Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

359results about "Decompilation/disassembly" patented technology

Control flow directed graph for use with program disassembler

Techniques and systems described herein relate to monitoring executions of computer instructions on computing devices based on learning and generating a control flow directed graph. The techniques and systems include determining a learned control flow directed graph for executable code of an application by observing executions of transitions during an observation period and determining destinations of indirect transfers based on the learned control flow directed graph. Next a disassembly of the executable code is determined based on the learned control flow directed graph, the destinations of the transfers, and the executable code.
Owner:CISCO TECHNOLOGY INC

Training / application method for representation learning model, and device and medium

Provided in the present application are a training / application method for a representation learning model, and a device and a medium. The training method comprises: extracting a plurality of source codes from an open-source repository, and on the basis of the plurality of source codes and a large language model, generating a training sample set, wherein each sample in the training sample set comprises assembly codes and natural language text; on the basis of an assembly code data set, performing pre-training to generate an assembly coder, and on the basis of a natural language data set, performing pre-training to generate a text coder; on the basis of the training sample set and a contrastive learning algorithm, performing alignment training on the assembly coder and the text coder, so as to obtain a code representation learning model and a natural language representation learning model which are semantically aligned; and on the basis of the code representation learning model and the natural language representation learning model, which are semantically aligned, constructing a representation learning model. The method of the present application significantly improves the generalization ability and accuracy of a representation learning model, and greatly reduces dependence of the model on samples and a large volume of tagged data.
Owner:TSINGHUA UNIVERSITY

Block chain abnormal smart contract detection method and system based on multi-modal knowledge distillation

The invention relates to the technical field of block chain abnormal behavior detection, in particular to a block chain abnormal smart contract detection method and system based on multi-modal knowledge distillation. The multi-dimensional feature data comprises smart contract source code static logic structure features, smart contract source code dynamic execution state features and smart contract transaction data transaction mode features; and inputting the multi-dimensional feature data into an intelligent contract detection model, and detecting and outputting the abnormal state of the to-be-detected block chain intelligent contract by using the intelligent contract detection model, the intelligent contract detection model performing knowledge distillation by using a teacher-student network model architecture. According to the method, the teacher contract detector is pre-trained by using the multi-source features, so that the student contract detector can still learn transaction behavior knowledge in the absence of transaction data, fraudulent behavior detection is realized in advance, and the detection performance of the abnormal contract is improved by integrating data of different modalities.
Owner:Chinese People's Liberation Army Cyberspace Force Information Engineering University

Control flow directed graph for use with program disassembler

Techniques and systems described herein relate to monitoring executions of computer instructions on computing devices based on learning and generating a control flow directed graph. The techniques and systems include determining a learned control flow directed graph for executable code of an application by observing executions of transitions during an observation period and determining destinations of indirect transfers based on the learned control flow directed graph. Next a disassembly of the executable code is determined based on the learned control flow directed graph, the destinations of the transfers, and the executable code.
Owner:CISCO TECHNOLOGY INC

Binary code block semantic information automatic capturing method and related device

The invention discloses a method for automatically capturing semantic information of a binary code block and a related device, and relates to the technical field of computers.The method comprises the following steps that code disassembling and instruction level analysis are conducted on the binary code block, and a binary stream original instruction sequence is generated; performing semantic intermediate representation conversion and vocabulary overflow standardization on the binary stream original instruction sequence to obtain a binary code standardized instruction sequence; obtaining an instruction data dependency relationship and an instruction control dependency relationship corresponding to the binary code block, and constructing a corresponding binary code program dependency graph; semantic code node embedding is carried out on the binary code program dependency graph to generate a binary code representation vector corresponding to context semantics; and performing automatic semantic capture reasoning on the binary code representation vector corresponding to the context semantics through a pre-trained semantic understanding model to obtain semantic information of the binary code block. According to the method, the semantic information of the binary code block can be efficiently and accurately captured.
Owner:HUANENG POWER INT INC +1

GNN-based cross-architecture binary program similarity detection method, apparatus and device

The invention provides a GNN-based cross-architecture binary program similarity detection method, apparatus and device, and relates to the technical field of information security processing. The method comprises the following steps: acquiring two binary programs to be detected, and disassembling the binary programs into a low-level virtual machine intermediate representation (LLVM) IR; constructing a program diagram based on LLVM IR; then inputting the program diagram into a FastText model to extract an LLVM IR instruction, and taking a corpus created based on the LLVM IR instruction as a vocabulary of the FastText model to perform multiple rounds of training so as to express an instruction mark as a word vector in a continuous vector space, and generating an instruction vector; according to the program diagram and the instruction vector, processing by using a global attention enhanced diagram neural network GNN to generate a diagram embedding vector with a fixed dimension; and calculating the similarity between the graph embedding vectors corresponding to the two binary programs to evaluate the similarity. According to the method, unified program representation of cross-framework binary programs can be realized, high-level semantic features are captured, and the processing efficiency of large-scale program library analysis is effectively improved.
Owner:XIAMEN UNIV OF TECH

Binary translation system and method applied to X86 program

The invention provides a binary translation system applied to an X86 program, which is used for translating a source program following X86 semantics into a target program following other semantics, and comprises a data acquisition module used for acquiring the source program; the disassembling module is used for dividing a source program into a plurality of basic blocks and analyzing subsequent basic blocks corresponding to each basic block; the backward data flow analysis module is used for sequentially analyzing each instruction in each basic block from back to front so as to obtain a target definition set and a target subsequent use set corresponding to each instruction in the source program; and the translation module is used for eliminating redundant instructions of high-order zero clearing or high-order retention of the general register generated in translation. According to the technical scheme, the register state of the general register corresponding to each instruction of the source program is analyzed through the backward data flow analysis module so as to eliminate redundant instructions generated in the translation process.
Owner:INST OF COMPUTING TECH CHINESE ACAD OF SCI

Small program privacy leakage detection method based on abstract syntax tree

The invention belongs to the technical field of applet privacy leakage detection methods, and discloses an applet privacy leakage detection method and system based on an abstract syntax tree. Decompiling the packaged file of the applet to obtain a source code file; all the logic layer JavaScript files are converted into AST by using an expression analysis library; obtaining a calling dependency graph between a page logic layer file and a tool file layer according to the file reference relationship, obtaining a field-level binding dependency graph of the page logic layer file and the tool file layer according to a data and event binding relationship of the page rendering layer and the page logic layer, and merging the two layers to obtain a global dependency graph; finally, combining the dependency graphs to generate a global dependency relationship graph; dividing the JavaSript code into a plurality of basic blocks according to the dividing rule of the boundary of the control flow, determining the type of the edge according to the information of the boundary, and obtaining a GCFG by combining the dependency graph; and inputting the GCFG into a taint-pointer analysis module, and obtaining a privacy disclosure path according to predefined sink and source libraries and a data flow propagation rule.
Owner:XIDIAN UNIV

Network security malicious code binary search method and system

The invention provides a network security malicious code binary search method and system, and relates to the technical field of data processing, and the method comprises the steps: calculating the multi-dimensional structural similarity between a to-be-detected binary file and each standard binary reference file based on a function level control flow semantic feature vector; determining a finally matched standard binary reference file according to the multi-dimensional structural similarity; performing fine-grained difference analysis on the binary file to be detected and the finally matched standard binary reference file to obtain a fine-grained difference analysis result; and on the basis of a fine-grained difference analysis result, in combination with sensitive data operation behavior feature detection, judging whether the to-be-detected binary file is a maliciously tampered version, and positioning a malicious code injection point. According to the method, the defects that in the prior art, dependence on fixed features is too high, and compilation optimization is sensitive are overcome.
Owner:BEIJING HANGYUN SCI & TECH CO LTD

Multi-dimensional binary software component analysis system and method

The invention discloses a multi-dimensional binary software component analysis system and method, and the system comprises a static enhanced feature extraction module which is used for extracting multi-dimensional features of a target binary system through a disassembling engine, carrying out the fusion of the multi-dimensional features to form an enhanced feature representation model, and carrying out the preliminary matching through the combination of a feature hash library; the component verification module is used for recording runtime behaviors and analyzing the behavior log to verify a static analysis result; the intelligent knowledge base linkage module is used for realizing automatic traceability and risk assessment; the false alarm filtering and confidence evaluation module is used for optimizing credibility grading of a final result, constructing a false alarm filtering mechanism based on Bayesian reasoning, integrating results of multiple analysis stages, calculating the confidence of an identification result of each component, outputting a grading report and supporting a user to screen high-credibility results as required; and comprehensiveness, accuracy and intelligence of binary software component identification are realized.
Owner:JIANGSU HOPERUN SOFTWARE CO LTD

Cloud native security configuration system and method based on container analysis and LLM

The invention discloses a cloud native security configuration system and method based on container analysis and LLM, and the system comprises a mirror image static analysis module which is used for compiling a Linux kernel and a standard library source code to extract intermediate representation, and tracking and constructing a double-layer mapping relation library from the system call to the container capability; the dynamic binary extraction module is used for executing the container mirror image and extracting a binary file of a core function; the mirror image static and dynamic association module is used for executing two-stage static binary file analysis and extracting function requirements required by system calling and mirror image for loading during container running; and the cue word construction and model fine adjustment module is used for constructing cue words, performing fine adjustment on the LLM model and generating a minimum privilege function limitation configuration file of the container. According to the method, static analysis and runtime analysis are combined, the container mirror image is thoroughly checked, the function, which is specified by a user and exceeds the original definition of the mirror image, of the LLM model is finely adjusted through the cue word, and privileged function security configuration is generated according to specific requirements.
Owner:ZHEJIANG UNIV

Data security-oriented mobile application dynamic and static dual-combination detection method and system

The invention relates to the technical field of data security detection, in particular to a data security-oriented mobile application dynamic and static dual-combination detection method and system. The method comprises the following steps: collecting basic information of a target mobile application from a plurality of heterogeneous data sources, and constructing a basic data set of the mobile application information; performing decompilation and static analysis based on the installation file in the resource library, and outputting a static risk feature vector in combination with the sensitive data operation rule set; dynamically running a target application in the controlled sandbox environment, monitoring network traffic, system calling and file operation behavior sequences, and outputting a dynamic behavior risk feature vector; and fusing the two types of feature vectors, and inputting the fused feature vectors into a risk assessment model to generate a comprehensive data security risk assessment report. According to the method, a comprehensive evaluation system is constructed by fusing static and dynamic risk features, and full-dimension coverage of the security risk of the mobile application is realized.
Owner:INSTITUTE OF NETWORK TECHNOLOGY (YANTAI) +1

Performance analysis method and device for cross-architecture semantic equivalence instruction stream, and storage medium

The invention provides a performance analysis method and device for a cross-architecture semantic equivalence instruction stream and a storage medium, and the method comprises the steps: taking a high-level language program as input, aiming at a plurality of target architectures, generating a multi-dimensional semantic equivalence instruction stream set from a high-level language form to an intermediate representation and then to an assembly code through a compiler; based on semantic equivalence instruction streams of code units with different granularities and compiler debugging information, establishing a mapping relationship between a target region in a source code and an intermediate representation and assembly codes, and forming a cross-hierarchy equivalence region fully-connected graph; and based on the semantic equivalence instruction stream set and the cross-level equivalence region fully-connected graph, automatically embedding a performance monitoring code at the boundary of the target region, and carrying out performance test on the elastic region. According to the method, the accurate performance test of the cross-architecture semantic equivalence instruction stream can be realized.
Owner:INST OF COMPUTING TECH CHINESE ACAD OF SCI

Smart contract decompilation code optimization method and system

The invention discloses a smart contract decompilation code optimization method and a smart contract decompilation code optimization system, which are used for solving the technical problem that an existing smart contract decompilation code optimization method cannot provide a more comprehensive optimization scheme. The method comprises the steps of obtaining a to-be-optimized smart contract decompilation code, and constructing a contract dependency graph based on the to-be-optimized smart contract decompilation code; performing fragment extraction on the contract dependency graph to generate a variable method code context; generating a plurality of thinking chain prompts based on the contract dependency graph; performing code optimization on the to-be-optimized smart contract decompilation code by adopting a large language model according to a variable method code context, a plurality of thinking chain prompts, a preset variable type reasoning candidate set and a preset contract attribute reasoning candidate set, and outputting an intermediate smart contract decompilation code; and performing consistency check on the middle smart contract decompilation code according to the to-be-optimized smart contract decompilation code by adopting a preset program analysis and verification technology, and determining a target smart contract decompilation code.
Owner:SUN YAT SEN UNIV

Determining source code of a software code

Systems, methods, and software can be used to determine source code of a software code. In some aspects, a method includes: processing a binary code by using a file encoder model to obtain a file embedding vector; and selecting one or more source code samples based on the file embedding vector and a distance function.
Owner:CYLANCE INC

Construction system and method for big data analysis algorithm library

Disclosed in the present invention is a construction system for a big data analysis algorithm library, comprising: an analysis process construction module, an operator platform selection module, a code reverse generation module, a user code verification module, a cluster control host, and a cluster computing host. Cross-platform and cross-language algorithm fusion can be realized, and data analysis is realized in a complete and heterogeneous data analysis flow. Also disclosed in the present invention is a construction method for a big data analysis algorithm library.
Owner:XI AN JIAOTONG UNIV

Strengthening method and device for gap application

The invention belongs to the technical field of information security, and particularly relates to a reinforcing method and device for a swan application. The method comprises the steps of obtaining a to-be-reinforced swan gap application, wherein the swan gap application comprises at least one first byte code file; decompiling the first byte code file into an editable first file, and modifying and reinforcing the first file to generate a second file; and compiling the second file into a second byte code file, and generating the reinforced swan application based on the second byte code file. The invention provides an application reinforcement scheme which is available for a swan-gap system and has better performance.
Owner:BEIJING ZHI YOU WANG AN TECH CO LTD

Binary vulnerability data set expansion method and system based on cross-modal alignment

The invention discloses a binary vulnerability data set expansion method and system based on cross-modal alignment, provides a hierarchical semantic fusion alignment framework, and remarkably improves the precision and expandability of binary vulnerability detection through a heterogeneous modal semantic bridging and transfer learning mechanism. A multi-modal semantic mapping channel is constructed by utilizing natural language interpretation and combining program structured analysis and constant anchor point coding, so that the semantic difference between a binary code and a source code is effectively bridged; a hierarchical attention mechanism enhances the fine-grained perception capability of cross-modal matching; furthermore, a migration framework driven by a vulnerability detection task is provided, binary vulnerability detection is mapped to a source code feature space through cross-modal alignment, a binary vulnerability data set is rapidly expanded by utilizing rich source code vulnerability data, and the data scale bottleneck is broken through.
Owner:Chinese People's Liberation Army Cyberspace Force Information Engineering University

Code embedding method based on semantic embedding vector generation model and related device

The invention discloses a code embedding method based on a semantic embedding vector generation model, which belongs to the technical field of computers, and comprises the following steps of: obtaining a binary code block, and performing disassembling processing and code structure analysis based on different granularities to obtain a basic block corresponding to the binary code block and a control flow diagram structure feature; performing assembly instruction linear conversion and cross-instruction-set semantic embedding conversion on the basis of the basic blocks corresponding to the binary code blocks and the structural features of the control flow graph to generate a unified binary code semantic embedding vector space corresponding to a cross-instruction-set architecture; obtaining a known vulnerability sample, and performing semantic vulnerability characterization analysis and candidate vulnerability retrieval positioning to generate a candidate vulnerability code block set; and carrying out dynamic analysis verification on the candidate vulnerability code block set and identifying a corresponding vulnerability repair state so as to output a corresponding binary vulnerability code block detection report. According to the method, high-precision semantic embedding of binary codes can be realized.
Owner:HUANENG POWER INT INC +1

Contract vulnerability detection method and system based on cross-granularity feature fusion and meta-learning

The invention discloses a contract vulnerability detection method and system based on cross-granularity feature fusion and meta-learning, and relates to the technical field of block chain security, the method comprises the following steps: obtaining a source code and a compiled byte code of a contract to be detected; source code semantic features are extracted from the source code, operation code execution features are extracted from the byte code, and graph structure features are extracted after a program dependency graph is constructed from the source code; performing cross-granularity attention interaction to generate cross-granularity fusion features; performing type-aware feature modulation on the cross-granularity fusion feature and a vulnerability type identifier of the current detection task, training a classifier by adopting a meta-learning strategy, and outputting a vulnerability detection result; and in response to the vulnerability detection result that the vulnerability exists, positioning the vulnerability code position based on the graph-source code attention weight matrix generated in the cross-granularity attention interaction process, thereby solving the problem of poor generalization ability in a rare vulnerability scene with scarce samples.
Owner:CHENGDU UNIV OF INFORMATION TECH

Automatic threat detection of executable files based on static data analysis

Aspects of the present disclosure relate to threat detection of executable files. A plurality of static data points may be extracted from an executable file without decrypting or unpacking the executable file. The executable file may then be analyzed without decrypting or unpacking the executable file. Analysis of the executable file may comprise applying a classifier to the plurality of extracted static data points. The classifier may be trained from data comprising known malicious executable files, known benign executable files and known unwanted executable files. Based upon analysis of the executable file, a determination can be made as to whether the executable file is harmful.
Owner:OPEN TEXT CORPORATION

Malicious APP family identification method based on multi-modal feature fusion

The invention relates to a malicious APP family identification method based on multi-modal feature fusion, and belongs to the technical field of information security. The method comprises the following steps: performing data preprocessing on the Android APK, including unpacking and decompiling operations, to obtain a byte code file and a smali code file; respectively extracting byte code image features, operation code sequence features and control flow chart features; according to the method, byte code image features are extracted by using an OfficientNetV2L convolutional neural network, operation code sequence features are extracted by using a k-Shingles algorithm and a SimHash algorithm, and control flow chart features are extracted by using a static analysis tool and a capsule graph neural network. And carrying out low-rank multi-modal fusion on the three features, and constructing a CNN-BiLSTM-Attention detection classification model, so as to realize identification and judgment on the malicious APP family. According to the method, the recognition accuracy is improved, and the generalization ability of the model is enhanced.
Owner:CHONGQING UNIV OF POSTS & TELECOMM

Cross-architecture binary code similarity detection method based on graph neural network

The invention discloses a graph neural network-based cross-architecture binary code similarity detection method, which comprises the following steps of: respectively implementing original feature extraction operation on an open source software binary file and a firmware binary file by utilizing a reverse engineering tool to obtain basic feature data of the open source software binary file and the firmware binary file; the control flow diagram of the open source software and the firmware is converted into an embedded representation through an embedded network, the open source software generates an embedded representation table, and the firmware generates a corresponding embedded representation; and storing the open source software embedded representation into an open source software database, storing the firmware embedded representation into a firmware database, and finally, comparing the similarity of data in the database to complete the similarity detection of the cross-architecture binary codes so as to screen out code fragments possibly having potential safety hazards in the firmware. According to the method, the similarity of the cross-architecture binary codes can be effectively detected, and the third-party codes with security risks in the firmware of the Internet of Things equipment can be accurately detected.
Owner:NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP +1

Large language model-based understandable evaluation index-oriented decompilation code optimization method

The invention discloses a large language model-based understandability evaluation index-oriented decompilation code optimization method, which mainly aims at Java decompilation codes, and comprises the following steps of: firstly, designing and realizing an understandability evaluation index to realize quantitative analysis on the understandability of the decompilation codes; on the basis, a grammar correctness and semantic consistency checking mechanism is introduced in the method, on the premise that code grammar correctness and semantic consistency before and after optimization are guaranteed, optimizable fragments in codes are automatically recognized through an abstract syntax tree and added into cue words, and a large language model is guided to optimize decompiled codes. Furthermore, quantitative comparison is performed on codes before and after optimization through evaluation indexes, and an iterative optimization process is controlled based on a comparison result. According to the method, the decompilation code can be optimized, the understandability of the decompilation code is improved, an index-oriented improvement thought can be provided for a decompiler developer, and the method can be widely applied to reverse engineering, safety analysis and other scenes.
Owner:NANJING UNIV

Static binary code taint analysis method based on propagation action range

The invention discloses a static binary code taint analysis method based on a propagation action scope, and relates to the field of static binary code taint analysis, and the static binary code taint analysis method comprises the following steps: extracting a program instruction set and a control flow structure based on a disassembling result of a target binary code; calculating a value set with a source of the binary code based on the control flow graph; on the basis of the control flow diagram and the value set with the source, executing cross-function stain propagation analysis, and identifying memory positions or registers influenced by pollution in each function and propagation action ranges of the memory positions or the registers; and extracting all instruction sets using the taint data based on the taint and the propagation action range thereof. According to the method, the false alarm rate of static binary taint analysis can be reduced and the instruction set involved in the taint analysis can be reduced without increasing the analysis overhead, so that the method has important significance in improving the instrumentation efficiency and the operation efficiency of dynamic taint analysis and improving the accuracy of protocol reversion, fuzzy testing and vulnerability mining based on the taint analysis.
Owner:EAST CHINA NORMAL UNIV

Automatic vulnerability detection method based on intermediate pseudo code and graph neural network

The invention provides an automatic vulnerability detection method based on an intermediate pseudo code and a graph neural network. The method comprises the following steps: converting an assembly code of a binary program into a pseudo code; identifying a sensitive function; constructing a data dependency graph (PDG), and extracting a data dependency sub-graph by taking the key function as a central node; generating a graph semantic embedding vector by combining a pre-training model CodeT5-small and a graph attention network (GAT), and generating a graph structure embedding vector by using a node2vec algorithm; training is carried out through a double-branch feature analysis model based on a graph convolutional neural network (GCN) and a classification model of a multi-layer perceptron (MLP); and detecting vulnerabilities by using the trained model. According to the method, the sensitive function vulnerability of the binary program can be distinguished under the condition that source codes do not exist, the accuracy and efficiency of automatic vulnerability mining are remarkably improved, the limitation of a traditional automatic vulnerability mining method is effectively solved, and the method has important practical application value.
Owner:NANJING UNIV OF POSTS & TELECOMM

Binary code decompilation system based on large model multi-stage fine tuning

The invention provides a binary code decompiling system based on large model multi-stage fine tuning. The method comprises two stages: a first stage: a data set acquisition and construction stage: acquiring a source code data set comprising source codes and binary file pairs from an open source project and code data set, and obtaining a high-quality decompilation data set through a data preprocessing process; the second stage is a decompilation stage based on large model fine adjustment and static analysis, decompilation is carried out after a decompilation data set is compiled, an assembly code obtained after decompilation is aligned with a source code in the decompilation data set to be used for fine adjustment of the open source large model, a function call graph analysis technology is cooperated, a program context is obtained, and the open source large model is subjected to static analysis; and obtaining a final decompilation large model. Therefore, the purpose of providing a high-quality decompilation data set and an efficient decompilation algorithm is achieved.
Owner:BEIHANG UNIV

Binary code semantic analysis method and device, electronic equipment and medium

The invention discloses a binary code semantic analysis method and device, electronic equipment and a medium. The method comprises the steps that static information and dynamic information corresponding to binary codes are determined, and a target control flow diagram is generated according to the static information and the dynamic information; wherein the static information is obtained by performing static disassembly on the binary code, and the dynamic information is obtained by performing dynamic instrumentation on the binary code; through a pre-constructed semantic model, a semantic vector is given to a node in the target control flow graph according to the static information, and a mixed feature vector corresponding to the node is obtained; through a heterogeneous attention mechanism, performing classification and antagonism analysis on nodes in the target control flow diagram according to the mixed feature vector; and disassembling the binary code according to the classification result and the antagonism analysis result to obtain a semantic analysis result of the binary code. According to the technical scheme provided by the embodiment of the invention, the semantic analysis accuracy of the binary code can be remarkably improved.
Owner:AGRICULTURAL BANK OF CHINA

Binary vulnerability retrieval and positioning method and system based on high-dimensional vulnerability characterization

The invention relates to the field of code vulnerability detection, in particular to a binary vulnerability retrieval and positioning method and system based on high-dimensional vulnerability characterization, and the method comprises the steps: firstly inputting a binary file, analyzing the structural information of the binary file, and analyzing a machine instruction; extracting binary file function information, generating a cross-platform basic block IR instruction sequence, constructing a control flow graph, and constructing a data dependency graph; splicing the program dependency graph feature vector and the basic block IR instruction sequence feature vector, and performing multi-modal feature fusion to generate a comprehensive high-dimensional vulnerability representation vector; and finally, inputting the high-dimensional vulnerability representation vector into an index for searching to obtain a plurality of nearest neighbor indexes and distances, converting the distances into similarity, filtering according to a similarity threshold to obtain a most similar vulnerability vector, and obtaining vulnerability information and vulnerability positions corresponding to the vulnerability vector. The problems that traditional binary vulnerability detection cross-platform and compiler optimization detection fails and the result reliability is low are solved.
Owner:HUANENG POWER INT INC +1

IDA microcode-based digital multimeter customized code obfuscator construction method and system

The invention relates to the technical field of software security, and discloses an IDA microcode-based digital multimeter customized code obfuscator construction method and system, and the method comprises the steps: carrying out the obfuscation replacement of a measurement algorithm and a data processing method in a digital multimeter code based on an instruction replacement technology; confusing a control flow of the digital multimeter based on a false control flow technology, namely obtaining a calling relation of basic blocks to reconstruct an original program, and avoiding generation of an endless loop in a symbolic execution process through a method of assigning a value to an opaque predicate in advance; randomly modifying variable names, identifiers and function names of the sensitive data information of the digital multimeter based on a variable name confusion algorithm; and carrying out decompilation and code conversion on the obfuscation algorithm based on the IDA microcode, and constructing the digital multimeter customized code obfuscator based on the IDA microcode. The method can be integrated into the development environment of the digital multimeter, the safety protection level of the digital multimeter is improved, and the measurement data is prevented from being illegally stolen.
Owner:YUNNAN POWER GRID CO LTD KUNMING POWER SUPPLY BUREAU