped to ensure convergence within a finite number of steps. For each control flow path from program position P to the basic block containing the target node, a weight is assigned to each jump edge on the path: intra-function jump edge weight wSEQ=1; cross-function call edge weight wCALL=5 (due to the additional call constraints required for cross-function calls, which present significant semantic obstacles). The control flow jump cost of a path is obtained by summing all edge weights on that path, and the minimum value among all paths is taken as the program position. of .
[0038] (2) Data flow depends on hierarchical computation Starting with the sensitive variables (width, height, bit_depth) involved in each target node in T_nodes, traverse backwards along the DEF_USE edge on dfg_edges (i.e., trace the source of each variable's definition at each level). Record the path from T_nodes to each program location. The number of DEF_USE edges traversed is taken as the number of edges on the path with the minimum edge count. .like If a certain variable has no direct path to the target variable in T_nodes in the data stream, then The penalty value is 1.5 times the longest chain in the current graph.
[0039] (3) Calculation of total coefficient of path constraint obstacle For each control flow path from program location P to the target vulnerability region Accumulate the constraint obstacle coefficients of all branch nodes B on the path. The total coefficient of path constraints and obstacles for this path is obtained. Take all paths The smallest one as of .
[0040] (4) Weighted summation of semantic distance When calculating each component, first calculate the total number of components in the entire program. , , Their respective maximum values , , For each program location Normalize each component to , , ; Preset weighting coefficients: =0.4 (control flow weight coefficient). =0.3 (data flow weight coefficient) =0.3 (constraint weight coefficient). The preset weight coefficient satisfies... + + = 1; The basis for weight allocation is: In guided fuzzing scenarios, the control flow jump cost directly determines the spatial distance between the path and the target vulnerability area in the program structure, and its directional contribution to semantic distance is the most direct, therefore it is given the highest weight. = 0.4; Both the data flow dependency level and the total coefficient of path constraint barriers reflect the difficulty of path access. Their impact on semantic distance is roughly equivalent, therefore they are assigned the same weight. = =0.3. The above weights can be adjusted according to the specific constraint structure characteristics of the target program. , , The reasonable range of values for all three is (0, 1), and the sum of the three values must be 1.
[0041] For each program location Calculate semantic distance: Write the SD values of all program locations into the semantic distance table sd_table(block_id, func_name, line, sd_value).
[0042] Furthermore, the process of generating the mutation test cases includes: inputting the seed to be tested into the target program and enabling the instrumentation module, recording the actual execution path of the seed to be tested in the program, and recording the constraint predicate hit results of each branch node on the execution path; for the hit branch node, reading the constraint type of the corresponding branch node in the semantic targeting graph, calling the corresponding candidate value derivation rule according to the constraint type, generating multiple candidate mutation values and writing them into the candidate mutation value set; selecting a target mutation value from the candidate mutation value set, determining the writing start position and writing length of the target mutation value in the input byte sequence; writing the target mutation value into the corresponding byte position of the seed to be tested to form a new input byte sequence, and using this input byte sequence as the mutation test case.
[0043] The specific process includes: (1) Compiler instrumentation Use afl-clang-lto provided by AFL++ to perform source-level compilation instrumentation on the target program. Enable AddressSanitizer in the compilation command with -fsanitize=address to catch out-of-bounds accesses. Example of the instrumentation compilation command: ; After instrumentation, every time the program reaches a control flow transfer point (branch, jump, call), it writes the current edge ID (the hash value of src_block_id ^ dst_block_id) to the AFL++ shared memory region. At the same time, this embodiment inserts additional constraint predicate capturing stubs in the LLVMPass layer: at each IfStmt branch, it inserts code that writes the left operand value, the right operand value, and the comparison result (true / false) to the constraint log file in CSV format: block_id, var_name, lhs_val, rhs_val, taken(0 / 1).
[0044] (2) Initial seed preparation Collect valid PNG image files as the initial seed set and place them in the seeds / directory. It is recommended to include at least one copy each of: a 1×1 pixel 1-bit grayscale PNG, a 64×64 pixel 8-bit RGB PNG, and a PNG containing a tEXt auxiliary block. Input the seed into the instrumentation program once to verify that the program runs normally (no crashes, no abnormalities in the coverage log).
[0045] (3) Dynamic instrumentation execution and path recording The AFL++ main control process forks the target process corresponding to the seed under test, and the byte sequence of the seed under test is passed into the program via standard input. After execution, AFL++ reads the edge overlay bitmap from shared memory and saves it as exec_trace[seed_id]. In this embodiment, the constraint log file is read simultaneously, and all branch node records (block_id, var_name, lhs_val, rhs_val, taken) hit in this execution are parsed and written to the runtime constraint table rt_constraints(seed_id, block_id, var_name, lhs_val, rhs_val, taken) are written.
[0046] (4) Candidate value derivation rules For each record in rt_constraints, query the constraint type of the corresponding block_id in STG (i.e., the predicate type corresponding to the constraint_barrier field in cpg_nodes), and generate a candidate mutation value set MutSet according to the following rules: ① Equivalence constraint (==): If taken=1 (the current branch hits the truth value), generate a candidate value set {rhs_val,rhs_val-1, rhs_val+1}; if taken=0 (the current branch hits the false value, i.e. the condition is not met), generate a candidate value set {rhs_val} to try to satisfy the equivalence condition; ② Inequality constraint (!=): If taken=0, generate a candidate value set {lhs_val} to construct a mutation that makes both sides equal, thus bypassing the != constraint; ③ Range constraints (<, >, <=, >=): Based on the difference Δ between lhs_val and rhs_val, generate a candidate value set {rhs_val, rhs_val±1, rhs_val±Δ / 2, lhs_val±1}; ④ Logical compound constraints (&&, ||): Recursively decompose sub-constraints, applying rules ①②③ to each sub-constraint; for logical AND (&&) constraints, take the Cartesian product of the sub-constraint mutation sets and then merge to remove duplicates; for logical OR (||) constraints, directly take the union of the sub-constraint mutation sets to remove duplicates. For compound constraints, the recursion depth is set to an upper limit of 3 levels, and sub-constraints exceeding 3 levels use the boundary value ±1 strategy instead; when the Cartesian product candidate set exceeds the preset upper limit (e.g., 1000), random sampling is used to retain a representative subset of boundary values to avoid the mutation efficiency decreasing due to an excessively large candidate set; for sub-constraints containing pointer dereferences, no candidate values are generated temporarily, only it is recorded that the constraint has not been covered, and it is left for processing in subsequent rounds; (5) Target mutation value selection and byte position mapping Randomly sample a target mutation value tval from MutSet. Use AFL++'s built-in byte influence mapping to determine the range of input bytes corresponding to tval: perform a bit flip test on each byte offset position in the input seed, observe which byte offset positions' flips will affect the lhs_val of the current branch node, and denote the set of byte offsets that affect the node as byte_range(block_id).
[0047] The write start position is determined by `write_offset = min(byte_range(block_id))`. When `byte_range(block_id)` is empty, a random offset or the byte range of adjacent logical blocks is used as the alternative write point. The write length `write_len` is determined by the data type width of `tval`. When handling multi-byte integer overwriting, byte alignment is performed according to the architecture of the target operating platform (big-endian or little-endian). `tval` is encoded in the byte order of the target program (big-endian in this example, conforming to the PNG standard) and written into the interval [`write_offset`, `write_offset + write_len`] of the seed byte sequence to be tested, forming the mutant byte sequence of the mutation test cases.
[0048] Further, the process of obtaining the hybrid score includes: before executing the mutation test case, reading the semantic distance from each program position on the previous execution path of the seed to be tested to the target vulnerability area from the semantic distance table, calculating the average semantic distance of the unique basic block set after deduplication of the basic blocks in the execution path as the initial semantic distance; inputting the mutation test case into the target program for execution, recording the execution path of the mutation test case, deduplicating the basic blocks in the execution path, reading the semantic distance corresponding to the unique basic block from the semantic distance table, and calculating the average semantic distance as the current semantic distance; subtracting the current semantic distance from the initial semantic distance to obtain the semantic distance decay, and weighting and summing the semantic distance decay with the coverage increment to obtain the base score; wherein, the coverage increment represents the number of newly added basic blocks in the current execution path; on the current execution path, detecting whether there are previously unhit branch nodes that have been successfully passed, recording the branch node as the breached branch node, reading the branch constraint obstacle coefficient of the branch node, calculating the bonus score based on the coefficient, and adding the bonus score to the base score to obtain the hybrid score.
[0049] The specific process includes: (1) Initial semantic distance calculation Before executing mutation test cases, read the exec_trace[seed_id] corresponding to the seed under test in the last execution, remove duplicate basic block identifiers from it, and obtain a unique set of basic blocks. .for For each basic block b in the code, its semantic distance value is taken according to the following rules. If b is statically initialized If a record exists, then retrieve it. If no record exists, a default penalty value equal to the maximum semantic distance `max_SD` across the entire program is uniformly assigned. The strategy of assigning a `max_SD` penalty value instead of eliminating the block is adopted because basic blocks without records are usually located in the edge region of the program or dynamically generated code segments. Their semantic distance is objectively far from the target vulnerability area. Assigning the maximum penalty value can accurately reflect the negative contribution of this path segment to the proximity to the target, avoiding calculation bias introduced by changes in the denominator due to elimination operations. Calculation The arithmetic mean of the semantic distances of all basic blocks in the matrix is used as the initial semantic distance: ; If the seed is being executed for the first time (without historical exec_trace records), then the arithmetic mean of the semantic distances of all recorded program positions in sd_table is used as the basis for the execution. Initial estimates: ; (2) Current semantic distance calculation The mutation test case `mutant` is input into the target program and executed to obtain a new execution path `exec_trace[mutant_id]`. The basic block identifiers within this path are deduplicated to obtain a unique set of basic blocks. .right Each basic block b in the middle is pressed with The same rule is taken in the calculation (If a record exists, retrieve it) Otherwise, assign max_SD), and calculate the arithmetic mean as the current semantic distance: ; (3) Calculation of basic score Semantic distance decay A positive value indicates that the execution path of the mutated test case semantically approaches the target vulnerability area compared to the original seed path, while a negative value indicates that the path deviates.
[0050] Number of newly added basic blocks: The basic block identifiers in exec_trace[mutant_id] and exec_trace[seed_id] are deduplicated to obtain unique basic block sets B_cur and B_seed. The number of newly added basic blocks in B_cur relative to B_seed is then calculated. ; That is, to count the number of basic blocks that appear in the execution path of the variant test cases but never appear in the seed execution path, and... The calculations use the same deduplication caliber to ensure... and The statistical logic of the two components is consistent.
[0051] To ensure the consistency of the scoring system across different program scales, the two components are normalized separately: The maximum absolute value observed within the current test period (each test period is counted as the completion of mutation execution for all seeds in the main queue). Normalize to map to the interval [-1, 1], i.e. ; Updated at the end of each test cycle, with the initial value set to 1.0 to prevent division by zero; Normalize to the [0,1] interval using a preset normalization window W_BB = 20 basic blocks, i.e. .
[0052] base score In this embodiment, = 0.7, = 0.3, Score_base ∈ [-0.7, 1.0]. This assigns... Higher weighting; making the semantic distance component dominant and the coverage component play a supplementary corrective role. The reasonable range of values for is [0.5, 0.9]. When the score is below 0.5, the scoring system becomes less sensitive to changes in semantic distance, degenerating into a comprehensive index with nearly equal weights, and its guiding effect weakens.
[0053] (4) Constraint breach event detection and reward score calculation Compare exec_trace[mutant_id] and exec_trace[seed_id] to check if there is a branch node B_break that satisfies the following condition: the target branch direction hit flag taken = 0 in exec_trace[seed_id] (i.e. the seed did not hit the target branch direction), while taken = 1 in exec_trace[mutant_id] (the mutation test case successfully hit the target branch direction).
[0054] If a constraint breach event is detected, read the branch constraint barrier coefficient CB_break of the corresponding branch node in cpg_nodes and calculate the original reward value for a single breach: Score_reward_raw(B_break) = CB_break² × 0.5; The quadratic nonlinear form is used because branch constraints with high barrier coefficients (such as compound predicates that depend on long data flows) are the core bottleneck that prevents fuzz testing from entering deep vulnerability regions. The quadratic form can provide exponential reward scaling for seeds that break through high-difficulty constraints. In the case of multiple constraint breach events in the same execution, the original reward values of all breached branch nodes are summed: Score_reward_raw = ΣCB_break_i² × 0.5; To maintain consistency between the reward score and the base score, the accumulated result is normalized to a preset upper limit of Score_reward_max = 15.0. Score_reward_norm = min(Score_reward_raw, Score_reward_max) / Score_reward_max Score_reward_norm ∈ [0,1]. The setting of Score_reward_max = 15.0 is based on the following: In the constraint obstacle coefficient range involved in this embodiment (CB ∈ [2.0, 20.0], typical values are about 3.0 to 8.0), the original reward value of a single typical constraint breakthrough is about 4.5 to 32.0. Taking 15.0 as the normalization benchmark, the normalized reward value of most constraint breakthrough events falls in the range of [0.3, 1.0], which matches the effective value range of the base score. At the same time, the upper limit truncation prevents the score from jumping due to a single trigger of an extremely high obstacle coefficient node.
[0055] The hybrid score, Score_hybrid = Score_base + Score_reward_norm, has an overall value range of [-0.7, 2.0]. If no constraint breach event is detected in this execution, then Score_reward_norm = 0, and Score_hybrid = Score_base.
[0056] For cases where Score_hybrid is negative (i.e., the execution path of the mutated test case deviates semantically from the target vulnerability area and does not trigger any constraint breach), the mutated test case will be marked as low priority in the seed queue energy allocation of the current test cycle; when the mutation energy is updated in the future, the mutated energy value will be uniformly reduced by the decay coefficient to ensure that the limited test resources are tilted towards high-potential seeds.
[0057] Furthermore, the specific adjustment process for the mutation energy allocation includes: setting an initial mutation energy value for each seed to be tested, the initial mutation energy value corresponding to the initial number of mutations; after each mutation test case is executed and a mixed score is obtained, comparing the current mixed score with a first preset threshold and a second preset threshold; when the mixed score is greater than the second preset threshold, setting the mutation energy value of the seed to the product of the current mutation energy value and the amplification coefficient; when the mixed score is not greater than the second preset threshold and not less than the first preset threshold, keeping the mutation energy value of the seed unchanged; when the mixed score is less than the first preset threshold, setting the mutation energy value of the seed to the product of the current mutation energy value and the attenuation coefficient; and determining the number of mutations that the seed can be allocated in the next round based on the updated mutation energy value.
[0058] Specifically, the first preset threshold is a low threshold TL; the second preset threshold is a high threshold TH. The high and low thresholds used for mutation energy allocation are adjusted according to the normalization strategy as follows: at the end of each test cycle, the Score_hybrid distribution of all seeds in this cycle is statistically analyzed, and the 20th percentile is used as the low threshold TL, and the 80th percentile is used as the high threshold TH. In the first test cycle after the test starts, since there is no historical distribution data, fixed initial values TH0 = 0.8 and TL0 = 0.1 are used as the default values for cold start. After the first test cycle ends, the dynamic percentile strategy is switched. This strategy ensures that the thresholds always adapt to the actual range of the current score distribution, avoiding the failure of fixed thresholds under different program scales.
[0059] Score_hybrid > TH (i.e., 0.8) indicates that the path is significantly approaching the target or has broken through the effective constraint, triggering energy amplification; Score_hybrid < TL (i.e., 0.1) indicates that the path has not advanced or has even deviated from the target, triggering energy decay; when TL≤ Score_hybrid ≤ TH, the energy remains unchanged.
[0060] Each seed s is initialized with a mutation energy of Energy(s) = 100 (corresponding to an initial mutation count of 100 times / round). The amplification factor kamp = 1.5, and the attenuation factor kdec = 0.7.
[0061] After obtaining Score_hybrid, perform the following update: ① If Score_hybrid > TH: Energy(s) = Energy(s) × kamp; ② If TL ≤ Score_hybrid ≤ TH: Energy(s) remains unchanged; ③ If Score_hybrid < TL: Energy(s) = Energy(s) × kdec; The Energy(s) is set with an upper limit of Emax = 500 and a lower limit of Emin = 10 to prevent energy from expanding indefinitely or reaching zero. The number of mutations allocated to seed s in the next round is N_mut(s) = ⌊Energy(s)⌋.
[0062] Furthermore, the logic for removing a seed from the main test queue includes: setting a round counter for each seed and initializing it to zero; after each round of execution, comparing the current semantic distance of the seed with the semantic distance of the previous round; if the current semantic distance of the seed is not less than the semantic distance of the previous round and no constraint breach event is detected in this round, incrementing the round counter of the seed; if the round counter of the seed is less than a preset round threshold, retaining it in the main test queue to participate in the next round of testing; if the round counter of the seed is not less than the preset round threshold, deleting it from the main test queue and no longer allocating mutation energy to it.
[0063] Specifically, each seed s maintains a round counter StaleCounter(s), initialized to 0. The preset round threshold T_stale = 10. At the end of each round (after processing all N_mut(s) mutations of that seed), the following checks are performed: ① Calculate the average semantic distance SD_cur(s) of the current execution path and the semantic distance SD_prev(s) of the previous execution path; ②If SD_cur(s)≥SD_prev(s) and there are no constraint breach events in this round, then let StaleCounter(s) = StaleCounter(s) + 1; ③ Otherwise: StaleCounter(s) = 0, and update SD_prev(s) = SD_cur(s); ④ When StaleCounter(s) is less than the preset round threshold T_stale, the seed s is kept in the main test queue[] to participate in the next round of testing; ⑤ When StaleCounter(s) is greater than or equal to the preset round threshold T_stale, it is determined as a stagnant seed, the seed s is removed from the main test queue[], mutation energy is no longer allocated to it, and it is archived to stale_archive[].
[0064] Further, repeating steps S3 to S4 until the target program triggers an exception, recording the mutated test cases that trigger the exception, and terminating the test includes: monitoring the process status and exception signals of the target program each time a mutated test case is executed; when a program crash, out-of-bounds access, and / or uncaught exception is detected, marking the current test case as a mutated test case that triggers the exception; writing the mutated test case that triggers the exception, along with the corresponding seed's input byte sequence, execution path information, and exception type, into the exception test case database; counting the number of mutated test cases that trigger the same target vulnerability area in the exception test case database; when this number reaches a preset upper limit, marking the current target as detected and ceasing to execute steps S3 and S4 for that target; and terminating the fuzzing process when all preset target vulnerability areas have been marked as detected.
[0065] The specific process includes: (1) Monitoring of abnormal signals AFL++ monitors the exit status of each forked child process using `waitpid()`. If a child process terminates due to SIGSEGV, SIGABRT, SIGBUS, SIGFPE, or SIGILL, AFL++ marks it as crashed. This embodiment, in addition to AFL++ exit status detection, additionally reads the AddressSanitizer output stream to capture out-of-bounds access reports such as "heap-buffer-overflow," "stack-buffer-overflow," and "use-after-free." For any of these abnormal signals, the current mutation test case is marked as a crash case.
[0066] (2) Writing exception test cases to the database Write the complete byte sequence of crash_case, the byte sequence of the corresponding original seed_id, the execution path exec_trace[mutant_id] (stored as a list of block_ids), the exception type (crash_type), and the target vulnerability area ID (target_id) at the time of triggering into the exception case database table crash_db(case_id, mutant_bytes, seed_bytes, exec_trace, crash_type, target_id, timestamp).
[0067] (3) Target detection completion judgment The preset trigger limit for each target_id is N_max = 5, and its value is determined as follows: For the same target vulnerability area, the first and second triggers are used to confirm the vulnerability reachability and basic reproducibility; the third and fourth triggers are used to cover different triggering modes caused by differences in input byte sequence or path variants; the fifth trigger is used for redundancy verification to confirm the stability of the aforementioned path coverage; after 5 triggers, the main triggering paths of the target vulnerability area are basically saturated, and the contribution of continuing to invest mutation energy to the discovery of new paths for the target is marginally reduced, so it is better to transfer computing power to other uncompleted target vulnerability areas. The statistical scope of N_max is the total count of trigger records for all crash_types (including SIGSEGV, SIGABRT, SIGBUS, SIGFPE, SIGILL, and heap-buffer-overflow, stack-buffer-overflow, and use-after-free reported by AddressSanitizer) under the same target_id, without distinguishing specific anomaly types, to avoid the failure to trigger the judgment due to the dispersion of anomaly types and the long-term insufficient number of triggers for a single type of trigger.
[0068] The reasonable range of N_max values is as follows: When N_max = 1, only a single trigger is confirmed and then stopped, which is suitable for scenarios with extremely high testing speed requirements and only need to quickly locate the existence of vulnerabilities, but may miss multiple trigger path variations of the same vulnerability; when N_max exceeds 10, the repeated trigger rate of the same target vulnerability area increases significantly, which significantly drags down the overall efficiency of discovering new vulnerability areas; in this embodiment, N_max = 5 is taken as the balance point between speed and coverage. For security audit scenarios that require systematic coverage of the diversity of vulnerability trigger paths, N_max can be adjusted to 10 to 20; for rapid verification scenarios, N_max can be adjusted to 1 to 3.
[0069] After each write to crash_db, count the number of records in crash_db where target_id = the current target, N_crash. If N_crash ≥ N_max, mark the target_id as completed, remove it from the target set targets[], and no longer include the related seeds of that target in the mutation task of the main test queue.
[0070] (4) Global termination condition When targets[] is empty (all preset target vulnerability areas are marked as completed), the AFL++ master process sends a stop signal to all child processes via SIGTERM, closes shared memory, outputs the final statistics report, and terminates the fuzzing process. If targets[] is not completed within the preset global timeout period (24 hours in this example), the above termination process is executed again, and the triggered exception test cases are output.
[0071] Example 2: A seed scheduling orientation fuzzy testing method based on semantic target ranging includes: S1. Extract the control flow graph and data flow graph of the target program and merge them to construct a code attribute graph; calculate the branch constraint obstacle coefficient of each branch node in the code attribute graph according to the constraint predicate type and variable dependency range to obtain the semantic target graph; S2. For each program location in the semantic targeting graph, calculate the semantic distance from that location to the target vulnerability region by weighted summation of control flow jump cost, data flow dependency level, and total coefficient of path constraint barriers. S3. Perform dynamic instrumentation on the seed under test, record the actual execution path and the constraint predicate hit status of each branch node; execute the candidate value derivation rule according to the constraint type of the corresponding branch node to generate a set of candidate mutation values; select a target mutation value to replace the corresponding byte position in the seed under test to generate mutation test cases. S4. Input the mutation test cases into the target program and collect feedback; use the weighted sum of semantic distance decay and coverage increment as the base score, and when a constraint breach event is detected, add nonlinear reward points based on the branch constraint obstacle coefficient of the breached branch node to obtain a mixed score and adjust the mutation energy allocation of the test seeds; remove seeds with no semantic distance decay and no constraint breach events from the main test queue within a consecutive preset round. S5. Repeat steps S3 to S4 until the target program triggers an exception. Record the variant test cases that trigger the exception and terminate the test.
[0072] Furthermore, the process of obtaining the code attribute graph includes: performing syntax parsing on the source code of the target program to obtain an abstract syntax tree; constructing a control flow graph and a data flow graph based on the abstract syntax tree, associating nodes that point to the same statement in both to obtain an initial graph structure containing control flow edges and data flow edges; adding node type label, source code line number, function name, and variable name information to each node in the initial graph structure to obtain a code attribute graph with semantic labels.
[0073] Furthermore, the process of obtaining the semantic targeting graph includes: reading the target function name, target variable name, and target constraint predicate form corresponding to the target vulnerability type from the vulnerability pattern dictionary; searching for nodes that match the target function name, target variable name, and target constraint predicate form in the code attribute graph, and marking these nodes as nodes related to the target vulnerability region; calculating the branch constraint barrier coefficient for all branch nodes in the code attribute graph according to the constraint predicate type on the branch node and the variable dependency range involved in the constraint predicate, and writing the calculation result into the branch node attribute to obtain the semantic targeting graph.
[0074] Further, the semantic distance acquisition process includes: in the semantic targeting graph, starting from the relevant nodes of the target vulnerability region, traversing backwards through all reachable program locations on the control flow graph, assigning corresponding jump weights to each jump edge on each control flow path based on whether it is a cross-function jump, and accumulating the jump weights of each path to obtain the control flow jump cost; starting from the sensitive variables involved in the target vulnerability region, traversing backwards along the variable definition usage chain on the data flow graph, counting the number of variable definition usage chain edges from the relevant nodes of the target vulnerability region to each program location, and using this number of edges as the data flow dependency level of each program location; for each control flow path from each program location to the target vulnerability region, accumulating the branch constraint obstacle coefficients of all branch nodes on the path to obtain the total path constraint obstacle coefficient of each path; for each program location, according to the preset control flow weight coefficient, data flow weight coefficient, and constraint weight coefficient, weighting and summing the control flow jump cost, data flow dependency level, and minimum path constraint obstacle total coefficient of the program location, and using the summation result as the semantic distance from the program location to the target vulnerability region.
[0075] Furthermore, the process of generating the mutation test cases includes: inputting the seed to be tested into the target program and enabling the instrumentation module, recording the actual execution path of the seed to be tested in the program, and recording the constraint predicate hit results of each branch node on the execution path; for the hit branch node, reading the constraint type of the corresponding branch node in the semantic targeting graph, calling the corresponding candidate value derivation rule according to the constraint type, generating multiple candidate mutation values and writing them into the candidate mutation value set; selecting a target mutation value from the candidate mutation value set, determining the writing start position and writing length of the target mutation value in the input byte sequence; writing the target mutation value into the corresponding byte position of the seed to be tested to form a new input byte sequence, and using this input byte sequence as the mutation test case.
[0076] Further, the process of obtaining the hybrid score includes: before executing the mutation test case, reading the semantic distance from each program position on the previous execution path of the seed to be tested to the target vulnerability area from the semantic distance table, and calculating the average semantic distance of the execution path as the initial semantic distance; inputting the mutation test case into the target program for execution, recording the execution path of the mutation test case, and reading the semantic distance of each program position on the execution path from the semantic distance table, and calculating the average semantic distance of the execution path as the current semantic distance; subtracting the current semantic distance from the initial semantic distance to obtain the semantic distance decay, and weighting and summing the semantic distance decay with the coverage increment to obtain the base score; wherein, the coverage increment represents the number of newly added basic blocks in the current execution path; on the current execution path, detecting whether there are previously missed branch nodes that have been successfully passed, recording the branch node as the breached branch node, reading the branch constraint obstacle coefficient of the branch node, calculating the bonus score based on the coefficient, and adding the bonus score to the base score to obtain the hybrid score.
[0077] Furthermore, the specific adjustment process for the mutation energy allocation includes: setting an initial mutation energy value for each seed to be tested, the initial mutation energy value corresponding to the initial number of mutations; after each mutation test case is executed and a mixed score is obtained, comparing the current mixed score with a first preset threshold and a second preset threshold; when the mixed score is greater than the second preset threshold, setting the mutation energy value of the seed to the product of the current mutation energy value and the amplification coefficient; when the mixed score is not greater than the second preset threshold and not less than the first preset threshold, keeping the mutation energy value of the seed unchanged; when the mixed score is less than the first preset threshold, setting the mutation energy value of the seed to the product of the current mutation energy value and the attenuation coefficient; and determining the number of mutations that the seed can be allocated in the next round based on the updated mutation energy value.
[0078] Furthermore, the logic for removing a seed from the main test queue includes: setting a round counter for each seed and initializing it to zero; after each round of execution, comparing the current semantic distance of the seed with the semantic distance of the previous round; if the current semantic distance of the seed is not less than the semantic distance of the previous round and no constraint breach event is detected in this round, incrementing the round counter of the seed; if the round counter of the seed is less than a preset round threshold, retaining it in the main test queue to participate in the next round of testing; if the round counter of the seed is not less than the preset round threshold, deleting it from the main test queue and no longer allocating mutation energy to it.
[0079] Further, repeating steps S3 to S4 until the target program triggers an exception, recording the mutated test cases that trigger the exception, and terminating the test includes: monitoring the process status and exception signals of the target program each time a mutated test case is executed; when a program crash, out-of-bounds access, and / or uncaught exception is detected, marking the current test case as a mutated test case that triggers the exception; writing the mutated test case that triggers the exception, along with the corresponding seed's input byte sequence, execution path information, and exception type, into the exception test case database; counting the number of mutated test cases that trigger the same target vulnerability area in the exception test case database; when this number reaches a preset upper limit, marking the current target as detected and ceasing to execute steps S3 and S4 for that target; and terminating the fuzzing process when all preset target vulnerability areas have been marked as detected.
[0080] Although embodiments of the invention have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the appended claims and their equivalents.
Claims
1. A seed scheduling orientation fuzzy testing method based on semantic target ranging, characterized in that, include: S1. Extract the control flow graph and data flow graph of the target program, and merge them to construct a code attribute graph; Calculate the branch constraint obstacle coefficient for each branch node in the code attribute graph according to the constraint predicate type and variable dependency range to obtain the semantic target graph; S2. For each program location in the semantic targeting graph, calculate the semantic distance from that location to the target vulnerability region by weighted summation of control flow jump cost, data flow dependency level, and total coefficient of path constraint barriers. S3. Perform dynamic instrumentation on the seed to be tested, record the actual execution path and the constraint predicate hit status of each branch node; execute the candidate value derivation rule according to the constraint type of the corresponding branch node, and generate a set of candidate mutation values. Select a target mutation value to replace the corresponding byte position in the seed to be tested, and generate mutation test cases; The process of generating mutation test cases includes: inputting the seed to be tested into the target program and enabling the instrumentation module, recording the actual execution path of the seed to be tested in the program, and recording the constraint predicate hit results of each branch node on the execution path; for the hit branch node, reading the constraint type of the corresponding branch node in the semantic targeting graph, calling the corresponding candidate value derivation rule according to the constraint type, generating multiple candidate mutation values and writing them into the candidate mutation value set; selecting a target mutation value from the candidate mutation value set, determining the writing start position and writing length of the target mutation value in the input byte sequence; writing the target mutation value into the corresponding byte position of the seed to be tested to form a new input byte sequence, and using this input byte sequence as a mutation test case; S4. Input the mutation test cases into the target program and collect feedback; use the weighted sum of semantic distance decay and coverage increment as the base score, and when a constraint breach event is detected, add a nonlinear reward score based on the branch constraint barrier coefficient of the breached branch node to obtain a mixed score and adjust the mutation energy allocation of the test seed; remove seeds whose semantic distance has not decayed and have no constraint breach events within a consecutive preset rounds from the main test queue; the process of obtaining the mixed score includes: before executing the mutation test cases, reading the semantic distance from each program position on the previous execution path of the test seed to the target vulnerability area from the semantic distance table, and calculating the average semantic distance of the execution path as the initial semantic distance; input the mutation test cases into the target program for execution. The execution path of the mutated test cases is recorded, and the semantic distance of each program position on the execution path is read from the semantic distance table. The average semantic distance of the execution path is calculated as the current semantic distance. The semantic distance decay is obtained by subtracting the current semantic distance from the initial semantic distance. The semantic distance decay is weighted and summed with the coverage increment to obtain the base score. The coverage increment is represented by the number of new basic blocks added in the current execution path. On the current execution path, it is checked whether there are previously missed branch nodes that have been successfully passed. The branch node is recorded as the broken branch node. The branch constraint obstacle coefficient of the branch node is read. The bonus score is calculated based on the coefficient. The bonus score is added to the base score to obtain the mixed score. S5. Repeat steps S3 to S4 until the target program triggers an exception. Record the variant test cases that trigger the exception and terminate the test.
2. The seed scheduling orientation fuzzy testing method based on semantic target ranging according to claim 1, characterized in that: The process of obtaining the code attribute graph includes: performing syntax parsing on the source code of the target program to obtain an abstract syntax tree; constructing a control flow graph and a data flow graph based on the abstract syntax tree, associating nodes that point to the same statement in both to obtain an initial graph structure containing control flow edges and data flow edges; adding node type label, source code line number, function name, and variable name information to each node in the initial graph structure to obtain a code attribute graph with semantic labels.
3. The seed scheduling orientation fuzzy testing method based on semantic target ranging according to claim 1, characterized in that: The process of obtaining the semantic targeting graph includes: reading the target function name, target variable name, and target constraint predicate form corresponding to the target vulnerability type from the vulnerability pattern dictionary; searching for nodes that match the target function name, target variable name, and target constraint predicate form in the code attribute graph, and marking these nodes as nodes related to the target vulnerability region; calculating the branch constraint barrier coefficient for all branch nodes in the code attribute graph according to the constraint predicate type on the branch node and the variable dependency range involved in the constraint predicate, and writing the calculation result into the branch node attribute to obtain the semantic targeting graph.
4. The seed scheduling orientation fuzzy testing method based on semantic target ranging according to claim 1, characterized in that: The semantic distance acquisition process includes: in the semantic targeting graph, starting from the relevant nodes of the target vulnerability region, traversing backwards through all reachable program locations on the control flow graph, assigning corresponding jump weights to each jump edge on each control flow path based on whether it is a cross-function jump, and summing the jump weights of each path to obtain the control flow jump cost; starting from the sensitive variables involved in the target vulnerability region, traversing backwards along the variable definition usage chain on the data flow graph, counting the number of variable definition usage chain edges from the relevant nodes of the target vulnerability region to each program location, and using this number of edges as the data flow dependency level of each program location; for each control flow path from each program location to the target vulnerability region, accumulating the branch constraint obstacle coefficients of all branch nodes on the path to obtain the total path constraint obstacle coefficient of each path; for each program location, according to the preset control flow weight coefficient, data flow weight coefficient, and constraint weight coefficient, weighting and summing the control flow jump cost, data flow dependency level, and minimum path constraint obstacle total coefficient of the program location, and using the summation result as the semantic distance from the program location to the target vulnerability region.
5. The seed scheduling orientation fuzzy testing method based on semantic target ranging according to claim 1, characterized in that: The specific adjustment process for the mutation energy allocation includes: setting an initial mutation energy value for each seed to be tested, the initial mutation energy value corresponding to the initial number of mutations; after each mutation test case is executed and a mixed score is obtained, comparing the current mixed score with a first preset threshold and a second preset threshold; when the mixed score is greater than the second preset threshold, setting the mutation energy value of the seed to the product of the current mutation energy value and the amplification coefficient; when the mixed score is not greater than the second preset threshold and not less than the first preset threshold, keeping the mutation energy value of the seed unchanged; when the mixed score is less than the first preset threshold, setting the mutation energy value of the seed to the product of the current mutation energy value and the attenuation coefficient; and determining the number of mutations that the seed can be allocated in the next round based on the updated mutation energy value.
6. The seed scheduling orientation fuzzy testing method based on semantic target ranging according to claim 1, characterized in that: The logic for removing a seed from the main test queue includes: setting a round counter for each seed and initializing it to zero; after each round of execution, comparing the current semantic distance of the seed with the semantic distance of the previous round; if the current semantic distance of the seed is not less than the semantic distance of the previous round and no constraint breach event is detected in this round, incrementing the round counter of the seed by one; if the round counter of the seed is less than a preset round threshold, retaining it in the main test queue to participate in the next round of testing; if the round counter of the seed is not less than the preset round threshold, deleting it from the main test queue and no longer allocating mutation energy to it.
7. The seed scheduling orientation fuzzy testing method based on semantic target ranging according to claim 1, characterized in that: The process of repeating steps S3 to S4 until the target program triggers an exception, recording the mutated test cases that trigger the exception, and terminating the test includes: monitoring the process status and exception signals of the target program each time a mutated test case is executed; when a program crash, out-of-bounds access, and / or uncaught exception is detected, marking the current test case as a mutated test case that triggers the exception; writing the mutated test case that triggers the exception, along with the corresponding seed's input byte sequence, execution path information, and exception type, into the exception test case database; counting the number of mutated test cases that trigger the same target vulnerability area in the exception test case database; when this number reaches a preset upper limit, marking the current target as detected and ceasing to execute steps S3 and S4 for that target; and terminating the fuzzing process when all preset target vulnerability areas have been marked as detected.
Citation Information
Patent Citations
Semantic clustering directional fuzzy test method and device driven by intelligent agent
CN122153923A
Apparatus, computer-readable data carrier, computer program, and method for fuzz testing software
WO2025045976A1