Link library detection method, device, electronic device and computer-readable storage medium
By matching binary code feature information and link library feature information, combined with static program analysis, the link library and version information called in the target binary code are determined, solving the problem of inefficient detection in the existing technology, and achieving efficient and accurate vulnerability detection.
Patent Information
- Application Number
- CN202010218854.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-03-25
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2040-03-25
AI Technical Summary
The prior art is difficult to efficiently detect open source link libraries and version information called in each binary code from massive binary codes, resulting in inefficient vulnerability detection.
By obtaining the target feature information in the target binary code, matching it with the feature information of the link library, the target link library called by the target binary code is determined. Then, the reference relationship between the data and the function is obtained through static program analysis, the target link library analyzes these reference relationships, determines the objective function including version information, and finally determines the version information of the target link library based on the objective function.
It realizes efficient and accurate determination of the target link library and its version information called in the target binary code, and improves the efficiency and accuracy of vulnerability detection.
Smart Images

Figure CN111488573B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of computer and Internet technology, and in particular to a link library detection method, device, electronic device and computer-readable storage medium. Background Art
[0002] At present, most software applications, whether mobile applications or desktop applications, more or less use open source code (a code that can be linked to the software, which can be called a link library) for the development of interfaces or functions in order to reduce development costs and improve development efficiency.
[0003] Most open source codes are packaged to provide users with corresponding interfaces, properties and methods. Users can use components but cannot see the source code. At present, developers who use open source codes usually focus on the functions of the components, and few people conduct in-depth research on them and care about whether there are security issues. However, according to CVE (Common Vulnerabilities and Exposures) statistics, open source codes are often exposed to have security vulnerabilities, which in turn leads to potential security risks in software products using the components.
[0004] Generally speaking, using open source code can indeed improve the work efficiency of developers and achieve the purpose of knowledge sharing and development. However, since some software developers do not disclose the use of open source code to customers, this will cause customers to misjudge the use of open source code in their own projects, and then misjudge the vulnerabilities in their own projects.
[0005] Currently, most of the detection of open source code sources in software is based on source code, but open source code usually exists in the form of binary code. Therefore, how to efficiently detect the open source code called in each binary code from the massive binary code is crucial for vulnerability detection.
[0006] It should be noted that the information disclosed in the above background technology section is only used to enhance the understanding of the background of the present disclosure, and therefore may include information that does not constitute the prior art known to ordinary technicians in the field. Summary of the invention
[0007] The embodiments of the present disclosure provide a link library detection method and device, an electronic device, and a computer-readable storage medium, which can efficiently and accurately determine the target link library called in the target binary code and its version information.
[0008] Other features and advantages of the present disclosure will become apparent from the following detailed description, or may be learned in part by the practice of the present disclosure.
[0009] The disclosed embodiment proposes a link library detection method, which includes: obtaining target feature information in a target binary code; matching the target feature information with feature information of a link library to determine a target link library called by the target binary code; obtaining a reference relationship between data and functions in the target binary code through static program analysis; analyzing the reference relationship between data and functions in the target binary code according to the target link library, and determining a target function including version information of the target link library in the target binary code; and determining version information of the target link library according to the target function.
[0010] The embodiment of the present disclosure provides a link library detection device, including: a target feature acquisition module, an information matching module, a reference relationship determination module, a target function determination module and a version information determination module.
[0011] Wherein, the target feature acquisition module is configured to acquire target feature information in the target binary code. The information matching module is configured to match the target feature information with the feature information of the link library to determine the target link library called by the target binary code. The reference relationship determination module is configured to obtain the reference relationship between data and functions in the target binary code through static program analysis. The target function determination module is configured to analyze the reference relationship between data and functions in the target binary code according to the target link library, and determine the target function including the version information of the target link library in the target binary code. The version information determination module is configured to determine the version information of the target link library according to the target function.
[0012] In some embodiments, the target link library includes a first function, and the first function includes version information and a first symbol feature.
[0013] In some embodiments, the target function determination module may include: a second symbol feature determination submodule, a second function determination submodule, and a function name determination submodule.
[0014] The second symbol feature determination submodule is configured to determine a second symbol feature matching the first symbol feature in the target binary code. The second function determination submodule is configured to determine a second function that calls the second symbol feature according to the reference relationship between the data and the function. The function name determination submodule is configured to determine that if the second function has the same function name as the first function, the second function is the target function.
[0015] In some embodiments, the version information determination module may include: an output information determination submodule, wherein the output information determination submodule is configured to extract information from the target function according to the position of the version information in the first function to obtain the version information of the target link library.
[0016] In some embodiments, the target link library includes a third function, and the third function calls a return function that returns version information.
[0017] In some embodiments, the version information extraction module further includes: a fourth function determination submodule, a call determination submodule, and a target function determination submodule.
[0018] The fourth function determination submodule is configured to determine a fourth function having the same function name as the third function in the target binary code. The call determination submodule can be configured to determine whether the fourth function calls a return function according to the reference relationship between the data and the function. The target function determination submodule is configured so that if the fourth function calls a return function, the fourth function is the target function.
[0019] In some embodiments, the reference relationship determination module may include: an intermediate representation submodule, a control flow graph determination submodule, and a reference relationship acquisition submodule.
[0020] The intermediate representation submodule is configured to translate the target binary code to obtain the intermediate representation of the target binary code. The control flow graph determination submodule is configured to obtain a function call graph and a control flow graph according to the intermediate representation of the target binary code. The reference relationship acquisition submodule is configured to determine the reference relationship between data and functions according to the function call graph and the control flow graph.
[0021] In some embodiments, the target feature information includes constant feature information.
[0022] In some embodiments, the information matching module may include: a valid feature determination submodule, a target link library determination submodule, and a memory feature processing submodule.
[0023] The effective feature determination submodule is configured to match the constant feature information with the constant feature library of the link library to determine the effective feature. The target link library determination submodule is configured to determine the target link library and the candidate link library according to the proportion of the effective feature in the constant feature library. The memory feature processing submodule is configured to determine the target link library called by the target binary code according to the memory feature of the candidate link library.
[0024] In some embodiments, the target link library determination submodule may include: a target link library determination unit and a candidate link library determination unit.
[0025] The target link library determination unit is configured such that if the ratio is greater than a first threshold, the link library corresponding to the constant feature library is the target link library. The candidate link library determination unit is configured such that if the ratio is less than or equal to the first threshold and greater than a second threshold, the link library corresponding to the constant feature library is the candidate link library.
[0026] In some embodiments, the constant feature information includes a fifth function name.
[0027] In some embodiments, the information matching module may further include: a sixth function name acquisition submodule, a target running function determination submodule, a memory feature acquisition submodule, and a memory feature matching submodule.
[0028] Among them, the sixth function name acquisition submodule is configured to obtain the sixth function in the candidate link library, and run the sixth function to generate the memory characteristics of the candidate link library. The target operation function determination submodule is configured to determine the target operation function matching the sixth function in the target binary code according to the fifth function name; the memory characteristic acquisition submodule is configured to run the target operation function to obtain the target memory characteristics. The memory characteristic matching submodule is configured to match the target memory characteristics with the memory characteristics of the candidate link library. If the match is successful, the candidate link library is the target link library.
[0029] In some embodiments, the link library determining device may further include: a first prefix information acquiring module, a second prefix information determining module, and a suffix information determining module.
[0030] The first prefix information acquisition module is configured to acquire the first prefix information of the version information in the target link library. The second prefix information determination module is configured to determine the second prefix information matching the first prefix information in the target binary. The suffix information determination module is configured to determine the version information of the target link library called by the target binary code according to the second prefix information.
[0031] In some embodiments, the suffix information determination module may include: a suffix information acquisition submodule, a naming rule acquisition submodule, and a naming rule matching submodule.
[0032] The suffix information acquisition submodule is configured to acquire the suffix information of the second prefix information. The explicit rule acquisition submodule is configured to determine the version name naming rule according to the version information of the target link library. The naming rule matching submodule is configured that if the suffix information satisfies the naming rule, the suffix information is the version information of the target link library.
[0033] In some embodiments, the link library detection device may further include: a regular matching rule acquisition module and a string matching submodule.
[0034] The regular matching rule acquisition module is configured to acquire the regular matching rule of the string containing the version information in the target link library. The string matching submodule is configured to determine the target string in the target binary code according to the regular matching rule and extract the version information of the target link library from the target string.
[0035] An embodiment of the present disclosure proposes an electronic device, which includes: one or more processors; a storage device for storing one or more programs, when the one or more programs are executed by the one or more processors, the one or more processors implement any of the link library detection methods described above.
[0036] The embodiment of the present disclosure provides a computer-readable storage medium on which a computer program is stored. When the program is executed by a processor, the link library detection method as described in any one of the above items is implemented.
[0037] The link library detection method, device, electronic device, and computer-readable storage medium provided by certain embodiments of the present disclosure, on the one hand, accurately and efficiently determine the target link library called by the target binary code by matching the target feature information of the target binary code with the feature information of the link library; on the other hand, obtain the reference relationship of the data and functions in the target binary code by static analysis of the target binary code, and analyze the reference relationship of the data and functions according to the target link library to accurately obtain the version information of the target link library from the target binary code. The solution provided by the present disclosure can effectively determine the target link library called in the target binary code and the version information of the target link library.
[0038] It is to be understood that the foregoing general description and the following detailed description are exemplary only and are not restrictive of the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS
[0039] The drawings herein are incorporated into the specification and constitute a part of the specification, illustrate embodiments consistent with the present disclosure, and together with the specification are used to explain the principles of the present disclosure. The drawings described below are only some embodiments of the present disclosure, and for ordinary technicians in this field, other drawings can also be obtained based on these drawings without creative work.
[0040] Figure 1 A schematic diagram showing an exemplary system architecture of a link base detection method or a link base detection device applied to an embodiment of the present disclosure is shown.
[0041] Figure 2 The diagram is a schematic diagram showing the structure of a computer system applied to a link library detection device according to an exemplary embodiment.
[0042] Figure 3 The figure is a flow chart of a link library detection method according to an exemplary embodiment.
[0043] Figure 4 yes Figure 3 Flowchart of step S2 in an exemplary embodiment.
[0044] Figure 5 yes Figure 4 Flowchart of step S22 in an exemplary embodiment.
[0045] Figure 6 yes Figure 3 Flowchart of step S2 in an exemplary embodiment.
[0046] Figure 7 yes Figure 3 Flowchart of step S3 in an exemplary embodiment.
[0047] Figure 8 yes Figure 3 Flowchart of step S4 in an exemplary embodiment.
[0048] Fig. 9 yes Figure 3 Flowchart of step S4 in an exemplary embodiment.
[0049] Fig.10 is a flow chart of a link library detection method according to an exemplary embodiment.
[0050] Fig.11 yes Fig.10 Flowchart of step S7 in an exemplary embodiment.
[0051] Fig.12 is a flow chart of a link library detection method according to an exemplary embodiment.
[0052] Fig.13 It is a schematic diagram showing a link library detection system according to an exemplary embodiment.
[0053] Fig.14 The figure is a block diagram showing a link library detection device according to an exemplary embodiment. DETAILED DESCRIPTION
[0054] Example embodiments will now be described more fully with reference to the accompanying drawings. However, example embodiments can be implemented in many forms and should not be construed as limited to the embodiments set forth herein; rather, these embodiments are provided so that this disclosure will be comprehensive and complete and will fully convey the concepts of the example embodiments to those skilled in the art. The same reference numerals in the figures represent the same or similar parts, and thus their repeated description will be omitted.
[0055] The features, structures or characteristics described in the present disclosure may be combined in one or more embodiments in any suitable manner. In the following description, many specific details are provided to provide a full understanding of the embodiments of the present disclosure. However, those skilled in the art will appreciate that the technical solutions of the present disclosure may be practiced while omitting one or more of the specific details, or other methods, components, devices, steps, etc. may be adopted. In other cases, known methods, devices, implementations or operations are not shown or described in detail to avoid blurring the various aspects of the present disclosure.
[0056] The accompanying drawings are only schematic diagrams of the present disclosure, and the same reference numerals in the drawings represent the same or similar parts, so their repeated description will be omitted. Some block diagrams shown in the accompanying drawings do not necessarily correspond to physically or logically independent entities. These functional entities can be implemented in software form, or in one or more hardware modules or integrated circuits, or in different networks and / or processor devices and / or microcontroller devices.
[0057] The flowcharts shown in the accompanying drawings are only exemplary and do not necessarily include all the contents and steps, nor must they be executed in the order described. For example, some steps can be decomposed, and some steps can be combined or partially combined, so the actual execution order may change according to actual conditions.
[0058] In this specification, the terms "a", "an", "the", "said" and "at least one" are used to indicate the presence of one or more elements / components / etc.; the terms "comprising", "including" and "having" are used to express an open-ended inclusion and mean that additional elements / components / etc. may exist in addition to the listed elements / components / etc.; the terms "first", "second" and "third" etc. are used only as labels and are not intended to limit the quantity of their objects.
[0059] The exemplary embodiments of the present disclosure are described in detail below with reference to the accompanying drawings.
[0060] Figure 1 A schematic diagram showing an exemplary system architecture that can be applied to a link base detection method or a link base detection device according to an embodiment of the present disclosure.
[0061] like Figure 1 As shown, system architecture 100 may include devices 101, 102, 103, network 104 and server 105. Network 104 is used to provide a medium for communication links between devices 101, 102, 103 and server 105. Network 104 may include various connection types, such as wired, wireless communication links or fiber optic cables, etc.
[0062] Users can use devices 101, 102, 103 to interact with server 105 through network 104 to receive or send messages, etc. Devices 101, 102, 103 can be various electronic devices with display screens and supporting web browsing, including but not limited to smart phones, tablet computers, laptop computers, desktop computers, wearable devices, virtual reality devices, smart homes, etc.
[0063] The server 105 may be a server that provides various services, such as a background management server that provides support for devices operated by users using devices 101, 102, and 103. The background management server may analyze and process the received request data, and feed back the processing results to the device.
[0064] The server 105 may, for example, obtain target feature information in the target binary code; the server 105 may, for example, match the target feature information with the feature information of the link library to determine the target link library called by the target binary code; the server 105 may, for example, obtain the reference relationship between the data and the function in the target binary code through static program analysis; the server 105 may, for example, analyze the reference relationship between the data and the function in the target binary code based on the target link library, and determine the target function including the version information of the target link library in the target binary code; the server 105 may, for example, determine the version information of the target link library based on the target function.
[0065] It should be understood that Figure 1 The number of devices, networks and servers in the figure is merely illustrative. The server 105 may be a physical server or may be composed of multiple servers. According to actual needs, there may be any number of devices, networks and servers.
[0066] In some embodiments, the embodiments of the present disclosure may also be completed by a single electronic device with computing functions, which may not only obtain the target binary code, but also complete the technical solution provided by the embodiments of the present disclosure according to the target binary code. The electronic device may be, for example, a smart phone, a tablet computer, a laptop computer, a desktop computer, a wearable device, a virtual reality device, a smart home, etc., but the present disclosure does not limit this.
[0067] In addition, the embodiments of the present disclosure may also be implemented through cloud computing. For example, the target link library matching service provided by the embodiments of the present disclosure may be provided to users through cloud computing, but the present disclosure does not limit this.
[0068] Reference below Figure 2 , which shows a schematic diagram of the structure of a computer system 200 suitable for implementing the device of the embodiment of the present application. Figure 2 The device shown is merely an example and should not bring any limitation to the functions and scope of use of the embodiments of the present application.
[0069] like Figure 2 As shown, the computer system 200 includes a central processing unit (CPU) 201, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 202 or a program loaded from a storage part 208 into a random access memory (RAM) 203. In the RAM 203, various programs and data required for the operation of the system 200 are also stored. The CPU 201, the ROM 202, and the RAM 203 are connected to each other via a bus 204. An input / output (I / O) interface 205 is also connected to the bus 204.
[0070] The following components are connected to the I / O interface 205: an input section 206 including a keyboard, a mouse, etc.; an output section 207 including a cathode ray tube (CRT), a liquid crystal display (LCD), etc., and a speaker, etc.; a storage section 208 including a hard disk, etc.; and a communication section 209 including a network interface card such as a LAN card, a modem, etc. The communication section 209 performs communication processing via a network such as the Internet. A drive 210 is also connected to the I / O interface 205 as needed. A removable medium 211, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 210 as needed, so that a computer program read therefrom is installed into the storage section 208 as needed.
[0071] In particular, according to an embodiment of the present disclosure, the process described above with reference to the flowchart can be implemented as a computer software program. For example, an embodiment of the present disclosure includes a computer program product, which includes a computer program carried on a computer-readable storage medium, and the computer program contains a program code for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from a network through the communication part 209, and / or installed from a removable medium 211. When the computer program is executed by the central processing unit (CPU) 201, the above-mentioned functions defined in the system of the present application are executed.
[0072] It should be noted that the computer-readable storage medium shown in the present application may be a computer-readable signal medium or a computer-readable storage medium or any combination of the above two. The computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or device, or any combination of the above. More specific examples of computer-readable storage media may include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present application, a computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in combination with an instruction execution system, device or device. In the present application, a computer-readable signal medium may include a data signal propagated in a baseband or as part of a carrier wave, in which a computer-readable program code is carried. This propagated data signal may take a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The computer-readable signal medium may also be any computer-readable storage medium other than a computer-readable storage medium that can send, propagate or transmit a program for use by or in conjunction with an instruction execution system, apparatus or device. The program code contained on the computer-readable storage medium may be transmitted using any appropriate medium, including but not limited to: wireless, wire, optical cable, RF, etc., or any suitable combination of the above.
[0073] The flow chart and block diagram in the accompanying drawings illustrate the possible architecture, function and operation of the system, method and computer program product according to various embodiments of the present application. In this regard, each box in the flow chart or block diagram can represent a module, a program segment or a part of a code, and the above-mentioned module, program segment or a part of a code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a different order from the order marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram or flow chart, and the combination of the boxes in the block diagram or flow chart can be implemented with a dedicated hardware-based system that performs a specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.
[0074] The modules and / or submodules and / or units involved in the embodiments of the present application may be implemented in software or in hardware. The modules and / or submodules and / or units described may also be provided in a processor, for example, may be described as: a processor including a sending unit, an acquiring unit, a determining unit, and a first processing unit. The names of these modules and / or submodules and / or units do not, in certain circumstances, constitute limitations on the modules and / or submodules and / or units themselves.
[0075] As another aspect, the present application also provides a computer-readable storage medium, which may be included in the device described in the above embodiment; or it may exist independently without being assembled into the device. The above computer-readable storage medium carries one or more programs, and when the above one or more programs are executed by a device, the device can implement functions including: obtaining target feature information in the target binary code; matching the target feature information with the feature information of the link library to determine the target link library called by the target binary code; obtaining the reference relationship between data and functions in the target binary code through static program analysis; analyzing the reference relationship between data and functions in the target binary code according to the target link library, and determining the target function including the version information of the target link library in the target binary code; determining the version information of the target link library according to the target function.
[0076] It should be understood that any number of elements in the drawings of the present disclosure is for illustration and not for limitation, and any naming is only for distinction and does not have any limiting meaning. For ease of understanding, the nouns involved in the embodiments of the present disclosure are explained below.
[0077] Static analysis technology: a code analysis technology that can scan binary code through lexical analysis, syntax analysis, control flow analysis, data flow analysis and other technologies without running the program code to verify whether the binary code meets the standards of standardization, security, reliability, maintainability and other indicators.
[0078] Function call graph: can be used to represent the calling relationship between various functions in the program code.
[0079] Control Flow Graph (CFG): A directed graph generated by static analysis. The nodes in the graph represent basic code blocks, the directed edges between nodes represent control flow paths, and the reverse edges represent possible loops.
[0080] Basic code block: refers to a sequence of statements executed sequentially by a program, in which there is only one entry and one exit. The entry is the first statement in the program, and the exit is the last statement in the program.
[0081] Data flow analysis technology: By traversing the control flow graph, the data assignment and storage, and memory reading and writing processes are analyzed during the execution of the code on different paths.
[0082] Data flow graph: The result of data flow analysis records the data assignment and storage, and memory reading and writing processes during the execution of the code on different paths.
[0083] Intermediate Representation (IR): Generally speaking, compilers are divided into the front-end and the back-end. The front-end performs lexical analysis, syntax analysis, and semantic analysis on the input program, and then generates an intermediate representation, namely IR. The back-end optimizes the IR and then generates the target code.
[0084] Static Single Assignment Intermediate Representation (SSA IR): A special form of IR in which each variable is defined only once.
[0085] Common Vulnerabilities and Exposures, also known as Common Weaknesses and Vulnerabilities, is a database related to information security that collects various information security weaknesses and vulnerabilities and gives them numbers for public access.
[0086] Executable and Linkable Format (ELF), often referred to as the ELF format, is a standard file format for executable files, object files, shared libraries, and core dumps in computer science.
[0087] Portable Executable (PE) is a file format used for executable files, object files, and dynamic link libraries.
[0088] Figure 3 The method provided in the embodiment of the present disclosure can be processed by any electronic device with computing and processing capabilities or by cloud computing, but the present disclosure is not limited thereto.
[0089] Reference Figure 3 The link library detection method provided by the embodiment of the present disclosure may include the following steps.
[0090] In step S1, target feature information in the target binary code is obtained.
[0091] In some embodiments, the target source code may be compiled by a compiler to obtain a target binary code, and the target binary code may be stored in a PE file, an ELF file, or a file in another format, which is not limited in the present disclosure.
[0092] In some embodiments, the invariant in the target binary code before and after compilation can be used as the target feature information. Generally speaking, the invariant can be a feature with distinguishing information such as a string constant or a numeric constant in the target binary code, but the present disclosure does not limit this.
[0093] In some embodiments, if the target binary code is stored in a PE file or an ELE file, string constants, numeric constants, etc. can be extracted from the header file of the PE file or the ELE file as target feature information; if the target binary code is stored in a binary file of other unknown format, string constants and numeric constants can be extracted from the entire binary file as target feature information.
[0094] In addition, memory features such as string constants or numeric constants left in the memory after running the target binary code can also be used as target feature information.
[0095] In step S2, the target feature information is matched with feature information of a link library to determine the target link library called by the target binary code.
[0096] In a software system, a software usually includes one or more projects, also called modules. The modules in the software system need to call a third-party library (such as open source code) or a self-packaged library. The third-party library or self-packaged library can be linked into the target binary code in a dynamic link or static link manner, so the third-party library or self-packaged library can be a link library in the embodiment of the present disclosure.
[0097] It can be understood that the link library in the embodiment of the present disclosure is any code that can be linked (including dynamic linking and static linking) to the target binary code, and the present disclosure does not limit this.
[0098] In some embodiments, a feature information library can be constructed in advance for each link library. The feature information library can be composed of string constants and numeric constants in binary code, or can be composed of string constants and numeric constants left in the memory after running the binary code. The present disclosure does not limit this.
[0099] In some embodiments, a link library may include various versions corresponding to the link library. For example, link library a may include version 1 link library a, version 2 link library a, and version 3 link library a. Therefore, the feature information library of the link library may include feature information of various versions.
[0100] In some embodiments, the target feature information of the target binary code may be matched with the feature information of the link library, and features that are successfully matched (for example, two completely equal features may be considered to be successfully matched) may be used as valid features.
[0101] In some embodiments, when the proportion of effective features in the feature information library of the link library exceeds a first threshold (eg, 60%), it can be considered that the target binary code has called the link library.
[0102] In addition, the target binary code can be run to obtain the memory characteristics of the target binary code, and then the memory characteristics of the target binary code are matched with the memory characteristics of the link library. If the match is successful (for example, the same memory characteristics exist), the link library can be considered to be the target link library.
[0103] In step S3, the reference relationship between data and functions in the target binary code is obtained through static program analysis.
[0104] In some embodiments, the reference relationship between data and functions may include a reference relationship between function calling data and function calling functions, which is not limited in the present disclosure.
[0105] In some embodiments, static program analysis can be performed on the target binary code by a target binary engine to obtain a control dependency graph, a function call graph, and a control flow graph of the target binary code. The target binary engine can be IDA Pro (Interactive Disassembler Professional), Binary Ninja (reverse platform), etc., and the present disclosure does not limit this.
[0106] By analyzing the above control dependency graph, function call graph, control flow graph, etc., the reference relationship between data and function, and between functions in the target binary code can be obtained.
[0107] Generally speaking, static analysis of the target binary code can be performed by translating the target binary code into an intermediate representation and obtaining the analysis results under the intermediate representation (such as a control dependency graph, a function call graph, or a control flow graph). The intermediate representation can be SSA IR. Of course, the target binary code can also be deassembled into assembly language to obtain the analysis results under assembly language (such as a control dependency graph, a function call graph, and a control flow graph). It is understandable that the method provided by the present disclosure is also implemented in other languages within the scope of protection of the present disclosure, and the present disclosure does not limit this.
[0108] To facilitate static analysis, the target binary code is usually translated into an intermediate representation (e.g., a static single assignment intermediate representation), and the intermediate representation obtained by the translation is subjected to program optimization, such as constant folding, constant propagation, strength reduction, and dead code elimination, etc., which is not limited in the present disclosure.
[0109] In the present disclosure, the embodiment will be explained by taking the translation of target binary code into SSA IR in static analysis as an example, but the present disclosure is not limited thereto.
[0110] In step S4, the reference relationship between data and functions in the target binary code is analyzed according to the target link library, and the target function including the version information of the target link library is determined in the target binary code.
[0111] In some embodiments, after the target link library called by the target binary code is determined, it is also necessary to determine the version information of the target link library called by the target binary code.
[0112] In some embodiments, in the target link library, the version name may be output or returned through a first function, and the first function may include some distinguishing feature information (such as first symbol feature information).
[0113] For example, the version information "7.60" in the target link library may be output through the first function printf_chk(1LL, aSSSUageNmapSc, "Nmap", "7.60"), and the first function printf_chk includes the first symbol feature information "aSSSUageNmapSc".
[0114] Since the first symbol feature "aSSSUageNmapSc" does not change when the target link library is called, the function including the target link library version information in the target binary code can be determined by locating the second symbol feature equal to the first symbol feature in the target binary code to further determine the version information of the target link library.
[0115] In step S5, the version information of the target link library is determined according to the target function.
[0116] In some embodiments, if the first function is an output function such as printf_chk, the version information can be extracted from the second function according to the position of the version information in the first function. For example, if the version information "7.60" is output at the 4th position in the first function printf_chk, the information at the 4th position in the second function can be extracted as the version information of the target link library.
[0117] The technical solution provided by this embodiment determines the target link library called by the target binary code by matching the feature information of the link library, and extracts the version information of the target link library from the target binary code through static analysis technology. This method, on the one hand, matches the link library with the target binary code through the invariant feature quantity to accurately determine the target link library called by the target binary code; on the other hand, accurately and efficiently extracts the version information of the target link library from the target binary code through static analysis technology.
[0118] Figure 4 yes Figure 3 Flowchart of step S2 in an exemplary embodiment.
[0119] In some embodiments, the target feature information of the target binary code may be composed of constant feature information of the target binary code (which may be a string constant and a numeric constant in the target binary code).
[0120] refer to Figure 4 , the above step S2 may include the following steps.
[0121] In step S21, the constant feature information is matched with the constant feature library of the link library to determine valid features.
[0122] In some embodiments, the constant feature information of the target binary code can be matched with the constant feature library of the link library. If the constant feature information in the target binary code is the same as the feature information in the constant feature library (or there is a relationship of inclusion and being included), the constant feature information can be considered as valid feature information.
[0123] In step S22, the target link library and the candidate link library are determined according to the proportion of the effective features in the constant feature library.
[0124] In some embodiments, a first threshold (e.g., 60%) and a second threshold (e.g., 50%) may be preset. If the proportion of valid features in the constant feature library is greater than the first threshold, the link library corresponding to the constant feature library may be considered to be the target link library. If the proportion of valid features in the constant feature library is greater than the second threshold and less than or equal to the first threshold, the link library corresponding to the constant feature library may be considered to be a candidate link library.
[0125] In step S23, the target link library called by the target binary code is determined according to the memory characteristics of the candidate link library.
[0126] In some embodiments, the candidate link library may include some functions that generate distinguishing feature information in the memory after being executed. For example, the candidate link library may include a function that concatenates string a and string b and outputs it. Then, after running the function, a string formed by concatenating string a and string b will be left in the memory, and the string can be a memory feature.
[0127] It is understandable that if the target binary code calls the candidate link library, then the memory feature information of the candidate link library will be left in the memory after the target binary code is run.
[0128] Therefore, if the memory features remaining in the memory after the binary code is executed include at least one memory feature in the memory feature library of the candidate link library, then the candidate link library can be considered to be the target link library called by the target binary code.
[0129] The technical solution provided by this embodiment determines the effective features by matching the target feature information with the feature information library of the link library, and determines the link target link library according to the effective features. This method distinguishes the target link library with a higher matching rate and the candidate link library with a relatively low matching rate according to the effective features, and makes an accurate judgment in the candidate link library according to the memory features of the candidate link library to determine the target link library. The detection efficiency of massive link libraries is improved, and the link library used in the target binary code is quickly detected.
[0130] Figure 5 yes Figure 4 Flowchart of step S22 in an exemplary embodiment.
[0131] refer to Figure 5 , the above step S22 may include the following steps.
[0132] In step S221, if the ratio is greater than a first threshold, the link library corresponding to the constant feature library is the target link library.
[0133] In some embodiments, if the effective features after comparing the target feature information with the feature information library of the link library are extremely close to the feature information library of the link library, it can be considered that the target binary code has called the link library.
[0134] In step S222, if the ratio is less than or equal to the first threshold and greater than the second threshold, the link library corresponding to the constant feature library is a candidate link library.
[0135] In some embodiments, since the link library may include different versions, each version may include different constant feature information, some versions may have more constant feature information, and some versions may have less constant feature information. Therefore, if the target link library is determined only by the proportion of valid features in the feature information library, the target link library called by the target binary code may be missed due to the small amount of constant feature information in the called version.
[0136] Therefore, this embodiment provides a certain buffer for determining the target link library. That is, if the proportion of valid features in the constant feature library is less than or equal to the first threshold and greater than the second threshold, the link library is considered to be a candidate link library, and the candidate link library can be further judged according to the memory feature library of the candidate link library to determine whether the candidate link library is the target link library.
[0137] The technical solution provided by the embodiment of the present disclosure not only accurately and efficiently determines the target link library with a very high feature information matching rate according to the first threshold, but also considers those link libraries with relatively low matching rates due to less feature information in the link library as candidate link libraries, and further analyzes the candidate link libraries to determine the target link library from the candidate link libraries.
[0138] Figure 6 yes Figure 3 Flowchart of step S2 in an exemplary embodiment.
[0139] In some embodiments, the constant feature information of the target binary code may include the function name of each function (which may be referred to as the fifth function name).
[0140] refer to Figure 6 , the above step S3 may further include the following steps.
[0141] In step S24, a sixth function in the candidate link library is obtained, and the sixth function is executed to generate memory features of the candidate link library.
[0142] In some embodiments, the candidate link library may include some functions that generate distinguishing characteristic information in the memory after running (the distinguishing characteristic information can be considered to be uniquely identifiable). These functions that generate distinguishing characteristic information in the memory after running can be called sixth functions.
[0143] In some embodiments, the sixth function may be pre-run to generate memory characteristics of the candidate link library.
[0144] In step S25, a target running function matching the sixth function name is determined in the target binary code according to the fifth function name.
[0145] In some embodiments, the target function can be determined in the target binary code according to the function name of the sixth function. For example, the fifth function having the same name as the sixth function can be determined in the target binary code as the target running function.
[0146] In step S26, the target function is run to obtain target memory characteristics.
[0147] In some embodiments, the target binary code may be run in a simulation environment, and string constants and numeric constants generated in the memory after the running are used as target memory features.
[0148] In step S27, the target memory feature is matched with the memory feature of the candidate link library. If the match is successful, the candidate link library is the target link library.
[0149] It can be understood that if the memory characteristics generated when running the fifth function are the same as the memory characteristics generated when running the sixth function, then the fifth function in the target binary code can be considered to be a function in the candidate link library, and further, it can be considered that the candidate link library is called by the target binary code.
[0150] The technical solution provided in this embodiment first obtains a target link library with an extremely high feature matching rate and a candidate link library with a matching rate within the target matching range through the feature information in the target binary code, and determines the target link library in the candidate link library through the memory feature information obtained after running the target binary code, effectively avoiding omissions and false positives.
[0151] Figure 7 yes Figure 3 Flowchart of step S3 in an exemplary embodiment.
[0152] refer to Figure 7 , the above step S3 may include the following steps.
[0153] In step S31, the target binary code is translated to obtain an intermediate representation of the target binary code.
[0154] Generally speaking, static analysis of the target binary code can be performed to translate the target binary code into an intermediate representation and obtain the analysis results under the intermediate representation (such as a control dependency graph, a function call graph, or a control flow graph). The intermediate representation can be SSA IR; of course, the target binary code can also be deassembled into assembly language to obtain the analysis results under the assembly language (such as a control dependency graph, a function call graph, and a control flow graph). It is understandable that the vulnerability detection method provided by the present disclosure is also implemented in other languages within the scope of protection of the present disclosure, and the present disclosure does not limit this.
[0155] To facilitate static analysis, the target binary code is usually translated into an intermediate representation (e.g., a static single assignment intermediate representation), and the intermediate representation obtained by the translation is subjected to program optimization, such as constant folding, constant propagation, strength reduction, and dead code removal, etc., which is not limited in the present disclosure.
[0156] In step S32, a function call graph and a control flow graph are obtained according to the intermediate representation of the target binary code.
[0157] In step S33, the reference relationship between data and functions is determined according to the function call graph and the control flow graph.
[0158] The technical solution provided in this embodiment analyzes the target binary code through the intermediate representation, which greatly improves the accuracy and efficiency of static analysis.
[0159] Figure 8 yes Figure 3 Flowchart of step S4 in an exemplary embodiment.
[0160] In some embodiments, the version name of the target link library may exist in the first function (for example, the output function printf), but since the target binary code may include multiple printf functions, if the function including the version information is determined in the target binary code only based on the name of the first function, the version information cannot be accurately obtained.
[0161] Therefore, the second function including the version information may be determined in the target binary code according to a unique invariant in the first function, wherein the unique invariant may be a first symbol feature in the first function.
[0162] refer to Figure 8 , the above step S4 may include the following steps.
[0163] In step S41, a second symbol feature matching the first symbol feature is determined in the target binary code.
[0164] For example, the version information "7.60" in the target link library may be output in the form shown in the first function printf_chk(1LL, aSSSUageNmapSc, "Nmap", "7.60"), and the string "aSSSUageNmapSc" can be determined in the target binary code as the second symbol feature.
[0165] In step S42, a second function for calling the second symbol feature is determined according to the reference relationship between the data and the function.
[0166] Since the first symbol feature and the version name can exist in the same function in the target link library, theoretically, since the first symbol feature is unique, if the function that calls the second symbol feature is determined, then it can be considered that the function includes version information.
[0167] In step S43, if the second function and the first function have the same function name, the second function is the target function.
[0168] However, since there may be multiple functions that call the second symbolic feature, it is necessary to further confirm the second function that calls the second symbolic feature, that is, to confirm whether the second function has the same function name as the first function. If the second function has the same function name as the first function, it can be considered that the second function is the function in the target binary code that includes the target link library version information.
[0169] In some embodiments, after the function in the target binary code including the target link library version information is determined, information of the target function can be extracted according to the position of the version information in the first function to obtain the version information of the target link library called by the target binary code.
[0170] In the above example, since the version information "7.60" is output at the 4th position in the first function printf_chk, the information output at the 4th position in the second function can be extracted as the version information of the target link library.
[0171] The technical solution provided in this embodiment accurately determines the target function including version information in the target binary code through the calling relationship between the first symbol feature and the first function that calls the first symbol feature, so that the version information of the target link library can be accurately determined based on the target function.
[0172] Fig. 9 yes Figure 3Flowchart of step S4 in an exemplary embodiment.
[0173] In some embodiments, the target link library includes a third function, the third function calls a return function that returns version information
[0174] refer to Fig. 9 , the above step S4 may include the following steps.
[0175] In step S44, a fourth function having the same function name as the third function is determined in the target binary code.
[0176] In some embodiments, the target link library may return version information through a third function, and the third function may be, for example:
[0177] int magic_version{
[0178] return 2010;% returns 2010
[0179] }.
[0180] Generally speaking, in the target link library, if the version information is returned by a third function (such as the above magic_version), the third function generally does not change during the version update process. Therefore, a fourth function with the same function name as the third function can be determined in the target binary code by function name matching.
[0181] In step S45, it is determined whether the fourth function calls a return function according to the reference relationship between the data and the function.
[0182] In step S46, if the fourth function call returns a function, the fourth function is the target function.
[0183] In some embodiments, if the fourth function is determined to be a target function, the version information of the target link library called by the target binary code whose return value is the fourth function can be obtained.
[0184] The technical solution provided in this embodiment can directly determine the fourth function with the same function name in the target binary code according to the function name of the third function that calls the return function, and obtain the version information of the target link library according to the return value of the fourth function. This method is direct and convenient.
[0185] Fig.10 is a flow chart of a link library detection method according to an exemplary embodiment.
[0186] In some embodiments, the version name may also exist in the target link library in the form of a string. For example, it may exist in the link library in the form of "libpng version 1.2XX", where "1.2XX" may be the version name of the target link library and "libpng version" may be the prefix information of the version name. When the target link library is linked to the target binary code in a dynamic or static form, the version name will exist in the target binary code in the form of a string.
[0187] refer to Fig.10 , the above-mentioned link library detection method may include the following steps.
[0188] In step S6, the first prefix information of the version information in the target link library is obtained.
[0189] In some embodiments, the version information of the target link library can be extracted from the target binary code through the prefix information of the version name in the target link library (the prefix information of different version information can be consistent). For example, the version information in the target link library may be "libpng version 1.2XX", where "1.2XX" may be the version information of the target link library, and "libpng version" may be the prefix information of the version information.
[0190] In step S7, second prefix information matching the first prefix information is determined in the target binary.
[0191] In some embodiments, second prefix information equal to the first prefix information may be determined in the target binary code through the first prefix information (eg, “libpng version”).
[0192] In step S8, the version information of the target link library called by the target binary code is determined according to the second prefix information.
[0193] In some embodiments, after the second prefix information is determined, the character string where the second prefix information is located may be further obtained, and the suffix information following the character string may be extracted as the version information of the target link library called by the target binary code.
[0194] Fig.11 yes Fig.10 Flowchart of step S7 in an exemplary embodiment.
[0195] In step S81, the suffix information of the second prefix information is obtained.
[0196] In step S82, a version name naming rule is determined according to the version information of the target link library.
[0197] In some embodiments, in order to further determine that the suffix information corresponding to the second prefix information is the version information of the target link library, a naming rule of the version information of the target link library may be further obtained, and it may be further determined whether the suffix information satisfies the naming rule.
[0198] In step S83, if the suffix information satisfies the naming rule, the suffix information is the version information of the target link library.
[0199] For example, the version name in the target library may be "libpng version XXXXXX". According to the first prefix information "libpng version", the target binary code may include the second prefix information "libpng version1.2.2010", and the suffix information "1.2.2010" of the second prefix information may be obtained. After comparison, it is found that the naming rule of "1.2.2010" is consistent with "XXXXXX", so it can be considered that "1.2.2010" is the version information of the target library.
[0200] Fig.12 is a flow chart of a link library detection method according to an exemplary embodiment.
[0201] In some embodiments, the version information of the target link library may also be determined in the target binary code in a regular expression matching manner.
[0202] refer to Fig.12 , the above-mentioned link library detection method may include the following steps.
[0203] In step S9, a regular matching rule of the string containing the version information in the target link library is obtained.
[0204] In step S10, a target string is determined in the target binary code according to the regular matching rule, and version information of the target link library is extracted from the target string.
[0205] For example, the version string can be similar to "GNU Awk 3.2.1", then a regular match with "GNU Awk(\\d+\\.\\d+\\.\\d+)" can obtain the string "3.2.1", which can be the version information.
[0206] Fig.13 It is a schematic diagram showing a link library detection system according to an exemplary embodiment.
[0207] refer to Fig.13The above-mentioned link library detection system may include: a binary code analyzer 131, a target feature information matcher 132 and a version information acquirer 133, wherein the binary code analyzer 131 may include a file format parser, a feature extraction parser and a static analysis parser.
[0208] In some embodiments, the link library detection system may perform link library detection on the target binary code including the following process.
[0209] After the binary code analyzer 131 receives the target binary file, the file format parser parses the target binary file to extract the target binary code from the target binary file, and the feature extraction parser extracts the target feature information (including but not limited to the target constant feature and the target memory feature) from the target binary code; the static analysis parser performs static analysis on the target binary code to obtain the reference relationship between the data and the function in the target binary code; the target feature information matcher 132 compares the constant feature information of the target binary code with the constant feature information of the link library to determine the target link library and the candidate link library; the target feature information matcher 132 matches the target memory feature information of the target binary code with the memory feature of the candidate link library to determine the target link library in the candidate link library; the version information acquirer 133 analyzes the static analysis result of the target binary code to obtain the version information of the target link library from the target binary code.
[0210] The technical solution provided by this embodiment determines the target link library called by the target binary code by matching the feature information of the link library, and extracts the version information of the target link library from the target binary code through static analysis technology. The system, on the one hand, matches the link library with the target binary code through the invariant feature quantity to accurately determine the target link library called by the target binary code; on the other hand, accurately and efficiently extracts the version information of the target link library from the target binary code through static analysis technology.
[0211] Fig.14 is a block diagram of a link library detection device according to an exemplary embodiment. Fig.14 The link library detection device 1400 provided in the embodiment of the present disclosure may include: a target feature acquisition module 1401, an information matching module 1402, a reference relationship determination module 1403, a target function determination module 1404 and a version information determination module 1405.
[0212] Among them, the target feature acquisition module 1401 can be configured to obtain target feature information in the target binary code. The information matching module 1402 can be configured to match the target feature information with the feature information of the link library to determine the target link library called by the target binary code. The reference relationship determination module 1403 can be configured to obtain the reference relationship between data and functions in the target binary code through static program analysis. The target function determination module 1404 can be configured to analyze the reference relationship between data and functions in the target binary code according to the target link library, and determine the target function including the version information of the target link library in the target binary code. The version information determination module 1405 is configured to determine the version information of the target link library according to the target function.
[0213] In some embodiments, the target link library includes a first function, and the first function includes version information and a first symbol feature.
[0214] In some embodiments, the target function determination module 1404 may include: a second symbol feature determination submodule, a second function determination submodule, and a function name determination submodule.
[0215] The second symbol feature determination submodule may be configured to determine a second symbol feature matching the first symbol feature in the target binary code. The second function determination submodule may be configured to determine a second function that calls the second symbol feature according to a reference relationship between the data and the function. The function name determination submodule may be configured such that if the second function has the same function name as the first function, the second function is the target function.
[0216] In some embodiments, the version information determination module may include: an output information determination submodule, wherein the output information determination submodule may be configured to extract information from the target function according to the position of the version information in the first function to obtain the version information of the target link library called by the target binary code.
[0217] In some embodiments, the target link library includes a third function, and the third function calls a return function that returns version information.
[0218] In some embodiments, the version information extraction module further includes: a fourth function determination submodule, a call determination submodule, and a target function determination submodule.
[0219] The fourth function determination submodule may be configured to determine a fourth function having the same function name as the third function in the target binary code. The call determination submodule may be configured to determine whether the fourth function calls a return function according to the reference relationship between the data and the function. The target function determination submodule may be configured such that if the fourth function calls a return function, the fourth function is the target function.
[0220] In some embodiments, the reference relationship determination module 1403 may include: an intermediate representation submodule, a control flow graph determination submodule, and a reference relationship acquisition submodule.
[0221] The intermediate representation submodule may be configured to translate the target binary code to obtain an intermediate representation of the target binary code. The control flow graph determination submodule may be configured to obtain a function call graph and a control flow graph according to the intermediate representation of the target binary code. The reference relationship acquisition submodule may be configured to determine the reference relationship between data and functions according to the function call graph and the control flow graph.
[0222] In some embodiments, the target feature information includes constant feature information.
[0223] In some embodiments, the information matching module 1402 may include: a valid feature determination submodule, a target link library determination submodule, and a memory feature processing submodule.
[0224] The effective feature determination submodule can be configured to match the constant feature information with the constant feature library of the link library to determine the effective feature. The target link library determination submodule can be configured to determine the target link library and the candidate link library according to the proportion of the effective feature in the constant feature library. The memory feature processing submodule can be configured to determine the target link library called by the target binary code according to the memory feature of the candidate link library.
[0225] In some embodiments, the target link library determination submodule may include: a target link library determination unit and a candidate link library determination unit.
[0226] The target link library determination unit may be configured such that if the ratio is greater than a first threshold, the link library corresponding to the constant feature library is the target link library. The candidate link library determination unit may be configured such that if the ratio is less than or equal to the first threshold and greater than a second threshold, the link library corresponding to the constant feature library is the candidate link library.
[0227] In some embodiments, the constant feature information includes a first function name.
[0228] In some embodiments, the information matching module 1402 may further include: a sixth function name acquisition submodule, a target running function determination submodule, a memory feature acquisition submodule, and a memory feature matching submodule.
[0229] Among them, the sixth function name acquisition submodule can be configured to obtain the sixth function in the candidate link library, and run the sixth function to generate the memory characteristics of the candidate link library. The target operation function determination submodule can be configured to determine the target operation function matching the sixth function in the target binary code according to the fifth function name; the memory characteristic acquisition submodule can be configured to run the target operation function to obtain the target memory characteristics. The memory characteristic matching submodule can be configured to match the target memory characteristics with the memory characteristics of the candidate link library. If the match is successful, the candidate link library is the target link library.
[0230] In some embodiments, the link library determining device may further include: a first prefix information acquiring module, a second prefix information determining module, and a suffix information determining module.
[0231] The first prefix information acquisition module may be configured to acquire first prefix information of version information in the target link library. The second prefix information determination module may be configured to determine second prefix information matching the first prefix information in the target binary. The suffix information determination module may be configured to determine version information of the target link library called by the target binary code according to the second prefix information.
[0232] In some embodiments, the suffix information determination module may include: a suffix information acquisition submodule, a naming rule acquisition submodule, and a naming rule matching submodule.
[0233] The suffix information acquisition submodule may be configured to acquire the suffix information of the second prefix information. The explicit rule acquisition submodule may be configured to determine the version name naming rule according to the version information of the target link library. The naming rule matching submodule may be configured such that if the suffix information satisfies the naming rule, the suffix information is the version information of the target link library.
[0234] In some embodiments, the link library detection device may further include: a regular matching rule acquisition module and a string matching submodule.
[0235] The regular matching rule acquisition module can be configured to acquire the regular matching rule of the string containing the version information in the target link library. The string matching submodule can be configured to determine the target string in the target binary code according to the regular matching rule and extract the version information of the target link library from the target string.
[0236] Since the functional modules of the link base detection device 1400 of the exemplary embodiment of the present disclosure correspond to the steps of the exemplary embodiment of the link base detection method described above, they will not be described in detail here.
[0237] Through the description of the above implementation methods, it is easy for those skilled in the art to understand that the example implementation methods described here can be implemented by software, or by combining software with necessary hardware. Therefore, the technical solution of the embodiment of the present disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.), including a number of instructions for a computing device (which can be a personal computer, a server, a mobile terminal, or a smart device, etc.) to execute the method according to the embodiment of the present disclosure, for example Figure 3 One or more of the steps shown.
[0238] In addition, the above-mentioned figures are only schematic illustrations of the processes included in the method according to the exemplary embodiments of the present disclosure, and are not intended to be limiting. It is easy to understand that the processes shown in the above-mentioned figures do not indicate or limit the time sequence of these processes. In addition, it is also easy to understand that these processes can be performed synchronously or asynchronously, for example, in multiple modules.
[0239] Those skilled in the art will readily appreciate other embodiments of the present disclosure after considering the specification and practicing the disclosure disclosed herein. The present disclosure is intended to cover any variations, uses, or adaptations of the present disclosure that follow the general principles of the present disclosure and include common knowledge or customary technical means in the art that are not applied for by the present disclosure. The specification and embodiments are to be regarded as exemplary only, and the true scope and spirit of the present disclosure are indicated by the claims.
[0240] It should be understood that the present disclosure is not limited to the detailed structures, drawings or implementations shown herein, but rather the present disclosure is intended to cover various modifications and equivalent arrangements included within the spirit and scope of the appended claims.
Claims
1. A link library determination method, characterized in that: include: Obtain target feature information in the target binary code; Matching the target feature information with the feature information of the link library to determine the target link library called by the target binary code; Obtaining reference relationships between data and functions in the target binary code through static program analysis; Analyzing the reference relationship between data and functions in the target binary code according to the target link library, and determining the target function including the version information of the target link library in the target binary code; The version information of the target link library is determined according to the target function.
2. The method according to claim 1, characterized in that: The target link library includes a first function, and the first function includes version information and a first symbol feature; wherein, analyzing the reference relationship between data and functions in the target binary code according to the target link library, and determining the target function including the version information of the target link library in the target binary code, comprises: determining, in the target binary code, a second symbol feature that matches the first symbol feature; Determining a second function that calls the second symbol feature according to a reference relationship between the data and the function; If the second function and the first function have the same function name, the second function is the target function.
3. The method according to claim 2, characterized in that: Determining the version information of the target link library according to the target function includes: Information is extracted from the target function according to the position of the version information in the first function to obtain version information of the target link library called by the target binary code.
4. The method according to claim 1, characterized in that: The target link library includes a third function, the third function calls a target return function, and the target return function returns version information; wherein, analyzing the reference relationship between data and functions in the target binary code according to the target link library, and determining the target function including the target link library version information in the target binary code includes: determining, in the target binary code, a fourth function having the same function name as the third function; Determining whether the fourth function calls a return function according to the reference relationship between the data and the function; If the fourth function call returns a function, then the fourth function is the target function.
5. The method according to claim 1, characterized in that: Obtaining the reference relationship between data and functions in the target binary code through static program analysis, including: Translating the target binary code to obtain an intermediate representation of the target binary code; Obtaining a function call graph and a control flow graph according to the intermediate representation of the target binary code; The reference relationship between data and functions is determined according to the function call graph and the control flow graph.
6. The method according to claim 1, characterized in that: The target feature information includes constant feature information; wherein, matching the target feature information with feature information of a link library to determine the target link library called by the target binary code includes: Matching the constant feature information with the constant feature library of the link library to determine valid features; Determine the target link library and the candidate link library according to the proportion of the effective features in the constant feature library; The target link library called by the target binary code is determined according to the memory characteristics of the candidate link library.
7. The method according to claim 6, characterized in that: Determining the target link library and the candidate link library according to the proportion of the effective features in the constant feature library includes: If the ratio is greater than a first threshold, the link library corresponding to the constant feature library is the target link library; If the ratio is less than or equal to the first threshold and greater than the second threshold, the link library corresponding to the constant feature library is a candidate link library.
8. The method according to claim 6, characterized in that: The constant feature information includes a fifth function name; wherein determining the target link library called by the target binary code according to the memory feature of the candidate link library includes: Obtaining a sixth function in the candidate link library, and running the sixth function to generate a memory feature of the candidate link library; Determining a target running function matching the sixth function in the target binary code according to the fifth function name; Running the target running function to obtain target memory characteristics; The target memory feature is matched with the memory feature of the candidate link library. If the match is successful, the candidate link library is the target link library.
9. The method according to claim 1, characterized in that: Also includes: Obtaining first prefix information of version information in the target link library; Determining, in the target binary, second prefix information that matches the first prefix information; The version information of the target link library called by the target binary code is determined according to the second prefix information.
10. The method according to claim 9, characterized in that: Determining the version information of the target link library called by the target binary code according to the second prefix information includes: Obtaining suffix information of the second prefix information; Determine a version name naming rule according to the version information of the target link library; If the suffix information satisfies the naming rule, the suffix information is the version information of the target link library.
11. The method according to claim 1, characterized in that: Also includes: Obtaining a regular expression matching rule for the string containing the version information in the target link library; A target character string is determined in the target binary code according to the regular matching rule, and version information of the target link library is extracted from the target character string.
12. A device for determining a link library, characterized in that: include: A target feature acquisition module, configured to acquire target feature information in a target binary code; An information matching module, configured to match the target feature information with feature information of a link library to determine a target link library called by the target binary code; A reference relationship determination module, configured to obtain the reference relationship between data and functions in the target binary code through static program analysis; a target function determination module configured to analyze the reference relationship between data and functions in the target binary code according to the target link library, and determine the target function including the version information of the target link library in the target binary code; The version information determination module is configured to determine the version information of the target link library.
13. An electronic device, characterized in that: include: one or more processors; a storage device for storing one or more programs, When the one or more programs are executed by the one or more processors, the one or more processors implement the method according to any one of claims 1 to 11.
14. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the method according to any one of claims 1 to 11 is implemented.
15. A computer program product comprising a computer program, which implements the method according to any one of claims 1 to 11 when executed.
Citation Information
Patent Citations
Third-party component vulnerability detection method based on binary code features
CN107844705A
Software analysis method and device by using big data and neural networks
CN108229170A