Static detection method and system for information leakage of Springboot application

By converting the bytecode of Springboot applications into Jimple intermediate code, configuring sensitive information sources and leakage points, and establishing a local call graph for data flow analysis, the problems of low efficiency and high memory consumption of Springboot application information leakage detection are solved, and flexible and efficient information leakage detection is achieved.

CN120729569APending Publication Date: 2025-09-30CHINA TELECOM DIGITAL INTELLIGENCE TECH CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202510831770.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-20
Publication Date
2025-09-30

AI Technical Summary

Technical Problem

Existing technologies cannot effectively detect information leakage in Springboot applications, and have problems such as high memory consumption, long analysis time, and poor scalability.

Method used

By parsing the Jar file of the Springboot application, converting the bytecode into Jimple intermediate code, configuring sensitive information sources and information leakage points, traversing and scanning classes with Spring annotations, establishing a local call graph, and performing data flow analysis, it can be identified whether sensitive information flows into the leakage point.

Benefits of technology

It realizes flexible configuration of analysis entry and exit, adapts to application environments of different complexities, improves detection speed and accuracy, reduces memory consumption, and adapts to the unique architectural characteristics of Springboot applications.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120729569A_ABST
    Figure CN120729569A_ABST
Patent Text Reader

Abstract

The invention discloses an information leakage static detection method and system for a Springboot application, and belongs to the field of network technologies and security, and the method comprises the steps: analyzing a Jar file generated by the Springboot application, and converting a byte code into a Jimple intermediate code representation form; configuring a sensitive information source and an information leakage point; traversing and scanning all classes with Spring annotations, and searching entry classes in which sensitive information sources possibly exist; all interface methods in the entry class are scanned, if sensitive information exists in acquisition parameters of an interface method i, the interface method i serves as the entry method, a local call graph of the entry method is established, and data flow analysis is conducted on the sensitive information of the entry method; wherein in the data flow analysis process, whether the sensitive information flows into the information leakage point or not is identified, if the sensitive information flows into the information leakage point, the sensitive information is leaked, and the current flowing-in information leakage point is the information leakage position. The method is suitable for leakage static detection of the Springboot application, and is high in expandability, low in memory resource consumption and short in analysis time.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of network technology and security, and specifically relates to a static detection method and system for information leakage of Springboot applications. Background Art

[0002] In existing technical solutions, static detection methods for information leaks are commonly applied to Android applications, such as detecting permissions. The technical details of the detection are as follows: 1. Analyze the APK file, obtain the AndroidManifest.xml configuration file within the APK file, extract information about various components (such as Activity, Service, Content Provider, and BroadcastReceiver), obtain the DEX file within the APK file, extract information about each class, and construct a class collection, SootClass. The classes in the class collection are analyzed to distinguish between source and third-party classes, and further determine the validity and invalidity of third-party classes. 2. Identify third-party classes: Third-party classes are identified through methods such as obfuscation detection and class name matching. For obfuscated classes, aggregated static feature recognition is used to determine whether they are third-party classes. For unobfuscated classes, the class name is matched against a preset third-party class name library. 3. Construct a control flow graph: Parse the XML files within the APK file to obtain the UI and rule files. A control flow graph (CFG and CG) is constructed based on the component information, class information, UI files, and rule files. Edges corresponding to invalid methods are removed, and the control flow graph is updated. 4. Data Flow Analysis: Use the FlowDroid tool to perform data flow analysis on the control flow graph to identify potential information leaks. During the analysis, nodes corresponding to invalid class labels are skipped, thereby optimizing the data flow analysis process and reducing unnecessary computation.

[0003] However, existing solutions are all designed for detecting information leaks in Android apps and cannot be directly applied to Spring Boot apps due to platform and language differences. Furthermore, information leaks in Android apps are typically related to permissions, requiring analysis of the AndroidManifest.xml file, which is completely different in Spring Boot apps. Furthermore, existing solutions using FlowDroid to construct CG graphs consume a large amount of memory resources, resulting in long analysis times and low efficiency. Furthermore, existing solutions have poor scalability and lack flexible configuration of source and sink points. Summary of the Invention

[0004] In response to the deficiencies in the prior art, the present invention provides a static detection method and system for information leakage of Springboot applications, which are suitable for Springboot applications and have strong scalability, low memory resource consumption, and short analysis time.

[0005] The present invention provides the following technical solutions:

[0006] First, a static detection method for information leakage of Springboot applications is provided, including:

[0007] Parse the Jar file generated by the Springboot application and convert the bytecode into Jimple intermediate code representation;

[0008] Configure sensitive information sources and information leakage points;

[0009] Based on the converted intermediate code representation, all classes with Spring annotations are scanned to find entry classes that may contain sensitive information sources;

[0010] Scan all interface methods in the entry class. If the acquisition parameters of interface method i contain sensitive information, then use interface method i as the entry method, establish a local call graph of the entry method, and perform data flow analysis on the sensitive information of the entry method. In the process of data flow analysis, identify whether the sensitive information has flowed into the information leakage point. If so, there is sensitive information leakage, and the current information leakage point is the information leakage location.

[0011] Optionally, use the Soot framework to parse the Jar file generated by the Springboot application;

[0012] The information leakage points include: HTTP response body, HTTP response header, log record, sending email, writing to the file system or sending network request location.

[0013] Optionally, the traversal scans all classes annotated with Spring to find entry classes that may contain sensitive information sources, specifically:

[0014] When the class annotated with Spring is a class annotated with @RestController or @Controller, it is a Controller class;

[0015] When the class annotated with Spring is a class annotated with @Service, it is a Service class;

[0016] When the class annotated with Spring is a class annotated with @Repository or @Mapper, it is a Repository class;

[0017] The entry class where the sensitive information source may exist is the Controller class.

[0018] Optionally, when scanning all Spring-annotated classes, identify dependencies between all classes by scanning for fields annotated with @Autowired or @Resource .

[0019] Optionally, all interface methods in the scanning entry class are scanned. If the acquisition parameters of interface method i contain sensitive information, interface method i is used as the entry method, specifically:

[0020] Analyze the fields inside the entry class. If the fields are injected through @Autowired or @Resource annotations, get the class that the current entry class depends on.

[0021] Based on the class that the current entry class depends on, all interface methods of the current entry class are traversed and scanned. If the parameters obtained from the outside by interface method i contain sensitive information, the current interface method i is the entry method.

[0022] Optionally, the establishing of the local call graph of the entry method is specifically as follows:

[0023] Scan the statement of the entry method. If the statement calls a method inside the dependency injection class, then based on the dependency relationships of all identified classes, use the entry method and the calling method as nodes to construct an edge about the calling relationship between the entry method and the calling method.

[0024] For the entry method, a local call graph of the entry method is constructed based on all its calling methods and its calling relationship with each calling method.

[0025] Optionally, the data flow analysis of the sensitive information of the entry method is specifically performed as follows:

[0026] Obtain the variable containing sensitive information in the entry method and assign data to the variable. Based on the constructed local call graph of the entry method, track all flows of sensitive information, including changes in the variable in the statement after assignment, calling the variable as a parameter after assignment, and returning the variable as a return value after assignment. Among them, when the variable after assignment is called as a parameter, it is necessary to perform data flow analysis of the sensitive information on the called method.

[0027] Secondly, a static information leakage detection system for Springboot applications is provided, including:

[0028] Parsing module: parses the Jar file generated by the Springboot application and converts the bytecode into Jimple intermediate code representation;

[0029] Configuration module: configure sensitive information sources and information leakage points;

[0030] Annotation scanning module: Based on the converted intermediate code representation, it traverses and scans all classes with Spring annotations to find entry classes that may contain sensitive information sources;

[0031] Tracking detection module: Scan all interface methods in the entry class. If there is sensitive information in the acquisition parameters of interface method i, interface method i is used as the entry method, a local call graph of the entry method is established, and data flow analysis is performed on the sensitive information of the entry method. In the process of data flow analysis, it is identified whether the sensitive information has flowed into the information leakage point. If so, there is sensitive information leakage, and the current information leakage point is the information leakage location.

[0032] In a third aspect, a computer device is provided, comprising a processor and a memory; wherein, when the processor executes a computer program stored in the memory, the steps of the static detection method for information leakage of the Springboot application described in any one of the first aspects are implemented.

[0033] In a fourth aspect, a computer-readable storage medium is provided for storing a computer program; when the computer program is executed by a processor, the steps of the static detection method for information leakage of the Springboot application described in any one of the first aspects are implemented.

[0034] Compared with the prior art, the present invention has the following beneficial effects:

[0035] (1) The present invention provides the ability to flexibly configure analysis entry points (Source Points) and analysis exit points (Sink Points). Users can freely set sensitive information sources and potential information leakage points based on their needs. This configuration flexibility enables the present invention to adapt to application environments of varying complexity, enhancing practicality and adaptability. It overcomes the shortcomings of existing solutions that have fixed Source and Sink points, resulting in limited scalability.

[0036] (2) The present invention is optimized and designed specifically for Springboot applications, taking into account the unique architectural features of Springboot applications, such as dependency injection and MVC mode. Since existing information leakage detection is all targeted at Android applications, most of them analyze Android permission declaration files to analyze whether information leakage is caused by permissions. The present invention specifically targets Springboot applications, which are unique from other types of applications, and analyzes from the perspective of interfaces. The present invention can better adapt to the needs of such applications and provide more accurate information leakage detection services.

[0037] (3) The present invention utilizes the characteristics of the Spring framework to identify potential sensitive information entries by scanning classes annotated with @RestController or @Controller. This design can quickly locate methods that may collect or process sensitive information. Compared with traditional methods, the present invention is more efficient in detecting sensitive information sources and reduces unnecessary code scanning, thereby improving detection speed.

[0038] (4) The present invention conducts an in-depth analysis of the data flow process of the variables containing sensitive data, including operations such as data assignment and parameter passing. In particular, when sensitive data is involved, it can accurately track its flow in the application and effectively capture how sensitive information flows from the source point to the potential leakage point, thereby helping developers discover and fix potential information leakage problems at an early stage. BRIEF DESCRIPTION OF THE DRAWINGS

[0039] Figure 1 This is a flow chart of the static detection method for information leakage of Springboot applications of the present invention;

[0040] Figure 2 This is a sensitive information data flow tracking diagram given as a specific example in the present invention;

[0041] Figure 3 It is a diagram of the implementation process of constructing a local call graph of the present invention;

[0042] Figure 4 This is an architectural diagram of the information leakage static detection system for Springboot applications of the present invention. DETAILED DESCRIPTION

[0043] The present invention will be further described below with reference to the accompanying drawings. The following examples are only used to more clearly illustrate the technical solutions of the present invention and are not intended to limit the scope of protection of the present invention. It should be noted that the term "comprising" and any variations thereof in the specification and claims of the present invention and the above-mentioned drawings are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.

[0044] Before explaining the embodiments of this solution, some terms that appear later are first explained.

[0045] Source Point (analysis entry point, sensitive information source): In the context of static analysis for information leakage detection, the source point refers to the location in a program where sensitive information first appears. These locations are typically where the application receives or generates sensitive information. In web applications, common sensitive data sources include data submitted by users through HTTP requests (such as form fields and URL query parameters), authentication information in HTTP request headers, session identifiers stored in cookies, and sensitive information read from databases or file systems.

[0046] SinkPoint (analysis exit, information leakage point): In the context of static analysis information leakage detection, a sinkpoint is a location or operation in a program that may expose sensitive information to external entities. These locations typically involve output operations, such as sending data to the network, writing to the file system, displaying it in a user interface, or storing it in a database accessible to third parties.

[0047] A control flow graph (CFG) is a graphical representation used to describe the control flow in a program. It is primarily used in compiler technology and program analysis to help understand and analyze the execution path of a program. A control flow graph is a graphical representation used to display the control flow structure of a program. In a control flow graph, nodes represent basic blocks in the program, and edges represent control flow transitions. A basic block is a section of code consisting of a series of consecutive instructions. During execution, this code does not branch or transfer control flow until the end of the basic block is reached. A control flow graph can clearly display branches, loops, and other control structures in a program, making the program's logical structure more intuitive.

[0048] A call graph, or CG graph, is a key concept in program analysis, used to represent the call relationships between functions or methods in a program. A call graph is a graphical representation that shows the call relationships between functions or methods in a program. In a call graph, nodes represent functions or methods in a program, and edges represent the call relationships from one function or method to another. Call graphs are helpful in understanding the structure and control flow of a program, particularly during program analysis, optimization, and debugging.

[0049] Intermediate Representation (IR) is a high-level language used between source code and target code. It is an internal representation of the source code generated after it is processed by the compiler front-end. Intermediate code is usually more concise than source code and more abstract than target code. It aims to retain the semantic information of the source code while removing redundant details to facilitate subsequent optimization and analysis. Intermediate code comes in various forms, the most common of which include three-address code, SSA (Static Single Assignment) form, Jimple, etc. By using intermediate code, the compiler can more easily perform various optimization operations, such as constant propagation, dead code elimination, loop optimization, etc., thereby generating more efficient target code.

[0050] Example 1

[0051] like Figure 1 As shown in the figure, a static detection method for information leakage of Springboot applications includes:

[0052] Step S1: Parse the Jar file generated by the Springboot application and convert the bytecode into Jimple intermediate code representation.

[0053] Because intermediate representation (IR) retains more semantic information than bytecode, such as variable declarations, assignments, and conditional statements, this information may have been optimized or simplified in the bytecode, resulting in information loss. Therefore, intermediate representation is more suitable for static analysis. The goal of step S1 is to convert the bytecode in the SpringBoot application Jar file into an intermediate representation to facilitate further analysis.

[0054] Specifically, the Soot framework is used to parse the JAR files generated by Spring Boot applications and convert the bytecode into Jimple intermediate code representation. This process eliminates the need to construct a global call graph, which helps reduce memory consumption and improve analysis efficiency compared to traditional methods.

[0055] Step S2: Configure sensitive information sources and information leakage points.

[0056] Information leak points include: HTTP response body, HTTP response headers, logging, sending emails, writing to the file system, or sending network requests.

[0057] Users can freely set which places are sensitive information sources and which places are possible information leakage points according to their needs. The flexibility of configuring sensitive information sources and information leakage points enables the present invention to adapt to application environments of different complexities, enhancing practicality and adaptability.

[0058] Step S3: Based on the converted intermediate code representation, traverse and scan all classes with Spring annotations to find entry classes that may contain sensitive information sources.

[0059] Static analysis of information leakage requires analyzing the entry point, so the goal of step S3 is to identify locations in the program where sensitive information may appear.

[0060] Specifically, it traverses and scans all class files, looking for classes with SpringMVC controller annotations (such as @RestController or @Controller). These classes are often used to process external requests and may be entry points for sensitive information. At the same time, it records methods that may involve operations such as user input information, database query results, and file reading.

[0061] Classes annotated with Spring include:

[0062] Controller class: A class annotated with @RestController or @Controller. The Controller class identifies all entry methods for processing external requests.

[0063] Service class: A class annotated with @Service. The Service class identifies the methods of the business logic layer. When analyzing the entry method, if there is a need to enter the business logic layer method, you can locate the logic layer method based on the method reference in the intermediate code and continue to perform data flow analysis.

[0064] Repository class: A class annotated with @Repository or @Mapper. The Repository class identifies the methods of the data access layer.

[0065] When scanning all classes annotated with Spring, the dependencies between all classes, that is, the dependency injection relationships, are identified by scanning the fields annotated with @Autowired or @Resource.

[0066] Step S4: Scan all interface methods in the entry class. If there is sensitive information in the acquisition parameters of interface method i, then use interface method i as the entry method, establish a local call graph of the entry method, and perform data flow analysis on the sensitive information of the entry method; wherein, in the process of performing data flow analysis, identify whether the sensitive information flows into the information leakage point. If so, there is sensitive information leakage, and the current information leakage point is the information leakage location.

[0067] Only local call graphs are built, not global ones. A local call graph only contains the call relationships of functions or methods relevant to the current analysis task. When analyzing a class or method, the call relationships associated with it are dynamically built, rather than building the call graph for the entire application from the outset. This significantly reduces memory usage and analysis time.

[0068] Step S4 specifically includes:

[0069] S41: Determine the entry method.

[0070] Within the entry class identified in step S3, further locate interface methods that may contain sensitive information and designate them as entry methods. It is important to note that when scanning methods within the entry class, pay particular attention to those that process HTTP request parameters, request headers, cookie data, session data, and so on. If these methods contain sensitive information (such as a user's name, address, or phone number), detailed data flow analysis is required.

[0071] Specifically, analyze the fields inside the entry class. If the fields are injected through the @Autowired or @Resource annotations, obtain the class that the current entry class depends on. Based on the class that the current entry class depends on, traverse and scan all interface methods of the current entry class. If the parameters obtained from the outside by interface method i contain sensitive information, the current interface method i is the entry method.

[0072] S42: Create a local call graph of the entry method.

[0073] Specifically, if Figure 3 As shown, the statement of the entry method is scanned. If the statement calls a method inside the dependency injection class, then based on the dependency relationships of all identified classes, the entry method and the calling method are used as nodes to construct an edge about the calling relationship between the entry method and the calling method; for the entry method, based on all its calling methods and its calling relationship with each calling method, a local call graph of the entry method is constructed.

[0074] In some other embodiments, the constructed call relationship can be cached. The next time the same call relationship is encountered, it is directly read from the cache to avoid reconstruction.

[0075] S43: Perform data flow analysis on sensitive information of entry methods.

[0076] The purpose of data flow analysis is to track the flow of sensitive data in the program.

[0077] Specifically: obtain the variable containing sensitive information in the entry method, and conduct an in-depth analysis of the flow of the variable in the program, including operations such as data assignment and parameter passing.

[0078] Based on the constructed local call graph of the entry method, all flows of sensitive information are tracked, including changes in variables after assignment in statements, calling variables after assignment as parameters, and returning variables after assignment as return values. Among them, when variables after assignment are called as parameters, data flow analysis of sensitive information is required for the called method.

[0079] For example, for the user address address, it is necessary to track its entire process from initialization to final use, including its changes in assignment statements, passing as method parameters, and returning as return values.

[0080] S44: Detecting information leakage points

[0081] Identify whether sensitive information has flowed into the information leakage point. If so, there is sensitive information leakage, and the current information leakage point is the information leakage location.

[0082] Specifically, the goal of step S44 is to identify operations that may lead to information leakage during the data flow analysis process. During the data flow analysis process, the focus is on whether the data flows into possible information leakage points, such as HTTP response bodies, HTTP response headers, logging, sending emails, writing to the file system, sending network requests, etc. If sensitive data flows into these locations, it indicates the risk of information leakage.

[0083] For this application, it has fine analysis granularity and pruning optimization of analysis paths.

[0084] Specifically, select the appropriate analysis granularity based on analysis requirements to avoid performance issues caused by global analysis. Perform data flow analysis at the method level, analyzing only methods that may interact with users and transmit sensitive information. Perform finer-grained statement-level analysis within the identified analysis methods to capture more detailed data flow information and track the transmission of sensitive information.

[0085] During the analysis process, paths that are not contaminated by sensitive variables are directly pruned to avoid wasting computing resources. The recursive depth of variable propagation is also limited. For methods that exceed the propagation depth threshold, analysis is no longer performed within the method itself, but only the determination of whether the variable can be returned is performed, thus continuing the downward transfer process.

[0086] Example 2

[0087] A specific example of applying the present invention is provided.

[0088] In the following scenario, a Spring Boot application handles user personal information and provides an API for external calls. User information is persisted in a database using the Mybatis framework. The goal of static information leakage detection is to ensure that the application does not accidentally leak sensitive information, such as a user's name, address, or phone number.

[0089] For this scenario, the technical solution proposed in Example 1 of this application is applied, specifically:

[0090] Step 1: Use the Soot framework to parse the JAR file generated by the Spring Boot application and convert the bytecode into the Jimple intermediate code representation to facilitate subsequent static analysis. This step ensures that the application bytecode is converted into an intermediate representation, which facilitates deeper analysis.

[0091] Step 2: Configure the source and sink points, using user input, database reading, and file reading as the source points, and log printing and file output as the sink points. This step clearly identifies the sources of sensitive information and potential leakage points, allowing for targeted analysis.

[0092] Step 3: All class files in the application are converted to SootClass classes. Traverse these SootClasses and identify classes marked with @RestController or @Controller. These classes typically handle user requests and are entry points for sensitive information. Use the @Mapper annotation to locate the MyBatis persistence interface and identify the methods in the data access layer. Among all SootClasses, identify classes that inject the persistence interface using the @Autowired or @Resource annotations or using constructors or getter methods. These classes serve as the starting classes for analysis.

[0093] Step 4: First, obtain the methods marked with the Mapping annotation from the Controller class. If these methods obtain request parameters, request headers and other information, determine whether the current parameters contain sensitive information such as the user's name, address and phone number. If so, execute the data flow analysis algorithm proposed in this patent to track the flow of this sensitive information in the program.

[0094] Step 5: Take the data flow of the phoneNum telephone number variable as an example, and analyze it from the initialization of the variable. If the variable appears on the right side of the assignment statement, the current tracking variable will be increased by the content on the left side of the assignment statement. If the variable is passed as a parameter to the method call, the tracking will enter the method. If the variable is returned as a return value, it is necessary to return to the original method to continue tracking. If not, determine whether the data flow in the current method flows into the Sink point. If not, continue tracking in the original method. If it is found that the data flow flows into the configured Sink point, it means that the application may have information leakage risks here. The specific data flow tracking is as follows Figure 2 shown.

[0095] Example 3

[0096] like Figure 4 As shown in the figure, a static information leakage detection system for Springboot applications includes:

[0097] Parsing module: parses the Jar file generated by the Springboot application and converts the bytecode into Jimple intermediate code representation;

[0098] Configuration module: configure sensitive information sources and information leakage points;

[0099] Annotation scanning module: Based on the converted intermediate code representation, it traverses and scans all classes with Spring annotations to find entry classes that may contain sensitive information sources;

[0100] Tracking detection module: Scan all interface methods in the entry class. If there is sensitive information in the acquisition parameters of interface method i, interface method i is used as the entry method, a local call graph of the entry method is established, and data flow analysis is performed on the sensitive information of the entry method. In the process of data flow analysis, it is identified whether the sensitive information has flowed into the information leakage point. If so, there is sensitive information leakage, and the current information leakage point is the information leakage location.

[0101] In some other embodiments, the static information leakage detection system of Springboot applications also includes a detection result analysis module, a detection result persistence module and a detection result report generation module; the detection result analysis module can perform in-depth analysis of all detected information leakage locations, such as assessing the level, scope and root cause tracing of leakage risks, etc. The detection result persistence module can securely store detection data, including detection results and analysis data of the detection result analysis module; the detection result report generation module can generate reports based on the detection results and analysis data according to set requirements, thereby supporting decision-making and response.

[0102] For more specific details about the above method, please refer to the corresponding contents disclosed in the aforementioned embodiments, which will not be described again here.

[0103] Example 4

[0104] The present invention provides a computer device comprising a processor and a memory; wherein, when the processor executes a computer program stored in the memory, the steps of the above-mentioned static detection method for information leakage of Springboot applications are implemented.

[0105] For more specific details about the above method, please refer to the corresponding contents disclosed in the aforementioned embodiments, which will not be described again here.

[0106] Example 5

[0107] The present invention provides a computer-readable storage medium for storing a computer program; when the computer program is executed by a processor, the steps of the above-mentioned static detection method for information leakage of Springboot applications are implemented.

[0108] For more specific details about the above method, please refer to the corresponding contents disclosed in the aforementioned embodiments, which will not be described again here.

[0109] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on its differences from the other embodiments. References to the same or similar parts between the various embodiments will be sufficient. The systems, devices, and storage media disclosed in the embodiments are described briefly because they correspond to the methods disclosed in the embodiments. For relevant details, refer to the method description.

[0110] Those skilled in the art will clearly understand that the techniques in the embodiments of the present invention can be implemented using software plus a necessary general-purpose hardware platform. Based on this understanding, the technical solutions in the embodiments of the present invention, or the portion that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a storage medium such as ROM / RAM, a magnetic disk, or an optical disk, and includes a number of instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute the methods described in various embodiments of the present invention or certain portions of the embodiments.

[0111] The above are merely preferred embodiments of the present invention. The scope of protection of the present invention is not limited to the above embodiments. All technical solutions based on the principles of the present invention are within the scope of protection of the present invention. It should be noted that for those skilled in the art, various improvements and modifications that do not depart from the principles of the present invention should be considered within the scope of protection of the present invention.

Claims

1. A static detection method for information leakage of Springboot applications, characterized in that: include: Parse the Jar file generated by the Springboot application and convert the bytecode into Jimple intermediate code representation; Configure sensitive information sources and information leakage points; Based on the converted intermediate code representation, all classes with Spring annotations are scanned to find entry classes that may contain sensitive information sources; Scan all interface methods in the entry class. If the acquisition parameters of interface method i contain sensitive information, then use interface method i as the entry method, establish a local call graph of the entry method, and perform data flow analysis on the sensitive information of the entry method. In the process of data flow analysis, identify whether the sensitive information has flowed into the information leakage point. If so, there is sensitive information leakage, and the current information leakage point is the information leakage location.

2. A static detection method for information leakage of Springboot applications according to claim 1, characterized in that: Use the Soot framework to parse the Jar file generated by the Springboot application; The information leakage points include: HTTP response body, HTTP response header, log record, sending email, writing to the file system or sending network request location.

3. A static detection method for information leakage of Springboot applications according to claim 1, characterized in that: The traversal scans all classes annotated with Spring to find entry classes that may contain sensitive information sources, specifically: When the class annotated with Spring is a class annotated with @RestController or @Controller, it is a Controller class; When the class annotated with Spring is a class annotated with @Service, it is a Service class; When the class annotated with Spring is a class annotated with @Repository or @Mapper, it is a Repository class; The entry class where the sensitive information source may exist is the Controller class.

4. A static detection method for information leakage of Springboot applications according to claim 1, characterized in that: When scanning all classes annotated with Spring, the dependencies between all classes are identified by scanning for fields annotated with @Autowired or @Resource.

5. A static detection method for information leakage of Springboot applications according to claim 1, characterized in that: All interface methods in the scanning entry class, if the acquisition parameters of interface method i contain sensitive information, then interface method i is used as the entry method, specifically: Analyze the fields inside the entry class. If the fields are injected through @Autowired or @Resource annotations, get the class that the current entry class depends on. Based on the class that the current entry class depends on, all interface methods of the current entry class are traversed and scanned. If the parameters obtained from the outside by interface method i contain sensitive information, the current interface method i is the entry method.

6. A static detection method for information leakage of Springboot applications according to claim 4, characterized in that: The local call graph of the entry method is established as follows: Scan the statement of the entry method. If the statement calls a method inside the dependency injection class, then based on the dependency relationships of all identified classes, use the entry method and the calling method as nodes to construct an edge about the calling relationship between the entry method and the calling method. For the entry method, a local call graph of the entry method is constructed based on all its calling methods and its calling relationship with each calling method.

7. A static detection method for information leakage of Springboot applications according to claim 1, characterized in that: The data flow analysis of the sensitive information of the entry method is specifically as follows: Obtain the variable containing sensitive information in the entry method and assign data to the variable. Based on the constructed local call graph of the entry method, track all flows of sensitive information, including changes in the variable in the statement after assignment, calling the variable as a parameter after assignment, and returning the variable as a return value after assignment. Among them, when the variable after assignment is called as a parameter, it is necessary to perform data flow analysis of the sensitive information on the called method.

8. A static detection system for information leakage of Springboot applications, characterized in that: include: Parsing module: parses the Jar file generated by the Springboot application and converts the bytecode into Jimple intermediate code representation; Configuration module: configure sensitive information sources and information leakage points; Annotation scanning module: Based on the converted intermediate code representation, it traverses and scans all classes with Spring annotations to find entry classes that may contain sensitive information sources; Tracking detection module: Scan all interface methods in the entry class. If there is sensitive information in the acquisition parameters of interface method i, interface method i is used as the entry method, a local call graph of the entry method is established, and data flow analysis is performed on the sensitive information of the entry method. In the process of data flow analysis, it is identified whether the sensitive information has flowed into the information leakage point. If so, there is sensitive information leakage, and the current information leakage point is the information leakage location.

9. A computer device, characterized in that: The invention comprises a processor and a memory; wherein, when the processor executes the computer program stored in the memory, the steps of the static detection method for information leakage of the Springboot application described in any one of claims 1 to 7 are implemented.

10. A computer-readable storage medium, characterized in that Used to store computer programs; when the computer program is executed by a processor, the steps of the static detection method for information leakage of Springboot applications according to any one of claims 1 to 7 are implemented.

Citation Information

Patent Citations

  • Method and system for privacy disclosure detection

    CN106778254A

  • Injection type vulnerability detection method and system for Java Web application

    CN116595533A

  • Method and system for detecting unauthorized vulnerabilities of Java Web system

    CN116738437A

  • Byte-level Android application program privacy disclosure static detection method and system

    CN118364464A

  • Data control-oriented smart contract static analysis method and system

    US11036614B1