Exploitation Analysis Method and Device for Heap / Stack Overflow Errors
By monitoring and recording heap/stack memory information on the monitoring platform, and judging and analyzing the availability of heap/stack overflow errors, the problem of inability to analyze the availability of overflow errors in the prior art is solved, and the security and defense capabilities of the system are improved.
Patent Information
- Application Number
- CN201811642380.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2018-12-29
- Publication Date
- 2025-06-24
- Estimated Expiration
- 2038-12-29
AI Technical Summary
The prior art cannot analyze the availability of heap/stack overflow errors in a timely and effective manner, resulting in the inability to detect and prevent enemy attackers from penetrating the system through heap/stack overflow errors in a timely manner.
By running the target program on the monitoring platform, monitoring and recording heap/stack memory information, when a write instruction to be written to the heap/stack is detected, it is determined whether there is a heap/stack overflow error, and the application of overflow error is determined through stain propagation and judging the execution of the program availability instruction.
It realizes timely judgment and availability analysis of heap/stack overflow errors, improves the security and defense capabilities of the system, and can promptly detect and prevent potential infiltration attacks.
Smart Images

Figure CN111382010B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and particularly to a method and device for analyzing the exploitability of heap / stack overflow errors. Background Art
[0002] Heap / stack overflow means writing too much data into a data block in the heap / stack regardless of the size of the allocated data block in the heap / stack, resulting in data out-of-bounds and overwriting other data. It can be understood as embedding a piece of code in a long string and overwriting the return address of the process with the address of this piece of code. In this way, when the process returns, the program will start to execute this self-written code. Thus, it can be seen that heap / stack overflow errors are one of the important threats affecting the stable operation of programs. Heap / stack overflow errors often cause the program to crash abnormally, and serious heap / stack overflow errors can provide an effective way for enemy attackers to penetrate our system. However, currently, it is only after the program has problems that it can be known that others use the overflow data by triggering heap / stack overflows to achieve their desired goals, and it is impossible to analyze in a timely and effective manner whether there is a possibility that the heap / stack overflow error is exploited. Summary of the Invention
[0003] In view of this, the present invention provides a method and device for analyzing the exploitability of heap / stack overflow errors, aiming to solve the problem that the prior art cannot analyze the exploitability of heap / stack overflow errors in a timely and effective manner.
[0004] The object of the present invention is achieved by the following technical solutions:
[0005] In a first aspect, the present invention provides a method for analyzing the exploitability of heap / stack overflow errors, the method comprising:
[0006] During the process of running a target program on a monitoring platform, monitoring and recording heap / stack memory information;
[0007] When a write instruction to be written to the heap / stack is monitored, determining whether the target program has a heap / stack overflow error according to the target address to be accessed by the write instruction and the current heap / stack memory information;
[0008] If there is a heap / stack overflow error, performing taint propagation with the to-be-overflowed data as a taint source, and determining whether there is an instruction for judging program exploitability being executed;
[0009] If there is an instruction for judging program exploitability being executed, determining that the heap / stack overflow error corresponding to the to-be-overflowed data is exploitable.
[0010] Optionally, when it is determined that there is a heap / stack overflow error, the method further comprises:
[0011] Save the data to be overflowed;
[0012] After the data to be overflowed overflows, perform a recovery operation on the overflowed data.
[0013] Optionally, monitoring and recording heap memory information includes:
[0014] By inputting the input data that can trigger a heap overflow error into the target program, monitor and record the heap memory allocation information and heap memory release information.
[0015] Optionally, the input data is obtained through fuzz testing technology.
[0016] Optionally, monitoring and recording stack memory information includes:
[0017] By monitoring stack memory management instructions, monitor and record the stack memory allocation information and stack memory release information.
[0018] In a second aspect, the present invention provides an exploitability analysis device for heap / stack overflow errors, and the device includes:
[0019] A monitoring and recording unit, configured to monitor and record heap / stack memory information during the process of running a target program on a monitoring platform;
[0020] A first judgment unit, configured to, when a write instruction to be written to the heap / stack is monitored, judge whether there is a heap / stack overflow error in the target program according to the target address to be accessed by the write instruction and the current heap / stack memory information;
[0021] A propagation unit, configured to, when there is a heap / stack overflow error, perform taint propagation with the data to be overflowed as a taint source;
[0022] A second judgment unit, configured to judge whether there is an instruction for judging program exploitability being executed;
[0023] A determination unit, configured to, when there is an instruction for judging program exploitability being executed, determine that the heap / stack overflow error corresponding to the data to be overflowed is exploitable.
[0024] Optionally, the device further includes:
[0025] A saving unit, configured to save the data to be overflowed when it is determined that there is a heap / stack overflow error;
[0026] A recovery unit, configured to perform a recovery operation on the overflowed data after the data to be overflowed overflows.
[0027] Optionally, the monitoring and recording unit is configured to monitor and record heap memory allocation information and heap memory release information by inputting input data that can trigger a heap overflow error into the target program.
[0028] Optionally, the input data used by the monitoring and recording unit 21 is obtained through fuzz testing technology.
[0029] Optionally, the monitoring and recording unit is configured to monitor and record stack memory allocation information and stack memory release information by monitoring stack memory management instructions.
[0030] In a third aspect, the present invention provides a storage medium storing multiple instructions, which are applicable to be loaded and executed by a processor to perform the method for analyzing the exploitability of heap / stack overflow errors as described in the first aspect.
[0031] In a fourth aspect, the present invention provides an electronic device, which includes a storage medium and a processor;
[0032] The processor is adapted to implement each instruction;
[0033] The storage medium is adapted to store multiple instructions;
[0034] The instructions are applicable to be loaded and executed by the processor to perform the method for analyzing the exploitability of heap / stack overflow errors as described in the first aspect.
[0035] By means of the above technical solutions, compared with the prior art in which the exploitability of stack overflow errors cannot be analyzed in a timely and effective manner, the method and device for analyzing the exploitability of heap / stack overflow errors provided by the present invention can monitor and record heap / stack memory information, and when a write instruction to be written to the heap / stack is monitored, based on the target address to be accessed by the write instruction and the current heap / stack memory information, it can timely determine whether there is a heap / stack overflow error in the target program. If it is determined that there is a heap / stack overflow error, the determined data to be overflowed is used as a taint source for taint propagation in a timely manner, and the exploitability of the heap / stack overflow error corresponding to the data to be overflowed is determined by judging whether there is an instruction for judging the exploitability of the program being executed.
[0036] The above description is only an overview of the technical solution of the present invention. In order to be able to understand the technical means of the present invention more clearly, it can be implemented according to the content of the specification. And in order to make the above and other objects, features and advantages of the present invention more obvious and understandable, the specific embodiments of the present invention are hereinafter specifically exemplified. Description of the Drawings
[0037] Various other advantages and benefits will become apparent to those of ordinary skill in the art by reading the following detailed description of the preferred embodiments. The drawings are only for the purpose of showing the preferred embodiments and are not considered to be a limitation of the present invention. Moreover, throughout the drawings, the same reference numerals are used to denote the same components. In the drawings:
[0038] Figure 1 A flowchart of a method for analyzing the exploitability of heap / stack overflow errors provided by an embodiment of the present invention is shown;
[0039] Figure 2 A block diagram of a device for analyzing the exploitability of heap / stack overflow errors provided by an embodiment of the present invention is shown;
[0040] Figure 3 A block diagram of another device for analyzing the exploitability of heap / stack overflow errors provided by an embodiment of the present invention is shown. Detailed Embodiments
[0041] Exemplary embodiments of the present disclosure will be described in more detail below with reference to the drawings. Although the exemplary embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure can be implemented in various forms and should not be limited by the embodiments set forth herein. On the contrary, these embodiments are provided so that the present disclosure can be more thoroughly understood and the scope of the present disclosure can be fully conveyed to those skilled in the art.
[0042] An embodiment of the present invention provides a method for analyzing the exploitability of heap / stack overflow errors, as Figure 1 shown, the method mainly includes:
[0043] 101. During the process of running the target program on the monitoring platform, monitor and record the heap / stack memory information.
[0044] Among them, the monitoring platform used in the embodiment of the present invention can be a system-level simulation monitoring platform. In order to determine whether the target program has heap / stack overflow errors and perform exploitability analysis on the errors in a timely manner, the target program can be deployed to run on the monitoring platform, and then the operation behavior of the target program on the heap / stack can be recorded in real time.
[0045] 102. When a write instruction to be written to the heap / stack is monitored, determine whether the target program has a heap / stack overflow error according to the target address to be accessed by the write instruction and the current heap / stack memory information.
[0046] The monitoring platform generally refers to an instruction instrumentation system. Instrumentation is implemented before the instruction runs, so the content of the instruction to be executed can be obtained, including the instruction type, operands, and the memory location to be operated on.
[0047] When the instruction to be executed by the target program is monitored, it can be determined whether the instruction is a write instruction for writing to the heap / stack based on the instruction type included in the instruction; if it is a write instruction for writing to the heap / stack, then the target address to be written by the write instruction is further obtained, and it is determined whether the target address is related to the base address of the heap / stack. If it is related, then continue to determine whether the target address exceeds the memory address range included in the heap / stack according to the base address and the memory size. If it exceeds, it is determined that there is an overflow error.
[0048] 103. If there is a heap / stack overflow error, the data to be overflowed is used as a taint source for taint propagation, and it is determined whether there is an instruction for judging the exploitability of the program being executed.
[0049] In practical applications, when it is determined that there is a heap / stack overflow error, the data to be overflowed can be immediately used as a taint source for propagation, or taint propagation can be carried out after the overflow error occurs.
[0050] Among them, the instructions for judging the exploitability of the program include function call (Call) or function return (Ret), etc. If it is traced through taint analysis that the data to be overflowed is used in instructions such as function call (Call) or function return (Ret), it indicates that the data damaged by the overflow can be used for control flow hijacking. In practical applications, if the overflow error is exploitable, the taint propagation can be detected after a period of time, while if the overflow error is not exploitable, there will be no result no matter how long the taint propagation is. Therefore, a reasonable propagation duration (such as an empirical value) needs to be set. When the propagation duration is reached, if there is an instruction for judging the exploitability of the program being executed, it is determined that the overflow error is exploitable; if there is no instruction for judging the exploitability of the program being executed, it is determined that the overflow error is not exploitable.
[0051] Exemplarily, the taint source can be represented by TaintCrash=(TaintCrashAddress, TaintSize), where TaintCrashAddress represents the memory address of the overflow data, and TaintSize represents the number of bytes to be damaged by the overflow by the current instruction. Among them, TaintSize can take values of 1, 2, 4, 8, etc. according to different types of instructions.
[0052] 104. If there is an instruction for judging the exploitability of the program being executed, it is determined that the heap / stack overflow error corresponding to the data to be overflowed is exploitable.
[0053] If there is no instruction for judging the exploitability of the program being executed, it is determined that the heap / stack overflow error corresponding to the data to be overflowed is not exploitable.
[0054] The method for analyzing the exploitability of heap / stack overflow errors provided by the embodiments of the present invention can monitor and record heap / stack memory information compared with the prior art that cannot analyze the exploitability of stack overflow errors in a timely and effective manner. When a write instruction to be written to the heap / stack is monitored, according to the target address accessed by the write instruction and the current heap / stack memory information, it can be timely determined whether there is a heap / stack overflow error in the target program. If it is determined that there is a heap / stack overflow error, the determined data to be overflowed is used as a taint source for taint propagation, and the exploitability of the heap / stack overflow error corresponding to the data to be overflowed is determined by judging whether an instruction for judging the exploitability of the program is executed.
[0055] Further, if a heap / stack overflow error occurs, it may cause the program to crash abnormally, and a serious heap / stack overflow error can provide an effective way for an enemy attacker to penetrate our system. To solve this technical problem in a timely manner, another embodiment of the present invention provides a method, which includes: when it is determined that there is a heap / stack overflow error, saving the data to be overflowed; after the data to be overflowed overflows, performing a recovery operation on the overflowed data. That is to say, when it is determined in advance that the data will overflow, the data to be overflowed is saved as soon as possible. When the replacement of the original data (i.e., the data to be overflowed) causes an overflow, a recovery operation is immediately performed to restore the replaced data to the original data, so as to ensure that there is no abnormality after the target program finishes execution.
[0056] Optionally, in practical applications, since there are certain differences between the heap and the stack, the monitoring methods for them also have certain differences. The implementation methods for monitoring the heap and the stack are described separately below:
[0057] (1) The specific implementation method for monitoring and recording heap memory information can be: by inputting input data that can trigger a heap overflow error into the target program, to monitor and record heap memory allocation information and heap memory release information.
[0058] Among them, the input data is obtained through fuzz testing technology, that is, an input data set can be generated first through fuzz testing technology, and then the target application program is made to run each input data to trigger potential overflow errors in the target program. The input data can be data related to functions such as "heap allocation" and "heap release". The heap memory allocation information includes the thread identifier corresponding to the heap memory allocation, the heap memory allocation size, and the base address; the heap memory release information includes the thread identifier corresponding to the heap memory release and the heap memory release size. The memory operand can be represented in the form of [base address + index * scale factor + offset], where the index, scale factor, and offset can be selected or discarded according to whether they are involved in the actual instruction, but the base address cannot be omitted during the heap / stack memory access process.
[0059] Exemplarily, embodiments of the present invention may use HeapInfo = (ThreadID, HeapBase, HeapSize) to describe related memory allocations. Among them, ThreadID is used to represent the thread identifier; HeapBase is used to represent the starting address of this memory allocation, also known as the memory address pointer, and subsequent operations such as monitoring the program's access and writing to this memory data will be tracked through this pointer; HeapSize is used to record the size of this memory allocation.
[0060] (2) The specific implementation method for monitoring and recording stack memory information may be: monitoring and recording stack memory allocation information and stack memory release information by monitoring stack memory management instructions.
[0061] Among them, stack memory management instructions include sub esp,N, etc. Stack memory allocation information includes the thread identifier corresponding to the stack memory allocation, the stack memory allocation size, and the base address; stack memory release information includes the thread identifier corresponding to the stack memory release and the stack memory release size.
[0062] Furthermore, according to the above method embodiments, another embodiment of the present invention also provides an exploitable analysis device for heap / stack overflow errors, as Figure 2 shown, the device includes:
[0063] A monitoring and recording unit 21, configured to monitor and record heap / stack memory information during the process of running a target program on a monitoring platform;
[0064] A first judgment unit 22, configured to, when a write instruction to be written to the heap / stack is monitored, judge whether there is a heap / stack overflow error in the target program according to the target address to be accessed by the write instruction and the current heap / stack memory information;
[0065] A propagation unit 23, configured to, when there is a heap / stack overflow error, perform taint propagation with the data to be overflowed as a taint source;
[0066] A second judgment unit 24, configured to judge whether there is an instruction for judging program exploitability being executed;
[0067] A determination unit 25, configured to, when there is an instruction for judging program exploitability being executed, determine that the heap / stack overflow error corresponding to the data to be overflowed is exploitable.
[0068] Optionally, as Figure 3 shown, the device further includes:
[0069] A saving unit 26, configured to save the data to be overflowed when it is determined that there is a heap / stack overflow error;
[0070] A recovery unit 27, configured to perform a recovery operation on the overflowed data after the data to be overflowed overflows.
[0071] Optionally, the monitoring and recording unit 21 is configured to monitor and record heap memory allocation information and heap memory release information by inputting input data that can trigger a heap overflow error into the target program.
[0072] Optionally, the input data used by the monitoring and recording unit 21 is obtained through fuzz testing technology.
[0073] Optionally, the monitoring and recording unit 21 is configured to monitor and record stack memory allocation information and stack memory release information by monitoring stack memory management instructions.
[0074] Compared with the prior art in which the exploitability of stack overflow errors cannot be analyzed in a timely and effective manner, the heap / stack overflow error exploitability analysis device provided by the embodiments of the present invention can monitor and record heap / stack memory information, and when a write instruction to be written to the heap / stack is monitored, based on the target address to be accessed by the write instruction and the current heap / stack memory information, timely determine whether there is a heap / stack overflow error in the target program. If it is determined that there is a heap / stack overflow error, the determined data to be overflowed is used as a taint source for taint propagation in a timely manner, and the exploitability of the heap / stack overflow error corresponding to the data to be overflowed is determined by determining whether there is an instruction for determining program exploitability being executed.
[0075] Further, according to the above method embodiments, another embodiment of the present invention further provides a storage medium, which stores multiple instructions, and the instructions are suitable for being loaded and executed by a processor to perform the heap / stack overflow error exploitability analysis method as described above.
[0076] The storage medium may include non-permanent storage media in computer-readable media, forms such as random access storage media (RAM) and / or non-volatile memory, such as read-only storage media (ROM) or flash memory (flash RAM), and the storage medium includes at least one storage chip.
[0077] Compared with the prior art in which the exploitability of stack overflow errors cannot be analyzed in a timely and effective manner, the instructions stored in the storage medium provided by the embodiments of the present invention can monitor and record heap / stack memory information, and when a write instruction to be written to the heap / stack is monitored, based on the target address to be accessed by the write instruction and the current heap / stack memory information, timely determine whether there is a heap / stack overflow error in the target program. If it is determined that there is a heap / stack overflow error, the determined data to be overflowed is used as a taint source for taint propagation in a timely manner, and the exploitability of the heap / stack overflow error corresponding to the data to be overflowed is determined by determining whether there is an instruction for determining program exploitability being executed.
[0078] Further, according to the above method embodiments, another embodiment of the present invention further provides an electronic device, and the electronic device includes a storage medium and a processor;
[0079] The processor is adapted to implement each instruction;
[0080] The storage medium is adapted to store multiple instructions;
[0081] The instructions are adapted to be loaded and executed by the processor for the exploitable analysis method of heap / stack overflow errors as described above.
[0082] The processor includes a kernel, and the kernel retrieves corresponding program units from the memory. One or more kernels can be set, and by adjusting the kernel parameters, the exploitable nature of heap / stack overflow errors can be analyzed in a timely and effective manner.
[0083] Compared with the prior art in which the exploitable nature of stack overflow errors cannot be analyzed in a timely and effective manner, the electronic device provided by the embodiments of the present invention can monitor and record heap / stack memory information, and when a write instruction to be written to the heap / stack is monitored, based on the target address to be accessed by the write instruction and the current heap / stack memory information, it can timely determine whether the target program has a heap / stack overflow error. If it is determined that there is a heap / stack overflow error, the determined data to be overflowed is used as a taint source for taint propagation, and the exploitable nature of the heap / stack overflow error corresponding to the data to be overflowed is determined by judging whether an instruction for judging the exploitability of the program is executed.
[0084] The present application also provides a computer program product, which is adapted to execute program code initialized with the following method steps when executed on a monitoring platform:
[0085] During the process of running a target program on the monitoring platform, monitor and record heap / stack memory information;
[0086] When a write instruction to be written to the heap / stack is monitored, based on the target address to be accessed by the write instruction and the current heap / stack memory information, judge whether the target program has a heap / stack overflow error;
[0087] If there is a heap / stack overflow error, use the data to be overflowed as a taint source for taint propagation, and judge whether an instruction for judging the exploitability of the program is executed;
[0088] If there is an instruction for judging the exploitability of the program that is executed, determine that the heap / stack overflow error corresponding to the data to be overflowed is exploitable.
[0089] The embodiments of the present invention also disclose:
[0090] A1. A method for analyzing the exploitability of heap / stack overflow errors, the method comprising:
[0091] During the process of running a target program on a monitoring platform, monitoring and recording heap / stack memory information;
[0092] When a write instruction to be written to the heap / stack is monitored, determining whether there is a heap / stack overflow error in the target program according to the target address to be accessed by the write instruction and the current heap / stack memory information;
[0093] If there is a heap / stack overflow error, using the data to be overflowed as a taint source for taint propagation, and determining whether there is an instruction for judging the exploitability of the program being executed;
[0094] If there is an instruction for judging the exploitability of the program being executed, determining that the heap / stack overflow error corresponding to the data to be overflowed is exploitable.
[0095] A2. The method according to A1, when it is determined that there is a heap / stack overflow error, the method further comprises:
[0096] Saving the data to be overflowed;
[0097] After the data to be overflowed overflows, performing a recovery operation on the data that has been overflowed.
[0098] A3. The method according to A1 or A2, monitoring and recording heap memory information includes:
[0099] By inputting input data that can trigger the occurrence of a heap overflow error into the target program, monitoring and recording heap memory allocation information and heap memory release information.
[0100] A4. The method according to A3, the input data is obtained by fuzz testing technology.
[0101] A5. The method according to A1 or A2, monitoring and recording stack memory information includes:
[0102] By monitoring stack memory management instructions to monitor and record stack memory allocation information and stack memory release information.
[0103] B6. An apparatus for analyzing the exploitability of heap / stack overflow errors, the apparatus comprising:
[0104] A monitoring and recording unit, configured to monitor and record heap / stack memory information during the process of running a target program on a monitoring platform;
[0105] A first judgment unit, configured to, when a write instruction to be written to a heap / stack is monitored, determine whether there is a heap / stack overflow error in the target program according to the target address to be accessed by the write instruction and the current heap / stack memory information;
[0106] A propagation unit, configured to, when there is a heap / stack overflow error, perform taint propagation with the to-be-overflowed data as a taint source;
[0107] A second judgment unit, configured to judge whether there is an instruction for judging program exploitability being executed;
[0108] A determination unit, configured to, when there is an instruction for judging program exploitability being executed, determine that the heap / stack overflow error corresponding to the to-be-overflowed data is exploitable.
[0109] B7. The apparatus according to B6, further comprising:
[0110] A saving unit, configured to save the to-be-overflowed data when it is determined that there is a heap / stack overflow error;
[0111] A recovery unit, configured to perform a recovery operation on the overflowed data after the to-be-overflowed data overflows.
[0112] B8. The apparatus according to B6 or B7, wherein the monitoring and recording unit is configured to monitor and record heap memory allocation information and heap memory release information by inputting input data that can trigger a heap overflow error into the target program.
[0113] B9. The apparatus according to B8, wherein the input data used by the monitoring and recording unit 21 is obtained by a fuzz testing technique.
[0114] B10. The apparatus according to B6 or B7, wherein the monitoring and recording unit is configured to monitor and record stack memory allocation information and stack memory release information by monitoring stack memory management instructions.
[0115] C11. A storage medium storing multiple instructions, the instructions being suitable for being loaded and executed by a processor to perform the method for analyzing the exploitability of a heap / stack overflow error according to any one of A1 - A5.
[0116] D12. An electronic device, comprising a storage medium and a processor;
[0117] The processor is suitable for implementing each instruction;
[0118] The storage medium is suitable for storing multiple instructions;
[0119] The instructions are adapted to be loaded and executed by the processor for the exploitability analysis method of heap / stack overflow errors as described in any one of A1 - A5.
[0120] In the above embodiments, the descriptions of the respective embodiments each have their own focuses. For parts not detailed in a certain embodiment, reference may be made to the relevant descriptions of other embodiments.
[0121] It can be understood that the relevant features in the above methods and devices can be referred to each other. Additionally, the "first", "second", etc. in the above embodiments are used to distinguish the embodiments, and do not represent the superiority or inferiority of the respective embodiments.
[0122] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the systems, devices, and units described above can refer to the corresponding processes in the foregoing method embodiments, and will not be elaborated herein.
[0123] The algorithms and displays provided herein are not inherently related to any particular computer, virtual system, or other device. Various general - purpose systems can also be used in conjunction with the teachings provided herein. The structure required to construct such systems is obvious from the above description. In addition, the present invention is not directed to any specific programming language. It should be understood that the content of the present invention described herein can be implemented using various programming languages, and the description of the specific language above is for disclosing the best mode of the present invention.
[0124] In the specification provided herein, a large number of specific details are set forth. However, it can be understood that the embodiments of the present invention can be practiced without these specific details. In some instances, well - known methods, structures, and technologies have not been shown in detail so as not to obscure the understanding of this specification.
[0125] Similarly, it should be understood that, in order to streamline this disclosure and assist in understanding one or more of the various inventive aspects, in the foregoing description of the exemplary embodiments of the present invention, the various features of the present invention are sometimes grouped together into a single embodiment, figure, or description thereof. However, the disclosed method should not be construed as reflecting an intention that the claimed invention requires more features than are expressly recited in each claim. Rather, as reflected in the following claims, the inventive aspects lie in less than all the features of the single foregoing disclosed embodiment. Thus, the claims following the detailed description are hereby expressly incorporated into this detailed description, with each claim standing on its own as a separate embodiment of the present invention.
[0126] Those skilled in the art can understand that the modules in the devices in the embodiments can be adaptively changed and set in one or more devices different from the embodiments. The modules or units or components in the embodiments can be combined into one module or unit or component, and in addition, they can be divided into multiple sub-modules or sub-units or sub-components. Except that at least some of such features and / or processes or units are mutually exclusive, any combination can be used to combine all the features disclosed in this specification (including the accompanying claims, abstract, and drawings) and all the processes or units of any method or device so disclosed. Unless otherwise explicitly stated, each feature disclosed in this specification (including the accompanying claims, abstract, and drawings) can be replaced by an alternative feature that provides the same, equivalent, or similar purpose.
[0127] In addition, those skilled in the art can understand that although some of the embodiments described herein include certain features included in other embodiments rather than other features, the combination of the features of different embodiments means that it is within the scope of the present invention and forms different embodiments. For example, in the following claims, any one of the claimed embodiments can be used in any combination.
[0128] Each component embodiment of the present invention can be implemented in hardware, or in software modules running on one or more processors, or in a combination thereof. Those skilled in the art should understand that a microprocessor or a digital signal processor (DSP) can be used in practice to implement some or all of the functions of some or all of the components in the method and device for analyzing the exploitability of stack / heap overflow errors according to the embodiments of the present invention. The present invention can also be implemented as a device or device program (e.g., a computer program and a computer program product) for executing part or all of the methods described herein. Such a program implementing the present invention can be stored on a computer-readable medium, or can be in the form of one or more signals. Such signals can be downloaded from an Internet website, or provided on a carrier signal, or in any other form.
[0129] It should be noted that the above embodiments illustrate the present invention rather than limit the present invention, and those skilled in the art can design alternative embodiments without departing from the scope of the appended claims. In the claims, any reference signs placed between parentheses shall not be construed as limiting the claim. The word "comprising" does not exclude the presence of elements or steps not listed in the claim. The word "a" or "an" preceding an element does not exclude the presence of a plurality of such elements. The present invention can be implemented by means of hardware including several different elements and by means of a suitably programmed computer. In the unit claims listing several devices, several of these devices may be embodied by the same item of hardware. The use of the words first, second, and third, etc. does not denote any order. These words can be interpreted as names.
Claims
1. An exploitable analysis method for heap / stack overflow errors, characterized in that, The method includes: During the process of running a target program on a monitoring platform, monitoring and recording heap / stack memory information; When a write instruction to be written to the heap / stack is monitored, based on the target address to be accessed by the write instruction and the current heap / stack memory information, determining whether the target program has a heap / stack overflow error; If there is a heap / stack overflow error, using the data to be overflowed as a taint source for taint propagation, and determining whether an instruction for determining program exploitability is executed; wherein, the instruction for determining program exploitability includes a function call instruction or a function disassembly instruction; If an instruction for determining program exploitability is executed, determining that the heap / stack overflow error corresponding to the data to be overflowed is exploitable.
2. The method according to claim 1, wherein When it is determined that there is a heap / stack overflow error, the method further includes: Saving the data to be overflowed; After the data to be overflowed overflows, performing a recovery operation on the overflowed data.
3. The method according to claim 1 or 2, characterized in that Monitoring and recording heap memory information includes: By inputting input data that can trigger a heap overflow error into the target program, monitoring and recording heap memory allocation information and heap memory release information.
4. The method according to claim 3, characterized in that The input data is obtained through fuzz testing technology.
5. The method according to claim 1 or 2, characterized in that, Monitoring and recording stack memory information includes: By monitoring stack memory management instructions, monitoring and recording stack memory allocation information and stack memory release information.
6. An exploitability analysis device for heap / stack overflow errors, characterized in that, The device includes: A monitoring and recording unit, configured to monitor and record heap / stack memory information during the process of running a target program on a monitoring platform; A first determination unit, configured to, when a write instruction to be written to the heap / stack is monitored, determine whether the target program has a heap / stack overflow error based on the target address to be accessed by the write instruction and the current heap / stack memory information; A propagation unit, configured to, when there is a heap / stack overflow error, use the data to be overflowed as a taint source for taint propagation; A second determination unit, configured to determine whether an instruction for determining program exploitability is executed; wherein, the instruction for determining program exploitability includes a function call instruction or a function disassembly instruction; A determination unit, configured to, when an instruction for determining program exploitability is executed, determine that the heap / stack overflow error corresponding to the data to be overflowed is exploitable.
7. The device according to claim 6, characterized in that, The device further includes: A saving unit, configured to save the data to be overflowed when it is determined that there is a heap / stack overflow error; A recovery unit, configured to perform a recovery operation on the overflowed data after the data to be overflowed overflows.
8. The device according to claim 6 or 7, characterized in that, The monitoring and recording unit is configured to, by inputting input data that can trigger a heap overflow error into the target program, monitor and record heap memory allocation information and heap memory release information.
9. The device according to claim 8, wherein The input data used by the monitoring and recording unit 21 is obtained through fuzz testing technology.
10. The device according to claim 6 or 7, characterized in that, The monitoring and recording unit is configured to monitor and record stack memory allocation information and stack memory release information by monitoring stack memory management instructions.
11. A storage medium, characterized in that, The storage medium stores multiple instructions, and the instructions are suitable for being loaded and executed by a processor to perform the method for analyzing the exploitability of a heap / stack overflow error according to any one of claims 1-5.
12. An electronic device, characterized in that, The electronic device includes a storage medium and a processor; The processor is adapted to implement each instruction; The storage medium is adapted to store a plurality of instructions; The instructions are adapted to be loaded and executed by the processor for the exploitability analysis method of heap / stack overflow errors according to any one of claims 1-5.
Citation Information
Patent Citations
Space memory error detection method with high efficiency and high availability
CN103745755A
Binary program-oriented heap overflow detection method
CN107729747A