A method and apparatus for vulnerability triggering condition-driven testing based on a large language model

CN122733698APending Publication Date: 2026-09-11TSINGHUA UNIVERSITY +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610577312.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-04-28
Publication Date
2026-09-11

AI Technical Summary

Technical Problem

[0003]然而,现有定向模糊测试方法中,过度聚焦于缩短到达目标代码的时间,却缺乏对漏洞触发约束的有效建模与引导策略

Benefits of technology

[0017]本发明实施例的一种大语言模型驱动的漏洞触发条件引导测试方法及装置,有效解决了现有定向模糊测试中到达目标代码后难以触发漏洞的效率瓶颈,显著缩短了漏洞触发时间。通过大语言模型生成并验证精确的触发条件,结合触发距离引导的种子调度与变异策略,大幅提升了漏洞复现的成功率与测试效率。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122733698A_ABST
    Figure CN122733698A_ABST
Patent Text Reader

Abstract

This invention proposes a method and apparatus for guiding vulnerability triggering conditions testing driven by a large language model, belonging to the field of computer technology. The invention includes: acquiring the source code and vulnerability report of the target vulnerability, generating a structured set of candidate vulnerability triggering conditions; performing dynamic verification on the candidate vulnerability triggering conditions, and filtering out verified vulnerability triggering conditions; calculating the trigger distance of the test input based on the verified vulnerability triggering conditions; adjusting the seed scheduling and input mutation strategy according to the trigger distance, prioritizing the allocation of mutation resources and performing deep mutation on test inputs with smaller trigger distances. This invention improves the effectiveness of vulnerability triggering conditions, enhances the directional guidance capability of fuzz testing, and improves the efficiency of target vulnerability discovery.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of computer technology, and in particular to a method and apparatus for guiding vulnerability triggering conditions driven by a large language model. Background Technology

[0002] Targeted fuzz testing, a core technology in software security, is widely used in critical engineering tasks such as vulnerability reproduction and patch verification. With the development of gray-box testing technology, related solutions have constructed a complete technical system from seed scheduling to path exploration through the collaborative operation of distance metrics, selective feedback, and reachability analysis. Specifically, this process covers the entire process from initial input generation to target code coverage, including key stages such as static analysis, dynamic instrumentation, and energy allocation, aiming to efficiently generate proof-of-concept inputs that trigger specific vulnerabilities.

[0003] However, existing targeted fuzzing methods overemphasize shortening the time to reach the target code while lacking effective modeling and guidance strategies for vulnerability triggering constraints. Because they fail to translate code semantics into quantifiable runtime feedback, the testing engine becomes prone to blind mutation after reaching the target location, making it difficult to satisfy complex logical triggering conditions. This structural flaw of "easy to reach, difficult to trigger" means that the actual vulnerability triggering time far exceeds the code arrival time, severely limiting the application effectiveness and automation level of targeted fuzzing in real-world scenarios. Summary of the Invention

[0004] The present invention aims to at least partially solve one of the technical problems in the related art.

[0005] Therefore, the first objective of this invention is to propose a vulnerability triggering condition-guided testing method driven by a large language model.

[0006] Another objective of this invention is to propose a vulnerability triggering condition-guided testing device driven by a large language model.

[0007] The third objective of this invention is to provide a computer device.

[0008] A fourth objective of this invention is to provide a non-transitory computer-readable storage medium.

[0009] To achieve the above objectives, a first aspect of the present invention proposes a vulnerability triggering condition-guided testing method driven by a large language model, comprising:

[0010] S1. Obtain the source code and vulnerability report of the target vulnerability, and use a large language model to perform reasoning analysis on the source code and vulnerability report to generate a set of candidate vulnerability triggering conditions represented in a structured form. S2, During the fuzzing process, the generated reachable input is used to perform dynamic verification on each candidate vulnerability triggering condition in the candidate vulnerability triggering condition set, and the verified vulnerability triggering conditions that meet the preset validity requirements are selected. S3, calculate the trigger distance of the current test input relative to the target vulnerability based on the verified vulnerability trigger conditions, and use the trigger distance as a runtime feedback signal; S4. Adjust the seed scheduling strategy and input mutation strategy of the fuzzing engine according to the runtime feedback signal, prioritize the allocation of mutation resources to test inputs with smaller trigger distances and perform deep mutation on key byte positions until test cases that trigger the target vulnerability are generated.

[0011] In one embodiment of the present invention, S1 includes: A prompt word template containing required and optional fields is constructed based on the vulnerability type and the trigger point code location. The source code is then sliced ​​to extract code fragments related to the target vulnerability and injected into the prompt word template. By using an automated intelligent agent to supplement missing function definitions to the large language model on demand through progressive prompting, and by combining few-shot thinking chain technology to provide step-by-step reasoning examples to guide the large language model to output candidate vulnerability triggering conditions in the format of five-tuple triggering condition units, a set of candidate vulnerability triggering conditions composed of multiple triggering condition units is obtained.

[0012] In one embodiment of the present invention, the step of outputting candidate vulnerability triggering conditions according to the five-tuple format of the triggering condition unit includes: Each trigger condition unit is formalized as a quintuple structure containing a condition statement, code location, execution order, logical conjunction identifier, and weight factor; The conditional statement is transformed into a trigger distance expression based on the Korel branch function principle to quantify the proximity of the program state to the condition. The logical conjunction identifier is used to decompose complex compound conditions into atomic conditions in the disjunctive normal form. The execution order is used to model the sequential execution constraints in multi-point vulnerabilities. The weight factor is dynamically determined based on runtime observation results, thereby generating a set of candidate vulnerability triggering conditions that can accurately describe complex vulnerability triggering scenarios in the real world.

[0013] In one embodiment of the present invention, S2 includes: The first type of source code-level instrumentation is performed on the program under test. Distance monitoring code is inserted into the code position corresponding to each trigger condition unit in the candidate vulnerability trigger condition set to record the trigger distance value when the program is executed in real time. When the trigger distance for the detected reachable input is less than or equal to zero, the corresponding candidate vulnerability trigger condition is determined to be an invalid trigger condition that is too lenient and is filtered out, resulting in a subset of candidate vulnerability trigger conditions that have been preliminarily screened.

[0014] In one embodiment of the present invention, it further includes: A second type of source code-level instrumentation is performed on the program under test. Assignment statements that force the conditions to be met are inserted into the code positions corresponding to the subset of candidate vulnerability triggering conditions that have been preliminarily screened, so as to generate the program under test after the instrumentation is forced to be met. Using program analysis tools, the reachable input to the tested program after the forced instrumentation is played back to verify whether a vulnerability manifestation consistent with the vulnerability report is observed after the forced fulfillment of the triggering condition. The candidate vulnerability triggering conditions that pass the verification are determined as verified vulnerability triggering conditions that meet the preset validity requirements.

[0015] In one embodiment of the present invention, S3 includes: The trigger distance expression calculation results of each trigger condition unit during the execution of the current test input are obtained. Based on the execution order attribute and logical conjunction identifier attribute in each trigger condition unit, the trigger distance expression calculation results are subjected to hierarchical aggregation operation to obtain the final trigger distance value reflecting the proximity of the current test input to triggering the vulnerability under multiple constraints and multiple execution order scenarios. The final trigger distance value is used as a runtime feedback signal to guide seed scheduling and input mutation.

[0016] In one embodiment of the present invention, S4 includes: Based on the traditional coverage-guided seed retention mechanism, a trigger distance retention criterion is added. In addition to retaining test inputs that can discover new execution paths, test inputs with smaller trigger distance values ​​are also retained to prevent seeds with high vulnerability triggering potential from being discarded. The total mutation energy of the seed is calculated by referring to the simulated annealing energy scheduling mechanism. The energy contribution calculated based on the trigger distance value is added to the energy contribution calculated based on the control flow distance. More mutation energy is allocated to the seed with the smaller trigger distance value to prioritize deep mutation.

[0017] This invention discloses a vulnerability triggering condition-guided testing method and apparatus driven by a large language model, which effectively solves the efficiency bottleneck of existing targeted fuzzing tests where it is difficult to trigger vulnerabilities after reaching the target code, and significantly shortens the vulnerability triggering time. By generating and verifying precise triggering conditions through a large language model, and combining trigger distance-guided seed scheduling and mutation strategies, the success rate of vulnerability reproduction and testing efficiency are greatly improved.

[0018] To achieve the above objectives, a third aspect of this application provides a computer device, including a processor and a memory; wherein the processor runs a program corresponding to the executable program code by reading executable program code stored in the memory, for implementing the method described in the first aspect embodiment.

[0019] To achieve the above objectives, a fourth aspect of this application provides a non-transitory computer-readable storage medium having a computer program stored thereon that, when executed by a processor, implements the method described in the first aspect.

[0020] Additional aspects and advantages of the invention will be set forth in part in the description which follows, and in part will be obvious from the description, or may be learned by practice of the invention. Attached Figure Description

[0021] Figure 1 This is a flowchart of a vulnerability triggering condition-guided testing method driven by a large language model according to an embodiment of the present invention; Figure 2 This is an architecture diagram of a vulnerability triggering condition-guided testing method driven by a large language model according to an embodiment of the present invention. Figure 3 This is a schematic diagram of a three-stage directional fuzzy testing mechanism according to an embodiment of the present invention; Figure 4 This is a trigger condition calculation diagram according to an embodiment of the present invention; Figure 5 This is a structural diagram of a vulnerability triggering condition guided testing device driven by a large language model according to an embodiment of the present invention; Figure 6 It is a computer device according to an embodiment of the present invention. Detailed Implementation

[0022] It should be noted that, unless otherwise specified, the embodiments and features described in the present invention can be combined with each other. The present invention will now be described in detail with reference to the accompanying drawings and embodiments.

[0023] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.

[0024] The following describes, with reference to the accompanying drawings, a method and apparatus for guiding vulnerability triggering conditions driven by a large language model, according to an embodiment of the present invention.

[0025] Figure 1 This is a flowchart of a vulnerability triggering condition-guided testing method driven by a large language model according to an embodiment of the present invention, such as... Figure 1 As shown, it includes: S1. Obtain the source code and vulnerability report of the target vulnerability, and use a large language model to perform reasoning analysis on the source code and vulnerability report to generate a set of candidate vulnerability triggering conditions represented in a structured form. S2, During the fuzzing process, the generated reachable input is used to perform dynamic verification on each candidate vulnerability triggering condition in the candidate vulnerability triggering condition set, and the verified vulnerability triggering conditions that meet the preset validity requirements are selected. S3, calculate the trigger distance of the current test input relative to the target vulnerability based on the verified vulnerability trigger conditions, and use the trigger distance as a runtime feedback signal; S4. Adjust the seed scheduling strategy and input mutation strategy of the fuzzing engine according to the runtime feedback signal, prioritize the allocation of mutation resources to test inputs with smaller trigger distances and perform deep mutation on key byte positions until test cases that trigger the target vulnerability are generated.

[0026] like Figure 2 As shown, in the trigger condition generation stage of this invention, we use the vulnerability type and trigger point code location of the target vulnerability as mandatory inputs, and the vulnerability call stack trace and vulnerability patch as optional inputs. We first embed prompt words into the source code slice containing the vulnerable function, and then use an automated agent to progressively supplement the function definition to the large language model as needed. Guided by a few-shot thought chain example, the large language model gradually infers and outputs a candidate set of trigger conditions represented in TCU5 tuple format. In a specific embodiment of this invention, we use GPT-5 as the main large language model, and use Python and Shell scripts to build an agent to automate the trigger condition generation and verification process. Three independent requests are made to the large language model, generating three sets of candidate trigger conditions. The optimal result is selected through the verification stage described in point 3 of the invention, with an average of 1.4 requests.

[0027] like Figure 2As shown in the middle part, in the trigger condition verification phase of the present invention, two source-level instrumentations are implemented on the program under test. For v1 instrumentation, distance monitoring codes are inserted at the code positions corresponding to each TCU, the trigger distance value of each TCU during program execution is recorded, and the trigger distance is hierarchically aggregated into the final trigger distance according to Algorithm 1. The instrumented binary file is simultaneously used as the actual test target of the fuzzing engine. For v2 instrumentation, assignment statements that forcibly satisfy conditions (e.g., inserting `a=b-1;` for the condition `a<b`) are inserted at corresponding code positions, and then program analysis tools such as AddressSanitizer (ASan) are used to replay reachable inputs, so as to check whether a vulnerability performance consistent with that in the vulnerability report can be observed after the trigger condition is forcibly satisfied. The present invention adopts a three-stage parallel advancement strategy: the pioneer stage focuses on generating reachable inputs; the verification stage continuously monitors the trigger distance through v1 instrumentation (to filter invalid trigger conditions) and verifies the trigger effectiveness through v2 instrumentation (to screen out high-quality trigger conditions); the utilization stage disables the monitoring of other candidate trigger conditions, and focuses on guiding fuzzing by using the verified trigger conditions.

[0028] As Figure 2 As shown on the right, in the trigger condition-guided directed fuzzing phase of the present invention, the fuzzing engine is constructed based on the AFLGo framework, and collects trigger distances as runtime feedback by extending the shared memory mechanism. The seed retention criterion adds retention of inputs with smaller trigger distances on the basis of the traditional coverage-guided retention standard. The energy allocation strategy refers to the annealing energy scheduling mechanism, and adds the energy contributions calculated respectively by the trigger distance and the control flow distance to determine the total mutation energy of the seed. The trigger byte-aware mutation strategy directly records mutation positions in the deterministic mutation phase, and determines mutation-related positions by comparing byte-level differences between the original input and the mutated input in the havoc stage; probe mutation is applied to the determined key positions, and systematic deep mutation is further performed if the trigger distance changes. Trigger condition instrumentation automatically generates a unified edit patch by a large language model through the unifieddiff editing format, and directly modifies the source code of the program under test to complete instrumentation.

[0029] This invention proposes a targeted fuzzing method guided by vulnerability triggering conditions, mainly comprising three stages: triggering condition generation, triggering condition verification, and targeted fuzzing guided by triggering conditions. In the triggering condition generation stage, this invention collects the source code and vulnerability report of the target vulnerability, drives a large language model through a carefully designed prompt word template, and generates triggering conditions formally represented as 5-tuples using progressive prompts and few-shot thought chain techniques. In the triggering condition verification stage, this invention designs a dynamic triggering verification mechanism, instrumenting the program under test using two instrumentation methods, and using reachable inputs generated during fuzzing to perform online screening and verification of candidate triggering conditions. In the targeted fuzzing stage guided by triggering conditions, the fuzzing engine calculates the trigger distance for each input based on the verified triggering conditions and uses it as runtime feedback to guide the seed scheduling strategy and the trigger byte-aware mutation strategy, thereby accelerating the generation of vulnerability triggering inputs. This scheme includes the following core modules: Formal Representation of Triggering Conditions (TCU 5-tuple): To enable the triggering conditions generated by large language models to be accurately quantified and utilized by fuzzing engines, this invention formalizes vulnerability triggering conditions as a combination of "TriggeringConditionUnits" (TCUs), each TCU consisting of 5 tuples.<cond,loc,seq,conj,w> This indicates that `cond` is the conditional statement, `loc` is the position of the condition in the code, `seq` is the execution order of the condition in a multi-point vulnerability, and `conj` is the logical conjunctive identifier (used to decompose complex conditions into atomic conditions in disjunctive normal form (DNF), such as: , Where i is the loop counter, ∧ is the conjunction symbol, ∨ is the disjunction symbol, and w is the weighting factor (dynamically determined based on runtime observations). For each TCU, this invention transforms its conditional statement into a trigger distance expression according to the calculation rules shown in Table 1. a and b are example variables used to quantify the proximity of the current program state to satisfying the condition. The basic design idea of ​​the calculation rule is that "when the trigger condition is satisfied, the trigger distance is less than / less than or equal to 0, while when the trigger condition is not yet satisfied, the trigger distance is a continuous value greater than 0". For special condition types such as pointer comparison and type checking, the code understanding capability of the large language model is used to process them into binary distances. The trigger condition of the entire vulnerability is a combination of multiple TCUs, supporting accurate modeling of complex real-world vulnerability triggering scenarios.

[0030] Table 1

[0031] Furthermore, for large language model trigger condition generation (progressive hints + few-shot thought chain): This invention designs a hint template and hint strategy for trigger condition generation tasks. The hint template includes mandatory fields such as vulnerability type and trigger point code location, as well as optional fields such as vulnerability call stack trace and patch information (which can improve generation quality). To reduce hint noise and adapt to the limited context window of the large language model, this invention uses progressive hint technology to slice the source code, injecting only the code fragments related to the target vulnerability into the hint words, and supplementing the large language model with the required function definitions as needed through an automated intelligent agent. Simultaneously, this invention employs few-shot thought chain (Few-shotCoT) technology to provide step-by-step reasoning examples to guide the large language model to output trigger conditions according to the TCU5 tuple format, effectively suppressing illusions and improving the standardization of the output format.

[0032] Furthermore, a dynamic trigger verification mechanism is implemented: Due to the instability of the output of a single large language model request, this invention designs a dynamic trigger verification method to filter multiple candidate trigger conditions generated by the large language model. This invention implements two types of instrumentation on the program under test: The first instrumentation (v1) monitors the trigger distance in real time at the code location corresponding to the trigger condition. If the trigger distance is ≤0 when the reachable input is executed, the trigger condition is determined to be too lenient (an invalid trigger condition) and is filtered out; the second instrumentation (v2) verifies whether the trigger condition can actually trigger the vulnerability by forcibly satisfying the trigger condition and replaying the reachable input.

[0033] Furthermore, three-stage directional fuzzy testing: such as Figure 3 This invention employs a three-stage directional fuzzing framework to achieve parallel advancement of continuous fuzzing and online verification: the pioneer fuzzing stage focuses on generating reachable inputs, the verification stage dynamically filters candidate triggering conditions while continuously fuzzing, and the exploitation stage focuses on using verified triggering conditions to guide fuzzing and accelerate vulnerability triggering, thus avoiding the time loss caused by pausing fuzzing and waiting for verification.

[0034] Furthermore, trigger distance-guided seed scheduling: This invention introduces additional seed retention criteria based on the traditional coverage-guided seed retention mechanism: in addition to retaining inputs that can discover new execution paths, it also retains inputs with smaller trigger distances, ensuring that seeds with higher vulnerability triggering potential are not discarded. Regarding energy allocation strategies, this invention references the simulated annealing energy scheduling mechanism, allocating more mutation energy to seeds with smaller trigger distances, allowing the fuzzing engine to prioritize deep mutation of inputs more likely to trigger vulnerabilities. The trigger distance is calculated by hierarchically aggregating the distance expressions of each TCU according to the seq and conj attributes, accurately reflecting the proximity of the current input to triggering a vulnerability in scenarios with multiple constraints and multiple execution sequences, such as... Figure 4As shown. The distances for all sequence-conjunction pairs are initialized using the following formula:

[0035] Where S represents the set of triggering condition sequences, which contains the condition execution sequences required to trigger the vulnerability; C represents the set of conjunctions, which are multiple logical AND branches under the same sequence; d(s,c) represents the distance between sequence s and conjunction c; DISTANCE_MAX represents the preset maximum distance value, which represents the default distance when the condition is not executed.

[0036] Furthermore, in the normalization and update phase, all trigger condition units are traversed, and the distance between the corresponding sequence-conjunction pairs is updated, as shown in the following formula:

[0037] Where T represents the runtime feedback set of the Trigger Condition Unit (TCU), which contains the execution information of all atomic conditions; tcu represents a single trigger condition unit, which is the atomic logic judgment that triggers the vulnerability; tcu.seq represents the identifier of the trigger condition sequence to which tcu belongs; tcu.conj represents the identifier of the conjunctive term to which tcu belongs; d_norm represents the normalized distance; tcu.d represents the original deviation distance of tcu, which represents the degree of deviation between the input and the atomic condition; tcu.w represents the weight coefficient of tcu, which represents the importance of the atomic condition in the overall logic; the meanings of s, c, d(s,c), and DISTANCE_MAX are consistent with the above formula.

[0038] Furthermore, in the sequence aggregation stage, the distance of each triggering condition sequence is calculated using the following formula:

[0039] Where s represents a single sequence in the set of trigger condition sequences S; d(s) represents the distance of sequence s; min represents the minimum value operation; C represents the set of conjunctions; d(s,c) represents the distance between sequence s and the corresponding conjunction c, and its meaning is consistent with the above formula.

[0040] Furthermore, the overall distance calculation and termination logic involves accumulating the sequence distance. If a sequence has not been executed, the process terminates directly and fills in the remaining distance, as shown in the following formula:

[0041]

[0042] Where s represents a single sequence in the set of trigger condition sequences S; d represents the final trigger distance; d(s) represents the distance of sequence s; DISTANCE_MAX represents the preset maximum distance value; n represents the number of untraversed remaining sequences in the set of trigger condition sequences S; s' represents the untraversed sequence in S; |·| represents the counting operation; break represents the termination of the traversal operation, and the meanings of the other variables are the same as those in the above formula.

[0043] Specifically, this invention first normalizes the expression value of each collected TCU using the w element corresponding to it. Then, it groups the TCUs according to the seq field, ensuring that all TCUs within the same group have the same seq value. For each group, this invention calculates the trigger distance based on the conj value of its TCUs, as follows: Figure 4 As shown. Finally, starting from index 0 (i.e., the point that must be reached first, such as the "free" position in a use-after-free vulnerability), the trigger distances of each group are sequentially accumulated to obtain the overall trigger distance. If the target corresponding to a certain sequence index is not reached, a predefined maximum distance is assigned to it regardless of whether subsequent indices are actually reached, to indicate that its prerequisite has not been met.

[0044] Furthermore, the invention proposes a byte-aware input mutation strategy. This strategy leverages a key observation: the input bytes affecting the trigger distance are often fixed. Specifically, mutation positions that reduce the trigger distance typically correspond to the input fields of relevant variables in the TCU conditional statement, and remain stable throughout the fuzzing process. Based on this observation, the invention dynamically monitors mutation operations that cause changes in the trigger distance during fuzzing and records the corresponding mutation positions. For identified key positions, probing mutations involving both value and length changes are applied. When the trigger distance changes, systematic deep mutations are performed (traversing the 0-255 range and multi-byte fields for value-change mutations, and progressively expanding insertion and deletion lengths for length-change mutations). This concentrates mutation efforts on the input positions most likely to trigger vulnerabilities, significantly reducing ineffective mutations.

[0045] The embodiments of this invention also have the following technical effects: Precise vulnerability triggering condition analysis: By utilizing a large language model for deep reasoning of source code and vulnerability reports, this invention can automatically generate precise triggering conditions for various vulnerability types. Evaluation experiments show that this invention can generate valid triggering conditions for over 90% of target vulnerabilities. Universal triggering condition formalization framework: The TCU5 tuple formal representation system proposed in this invention uniformly supports multiple condition types such as equality, inequality, and logical conjunction / disjunction. It decomposes complex composite conditions through disjunction paradigm decomposition, supports multi-execution order constraint modeling (such as the sequential execution order in release-use vulnerabilities), and can accurately describe the triggering scenarios of various complex vulnerabilities in the real world. It also provides a unified and operable foundation for the quantitative calculation of trigger distance. Efficient trigger acceleration and strong complementarity: The trigger distance-guided seed scheduling and trigger byte-aware mutation strategy of this invention focus on narrowing the efficiency gap between "reaching the target code" and "triggering the vulnerability," and are positively complementary in design to existing directional fuzzing tools that focus on accelerating the arrival at the target code. Experiments show that integrating this invention with existing baseline-oriented fuzzing tools that focus on reaching the target code and share the same framework (i.e., the AFL framework) significantly improves vulnerability triggering efficiency compared to using either the baseline-oriented fuzzing tool alone or this invention alone, fully validating the complementary gain effect of this invention. Lightweight and scalable: This invention collects trigger distances through source code-level instrumentation, eliminating the need for complex path constraint solutions and resulting in extremely low overhead. Large language model requests are executed only once before fuzzing begins, without affecting the fuzzing throughput. The fuzzing strategy of this invention is based on the AFL framework and can be easily integrated into existing mainstream fuzzing tools, possessing broad applicability and scalability.

[0046] This invention organically combines the code reasoning capabilities of large language models with the dynamic execution capabilities of targeted fuzzing, providing a more efficient, accurate, and compatible vulnerability triggering solution for targeted fuzzing. It has significant application value in core security engineering tasks such as vulnerability reproduction and vulnerability verification.

[0047] To achieve the above embodiments, such as Figure 5 As shown, this embodiment also provides a vulnerability triggering condition-guided testing device 10 driven by a large language model, including: The condition generation module 100 is used to obtain the source code and vulnerability report of the target vulnerability, and to perform reasoning analysis on the source code and vulnerability report using a large language model to generate a set of candidate vulnerability triggering conditions represented in a structured form. The condition verification module 200 is used to perform dynamic verification on each candidate vulnerability triggering condition in the candidate vulnerability triggering condition set during the fuzzing process using the generated reachable input, and to filter out the verified vulnerability triggering conditions that meet the preset validity requirements. The trigger distance calculation module 300 is used to calculate the trigger distance of the current test input relative to the target vulnerability based on the verified vulnerability trigger conditions, and to use the trigger distance as a runtime feedback signal; The fuzzing guidance module 400 is used to adjust the seed scheduling strategy and input mutation strategy of the fuzzing engine according to the runtime feedback signal, prioritize the allocation of mutation resources to test inputs with small trigger distances and perform deep mutation on key byte positions until test cases that trigger the target vulnerability are generated.

[0048] This invention discloses a vulnerability triggering condition-guided testing device driven by a large language model, which effectively solves the efficiency bottleneck of existing targeted fuzzing tests where it is difficult to trigger vulnerabilities after reaching the target code, and significantly shortens the vulnerability triggering time. By generating and verifying precise triggering conditions through a large language model, and combining trigger distance-guided seed scheduling and mutation strategies, the success rate of vulnerability reproduction and testing efficiency are greatly improved.

[0049] To implement the methods of the above embodiments, the present invention also provides a computer device, such as... Figure 6 As shown, the computer device 600 includes a memory 601 and a processor 602; wherein, the processor 602 reads the executable program code stored in the memory 601 to run a program corresponding to the executable program code, so as to implement the various steps of the large language model-driven vulnerability triggering condition bootstrapping test method described above.

[0050] To implement the above embodiments, this application also proposes a non-transitory computer-readable storage medium storing a computer program thereon, which, when executed by a processor, implements a large language model-driven vulnerability triggering condition bootstrapping test method as described in the foregoing embodiments.

[0051] In the description of this specification, the references to terms such as "one embodiment," "some embodiments," "example," "specific example," or "some examples," etc., indicate that a specific feature, structure, material, or characteristic described in connection with that embodiment or example is included in at least one embodiment or example of the present invention. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples. Moreover, without contradiction, those skilled in the art can combine and integrate the different embodiments or examples described in this specification, as well as the features of different embodiments or examples.

[0052] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Thus, a feature defined as "first" or "second" may explicitly or implicitly include at least one of that feature. In the description of this invention, "a plurality of" means at least two, such as two, three, etc., unless otherwise explicitly specified.

Claims

1. A large language model driven vulnerability trigger condition guided testing method, characterized in that, The method comprises the following steps: S1, obtaining the source code of the target vulnerability and the vulnerability report, and using a large language model to analyze the source code and the vulnerability report to generate a candidate vulnerability trigger condition set in a structured form; S2, using the generated reachable input to perform dynamic verification on each candidate vulnerability trigger condition in the candidate vulnerability trigger condition set during the fuzzing process, and screening out verified vulnerability trigger conditions that meet the preset effectiveness requirements; S3, calculating the trigger distance of the current test input relative to the target vulnerability based on the verified vulnerability trigger condition, and taking the trigger distance as a runtime feedback signal; S4, adjusting the seed scheduling strategy and input mutation strategy of the fuzzing engine according to the runtime feedback signal, preferentially allocating mutation resources to test inputs with smaller trigger distances and performing deep mutation on key byte positions until a test case that triggers the target vulnerability is generated.

2. The method of claim 1, wherein, The S1 comprises: Based on the vulnerability type and the trigger point code position, a prompt word template containing mandatory fields and optional fields is constructed, and the source code is processed to extract the code segment related to the target vulnerability and inject the prompt word template; By using an automatic intelligent agent, the large language model is supplemented with missing function definitions in a progressive prompting manner, and a few-shot thinking chain technology is used to provide step-by-step reasoning examples to guide the large language model to output candidate vulnerability trigger conditions in the five-tuple format of the trigger condition unit, thereby obtaining a candidate vulnerability trigger condition set composed of multiple trigger condition units.

3. The method of claim 2, wherein, The candidate vulnerability trigger condition output in the five-tuple format of the trigger condition unit comprises: Each trigger condition unit is formalized into a five-tuple structure containing a condition statement, a code position, an execution order, a logical conjunction identifier, and a weight factor; The condition statement is converted into a trigger distance expression for quantifying the proximity of the program state and the satisfaction of the condition according to the Korel branch function principle, the logical conjunction identifier is used to decompose complex compound conditions into atomic conditions in the disjunctive normal form, the execution order is used to model the execution constraints in the multi-point vulnerability, and the weight factor is dynamically determined according to the runtime observation results, thereby generating a candidate vulnerability trigger condition set that can accurately describe the complex vulnerability trigger scenario in the real world.

4. The method of claim 1, wherein, The S2 comprises: A first source code level instrumentation is implemented on the program under test, and distance monitoring code is inserted at the code position corresponding to each trigger condition unit in the candidate vulnerability trigger condition set to record the trigger distance value in real time during program execution; When it is detected that the trigger distance during the execution of the reachable input is less than or equal to zero, it is determined that the corresponding candidate vulnerability trigger condition is an invalid trigger condition that is too loose and is filtered out, thereby obtaining a subset of candidate vulnerability trigger conditions after preliminary screening.

5. The method of claim 4, wherein, The method further comprises: A second source code level instrumentation is implemented on the program under test, and assignment statements that forcibly satisfy the conditions are inserted at the code positions corresponding to the subset of candidate vulnerability trigger conditions after preliminary screening to generate a program under test after forced satisfaction instrumentation; The program analysis tool is used to replay the reachable input to the measured program after the forced satisfaction instrumentation, verify whether the vulnerability manifestation consistent with the vulnerability report is observed after the forced satisfaction trigger condition, and determine the verified vulnerability trigger condition that meets the preset effectiveness requirement as the verified vulnerability trigger condition that meets the preset effectiveness requirement.

6. The method of claim 1, wherein, The S3 comprises: The trigger distance expression calculation results of each trigger condition unit in the current test input execution process are obtained, the trigger distance expression calculation results are subjected to hierarchical aggregation operation according to the execution order attribute and the logical conjunction identifier attribute in each trigger condition unit, the final trigger distance value reflecting the closeness to triggering the vulnerability of the current test input in the multi-constraint and multi-execution order scene is obtained, and the final trigger distance value is taken as a runtime feedback signal for guiding seed scheduling and input mutation.

7. The method of claim 1, wherein, The S4 comprises: The trigger distance reservation criterion is added on the basis of the traditional coverage guided seed reservation mechanism, and in addition to reserving the test input capable of discovering a new execution path, the test input with a smaller trigger distance value is additionally reserved to prevent the seed with high vulnerability trigger potential from being discarded; The total mutation energy of the seed is calculated by referring to the simulated annealing energy scheduling mechanism, the energy contribution calculated based on the trigger distance value is added to the energy contribution calculated based on the control flow distance, and more mutation energy is allocated to the seed with a smaller trigger distance value to preferentially perform deep mutation.

8. A large language model driven vulnerability trigger condition guided testing apparatus, characterized in that, Comprise: The condition generation module is configured to obtain source code of a target vulnerability and a vulnerability report, and perform reasoning analysis on the source code and the vulnerability report by using a large language model to generate a candidate vulnerability trigger condition set represented in a structured form; The condition verification module is configured to perform dynamic verification on each candidate vulnerability trigger condition in the candidate vulnerability trigger condition set by using the generated reachable input in a fuzz testing process, and screen out verified vulnerability trigger conditions that meet preset effectiveness requirements; The trigger distance calculation module is configured to calculate a trigger distance of a current test input relative to the target vulnerability based on the verified vulnerability trigger conditions, and take the trigger distance as a runtime feedback signal; The fuzz testing guide module is configured to adjust a seed scheduling strategy and an input mutation strategy of a fuzz testing engine according to the runtime feedback signal, preferentially allocate mutation resources to test inputs with smaller trigger distances, and perform deep mutation on key byte positions, until a test case triggering the target vulnerability is generated.

9. A computer device, comprising: Comprise a processor and a memory; The processor runs a program corresponding to the executable program code stored in the memory by reading the executable program code, to implement the vulnerability trigger condition guided testing method driven by the large language model.

10. A non-transitory computer-readable storage medium having stored thereon a computer program, characterized in that, The program is executed by the processor to implement the vulnerability trigger condition guided testing method driven by the large language model.