A PHP Static Code Analysis Method Based on Taint Analysis

Through the static code analysis method based on taint analysis, the PHP source code is lexical and syntax analysis is carried out, the abstract syntax tree is built, and the taint data flow in each function is marked, which solves the problem that existing tools are difficult to adapt to the new version of PHP syntax characteristics and high false alarm rates, and realizes accurate identification of vulnerabilities in the new features and reduces false alarm rates.

CN113836532BActive Publication Date: 2025-06-13CHINA YOUKE COMM TECH
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202111132194.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-09-27
Publication Date
2025-06-13
Estimated Expiration
2041-09-27

AI Technical Summary

Technical Problem

The existing PHP source code auditing tools are difficult to adapt to the syntax features of the new version of PHP, resulting in the inability to correctly identify vulnerabilities introduced in the new features and the false positive rate is high.

Method used

The static code analysis method based on taint analysis is adopted to construct an abstract syntax tree through lexical analysis and grammatical analysis, segment it into subfunctions, and use taint analysis technology to mark the taint data flow in each function to determine whether there are vulnerabilities.

Benefits of technology

It effectively reduces the false alarm rate of vulnerabilities, can correctly identify vulnerabilities introduced in new features, and facilitates the analysis and processing of security personnel through visual reports.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113836532B_ABST
    Figure CN113836532B_ABST
Patent Text Reader

Abstract

The present invention relates to a PHP static code analysis method based on taint analysis. The method: First, perform lexical analysis and syntactic analysis on the PHP static code to construct an abstract syntax tree corresponding to the code; Second, split the abstract syntax tree into different sub-functions, and use taint analysis technology to mark the taint data flow in each function; Finally, determine whether there are vulnerabilities according to the nature of the convergence point parameters of the taint data flow; In addition, when marking the taint data flow, the variable range is reduced by restricting the data type of the newly added variables, and measures such as the conditions when the functions with security threats are exploited are combined to reduce the false positive rate of vulnerabilities. The present invention can realize automatic tool vulnerability detection, and under the condition that there are no branches in the code, the method of the present invention can more efficiently and accurately complete the vulnerability detection of Web applications.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security, and particularly to a PHP static code analysis method based on taint analysis. Background Art

[0002] For code auditing, the current mainstream methods are divided into black-box testing and white-box testing. The biggest difference between the two testing methods lies in whether the auditing system can obtain the source code of the target system. In black-box testing, the auditing system does not know the source code of the target. It regards the target program as a black box and does not need to consider the internal structure and logic of the target program. The auditing system determines whether there are vulnerabilities by continuously changing the input data and obtaining the output of the program or its working state. Since each test causes an abnormal result through determined data, black-box testing is a testing method with a very low false positive rate. However, its detection coverage rate for vulnerabilities depends on the capacity of the input data and it is often difficult to completely cover all branches of the program, easily resulting in missed reports.

[0003] White-box testing is to find vulnerabilities by analyzing specific codes such as syntax and function calls in the source code when the software source code is mastered. Since the white-box auditing tool can read the source code, that is, it can completely cover all branches in the code compared with black-box testing, the false negative rate of white-box testing is low. However, compared with black-box testing where each vulnerability discovery is caused by exact malicious data, static analysis in white-box testing to discover vulnerabilities will bring a higher false positive rate.

[0004] Currently, the auditing tools for PHP source code include: Pixy, RIPS, etc. Among them, Pixy is a static detection tool developed by Java. It only supports automatically scanning the source code under PHP4 syntax and part of the source code under PHP5 syntax, and can no longer handle the latest PHP7 syntax features. Moreover, it can only identify XSS vulnerabilities and cannot detect other types of vulnerabilities. RIPS is also a well-known open-source static detection tool that can detect vulnerabilities through code analysis and regular analysis and will give repair tips.

[0005] Generally speaking, although there are already PHP vulnerability analysis tools in the industry, most of the current source code analysis tools have stopped updating and can no longer adapt to the syntax features of the current new version of PHP. This results in the inability to correctly identify the vulnerabilities introduced from the new features and also brings false positives for the new features. Summary of the Invention

[0006] The purpose of the present invention is to study how to use the taint analysis technology to analyze PHP source code, so a PHP static code analysis method based on taint analysis is provided. The common vulnerabilities and their principles of Web applications are first analyzed, the currently popular taint analysis detection methods are studied, and the variable type constraints are creatively added to each variable. In addition, the audit system reports vulnerabilities through Web pages, and visualizes the vulnerability information and the taint transmission process, which is convenient for security personnel to view and analyze.

[0007] To achieve the above-mentioned purpose, the technical solution of the present invention is: a PHP static code analysis method based on taint analysis, first, lexical analysis and syntax analysis are performed on the PHP static code to construct an abstract syntax tree of the corresponding code; secondly, the abstract syntax tree is divided into different sub-functions, and the taint analysis technology is used to mark the tainted data flow in each function; finally, whether there is a vulnerability is determined based on the properties of the convergence point parameters of the tainted data flow.

[0008] In one embodiment of the present invention, when marking a tainted data stream, the variable range is narrowed by limiting the data type of the newly added variable, and the condition when the security threat function is exploited is combined to reduce the vulnerability false alarm rate.

[0009] In one embodiment of the present invention, the method is specifically implemented in the following steps:

[0010] Step S1, perform lexical analysis and syntax analysis on the PHP code, and construct an abstract syntax tree of the corresponding code. The structural information in the source code will be in each node of the abstract syntax tree; this will not destroy the logic or syntax rules of the original code. The abstract syntax tree plays an important role in syntax checking, code formatting, etc. The present invention uses the abstract syntax tree to convert the source code to be detected into a syntax structure that is more conducive to analysis.

[0011] Step S2: Split the abstract syntax tree into different sub-functions, and use the taint analysis technology to mark the tainted data flow in each sub-function. Each input point will carry a tainted state during initialization, and each variable in the analyzed code will have a set of associated state tables, representing the code in the process of tainted state transformation; generally speaking, tainted flows will be propagated explicitly. The operations that are transformed into taints in the taint analysis strategy are mainly input sources, propagation (assignment), function calls, etc., and there will also be some operations to clean up taints, such as hash algorithms.

[0012] Step S3: Determine whether there is a vulnerability based on the properties of the convergence point parameters of the tainted data stream. When the tainted data stream propagates in the code, once a tainted convergence point appears, it is necessary to determine whether the tainted convergence point carries a taint identifier. If there is a taint identifier, it is determined that a vulnerability exists.

[0013] In an embodiment of the present invention, in step S1, the implementation manner of constructing the abstract syntax tree corresponding to the code is as follows:

[0014] Step S11: Obtain the source code;

[0015] Step S12: Pass through the lexical analyzer to generate a token stream from the source code according to the syntax standard in PHP;

[0016] Step S13: Then pass through the syntax analyzer to convert the token stream into an abstract syntax tree that conforms to the PHP syntax.

[0017] Compared with the prior art, the present invention has the following beneficial effects:

[0018] (1) Creatively propose to narrow the range of variables by adding a restricted data type for variables, and jointly reduce false positives by combining the conditions for the utilization of functions with security threats.

[0019] (2) The system can automatically analyze, mark, and trace the taint flow of PHP files in the directory through the coupling of different modules to discover potential application vulnerabilities and generate a visual data report.

[0020] (3) From the perspective of future development, automated auditing will surely gradually replace traditional manual auditing. Currently, auditing tools based on taint analysis technology have a low false positive rate and will surely become a research hotspot for future network security. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] Figure 1 It is a flowchart of the static code analysis tool of the present invention.

[0022] Figure 2 It is the structure of the function node.

[0023] Figure 3 It is the design and implementation of a PHP static code analysis tool based on taint analysis for code with conditional branches.

[0024] Figure 4 It is the code with a cleaning function.

[0025] Figure 5 It is the overall result display.

[0026] Figure 6 It is the display of vulnerability details. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0027] The technical solution of the present invention will be specifically described below with reference to the accompanying drawings.

[0028] A PHP static code analysis method based on taint analysis. First, perform lexical analysis and syntax analysis on the PHP static code to construct an abstract syntax tree corresponding to the code. Secondly, divide the abstract syntax tree into different sub-functions, and use taint analysis technology to mark the taint data flow in each function. Finally, determine whether there are vulnerabilities according to the nature of the convergence point parameters of the taint data flow.

[0029] Based on a PHP static code analysis method based on taint analysis, the present invention realizes a prototype tool for detecting PHP static code vulnerabilities based on taint analysis, that is, introducing a static code analysis tool into the coding stage, and designing and implementing a static code analysis tool based on PHP. First, the present invention will introduce the framework structure of static code analysis attacks and the functions of each module, and then analyze the implementation methods in each framework.

[0030] 1. PHP Static Code Analysis Framework

[0031] For the PHP static code analysis tool, it follows a top-down design pattern of folder, single file, and single function. The entire tool is divided into four modules: folder analysis module, file analysis module, function analysis module, and result display module, as Figure 1 shown.

[0032] 1) The folder analysis module, as the entry module of the entire analysis, needs to collect the files to be detected under the target directory and perform file analysis in sequence.

[0033] 2) The file analysis module needs to split the corresponding file into smaller function blocks internally, and then use the function analysis module for analysis.

[0034] 3) The function analysis module uses taint analysis to analyze whether there is taint data in the corresponding function being executed by dangerous functions.

[0035] 4) The result display module uses HTML technology to visually display the discovered vulnerabilities.

[0036] 2. Folder Analysis Module

[0037] The folder analysis module is the starting point of the entire analysis project. Its main functions are: 1) Traverse and store all PHP files under the target folder directory; 2) Analyze the mutual reference relationships of each PHP file; 3) Determine the order of parsing files according to the mutual relationships.

[0038] Algorithm 1: Analyze files in sequence (Files, IncludesMap)

[0039] / * Since "include" can be used in PHP files to reference external PHP code, it is necessary to analyze each file in a certain order.

[0040] * /

[0041] / * Files is the set of file paths to be processed; * /

[0042] Figure 4-1 Flowchart of PHP Static Code Analysis Tool Undergraduate Graduation Project (Thesis) of Fuzhou University 12

[0044] / * IncludesMap is the relationship of mutual references between each file * /

[0045] 1. begin

[0046] 2. handledFiles ← Ø

[0047] 3. do

[0048] 4. list = Files \ handledFiles

[0049] 5. if list = Ø then

[0050] 6. break

[0051] 7. end

[0052] 8. for each file ∈ list do

[0053] 9. if includesMap[file] \ handledFiles = Ø then

[0054] 10. doFileAnalysis(file)

[0055] 11. Add file to handledFiles

[0056] 12. end

[0057] 13. end

[0058] 14. end

[0059] 15. end

[0060] Algorithm 1 shows how to determine the order of file parsing. The input of the algorithm is a set of files to be processed and the reference relationships of each file. At the beginning of the program, an array is initialized to store the set of processed files. Then the algorithm enters a loop, and the termination condition of the loop is that all files are processed, that is, the difference between the set of files to be processed and the set of processed files is an empty set. Inside the loop, the files to be processed in the current round will be processed in turn. By checking whether the difference between the file reference relationship table and the processed files is empty, it can be determined whether the files referenced by the current file have been processed. If the files referenced by the current file have been processed, then the current file can be processed, and after processing, the current file is added to the set of processed files. Otherwise, the current file is skipped and the next file is processed.

[0061] 3. File Analysis Module

[0062] The file analysis module needs to construct the corresponding abstract syntax tree by syntax analysis and lexical analysis of the code inside the file. Secondly, the given file needs to be cut into individual functions for the function analysis module to process. However, when running and referencing external files in PHP, if not processed in advance, it will lead to a large number of undefined functions and unknown taint flows during later function analysis, thus reducing the accuracy of code analysis.

[0063] 3.1. Handling File Inclusion

[0064] Regarding the problem of file inclusion, since in PHP code, other PHP files can only be referenced through "include" or other alias functions. These reference methods are all aggregated into the \PhpParser\Node\Expr\Include_ node in the corresponding abstract syntax tree. Therefore, as long as the corresponding node is detected, it can be determined that an external file is introduced. In this way, the design and implementation of the corresponding PHP static code analysis tool based on taint analysis, the functions and taint source data in the PHP file can be inherited into the current file. Since in Algorithm 1, we can ensure that when a single PHP file is analyzed, the corresponding referenced file has been analyzed, so here the corresponding data can be directly inherited without judgment.

[0065] 3.2. Splitting Functions

[0066] For the entire PHP code file, it can be divided into user-defined functions and non-function parts. User-defined functions will not be automatically executed when not called. The non-function parts will be automatically executed in sequence when the script is executed. We can regard the code in these non-function parts as a function without input parameters, and we call this kind of function the main function. In the constructed abstract syntax tree, each function is stored as a \PhpParser\Node\Stmt\Function_ node, and the node structure is as Figure 2 . The node contains the function name, function parameters, and statements in the function. For the extraction of user functions, it only needs to traverse all \PhpParser\Node\Stmt\Function_ in the node.

[0067] For the main function, a \PhpParser\Node\Stmt\Function_ node needs to be manually created, and the function name is set with empty parameters. Traverse all \PhpParser\Node\Stmt under the non-\PhpParser\Node\Stmt\Function_ node in the file, that is, the single-line statement nodes are stored in the statement set of \PhpParser\Node\Stmt\Function_. Finally, we analyze each PHP file with many independent functions by splitting each function in the PHP file and grouping the non-function code segments into a function.

[0068] 4. Function Analysis Module

[0069] The function analysis module can determine whether the functions defined by developers belong to functions with security threats, that is, in insecure calls, whether system security threat functions will be called. If it is for the analysis of the main function, it can judge whether there are security vulnerabilities in this file.

[0070] 4.1. Tainted Object

[0071] For each tainted variable, an object is used for storage, called a tainted object. What needs to be stored in the tainted object are:

[0072] 1) The taint flag in the current state;

[0073] 2) The current variable type, the main types are common PHP types such as "Int", "String", "Boolean", etc., and there is also a category of Mixed that can represent any type;

[0074] 3) The value of the current variable. If it is marked as the tainted state, the value will be set to null;

[0075] 4) All statement structures that have changed the taint value during code execution.

[0076] 4.2 Taint Propagation Analysis

[0077] For an initial function, first the program analyzes the function's parameters: whether the function contains parameters and whether the parameters strongly define certain types. Mark the taint status of these parameters and add them to the taint source. Then analyze each line of code. Here, a combination of static and dynamic methods is adopted:

[0078] 1) For some common numeric operations "+", "-", "*", " / ", bitwise operations "&", "|", "!", etc., when the left and right values are both non-tainted, that is, both the left and right values are known. In this case, the operation can be directly performed. Obtain the value after the operation. At this time, the obtained value is also a determined value and is in a non-tainted state.

[0079] 2) For functions that are not in the threat function and non-executable function tables, they can also be executed in the same way as in 1). When all the parameters in the called function are non-tainted values, the function can be executed to obtain the corresponding return value.

[0080] 3) When there are taint values in the operation value or parameters, we adopt a variable-type-based method to reduce the propagated taint type. For arithmetic operators, we can be sure that the result after the operation must be of a numeric type, including integers and floating-point numbers. For example, in PHP, "1 + 1 = 2", and for " 'a' + 1", a warning will be thrown and then the execution will continue, and the final result is 1. For operations between strings, such as the concatenation operator ".", the final returned value is a string-type variable. At this time, it can be boldly determined that the taint variable is of string type.

[0081] 4) Taint data may also appear in some function calls, which means that the return value cannot be directly obtained by executing the function. Here, a solution similar to 3) is adopted. In this design, a total of 10,000 functions in PHP's built-in and extension libraries are counted. Based on the return values given in the official documentation, a "function - parameter - return value" table is established. Through this table, we can increase the type of the marked taint variable and reduce the false alarm rate in the later stage.

[0082] 4.3 Analysis of Code Branches

[0083] Branch-type code also appears in the program. For example, the "if" statement can execute different code according to different conditions. Take Figure 3 the code as an example.

[0084] It is very easy to find that "exec" on line 6 is a function for executing system commands in PHP, which is a function with security threats. Then the taint status of the "$var" variable determines whether this function needs to report a vulnerability. By tracking the source of the "$var" variable, it will be found that the "$var" variable has been tainted modified in both line 2 and line 4. In line 2, the "$var" variable is changed to the tainted state, while in line 4 it becomes the non-tainted state. All of this depends on the condition in line 1. So for this situation, we adopt the following two strategies in sequence:

[0085] 1) When all variables in the condition are in the non-tainted state, since the variables within the expression have definite values, the truth or falsehood of the condition can be directly judged to determine the selected branch.

[0086] 2) When there are some variables in the condition in the tainted state, at this time, the branch cannot be determined through direct calculation. Here, the principle of taint priority is adopted. When multiple branches modify the taint state of a variable, the final taint state is the logical AND of each taint state. Simply put, if one branch makes a variable tainted, then this variable will be marked as tainted. Only when all branches make a variable become the clean state, will this variable be in the clean state.

[0087] 4.4. Taint Convergence Analysis

[0088] After analyzing the code within the function and taint tracking, functions that may pose security threats will be tracked. As we all know, even functions that pose security threats need certain conditions to be executed. Take Figure 4 the code as an example:

[0089] There are two functions in the code. The function "intval" in line 1 is used to convert the input variable into an integer, and its return value is of integer type. The function "system" in line 2 is used to execute system commands and output the result of the executed command to the screen. In our program analysis, "$_GET" is a super global variable that can be controlled by the user and is tainted data. Then its sub-element "evil" is also tainted data. After passing through the intval function and being assigned to "$var", the "$var" variable is thus infected as a tainted variable through "$_GET['eval']". Secondly, by querying the function table in the program analysis, it is extracted that the return of "intval" is of the "int" type, and finally the "$var" variable is marked as a tainted variable of integer type. The program continues to analyze and reaches line 2, where it is found that a function with a security threat is called. After performing taint discrimination on each parameter, it is found that it does not match the required string type tainted data, and finally the code security is reported.

[0090] As can be seen from the above example, by judging the types of tainted variables, the phenomenon of false positives that cannot be utilized can be effectively reduced.

[0091] 4.5, Identification of Function Properties

[0092] After analyzing the entire function, we will focus on the following two issues: 1) Whether functions with security threats are called in this function and whether there are possible vulnerabilities that can be triggered. If there are possible vulnerabilities, then this function defined by the developer is a function with security threats. If called in other functions in the future, there will also be security threats. Conversely, this function is a secure function. 2) Whether the return value of the function is determined and what the return value type is. We can use the "return" keyword to make a simple judgment summary. If each return value is of a certain type, then the return value type of this function is also determined. If there are multiple different types, in the present invention, they are uniformly classified as the "Mixed" mixed type.

[0093] 5. Result Display

[0094] After the analysis and processing of the previous several modules, although we can already find the situation of vulnerabilities in the code to be analyzed, these are only text data and are not intuitive enough. There is a need for a corresponding system for visual display so that the vulnerability information can be viewed manually. Therefore, the tool designs a module to display the results and vulnerability information. The entire visualization module uses the front-end framework Vue and the code highlighting module PrismJS. There are two main pages in total:

[0095] 1) Overall result display, showing the number of files analyzed and the number of vulnerabilities of different levels found. For example, Figure 5 , from the figure, we can clearly obtain the number of scanned files, the number of detected vulnerabilities, and their proportions in different levels of vulnerabilities.

[0096] 2) For the vulnerability details, a three-section structure is adopted. The left end is the file list and the module information of the current file, the middle is the source code of the currently viewed file, and the right end is the vulnerability information, and the taint flow can be viewed. Among them, the vulnerability points will be highlighted in red, and the taint flow will be highlighted in yellow. For example, Figure 6 . We can see that there are two serious types of vulnerabilities in this file, and they both call the dangerous function "shell_exec". In the middle pane, it can be seen that the 10th line of code is highlighted in red, indicating that it is the convergence point of the vulnerability currently; the 5th line is highlighted in yellow, indicating that the tainted data "$target" is affected at this line, and the source of the influence is "$_REQUEST['ip']".

[0097] The above are the preferred embodiments of the present invention. Any changes made to the technical solution of the present invention that do not exceed the scope of the technical solution of the present invention in terms of the functions and effects produced shall fall within the protection scope of the present invention.

Claims

1. A PHP static code analysis method based on taint analysis, characterized in that, firstly, perform lexical analysis and syntax analysis on the PHP static code to construct an abstract syntax tree corresponding to the code; secondly, split the abstract syntax tree into different sub-functions, and use taint analysis technology to mark the taint data flow in each function; finally, determine whether there are vulnerabilities according to the nature of the convergence point parameters of the taint data flow; the method is specifically implemented by constructing a PHP static code analysis tool, and the PHP static code analysis tool is divided into 4 modules: a folder analysis module, a file analysis module, a function analysis module, and a result display module; among them, the folder analysis module collects the PHP files to be detected under the target folder directory, analyzes the mutual reference relationships of each PHP file, determines the order of parsing files according to the mutual relationships, and performs file analysis in sequence. Specifically, based on the file set to be processed and the mutual reference relationships of each PHP file, an array is initialized to store the processed file set, and then a loop is entered. The termination condition of the loop is that all files are processed, that is, the difference set between the file set to be processed and the processed file set is an empty set. Inside the loop, the files to be processed in the current round will be processed in sequence. Whether the file referenced by the corresponding file has been processed is judged by whether the difference set between the file reference relationship table and the processed files is an empty set. If the file referenced by the corresponding file has been processed, the corresponding file can be processed, and the corresponding file is added to the processed file set after processing, otherwise the corresponding file is skipped and the next file is continued to be processed; the file analysis module constructs the corresponding abstract syntax tree through syntax analysis and lexical analysis of the code inside the file. Secondly, the given file needs to be cut into each function for the function analysis module to process. Specifically, based on the folder analysis module to handle the file inclusion problem, the user-defined functions and the main function in the PHP file are split. For user functions, all \PhpParser\Node\Stmt\Function_ nodes in the constructed abstract syntax tree nodes are traversed; for the main function, a \PhpParser\Node\Stmt\Function_ node is created, and all \PhpParser\Node\Stmt under the non-\PhpParser\Node\Stmt\Function_ nodes in the PHP file, that is, the single-line statement nodes, are traversed and stored in the statement set of the \PhpParser\Node\Stmt\Function_ node; the function analysis module determines whether the functions defined by the developer belong to functions with security threats, that is, whether the system's security threat functions will be called in insecure calls; if the analysis of the main function is performed, it can be judged whether there are security vulnerabilities in this file; the result display module is used to display the results and vulnerability information, including: overall result display, showing the number of analyzed files and the number of vulnerabilities at different levels found; The vulnerability details show that a three - segment structure is adopted. The left - end text is the file list and the module information of the current file. The middle part is the source code of the currently viewed file, and the right - end is the vulnerability information; When marking the tainted data flow, the variable range is narrowed by restricting the data types of newly added variables, and the conditions when security - threat functions are exploited are combined to reduce the false - positive rate of vulnerabilities.

2. A PHP static code analysis method based on taint analysis according to claim 1, characterized in that, the specific implementation steps of this method are as follows: Step S1: Perform lexical analysis and syntax analysis on the PHP code to construct an abstract syntax tree corresponding to the code. The structural information in the source code will be in each node of the abstract syntax tree; Step S2: Split the abstract syntax tree into different sub - functions, and use taint analysis technology to mark the tainted data flow in each sub - function. Each input point will carry a taint status during initialization, and each variable in the analyzed code will have a set of associated status tables, representing the code during the process of taint status transformation; Step S3: Determine whether there is a vulnerability according to the parameter nature of the convergence point of the tainted data flow. When the tainted data flow propagates in the code, once a taint convergence point appears, it is necessary to determine whether the taint convergence point carries a taint flag. If there is a taint flag, it is determined that there is a vulnerability.

3. A PHP static code analysis method based on taint analysis according to claim 1, characterized in that, in step S1, the implementation method of constructing the abstract syntax tree corresponding to the code is as follows: Step S11: Obtain the source code; Step S12: Pass through the lexical analyzer to generate a morpheme stream from the source code according to the syntax standard in PHP; Step S13: Then pass through the syntax analyzer to convert the morpheme stream into an abstract syntax tree that conforms to PHP syntax.

Citation Information

Patent Citations

  • Code auditing method and device

    CN110059006A