基于特征矩阵的工控协议模糊测试方法 | |
Alternative Title | Fuzzing Test Method Based on Feature Matrix for Industrial Control Protocols |
尚文利1,2,4,5![]() ![]() | |
Department | 工业控制网络与系统研究室 |
Source Publication | 信息与控制
![]() |
ISSN | 1002-0411 |
2020 | |
Volume | 49Issue:4Pages:433-443 |
Indexed By | CSCD |
CSCD ID | CSCD:6816149 |
Contribution Rank | 1 |
Funding Organization | 国家重点研发计划资助项目(2018YFB2004200) ; 国家自然科学基金资助项目(61773368) ; 工信部2018年工业互联网创新发展工程“工业互联网安全标准体系与试验验证环境建设”项目 |
Keyword | 工控协议 模糊测试 特征矩阵 约束规则 组合测试 |
Abstract | 针对现有工控协议模糊测试框架生成的测试用例存在覆盖度低和效率低的问题,提出了一种基于特征矩阵的测试用例生成方法。首先通过解析协议规约提取协议特征和约束规则,利用各协议特征的属性值进行笛卡尔积进而构造协议特征矩阵,然后设计针对性的结构变异策略作用于特征矩阵,同时不断采用约束规则降低用例冗余进而得到高质量的组合测试用例集。最后提出基于特征矩阵的测试用例生成算法,并将本方案与Peach框架进行对比实验,其结果表明该方法能够有效地提高测试用例覆盖度和测试执行效率,并具有漏洞检测能力。 |
Other Abstract | To address the problem of low coverage and efficiency of the test cases generated by the existing industrial control protocol fuzzy test framework, we propose a test case generation method based on feature matrix. First, through an analysis of the protocol agreement to extract protocol features and constraint rules, the protocol feature matrix is constructed by the Cartesian product of the property values of each protocol feature. Then, the targeted structural variation strategy is designed to act on the feature matrix, while the constraint rules are used to reduce the redundancy of test cases and obtain a high-quality combination test case set. Finally, the test case generation algorithm based on the feature matrix is proposed. A comparison with the Peach framework shows that the method can effectively improve the coverage of test cases and test execution efficiency. Moreover, the method can detect vulnerabilities. |
Language | 中文 |
Citation statistics | |
Document Type | 期刊论文 |
Identifier | http://ir.sia.cn/handle/173321/27317 |
Collection | 工业控制网络与系统研究室 |
Corresponding Author | 李文轩 |
Affiliation | 1.中科院网络化控制系统重点实验室 2.中国科学院沈阳自动化研究所 3.中国科学院机器人与智能制造创新研究院 4.中国科学院大学 5.沈阳理工大学自动化与电气工程学院 |
Recommended Citation GB/T 7714 | 尚文利,李文轩,陈春雨,等. 基于特征矩阵的工控协议模糊测试方法[J]. 信息与控制,2020,49(4):433-443. |
APA | 尚文利,李文轩,陈春雨,和晓军,&曾鹏.(2020).基于特征矩阵的工控协议模糊测试方法.信息与控制,49(4),433-443. |
MLA | 尚文利,et al."基于特征矩阵的工控协议模糊测试方法".信息与控制 49.4(2020):433-443. |
Files in This Item: | ||||||
File Name/Size | DocType | Version | Access | License | ||
基于特征矩阵的工控协议模糊测试方法.pd(1368KB) | 期刊论文 | 作者接受稿 | 开放获取 | CC BY-NC-SA | View Application Full Text |
Items in the repository are protected by copyright, with all rights reserved, unless otherwise indicated.
Edit Comment