SIA OpenIR  > 工业控制网络与系统研究室
基于特征矩阵的工控协议模糊测试方法
Alternative TitleFuzzing Test Method Based on Feature Matrix for Industrial Control Protocols
尚文利1,2,4,5; 李文轩1,2,3,4; 陈春雨1,2,5; 和晓军3; 曾鹏1,2,4,5
Department工业控制网络与系统研究室
Source Publication信息与控制
ISSN1002-0411
2020
Volume49Issue:4Pages:433-443
Indexed ByCSCD
CSCD IDCSCD:6816149
Contribution Rank1
Funding Organization国家重点研发计划资助项目(2018YFB2004200) ; 国家自然科学基金资助项目(61773368) ; 工信部2018年工业互联网创新发展工程“工业互联网安全标准体系与试验验证环境建设”项目
Keyword工控协议 模糊测试 特征矩阵 约束规则 组合测试
Abstract

针对现有工控协议模糊测试框架生成的测试用例存在覆盖度低和效率低的问题,提出了一种基于特征矩阵的测试用例生成方法。首先通过解析协议规约提取协议特征和约束规则,利用各协议特征的属性值进行笛卡尔积进而构造协议特征矩阵,然后设计针对性的结构变异策略作用于特征矩阵,同时不断采用约束规则降低用例冗余进而得到高质量的组合测试用例集。最后提出基于特征矩阵的测试用例生成算法,并将本方案与Peach框架进行对比实验,其结果表明该方法能够有效地提高测试用例覆盖度和测试执行效率,并具有漏洞检测能力。

Other Abstract

To address the problem of low coverage and efficiency of the test cases generated by the existing industrial control protocol fuzzy test framework, we propose a test case generation method based on feature matrix. First, through an analysis of the protocol agreement to extract protocol features and constraint rules, the protocol feature matrix is constructed by the Cartesian product of the property values of each protocol feature. Then, the targeted structural variation strategy is designed to act on the feature matrix, while the constraint rules are used to reduce the redundancy of test cases and obtain a high-quality combination test case set. Finally, the test case generation algorithm based on the feature matrix is proposed. A comparison with the Peach framework shows that the method can effectively improve the coverage of test cases and test execution efficiency. Moreover, the method can detect vulnerabilities.

Language中文
Citation statistics
Document Type期刊论文
Identifierhttp://ir.sia.cn/handle/173321/27317
Collection工业控制网络与系统研究室
Corresponding Author李文轩
Affiliation1.中科院网络化控制系统重点实验室
2.中国科学院沈阳自动化研究所
3.中国科学院机器人与智能制造创新研究院
4.中国科学院大学
5.沈阳理工大学自动化与电气工程学院
Recommended Citation
GB/T 7714
尚文利,李文轩,陈春雨,等. 基于特征矩阵的工控协议模糊测试方法[J]. 信息与控制,2020,49(4):433-443.
APA 尚文利,李文轩,陈春雨,和晓军,&曾鹏.(2020).基于特征矩阵的工控协议模糊测试方法.信息与控制,49(4),433-443.
MLA 尚文利,et al."基于特征矩阵的工控协议模糊测试方法".信息与控制 49.4(2020):433-443.
Files in This Item:
File Name/Size DocType Version Access License
基于特征矩阵的工控协议模糊测试方法.pd(1368KB)期刊论文作者接受稿开放获取CC BY-NC-SAView Application Full Text
Related Services
Recommend this item
Bookmark
Usage statistics
Export to Endnote
Google Scholar
Similar articles in Google Scholar
[尚文利]'s Articles
[李文轩]'s Articles
[陈春雨]'s Articles
Baidu academic
Similar articles in Baidu academic
[尚文利]'s Articles
[李文轩]'s Articles
[陈春雨]'s Articles
Bing Scholar
Similar articles in Bing Scholar
[尚文利]'s Articles
[李文轩]'s Articles
[陈春雨]'s Articles
Terms of Use
No data!
Social Bookmark/Share
File name: 基于特征矩阵的工控协议模糊测试方法.pdf
Format: Adobe PDF
All comments (0)
No comment.
 

Items in the repository are protected by copyright, with all rights reserved, unless otherwise indicated.