Program, processing device, and method
By identifying and scoring system call commands and functions within call flows, the program and device enhance software inspection efficiency by prioritizing inspection resources based on importance scores.
Patent Information
- Application Number
- PCT/JP2024/009981
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-03-14
- Publication Date
- 2025-09-18
AI Technical Summary
Existing static analysis methods treat all call flows in software equally, leading to inefficient inspection processing.
A program and processing device that identifies predetermined system call commands or functions within call flows, assigns importance scores based on a correspondence relationship, and outputs call flow information to prioritize inspection resources.
Improves the efficiency of software inspection by preferentially allocating resources to functions with higher importance scores and call flows, enhancing the effectiveness of the inspection process.
Smart Images

Figure JP2024009981_18092025_PF_FP_ABST
Abstract
Description
Program, processing device, and method
[0001] The present disclosure relates to a program, a processing device, and a method.
[0002] Patent Document 1 discloses a technology that performs static analysis on binary code (i.e., software to be inspected), extracts the functions, system calls, and API calls that are called, as well as the argument values and conditions at the time of the calls, compares the extracted information with the contents of specifications, etc., and detects malicious code based on the comparison results.
[0003] JP 2009-98851 A
[0004] However, the technology disclosed in Patent Document 1 treats all call flows included in the software under inspection equally, which may result in inefficient inspection processing. A "call flow" refers to a flow that includes multiple functions that have a call relationship.
[0005] An object of the present disclosure is to provide a program, a processing device, and a method that can realize an efficient inspection process. It should be noted that this object is only one of multiple objects that the multiple embodiments disclosed in this specification aim to achieve. Other objects or problems and novel features will become apparent from the description of this specification or the accompanying drawings.
[0006] The program according to the present disclosure causes a processing device to execute processing including: identifying a predetermined system call command or a predetermined function in a call flow that includes a start function and an end function of the call flow included in target software and has a plurality of functions that have a call relationship; identifying an importance score corresponding to the identified type of predetermined system call command or predetermined function based on a correspondence relationship between a plurality of types of system call commands or functions and the importance scores corresponding to each type; assigning the identified importance score to each function included in the call flow; and outputting call flow information regarding each function included in the call flow and the importance scores assigned to each function.
[0007] The processing device according to the present disclosure includes a first identification unit that identifies a predetermined system call command or a predetermined function in a call flow that includes a start function and an end function of the call flow included in target software and has a plurality of functions that have a call relationship; a second identification unit that identifies an importance score corresponding to the identified type of predetermined system call command or predetermined function based on a correspondence relationship between a plurality of types of system call commands or functions and an importance score corresponding to each type; an assignment unit that assigns the identified importance score to each function included in the call flow; and an output unit that outputs call flow information regarding each function included in the call flow and the importance score assigned to each function.
[0008] The method disclosed herein includes identifying a predetermined system call command or a predetermined function in a call flow that includes a start function and an end function of the call flow included in target software and has a plurality of functions that have a call relationship; identifying an importance score corresponding to the identified type of predetermined system call command or predetermined function based on a correspondence relationship between a plurality of types of system call commands or functions and an importance score corresponding to each type; assigning the identified importance score to each function included in the call flow; and outputting call flow information related to each function included in the call flow and the importance score assigned to each function.
[0009] The present disclosure can provide a program, a processing device, and a method that can realize efficient inspection processing.
[0010] 1 is a block diagram illustrating an example of a processing device of the present disclosure. FIG. 2 is a flowchart illustrating an example of processing operation of the processing device of the present disclosure. FIG. 3 is a block diagram illustrating another example of a processing device of the present disclosure. FIG. 4 is a flowchart illustrating another example of processing operation of the processing device of the present disclosure. FIG. 5 is a block diagram illustrating another example of a processing device of the present disclosure. FIG. 6 is a flowchart illustrating another example of processing operation of the processing device of the present disclosure. FIG. 7 is a diagram illustrating another example of processing operation of the processing device of the present disclosure. FIG. 8 is a diagram illustrating another example of call flow information. FIG. 9 is a diagram illustrating an example of call flow information. FIG. 10 is a block diagram illustrating an example of a software inspection device of the present disclosure. FIG. 11 is a flowchart illustrating another example of processing operation of the processing device of the present disclosure. FIG. 12 is a diagram illustrating an example of a configuration of a processing device. FIG. 13 is a diagram illustrating an example of a configuration of a software inspection device.
[0011] Hereinafter, embodiments will be described with reference to the drawings. In this disclosure, the drawings may relate to one or more embodiments. Furthermore, each element in the drawings may apply to one or more embodiments. Furthermore, in the embodiments, identical or equivalent elements are given the same reference numerals, and redundant description will be omitted.
[0012] First Embodiment Configuration Example of Processing Device Fig. 1 is a block diagram showing an example of a processing device according to the present disclosure. In Fig. 1, a processing device 10 includes an identification unit (first identification unit) 11, an identification unit (second identification unit) 12, an assignment unit 13, and an output unit 14.
[0013] The identification unit 11 identifies a predetermined system call command or a predetermined function in a "call flow" included in target software (e.g., software to be inspected). The "call flow" has a plurality of functions, including a start function and an end function of the call flow, that have a call relationship.
[0014] For example, the identification unit 11 acquires "information about the call flow." The "information about the call flow" includes at least information about a plurality of functions and system call instructions included in the call flow, and information about the call relationships among the plurality of functions. The identification unit 11 may then identify a predetermined system call instruction or a predetermined function included in the call flow based on a list that holds information about a predetermined system call instruction and a predetermined function, and the information about the call flow.
[0015] The identification unit 12 identifies an importance score corresponding to the type of predetermined system call instruction or predetermined function identified by the identification unit 11, based on a correspondence relationship between multiple types of system call instructions or functions and the "importance scores" corresponding to each type. In the above correspondence relationship, for example, a system call instruction or function that has a greater impact on the system when exploited by a backdoor or the like may be associated with a higher importance score. In this case, the importance score may also be called a malignancy score.
[0016] The assigning unit 13 assigns the importance score identified by the identifying unit 12 to each function included in the call flow. That is, the assigning unit 13 propagates the importance score corresponding to the type of system call instruction or function included in the call flow to all functions included in the same call flow.
[0017] The output unit 14 outputs information about each function included in the call flow and the importance score assigned to each function (hereinafter, sometimes referred to as "call flow information"). The output unit 14 may output the target software together with the call flow information.
[0018] <Example of Processing Device Operation> FIG. 2 is a flowchart showing an example of processing operation of the processing device of the present disclosure.
[0019] The identification unit 11 identifies a predetermined system call instruction or a predetermined function in the "call flow" (step S11). For example, the identification unit 11 acquires "information about the call flow." Then, the identification unit 11 identifies the predetermined system call instruction or the predetermined function included in the call flow based on a list that holds information about the predetermined system call instruction and the predetermined function and the information about the call flow.
[0020] FIG. 3 is a diagram illustrating an example of the processing operation of the processing device of the present disclosure. For example, the above list holds "execve" as a predetermined system call instruction. The call flow shown in FIG. 3 includes the system call instruction "execve," functions "func2," "func1," and "do_com." In this case, the identification unit 11 identifies the system call instruction "execve" as the predetermined system call instruction in the call flow. Note that the binary in FIG. 3 represents the target software.
[0021] The identifying unit 12 identifies an importance score corresponding to the identified type of predetermined system call instruction or predetermined function based on the "correspondence" (step S12). In the example of FIG. 3, the system call instruction "execve" is associated with an importance score of "10" in the list. In this case, the identifying unit 12 identifies the score "10" as the importance score corresponding to the identified type of predetermined system call instruction. For example, an importance score of "10" may be the most important, and an importance score of "0" may be the least important.
[0022] The assigning unit 13 assigns the importance score identified by the identifying unit 12 to each function included in the call flow (step S13). As described above, in the example of FIG. 3, the call flow includes the system call command "execve", the function "func2", the function "func1", and the function "do_com". Therefore, in the example of FIG. 3, an importance score of "10" is assigned to each of the functions "func2", "func1", and "do_com". Note that the assigning unit 13 does not need to assign an importance score to the function "func1", which is an internal function that is not exported.
[0023] The output unit 14 outputs call flow information relating to each function included in the call flow and the importance score assigned to each function (step S14). This call flow information is described as "policy" in FIG.
[0024] As described above, according to the first embodiment, the identification unit 11 in the processing device 10 identifies a predetermined system call instruction or a predetermined function in a call flow. The identification unit 12 identifies an importance score corresponding to the type of predetermined system call instruction or function identified by the identification unit 11, based on a correspondence relationship between a plurality of types of system call instructions or functions and the importance scores corresponding to each type. The assignment unit 13 assigns the importance score identified by the identification unit 12 to each function included in the call flow. The output unit 14 outputs call flow information related to each function included in the call flow and the importance score assigned to each function.
[0025] The configuration of the processing device 10 makes it possible to obtain call flow information relating to each function included in a call flow and the importance score assigned to each function. By using this call flow information during software inspection processing, resources can be preferentially allocated to inspection processing of functions assigned importance scores indicating higher importance and call flows including such functions, thereby improving the efficiency of software inspection processing.
[0026] Second Embodiment Configuration Example of Processing Device Fig. 4 is a block diagram showing another example of a processing device according to the present disclosure. In Fig. 4, a processing device 20 includes an identification unit (first identification unit) 21, an identification unit (second identification unit) 22, an assignment unit 23, and an output unit 24.
[0027] Similar to the identification unit 11, the identification unit 21 identifies a predetermined system call instruction or a predetermined function in a "call flow" included in target software (e.g., software to be inspected). The target software includes multiple call flows, i.e., a first call flow and a second call flow. The identification unit 21 identifies a predetermined system call instruction or a predetermined function in each of the first call flow and the second call flow.
[0028] For example, the identification unit 21 acquires "call flow information." The "call flow information" includes at least information about a plurality of functions and system call instructions included in a first call flow, and information about the call relationships among the plurality of functions. The "call flow information" includes at least information about a plurality of functions and system call instructions included in a second call flow, and information about the call relationships among the plurality of functions. The identification unit 21 may then identify a predetermined system call instruction or a predetermined function included in the first call flow based on a list that holds information about predetermined system call instructions and predetermined functions, and the information about the call flow. The identification unit 21 may also identify a predetermined system call instruction or a predetermined function included in the second call flow based on a list that holds information about predetermined system call instructions and predetermined functions, and the information about the call flow.
[0029] Similar to the identification unit 12, the identification unit 22 identifies an importance score corresponding to the type of predetermined system call instruction or predetermined function identified by the identification unit 21 based on a correspondence between multiple types of system call instructions or functions and the "importance scores" corresponding to each type. Specifically, the identification unit 22 identifies an importance score corresponding to the type of predetermined system call instruction or predetermined function identified in the first call flow, and an importance score corresponding to the type of predetermined system call instruction or predetermined function identified in the second call flow. Hereinafter, the importance score corresponding to the type of predetermined system call instruction or predetermined function identified in the first call flow may be referred to as a "first importance score." Furthermore, the importance score corresponding to the type of predetermined system call instruction or predetermined function identified in the second call flow may be referred to as a "second importance score."
[0030] The assigning unit 23 assigns a first importance score to each function included in the first call flow. The assigning unit 23 also assigns a second importance score to each function included in the second call flow. That is, the assigning unit 23 propagates the importance score corresponding to the type of system call command or function included in the call flow to all functions included in the same call flow.
[0031] Here, when a common function is included in the first call flow and the second call flow, the assigning unit 23 selects the importance score corresponding to the highest importance as the importance score of the common function.
[0032] The output unit 24 outputs call flow information relating to each function included in the first call flow and the importance score assigned to each function, and each function included in the second call flow and the importance score assigned to each function. The output unit 24 may output the target software together with the call flow information.
[0033] <Example of Processing Device Operation> FIG. 5 is a flowchart showing another example of the processing device operation of the present disclosure.
[0034] The identifying unit 21 identifies a predetermined system call instruction or a predetermined function in each call flow included in the target software (step S21).
[0035] FIG. 6 is a diagram illustrating another example of the processing operation of the processing device of the present disclosure. For example, the above list holds "execve" and "syscall A" as predetermined system call instructions. The first call flow shown in FIG. 6 includes the system call instruction "execve," functions "func2," "func1," and "do_com." The second call flow shown in FIG. 6 includes the system call instruction "syscall A," functions "func4," "func3," and "do_com." In this case, the identification unit 21 identifies the system call instruction "execve" as the predetermined system call instruction in the first call flow. The identification unit 21 also identifies the system call instruction "syscall A" as the predetermined system call instruction in the second call flow.
[0036] The identification unit 22 identifies an importance score corresponding to the identified type of predetermined system call instruction or predetermined function based on the "correspondence" (step S22). In the example of Fig. 6, the above correspondence associates the system call instruction "execve" with an importance score of "10," and the system call instruction "syscall A" with an importance score of "8." In this case, the identification unit 22 identifies a score of "10" as the importance score corresponding to the type of system call instruction "execve" identified for the first call flow. Furthermore, the identification unit 22 identifies a score of "8" as the importance score corresponding to the type of system call instruction "syscall A" identified for the second call flow.
[0037] The assigning unit 23 assigns the importance score identified for each call flow to each function included in each call flow (step S23). As described above, in the example of FIG. 6, the first call flow includes the system call command "execve," the functions "func2," "func1," and "do_com." Therefore, in the example of FIG. 6, an importance score of "10" is assigned to each of the functions "func2," "func1," and "do_com." Also, in the example of FIG. 6, the second call flow includes the system call command "syscall A," the functions "func4," "func3," and "do_com." Therefore, in the example of FIG. 6, an importance score of "8" is assigned to each of the functions "func4," "func3," and "do_com." Note that the assigning unit 23 does not need to assign importance scores to the functions "func1" and "func3," which are internal functions that are not exported.
[0038] The assigning unit 23 determines whether there is a common function included in multiple call flows (step S24).
[0039] If there is a common function included in multiple call flows (step S24 YES), the assigning unit 23 selects the importance score corresponding to the highest importance as the importance score of the common function (step S25). In the example of Fig. 6, the function "do_com" is a common function, and the importance score "10" and the importance score "8" are assigned to the function "do_com". Therefore, the assigning unit 23 selects the importance score "10" from the importance score "10" and the importance score "8" as the importance score of the function "do_com".
[0040] The output unit 24 outputs call flow information regarding each function included in each call flow and the importance score assigned to each function (step S26). Note that if there is no common function included in multiple call flows (step S24 NO), the processing proceeds to step S26.
[0041] As described above, according to the second embodiment, the identification unit 21 in the processing device 20 identifies a predetermined system call instruction or a predetermined function in each of the first call flow and the second call flow. The identification unit 22 identifies an importance score corresponding to the predetermined system call instruction or the type of predetermined function identified in the first call flow, and an importance score corresponding to the predetermined system call instruction or the type of predetermined function identified in the second call flow. The assignment unit 23 assigns a first importance score to each function included in the first call flow. The assignment unit 23 also assigns a second importance score to each function included in the second call flow. The output unit 24 outputs call flow information related to each function included in the first call flow and the importance scores assigned to each function, and each function included in the second call flow and the importance scores assigned to each function.
[0042] With this configuration of the processing device 20, even if the target software includes multiple call flows, it is possible to obtain call flow information regarding each function included in each call flow and the importance score assigned to each function.
[0043] Third Embodiment Configuration Example of Processing Device Fig. 7 is a block diagram showing another example of a processing device according to the present disclosure. In Fig. 7, a processing device 30 includes an identification unit (first identification unit) 31, an identification unit (second identification unit) 32, an assignment unit 33, and an output unit 34.
[0044] Similar to the identifying unit 21, the identifying unit 31 identifies a predetermined system call command or a predetermined function in each of the first call flow and the second call flow.
[0045] The identification unit 32 identifies an importance score and a category corresponding to the type of the predetermined system call instruction or the predetermined function identified by the identification unit 31 based on the "correspondence relationship." Here, the "correspondence relationship" associates multiple types of system call instructions or functions with "importance scores" and "categories" corresponding to each type. Specifically, the identification unit 32 identifies a first importance score and a first category corresponding to the type of the predetermined system call instruction or the predetermined function identified in the first call flow. Furthermore, the identification unit 32 identifies a second importance score and a second category corresponding to the type of the predetermined system call instruction or the predetermined function identified in the second call flow.
[0046] Here, the categories may be defined from the perspective of the functionality of the functions, such as "writing to a file" or "creating a process." Alternatively, the categories may be defined for each security function, such as "integrity," "confidentiality," or "availability." Alternatively, the categories may be categories of vulnerabilities that may occur due to the functions, and may be defined by, for example, the Common Weakness Enumeration (CWE).
[0047] The assigning unit 33 assigns a first importance score and a first category to each function included in the first call flow, and the assigning unit 23 assigns a second importance score and a second category to each function included in the second call flow.
[0048] Here, when the first call flow and the second call flow include a common function and the first category is the same as the second category, the assigning unit 33 selects the importance score corresponding to the highest importance among the first importance score and the second importance score as the importance score of the common function. In other words, when the first call flow and the second call flow include a common function and the first category is the same as the second category, the assigning unit 33 assigns the score corresponding to the higher importance among the first importance score and the second importance score to the common function.
[0049] When the first category and the second category are different, the output unit 34 outputs call flow information regarding each function included in the first call flow and the importance score assigned to each function, i.e., the policy of the first category. When the first category and the second category are different, the output unit 34 outputs call flow information regarding each function included in the second call flow and the importance score assigned to each function, i.e., the policy of the second category.
[0050] When the first category and the second category are the same, the output unit 34 outputs call flow information regarding each function included in the first call flow and the second call flow and the importance score assigned to each function, i.e., the policy of the first category (= second category).
[0051] The output unit 34 may also output the target software together with the call flow information.
[0052] <Example of Processing Device Operation> FIG. 8 is a flowchart showing another example of the processing device operation of the present disclosure.
[0053] The identifying unit 31 identifies a predetermined system call instruction or a predetermined function in each call flow included in the target software (step S31).
[0054] FIG. 9 is a diagram illustrating another example of the processing operation of the processing device of the present disclosure. For example, the above list holds "execve" and "syscall A" as predetermined system call instructions. The first call flow shown in FIG. 9 includes the system call instruction "execve," functions "func2," "func1," and "do_com." The second call flow shown in FIG. 9 includes the system call instruction "syscall A," functions "func4," "func3," and "do_com." In this case, the identification unit 31 identifies the system call instruction "execve" as the predetermined system call instruction in the first call flow. The identification unit 31 also identifies the system call instruction "syscall A" as the predetermined system call instruction in the second call flow.
[0055] The identification unit 32 identifies an importance score and a category corresponding to the identified type of predetermined system call instruction or predetermined function based on the "correspondence" (step S32). In the example of FIG. 9 , the above correspondence corresponds the system call instruction "execve" with an importance score of "10" and the category "A," and the system call instruction "syscall A" with an importance score of "8" and the category "B." In this case, the identification unit 32 identifies the score "10" and the category "A" as the importance score and the category corresponding to the type of system call instruction "execve" identified for the first call flow. Furthermore, the identification unit 32 identifies the score "8" and the category "B" as the importance score and the category corresponding to the type of system call instruction "syscall A" identified for the second call flow.
[0056] The assigning unit 33 assigns the importance score identified for each call flow to each function included in each call flow (step S33). As described above, in the example of FIG. 9, the first call flow includes the system call command "execve," the functions "func2," "func1," and "do_com." Therefore, in the example of FIG. 9, the functions "func2," "func1," and "do_com" are assigned an importance score of "10" and a category of "A," respectively. Also, in the example of FIG. 9, the second call flow includes the system call command "syscall A," the functions "func4," "func3," and "do_com." Therefore, in the example of FIG. 9, the functions "func4," "func3," and "do_com" are assigned an importance score of "8" and a category of "B," respectively. The assigning unit 33 does not need to assign importance scores and categories to the functions "func1" and "func3", which are internal functions that are not exported.
[0057] The assigning unit 33 determines whether there is a common function included in multiple call flows of the same category (step S34).
[0058] If there is a common function included in multiple call flows of the same category (step S34 YES), the assigning unit 33 selects the importance score corresponding to the highest importance as the importance score of the common function (step S35). In the example of Figure 9, the function "do_com" is a common function in the first call flow and the second call flow, but the category of the first call flow is different from the category of the second call flow. If the category of the first call flow is "A" and the category of the second call flow is also "A", the assigning unit 33 selects the importance score "10" from the importance score "10" and the importance score "8" as the importance score of the function "do_com".
[0059] The output unit 34 outputs call flow information regarding each function included in each call flow and the importance score assigned to each function (step S26). Here, for multiple call flows that are in different categories, the output unit 34 outputs call flow information (policy) for each call flow. Furthermore, for multiple call flows that include a common function and are in the same category, the output unit 34 outputs call flow information (policy) common to the multiple call flows.
[0060] As described above, according to the third embodiment, the assigning unit 33 in the processing device 30 assigns the importance score and category identified by the identifying unit 32 to each function included in the call flow. The output unit 34 outputs call flow information related to each function included in the call flow and the importance score and category assigned to each function.
[0061] This configuration of the processing device 30 makes it possible to obtain call flow information relating to each function included in the call flow and the importance score and category assigned to each function. By using this call flow information during software inspection processing, resources can be preferentially allocated to inspection processing of call flows in desired categories, thereby improving the efficiency of software inspection processing.
[0062] <Modification of Third Embodiment> FIG. 10 is a diagram illustrating another example of the processing operation of the processing device of the present disclosure. As shown in FIG. 10 , a call flow may span multiple binaries (in FIG. 10 , a main binary and a sub-binary (library (lib))). In this case, the output unit 34 may output call flow information (policy) on a binary basis (library basis). FIGS. 11A, 11B, and 11C are diagrams illustrating examples of call flow information. FIG. 11A shows call flow information after analysis of library C. FIG. 11B shows call flow information after analysis of library B. FIG. 11C shows call flow information after analysis of library A. As shown in FIG. 11C , an importance score of "10" is selected as the importance score for the library A function "do_com" from among importance scores of "10" and "8."
[0063] <Fourth Embodiment> <Configuration Example of Software Inspection Device> Fig. 12 is a block diagram showing an example of a software inspection device according to the present disclosure. In Fig. 12, a software inspection device 50 includes an identification unit (first identification unit) 51, an identification unit (second identification unit) 52, an assignment unit 53, an output unit 54, and an inspection processing unit 55. The identification unit 51, the identification unit 52, the assignment unit 53, and the output unit 54 may have the same functions as the identification unit 11, the identification unit 12, the assignment unit 13, and the output unit 14. Alternatively, the identification unit 51, the identification unit 52, the assignment unit 53, and the output unit 54 may have the same functions as the identification unit 21, the identification unit 22, the assignment unit 23, and the output unit 24. Alternatively, the identification unit 51, the identification unit 52, the assignment unit 53, and the output unit 54 may have the same functions as the identification unit 31, the identification unit 32, the assignment unit 33, and the output unit 34. Here, the description will be given by taking as an example that the identification unit 51, the identification unit 52, the assignment unit 53, and the output unit 54 have the same functions as the identification unit 31, the identification unit 32, the assignment unit 33, and the output unit 34.
[0064] The inspection processing unit 55 sets a part of the target software as an inspection range based on the specified inspection range specification parameters, and executes inspection of the target software within the set inspection range. For example, the inspection processing unit 55 executes "process flow analysis" as an inspection process of the target software.
[0065] The inspection range specification parameter may be a score threshold, a category, or a combination of a score threshold and a category.
[0066] For example, if a score threshold of "9" is set as the inspection range specification parameter, the inspection processing unit 55 inspects the target software with an inspection range including functions whose importance score is equal to or greater than 9. That is, based on the call flow information, the inspection processing unit 55 may inspect functions whose importance indicated by an importance score is higher than a predetermined level among multiple functions included in the call flow of the target software.
[0067] Furthermore, for example, when category "A" is set as the inspection range specification parameter, the inspection processing unit 55 inspects the target software with functions of category "A" as the inspection range.
[0068] Also, for example, if a score threshold of "9" and a category of "A" are set as the inspection range specification parameters, the inspection processing unit 55 inspects the target software with functions in category "A" and with an importance score value of 9 or more as the inspection range.
[0069] For example, the inspection processing unit 55 receives a "call flow function list" corresponding to each call flow, and call flow information regarding each function included in each call flow and the importance score and category assigned to each function.The inspection processing unit 55 then performs data flow analysis and control flow analysis on the call flow (i.e., functions) in the inspection range specified by the inspection range specification parameters, thereby identifying conditional branches in the call flow in the inspection range that are likely to trigger a backdoor.The inspection processing unit 55 then outputs inspection results including information regarding the identified conditional branches, etc.
[0070] <Example of Operation of Software Inspection Device> FIG. 13 is a flowchart showing another example of the processing operation of the processing device of the present disclosure.
[0071] The identifying unit 51 identifies a predetermined system call command or a predetermined function in each call flow included in the target software (step S41).
[0072] The identifying unit 52 identifies the importance score and category corresponding to the identified type of predetermined system call instruction or predetermined function based on the "correspondence" (step S42).
[0073] The assigning unit 53 assigns the importance score identified for each call flow to each function included in each call flow (step S43).
[0074] The assigning unit 53 determines whether there is a common function included in multiple call flows of the same category (step S44).
[0075] If there is a common function included in multiple call flows of the same category (YES in step S44), the assigning unit 53 selects the importance score corresponding to the highest importance as the importance score of the common function (step S45).
[0076] The output unit 54 outputs call flow information relating to each function included in each call flow and the importance score assigned to each function, and the target software (step S46).
[0077] The inspection processing unit 55 sets a part of the target software as an inspection range based on the specified inspection range designation parameters, and inspects the target software within the set inspection range (step S47).
[0078] As described above, according to the fourth embodiment, the inspection processing unit 55 in the software inspection device 50 sets a portion of the target software as the inspection range based on the specified inspection range designation parameters, and performs inspection of the target software within the set inspection range.
[0079] This configuration of the software inspection device 50 allows resources to be preferentially allocated to inspection processing within the inspection range, thereby improving the efficiency of software inspection processing.
[0080] <Other Embodiments> <1> Fig. 14 is a diagram showing an example of the configuration of a processing device. In Fig. 14, the processing device 100 has a processor 101 and a memory 102. The processor 101 may be, for example, a microprocessor, a micro processing unit (MPU), or a central processing unit (CPU). The processor 101 may include multiple processors. The memory 102 is configured by a combination of volatile memory and non-volatile memory. The memory 102 may include storage located remotely from the processor 101. In this case, the processor 101 may access the memory 102 via an I (Input) / O (Output) interface (not shown).
[0081] The processing devices 10, 20, and 30 of the first to third embodiments may each have the configuration shown in FIG. 14 . The identifying units 11, 21, and 31, the identifying units 12, 22, and 32, the assigning units 13, 23, and 33, and the output units 14, 24, and 34 of the processing devices 10, 20, and 30 of the first to third embodiments may be realized by the processor 101 reading and executing a program stored in the memory 102. That is, the processing devices 10, 20, and 30 of the first to third embodiments may be realized by software. The program can be stored using various types of non-transitory computer-readable media and supplied to the processing devices 10, 20, and 30. Examples of non-transitory computer-readable media include magnetic recording media (e.g., flexible disks, magnetic tapes, and hard disk drives) and magneto-optical recording media (e.g., magneto-optical disks). Further examples of non-transitory computer-readable media include CD-ROMs (Read Only Memory), CD-Rs, and CD-R / Ws. Further, examples of non-transitory computer-readable media include semiconductor memory. Semiconductor memory includes, for example, mask ROM, programmable ROM (PROM), erasable PROM (EPROM), flash ROM, and random access memory (RAM). The program may also be provided to the processing devices 10, 20, and 30 by various types of transitory computer-readable media. Examples of transitory computer-readable media include electrical signals, optical signals, and electromagnetic waves. The transitory computer-readable media may provide the program to the processing devices 10, 20, and 30 via wired communication paths such as electrical wires and optical fibers, or wireless communication paths.
[0082] Alternatively, the identification units 11, 21, and 31, the identification units 12, 22, and 32, the assignment units 13, 23, and 33, and the output units 14, 24, and 34 of the processing devices 10, 20, and 30 of the first to third embodiments may each be realized by dedicated hardware. Furthermore, some or all of the components of each device may be realized by general-purpose or dedicated circuits, processors, etc., or a combination thereof. These may be configured by a single chip or by multiple chips connected via a bus. Some or all of the components of each device may be realized by a combination of the above-mentioned circuits, etc., and a program. Furthermore, a CPU (Central Processing Unit), a GPU (Graphics Processing Unit), an FPGA (Field-Programmable Gate Array), a quantum processor (quantum computer control chip), etc., may be used as the processor.
[0083] Furthermore, when some or all of the components of the processing devices 10, 20, and 30 of the first to third embodiments are realized by multiple information processing devices, circuits, etc., the multiple information processing devices, circuits, etc. may be centrally or distributed. For example, the information processing devices, circuits, etc. may be realized as a client-server system, a cloud computing system, or the like, in a form in which each is connected via a communication network. Furthermore, the functions of the processing devices 10, 20, and 30 of the first to third embodiments may be provided in a Software as a Service (SaaS) format.
[0084] <2> Figure 15 is a diagram showing an example of the configuration of a software inspection device. In Figure 15, the software inspection device 200 has a processor 201 and a memory 202. The processor 201 may be, for example, a microprocessor, a microprocessing unit (MPU), or a central processing unit (CPU). The processor 201 may include multiple processors. The memory 202 is configured by a combination of volatile memory and non-volatile memory. The memory 202 may include storage located away from the processor 201. In this case, the processor 201 may access the memory 202 via an I (Input) / O (Output) interface (not shown).
[0085] The software inspection apparatus 50 of the fourth embodiment may have the configuration shown in FIG. 15 . The identifying unit 51, identifying unit 52, assigning unit 53, output unit 54, and inspection processing unit 55 of the software inspection apparatus 50 of the fourth embodiment may be realized by the processor 201 reading and executing a program stored in the memory 202. That is, the software inspection apparatus 50 of the fourth embodiment can be realized by software. The program can be stored using various types of non-transitory computer-readable media and supplied to the software inspection apparatus 50. Examples of non-transitory computer-readable media include magnetic recording media (e.g., flexible disks, magnetic tapes, hard disk drives) and magneto-optical recording media (e.g., magneto-optical disks). Further examples of non-transitory computer-readable media include CD-ROMs (Read Only Memory), CD-Rs, and CD-R / Ws. Further examples of non-transitory computer-readable media include semiconductor memories. The semiconductor memory may include, for example, a mask ROM, a programmable ROM (PROM), an erasable PROM (EPROM), a flash ROM, and a random access memory (RAM). The program may also be supplied to the software inspection device 50 by various types of transitory computer-readable media. Examples of transitory computer-readable media include electrical signals, optical signals, and electromagnetic waves. The transitory computer-readable media may supply the program to the software inspection device 50 via a wired communication path such as an electrical wire or optical fiber, or via a wireless communication path.
[0086] Alternatively, the identifying unit 51, the identifying unit 52, the assigning unit 53, the output unit 54, and the inspection processing unit 55 of the software inspection device 50 of the fourth embodiment may each be realized by dedicated hardware. Furthermore, some or all of the components of each device may be realized by general-purpose or dedicated circuits, processors, etc., or a combination thereof. These may be configured by a single chip, or by multiple chips connected via a bus. Some or all of the components of each device may be realized by a combination of the above-mentioned circuits, etc., and a program. Furthermore, a CPU (Central Processing Unit), a GPU (Graphics Processing Unit), an FPGA (Field-Programmable Gate Array), a quantum processor (quantum computer control chip), etc., may be used as the processor.
[0087] Furthermore, when some or all of the components of the software inspection device 50 of the fourth embodiment are realized by multiple information processing devices, circuits, etc., the multiple information processing devices, circuits, etc. may be centrally or decentralized. For example, the information processing devices, circuits, etc. may be realized as a client-server system, a cloud computing system, or the like, in a form in which each is connected via a communication network. Furthermore, the functions of the software inspection device 50 of the fourth embodiment may be provided in a SaaS (Software as a Service) format.
[0088] Although the present invention has been described above with reference to the embodiments, the present invention is not limited to the above. Various modifications that can be understood by those skilled in the art can be made to the configuration and details of the present invention within the scope of the invention. Furthermore, each embodiment can be combined with other embodiments as appropriate.
[0089] Each drawing is merely an example for describing one or more embodiments. Each drawing may not relate to only one particular embodiment, but may also relate to one or more other embodiments. As will be understood by those skilled in the art, various features or steps described with reference to any one drawing can be combined with features or steps shown in one or more other drawings to create, for example, an embodiment not explicitly shown or described. Not all features or steps shown in any one drawing are necessary to describe an exemplary embodiment, and some features or steps may be omitted. The order of steps described in any drawing may be changed as appropriate.
[0090] Some or all of the above embodiments may be described as, but are not limited to, the following supplementary notes: (Supplementary Note 1) A program that causes a processing device to execute processing including: identifying a predetermined system call command or a predetermined function in a call flow that includes a start function and an end function of the call flow included in target software and has a plurality of functions that have a call relationship, identifying an importance score corresponding to the type of the identified predetermined system call command or predetermined function based on a correspondence relationship between a plurality of types of system call commands or functions and the importance scores corresponding to each type, assigning the identified importance score to each function included in the call flow, and outputting call flow information related to each function included in the call flow and the importance score assigned to each function. (Supplementary Note 2) The program according to Supplementary Note 1, wherein the target software includes a first call flow and a second call flow, wherein identifying the predetermined system call instruction or the predetermined function includes identifying the predetermined system call instruction or the predetermined function in each of the first call flow and the second call flow, wherein identifying the importance score includes identifying a first importance score corresponding to the type of the predetermined system call instruction or the predetermined function identified in the first call flow and a second importance score corresponding to the type of the predetermined system call instruction or the predetermined function identified in the second call flow, and wherein assigning the importance score includes assigning the first importance score to each function included in the first call flow and assigning the second importance score to each function included in the second call flow. (Supplementary Note 3) The program according to Supplementary Note 2, wherein assigning the importance score includes, when a common function exists that is included in both the first call flow and the second call flow, assigning the common function the score corresponding to the higher importance of the first importance score or the second importance score.(Supplementary Note 4) The program according to Supplementary Note 1, wherein the correspondence relationship associates the plurality of types with importance scores and categories corresponding to each type, and assigning the importance scores includes assigning the identified importance scores and categories to each function included in the call flows. (Supplementary Note 5) The program according to Supplementary Note 4, wherein the target software includes a first call flow and a second call flow, wherein identifying the predetermined system call instruction or the predetermined function includes identifying the predetermined system call instruction or the predetermined function in each of the first call flow and the second call flow, wherein identifying the importance scores includes identifying a first importance score and a first category corresponding to the type of predetermined system call instruction or predetermined function identified in the first call flow, and a second importance score and a second category corresponding to the type of predetermined system call instruction or predetermined function identified in the second call flow, and wherein assigning the importance scores includes assigning the first importance score and the first category to each function included in the first call flow, and assigning the second importance score and the second category to each function included in the second call flow. (Supplementary Note 6) The program according to Supplementary Note 5, wherein assigning the importance score includes, when a common function included in both the first call flow and the second call flow exists and the first category and the second category are the same, assigning the common function a score corresponding to a higher importance between the first importance score and the second importance score. (Supplementary Note 7) The program according to any one of Supplements 1 to 6, wherein outputting includes outputting the target software and the call flow information. (Supplementary Note 8) The program according to Supplementary Note 7, wherein the processing includes targeting, based on the call flow information, functions of a plurality of functions included in the call flow of the target software whose importance indicated by an importance score is higher than a predetermined level as inspection processing targets.(Supplementary Note 9) A processing device comprising: a first identification unit that identifies a predetermined system call command or a predetermined function in a call flow that includes a start function and an end function of the call flow included in target software and has a plurality of functions that have a call relationship; a second identification unit that identifies an importance score corresponding to the identified type of predetermined system call command or predetermined function based on a correspondence relationship between a plurality of types of system call commands or functions and an importance score corresponding to each type; an assignment unit that assigns the identified importance score to each function included in the call flow; and an output unit that outputs call flow information regarding each function included in the call flow and the importance score assigned to each function. (Supplementary Note 10) The processing device according to Supplementary Note 9, wherein the target software includes a first call flow and a second call flow, the first identification unit identifies a predetermined system call instruction or a predetermined function in each of the first call flow and the second call flow, the second identification unit identifies a first importance score corresponding to the type of the predetermined system call instruction or the predetermined function identified in the first call flow and a second importance score corresponding to the type of the predetermined system call instruction or the predetermined function identified in the second call flow, and the assigning unit assigns the first importance score to each function included in the first call flow and the second importance score to each function included in the second call flow. (Supplementary Note 11) The processing device according to Supplementary Note 10, wherein, when a common function included in both the first call flow and the second call flow exists, the assigning unit assigns the score corresponding to the higher importance of the first importance score or the second importance score to the common function. (Supplementary Note 12) The processing device according to Supplementary Note 9, wherein the correspondence relationship associates the plurality of types with importance scores and categories corresponding to each type, and the assigning unit assigns the identified importance score and category to each function included in the call flow.(Supplementary Note 13) The processing device according to Supplementary Note 12, wherein the target software includes a first call flow and a second call flow, the first identification unit identifies a predetermined system call instruction or a predetermined function in each of the first call flow and the second call flow, the second identification unit identifies a first importance score and a first category corresponding to the predetermined system call instruction or the type of predetermined function identified in the first call flow, and a second importance score and a second category corresponding to the predetermined system call instruction or the type of predetermined function identified in the second call flow, and the assigning unit assigns the first importance score and the first category to each function included in the first call flow, and assigns the second importance score and the second category to each function included in the second call flow. (Supplementary Note 14) The processing device according to Supplementary Note 13, wherein, when a common function included in both the first call flow and the second call flow exists and the first category is the same, the assigning unit assigns the score corresponding to the higher importance of the first importance score or the second importance score to the common function. (Supplementary Note 15) The processing device according to any one of Supplementary Notes 9 to 14, wherein the output unit outputs the target software and the call flow information. (Supplementary Note 16) A software inspection device comprising: the processing device according to Supplementary Note 15; and an inspection processing unit that, based on the call flow information, inspects functions of a plurality of functions included in the call flow of the target software, the functions having an importance indicated by an importance score higher than a predetermined level.(Supplementary Note 17) A method comprising: identifying a predetermined system call command or a predetermined function in a call flow that includes a start function and an end function of the call flow included in target software and has a plurality of functions that have a call relationship; identifying an importance score corresponding to the identified type of predetermined system call command or predetermined function based on a correspondence relationship between a plurality of types of system call commands or functions and an importance score corresponding to each type; assigning the identified importance score to each function included in the call flow; and outputting call flow information regarding each function included in the call flow and the importance score assigned to each function. (Supplementary Note 18) The method according to Supplementary Note 17, wherein the target software includes a first call flow and a second call flow, wherein identifying the predetermined system call instruction or the predetermined function includes identifying the predetermined system call instruction or the predetermined function in each of the first call flow and the second call flow, wherein identifying the importance score includes identifying a first importance score corresponding to the type of the predetermined system call instruction or the predetermined function identified in the first call flow and a second importance score corresponding to the type of the predetermined system call instruction or the predetermined function identified in the second call flow, and wherein assigning the importance score includes assigning the first importance score to each function included in the first call flow and assigning the second importance score to each function included in the second call flow. (Supplementary Note 19) The method according to Supplementary Note 18, wherein assigning the importance score includes, when a common function exists that is included in both the first call flow and the second call flow, assigning the common function the score corresponding to the higher importance of the first importance score or the second importance score. (Supplementary Note 20) The method of Supplementary Note 17, wherein the correspondence associates the plurality of types with importance scores and categories corresponding to each type, and assigning the importance scores includes assigning the identified importance scores and categories to each function included in the call flow.(Supplementary Note 21) The method according to Supplementary Note 20, wherein the target software includes a first call flow and a second call flow; identifying the specified system call instruction or the specified function includes identifying the specified system call instruction or the specified function in each of the first call flow and the second call flow; identifying the importance score includes identifying a first importance score and a first category corresponding to the type of specified system call instruction or the specified function identified in the first call flow, and a second importance score and a second category corresponding to the type of specified system call instruction or the specified function identified in the second call flow, respectively; and assigning the importance score includes assigning the first importance score and the first category to each function included in the first call flow, and assigning the second importance score and the second category to each function included in the second call flow. (Supplementary Note 22) The method according to Supplementary Note 21, wherein assigning the importance score includes, when a common function included in both the first call flow and the second call flow exists and the first category and the second category are the same, assigning the common function a score corresponding to the higher importance of the first importance score or the second importance score. (Supplementary Note 23) The method according to any one of Supplements 17 to 22, wherein the outputting includes outputting the target software and the call flow information. (Supplementary Note 24) The method according to Supplementary Note 23, wherein the method includes designating, as an inspection process target, of a plurality of functions included in the call flow of the target software, functions whose importance indicated by an importance score is higher than a predetermined level, based on the call flow information.
[0091] REFERENCE SIGNS LIST 10 Processing device 11 Identification unit (first identification unit) 12 Identification unit (second identification unit) 13 Assignment unit 14 Output unit 20 Processing device 21 Identification unit (first identification unit) 22 Identification unit (second identification unit) 23 Assignment unit 24 Output unit 30 Processing device 31 Identification unit (first identification unit) 32 Identification unit (second identification unit) 33 Assignment unit 34 Output unit 50 Software inspection device 51 Identification unit (first identification unit) 52 Identification unit (second identification unit) 53 Assignment unit 54 Output unit 55 Inspection processing unit
Claims
1. A program that causes a processing device to execute processing including: identifying a specific system call command or a specific function in a call flow that includes a start function and an end function of the call flow included in the target software and has multiple functions that have a call relationship; identifying an importance score corresponding to the type of the identified specific system call command or specific function based on the correspondence between multiple types of system call commands or functions and the importance scores corresponding to each type; assigning the identified importance score to each function included in the call flow; and outputting call flow information regarding each function included in the call flow and the importance scores assigned to each function.
2. The program of claim 1, wherein the target software includes a first call flow and a second call flow; identifying the specified system call instruction or the specified function includes identifying the specified system call instruction or the specified function in each of the first call flow and the second call flow; identifying the importance score includes identifying a first importance score corresponding to the type of specified system call instruction or the specified function identified in the first call flow, and a second importance score corresponding to the type of specified system call instruction or the specified function identified in the second call flow; and assigning the importance score includes assigning the first importance score to each function included in the first call flow and assigning the second importance score to each function included in the second call flow.
3. The program of claim 2, wherein assigning the importance score includes, when there is a common function included in both the first call flow and the second call flow, assigning the common function a score corresponding to a higher importance out of the first importance score and the second importance score.
4. The program of claim 1, wherein the correspondence relationship associates the multiple types with importance scores and categories corresponding to each type, and assigning the importance scores includes assigning the identified importance scores and categories to each function included in the call flow.
5. The program of claim 4, wherein the target software includes a first call flow and a second call flow; identifying the specified system call instruction or the specified function includes identifying the specified system call instruction or the specified function in each of the first call flow and the second call flow; identifying the importance score includes identifying a first importance score and a first category corresponding to the type of specified system call instruction or the specified function identified in the first call flow, and a second importance score and a second category corresponding to the type of specified system call instruction or the specified function identified in the second call flow, respectively; and assigning the importance score includes assigning the first importance score and the first category to each function included in the first call flow, and assigning the second importance score and the second category to each function included in the second call flow.
6. The program of claim 5, wherein assigning the importance score includes, when there is a common function included in both the first call flow and the second call flow and the first category and the second category are the same, assigning the common function a score corresponding to the higher importance of the first importance score or the second importance score.
7. The program according to any one of claims 1 to 6, wherein the outputting includes outputting the target software and the call flow information.
8. The program described in claim 7, wherein the processing includes selecting, based on the call flow information, functions among a plurality of functions included in the call flow of the target software whose importance indicated by an importance score is higher than a predetermined level as the inspection processing target.
9. A processing device comprising: a first identification unit that identifies a predetermined system call command or a predetermined function in a call flow that includes a start function and an end function of the call flow included in target software and has a plurality of functions that have a call relationship; a second identification unit that identifies an importance score corresponding to the identified predetermined system call command or type of predetermined function based on the correspondence between a plurality of types of system call command or function and the importance score corresponding to each type; an assignment unit that assigns the identified importance score to each function included in the call flow; and an output unit that outputs call flow information regarding each function included in the call flow and the importance score assigned to each function.
10. The processing device according to claim 9, wherein the target software includes a first call flow and a second call flow; the first identification unit identifies a predetermined system call command or a predetermined function in each of the first call flow and the second call flow; the second identification unit identifies a first importance score corresponding to the type of predetermined system call command or predetermined function identified in the first call flow, and a second importance score corresponding to the type of predetermined system call command or predetermined function identified in the second call flow; and the assignment unit assigns the first importance score to each function included in the first call flow and the second importance score to each function included in the second call flow.
11. The processing device according to claim 10, wherein, when there is a common function included in both the first call flow and the second call flow, the assigning unit assigns the common function a score corresponding to the higher importance between the first importance score and the second importance score.
12. The processing device according to claim 9, wherein the correspondence relationship associates the multiple types with importance scores and categories corresponding to each type, and the assigning unit assigns the identified importance scores and categories to each function included in the call flow.
13. The processing device according to claim 12, wherein the target software includes a first call flow and a second call flow; the first identification unit identifies a predetermined system call instruction or a predetermined function in each of the first call flow and the second call flow; the second identification unit identifies a first importance score and a first category corresponding to the type of predetermined system call instruction or predetermined function identified in the first call flow, and a second importance score and a second category corresponding to the type of predetermined system call instruction or predetermined function identified in the second call flow; and the assignment unit assigns the first importance score and the first category to each function included in the first call flow, and assigns the second importance score and the second category to each function included in the second call flow.
14. The processing device according to claim 13, wherein, when a common function exists that is included in both the first call flow and the second call flow and the first category and the second category are the same, the assigning unit assigns the common function a score corresponding to the higher importance of the first importance score or the second importance score.
15. The processing device according to any one of claims 9 to 14, wherein the output unit outputs the target software and the call flow information.
16. A software inspection device comprising: a processing device according to claim 15; and an inspection processing unit that inspects functions of a plurality of functions included in the call flow of the target software, the functions having an importance score indicating an importance level higher than a predetermined level, based on the call flow information.
17. A method comprising: identifying a predetermined system call command or a predetermined function in a call flow that includes a start function and an end function of the call flow included in target software and has a plurality of functions that have a call relationship; identifying an importance score corresponding to the identified type of predetermined system call command or predetermined function based on the correspondence between a plurality of types of system call commands or functions and the importance scores corresponding to each type; assigning the identified importance score to each function included in the call flow; and outputting call flow information regarding each function included in the call flow and the importance score assigned to each function.
18. The method of claim 17, wherein the target software includes a first call flow and a second call flow; identifying the specified system call instruction or the specified function includes identifying the specified system call instruction or the specified function in each of the first call flow and the second call flow; identifying the importance score includes identifying a first importance score corresponding to the type of specified system call instruction or the specified function identified in the first call flow and a second importance score corresponding to the type of specified system call instruction or the specified function identified in the second call flow, respectively; and assigning the importance score includes assigning the first importance score to each function included in the first call flow and assigning the second importance score to each function included in the second call flow.
19. The method of claim 18, wherein assigning the importance score includes, if there is a common function included in both the first call flow and the second call flow, assigning the common function a score corresponding to a higher importance among the first importance score and the second importance score.
20. The method of claim 17, wherein the correspondence associates the plurality of types with importance scores and categories corresponding to each type, and assigning the importance scores includes assigning the identified importance scores and categories to each function included in the call flow.
21. The method of claim 20, wherein the target software includes a first call flow and a second call flow; identifying the specified system call instruction or the specified function includes identifying the specified system call instruction or the specified function in each of the first call flow and the second call flow; identifying the importance score includes identifying a first importance score and a first category corresponding to the type of the specified system call instruction or the specified function identified in the first call flow, and a second importance score and a second category corresponding to the type of the specified system call instruction or the specified function identified in the second call flow, respectively; and assigning the importance score includes assigning the first importance score and the first category to each function included in the first call flow, and assigning the second importance score and the second category to each function included in the second call flow.
22. The method of claim 21, wherein assigning the importance score includes, when there is a common function included in both the first call flow and the second call flow and the first category and the second category are the same, assigning the common function a score corresponding to a higher importance among the first importance score and the second importance score.
23. The method of any one of claims 17 to 22, wherein the outputting includes outputting the target software and the call flow information.
24. The method according to claim 23, further comprising: determining, based on the call flow information, among a plurality of functions included in the call flow of the target software, functions whose importance indicated by an importance score is higher than a predetermined level as targets for inspection processing.
Citation Information
Patent Citations
Code placement using a dynamic call graph
US20170161038A1
Software visualization device, software visualization method, and software visualization program
WO2019159397A1
Software analysis device
WO2021079408A1