Heap memory vulnerability detection method, device, storage medium and electronic device

By using the binary instrumentation module in the target binary program to obtain and match the target calling function, combined with the risk function model, targeted heap memory vulnerability detection strategy is solved, and the problem of low detection efficiency of heap memory corruption vulnerability in the existing technology is solved, and efficient vulnerability detection is achieved.

CN113987507BActive Publication Date: 2025-05-09INDUSTRIAL AND COMMERCIAL BANK OF CHINA
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202111236368.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-10-22
Publication Date
2025-05-09
Estimated Expiration
2041-10-22

AI Technical Summary

Technical Problem

In the prior art, the detection efficiency of heap memory corruption vulnerabilities is low, especially Fuzzing fuzzing testing technology, stain analysis-based methods and existing detection technologies require modification of source code or target binary programs, resulting in inefficient detection.

Method used

The binary instrumentation module obtains the target call function in the target binary program, matches its function name and risk function model, determines its type, and executes the corresponding heap memory vulnerability detection strategy based on the type.

Benefits of technology

It improves the detection efficiency of heap memory corruption vulnerabilities, avoids modification of source code or binary programs, and realizes the effective detection of heap block metadata corruption, uninitialized heap memory access and memory leaks without the need for complex semantic instruction set modeling.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113987507B_ABST
    Figure CN113987507B_ABST
Patent Text Reader

Abstract

The present application discloses a heap memory vulnerability detection method, device, storage medium and electronic device, which relate to the field of information security. The method comprises: obtaining a target call function in a target binary program through a binary plug-in module, wherein the target call function at least includes the function name of the target call function; matching the function name of the target call function with a risk function model to obtain a matching result, wherein the risk function model includes the function names of multiple functions, whether each function belongs to a risky memory operation function, and the type corresponding to each function name; if the matching result indicates that the target call function belongs to a risky memory operation function, determining the type of the target call function; and executing the heap memory vulnerability detection strategy corresponding to the target call function according to the type of the target call function. Through the present application, the problem of low detection efficiency of heap memory corruption vulnerabilities in related technologies is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of heap memory vulnerability detection, and in particular, to a heap memory vulnerability detection method, device, storage medium and electronic device. Background Art

[0002] With the frequent occurrence of heap memory corruption vulnerabilities, the exploitation and protection of heap memory corruption vulnerabilities have begun to become the research focus of memory security in the field of information security. Common heap memory corruption vulnerabilities include heap buffer overflow vulnerabilities, Doublefree double release vulnerabilities, and UAF use-after-release vulnerabilities. Malicious users can carefully construct input data to bypass existing protection mechanisms, and use these heap memory corruption vulnerabilities to perform various illegal access operations on the heap memory allocated during program runtime, and directly or indirectly control the metadata of the heap block itself and tamper with the heap block layout to leak memory information during program runtime and hijack the program control flow.

[0003] GNU libc is the standard C language library of the Linux operating system. It is deployed in all Linux distributions and uses a heap management mechanism derived from ptmalloc. This mechanism allocates large pieces of memory for management when the program first requests memory from the operating system through the system call function brk() / mmap(). Ptmalloc has three most basic data structures, among which malloc_chunk is the basic unit of memory allocation and the structure that actually stores heap data information in glibc. The heap memory (chunk) requested by the program is represented by the malloc_chunk structure inside ptmalloc. Chunks are mainly divided into three types: Allocated Chunk, Free Chunk, and Top Chunk.

[0004] The current detection methods for heap memory corruption vulnerabilities mainly include fuzz testing technology, taint analysis technology, and compilation instrumentation technology, which have the following problems:

[0005] (1) Fuzzing testing technology is a widely used vulnerability discovery method. Its core idea is to use automatically or semi-automatically generated random test cases as input during program execution, monitor whether there are abnormal situations such as crashes during program execution to discover possible program errors in source code or binary software. The fuzz test data generated by this method has the problem of high redundancy. The heap is dynamically allocated and released by the user. It is a variable-sized memory space that is affected by the input during program execution and is dynamically allocated and released according to the needs of program execution. Therefore, the execution behavior of the program is difficult to predict. In addition, since the input instance of the heap memory corruption vulnerability usually only destroys the heap block metadata and does not directly control the value of the instruction pointer register and tamper with the program execution flow, it will not directly cause the program to crash, resulting in the low detection efficiency of the fuzzing testing technology for heap memory corruption vulnerabilities.

[0006] (2) The taint analysis-based method mainly analyzes whether the data marked as tainted in the program complies with the preset strategy during execution. It relies heavily on accurate semantic instruction set modeling, which is difficult and further leads to low detection efficiency of heap memory corruption vulnerabilities.

[0007] (3) Most existing detection technologies require modifying the source code and target binary program, and recompiling and linking the program to implement the detection process, which further leads to low detection efficiency for heap memory corruption vulnerabilities.

[0008] Currently, no effective solution has been proposed to address the problem of low detection efficiency of heap memory corruption vulnerabilities in related technologies. Summary of the invention

[0009] The main purpose of the present application is to provide a heap memory vulnerability detection method, device, storage medium and electronic device to solve the problem of low efficiency in detecting heap memory corruption vulnerabilities in related technologies.

[0010] In order to achieve the above-mentioned purpose, according to one aspect of the present application, a heap memory vulnerability detection method is provided. The method comprises: obtaining a target call function in a target binary program through a binary plug-in module, wherein the target call function at least includes the function name of the target call function; matching the function name of the target call function with a risk function model to obtain a matching result, wherein the risk function model includes the function names of multiple functions, whether each function belongs to a risky memory operation function, and the type corresponding to each function name; if the matching result indicates that the target call function belongs to a risky memory operation function, determining the type of the target call function; and executing the heap memory vulnerability detection strategy corresponding to the target call function according to the type of the target call function.

[0011] Furthermore, the type of the target calling function is at least one of the following: a type of a heap allocation function, a type of a heap release function, a type of a heap memory read function, and a type of a heap memory write function.

[0012] Furthermore, before executing the heap memory vulnerability detection strategy corresponding to the target calling function according to the type of the target calling function, the method also includes: if the type of the target calling function is the type of the heap allocation function, obtaining the function parameters of the heap allocation function through the target interface of the program; and calculating the heap memory space allocated by the target calling function according to the function parameters.

[0013] Furthermore, according to the type of the target calling function, executing the heap memory vulnerability detection strategy corresponding to the target calling function includes: if the type of the target calling function is the type of the heap allocation function, obtaining the execution result of the heap allocation function according to the target interface of the program, wherein the execution result includes the content of the heap block metadata; judging whether the heap memory space of the target calling function is allocated successfully through the execution result, if the heap memory space of the target calling function is allocated successfully, judging the number of applications for the heap memory space; if the number of applications for the heap memory space is a first preset value, determining the heap memory usage log through the function parameters of the heap allocation function and the program execution result of the heap allocation function; if the number of applications for the heap memory space is greater than the first preset value, judging whether the heap memory space address is an idle heap memory address, if the heap memory space address is an idle heap memory address, judging whether the heap allocation function is the target function, and if the heap allocation function is the target function, updating the heap memory usage log.

[0014] Furthermore, according to the type of the target calling function, executing the heap memory vulnerability detection strategy corresponding to the target calling function includes: if the type of the target calling function is the type of the heap release function, obtaining the function parameters of the heap release function through the target interface of the program; obtaining the heap memory address to be released according to the function parameters of the heap release function, and judging whether the heap memory address to be released has a matching record with the first address of the heap block already allocated in the heap memory usage log; if the heap memory address to be released has a matching record with the first address of the heap block already allocated in the heap memory usage log, releasing the heap memory address to be released, and updating the heap memory usage log.

[0015] Furthermore, according to the type of the target calling function, executing the heap memory vulnerability detection strategy corresponding to the target calling function includes: if the type of the target calling function is the type of the heap memory reading function, obtaining the function parameters of the heap memory reading function and the program execution result of the heap memory reading function through the target interface of the program; determining the target information of the heap memory reading function according to the function parameters of the heap memory reading function and the program execution result of the heap memory reading function, wherein the target information includes at least: the address of the read memory and the length of the read content; judging whether the target binary program has heap memory data read through the target information, and if the target information has heap memory data read, judging whether the address of the read memory is a released heap memory address according to the heap memory allocation status in the memory usage log of the heap allocation function; if the address of the read memory is a released heap memory address, triggering an abnormal alarm and terminating the target binary program process.

[0016] Furthermore, according to the type of the target calling function, executing the heap memory vulnerability detection strategy corresponding to the target calling function includes: if the type of the target calling function is the type of the heap memory writing function, obtaining the function parameters of the heap memory writing function and the program execution result of the heap memory writing function through the target interface of the program; determining the target information of the heap memory writing function according to the function parameters of the heap memory writing function and the program execution result of the heap memory writing function, wherein the target information at least includes: the address of the write memory and the length of the write content; judging whether the heap memory writing function is a heap memory initialization function according to the address of the write memory, if the heap memory writing function is a heap memory initialization function, updating the heap memory usage log, if the heap memory writing function is not a heap memory initialization function, judging whether the target binary program has a heap memory writing situation according to the address of the write memory and the heap memory usage log; in the case that the target binary program has read heap memory data, judging whether the address of the write memory is in a released state or judging whether the heap memory of the address of the write memory is not allocated; if the address of the write memory is in a released state or the heap memory of the address of the write memory is not allocated, triggering an abnormal alarm and terminating the target binary program process.

[0017] Furthermore, after executing the heap memory vulnerability detection strategy corresponding to the target calling function according to the type of the target calling function, the method also includes: traversing the heap memory allocation status records in the heap memory usage log to obtain the traversal results; and monitoring the target binary program based on the traversal results.

[0018] In order to achieve the above-mentioned purpose, according to another aspect of the present application, a heap memory vulnerability detection device is provided. The device includes: a first acquisition unit, which is used to acquire the target call function in the target binary program through a binary plug-in module, wherein the target call function at least includes the function name of the target call function; a first matching unit, which is used to match the function name of the target call function with the risk function model to obtain a matching result, wherein the risk function model includes the function names of multiple functions, whether each function belongs to a risky memory operation function, and the type corresponding to each function name; a first determination unit, which is used to determine the type of the target call function if the matching result indicates that the target call function belongs to a risky memory operation function; a first execution unit, which is used to execute the heap memory vulnerability detection strategy corresponding to the target call function according to the type of the target call function.

[0019] Furthermore, the type of the target calling function is at least one of the following: a type of a heap allocation function, a type of a heap release function, a type of a heap memory read function, and a type of a heap memory write function.

[0020] Furthermore, the device also includes: a second acquisition unit, which is used to obtain function parameters of the heap allocation function through the target interface of the program before executing the heap memory vulnerability detection strategy corresponding to the target calling function according to the type of the target calling function, if the type of the target calling function is the type of the heap allocation function; and a first calculation unit, which is used to calculate the heap memory space allocated by the target calling function according to the function parameters.

[0021] Furthermore, the first execution unit includes: a first acquisition module, which is used to obtain the execution result of the heap allocation function according to the target interface of the program if the type of the target calling function is the type of the heap allocation function, wherein the execution result includes the content of the heap block metadata; a first judgment module, which is used to judge whether the heap memory space of the target calling function is allocated successfully through the execution result, and if the heap memory space of the target calling function is allocated successfully, judge the number of applications for the heap memory space; a first determination module, which is used to determine the heap memory usage log through the function parameters of the heap allocation function and the program execution result of the heap allocation function if the number of applications for the heap memory space is a first preset value; a first update module, which is used to judge whether the heap memory space address is an idle heap memory address if the number of applications for the heap memory space is greater than the first preset value, and if the heap memory space address is an idle heap memory address, judge whether the heap allocation function is the target function, and if the heap allocation function is the target function, update the heap memory usage log.

[0022] Furthermore, the first execution unit includes: a second acquisition module, which is used to obtain function parameters of the heap release function through the target interface of the program if the type of the target calling function is the type of the heap release function; a second judgment module, which is used to obtain the heap memory address to be released according to the function parameters of the heap release function, and judge whether the heap memory address to be released has a matching record with the first address of the heap block already allocated in the heap memory usage log; a second update module, which is used to release the heap memory address to be released and update the heap memory usage log if there is a matching record between the heap memory address to be released and the first address of the heap block already allocated in the heap memory usage log.

[0023] Furthermore, the first execution unit includes: a third acquisition module, which is used to obtain function parameters of the heap memory read function and the program execution result of the heap memory read function through the target interface of the program if the type of the target calling function is the type of the heap memory read function; a second determination module, which is used to determine the target information of the heap memory read function according to the function parameters of the heap memory read function and the program execution result of the heap memory read function, wherein the target information at least includes: the address of the read memory and the length of the read content; a third judgment module, which is used to judge whether the target binary program has a situation of reading heap memory data through the target information, and if the target information has a situation of reading heap memory data, judge whether the address of the read memory is a released heap memory address according to the heap memory allocation status in the memory usage log of the heap allocation function; a first trigger module, which is used to trigger an abnormal alarm and terminate the target binary program process if the address of the read memory is a released heap memory address.

[0024] Further, the first execution unit includes: a fourth acquisition module, which is used to obtain the function parameters of the heap memory write function and the program execution result of the heap memory write function through the target interface of the program if the type of the target call function is the type of the heap memory write function; a third determination module, which is used to determine the target information of the heap memory write function according to the function parameters of the heap memory write function and the program execution result of the heap memory write function, wherein the target information at least includes: the address of the write memory and the length of the write content; a fourth judgment module, which is used to judge whether the heap memory write function is a heap memory initialization function according to the address of the write memory, if the heap memory write function is a heap memory initialization function, update the heap memory usage log, if the heap memory write function is not a heap memory initialization function, judge whether the target binary program has a heap memory write situation according to the address of the write memory and the heap memory usage log; a fifth judgment module, which is used to judge whether the address of the write memory is in a released state or whether the heap memory of the address of the write memory is not allocated when the target binary program has read heap memory data; a second trigger module, which is used to trigger an abnormal alarm and terminate the target binary program process if the address of the write memory is in a released state or the heap memory of the address of the write memory is not allocated.

[0025] Furthermore, the device also includes: a first traversal unit, which is used to traverse the heap memory allocation status records in the heap memory usage log to obtain a traversal result after executing the heap memory vulnerability detection strategy corresponding to the target calling function according to the type of the target calling function; and a first monitoring unit, which is used to monitor the target binary program based on the traversal result.

[0026] According to another aspect of an embodiment of the present application, an electronic device is also provided, including one or more processors and a memory, wherein the memory is used to store one or more programs, wherein when the one or more programs are executed by one or more processors, the one or more processors implement any of the above methods.

[0027] According to another aspect of an embodiment of the present application, a computer-readable storage medium is provided, on which a computer program / instruction is stored. When the computer program / instruction is executed by a processor, any one of the above methods is performed.

[0028] Through this application, the following steps are adopted: obtain the target call function in the target binary program through the binary plug-in module, wherein the target call function at least includes the function name of the target call function; match the function name of the target call function with the risk function model to obtain a matching result, wherein the risk function model includes the function names of multiple functions, whether each function belongs to a risky memory operation function, and the type corresponding to each function name; if the matching result indicates that the target call function belongs to a risky memory operation function, determine the type of the target call function; according to the type of the target call function, execute the heap memory vulnerability detection strategy corresponding to the target call function. The problem of low detection efficiency of heap memory corruption vulnerabilities in the related art is solved. Obtain the target call function in the target binary program through the binary plug-in module, match the function name of the target call function with the risk function model, determine the type of the target call function based on the matching result, and execute the heap memory vulnerability detection strategy corresponding to the target call function according to the type of the target call function, thereby achieving the effect of improving the detection efficiency of heap memory corruption vulnerabilities. BRIEF DESCRIPTION OF THE DRAWINGS

[0029] The drawings constituting a part of the present application are used to provide a further understanding of the present application. The illustrative embodiments and descriptions of the present application are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:

[0030] Figure 1 is a flow chart of a heap memory vulnerability detection method provided according to an embodiment of the present application;

[0031] Figure 2It is a heap allocation operation detection flow chart of the heap memory vulnerability detection method provided in an embodiment of the present application;

[0032] Figure 3 It is a heap release operation detection flow chart of the heap memory vulnerability detection method provided in an embodiment of the present application;

[0033] Figure 4 It is a memory read operation detection flow chart of the heap memory vulnerability detection method provided in an embodiment of the present application;

[0034] Figure 5 It is a memory write operation detection flow chart of the heap memory vulnerability detection method provided in an embodiment of the present application;

[0035] Figure 6 It is a schematic diagram of the system architecture of the heap memory vulnerability detection method provided in an embodiment of the present application;

[0036] Figure 7 is a schematic diagram of a heap memory vulnerability detection device provided according to an embodiment of the present application. DETAILED DESCRIPTION

[0037] It should be noted that, in the absence of conflict, the embodiments and features in the embodiments of the present application can be combined with each other. The present application will be described in detail below with reference to the accompanying drawings and in combination with the embodiments.

[0038] In order to enable those skilled in the art to better understand the solution of the present application, the technical solution in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of the present application.

[0039] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequential order. It should be understood that the data used in this way can be interchanged where appropriate, so that the embodiments of the present application described here. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device comprising a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.

[0040] For the convenience of description, some nouns or terms involved in the embodiments of the present application are explained below:

[0041] Glibc: glibc is the libc library released by GNU, that is, the C runtime library. glibc is the lowest-level API in the Linux system. Almost any other runtime library will depend on glibc.

[0042] According to an embodiment of the present application, a heap memory vulnerability detection method is provided.

[0043] Figure 1 is a flow chart of a heap memory vulnerability detection method according to an embodiment of the present application. Figure 1 As shown, the method comprises the following steps:

[0044] Step S101, obtaining a target calling function in a target binary program through a binary stub module, wherein the target calling function at least includes a function name of the target calling function.

[0045] For example, a dynamic binary instrumentation module is used to load a target binary program, and function-level binary instrumentation is performed while the program is running. In a custom instrumentation module, the link library, function name, and corresponding function offset of the currently called function are obtained.

[0046] Step S102, matching the function name of the target calling function with the risk function model to obtain a matching result, wherein the risk function model includes the function names of multiple functions, whether each function belongs to a risky memory operation function, and the type corresponding to each function name.

[0047] Specifically, the obtained function name is matched with the dangerous function model (corresponding to the risk function model in this application), and whether the function called by the target binary program is a dangerous memory operation function and the function type is determined based on the matching result.

[0048] Step S103: if the matching result indicates that the target calling function is a risky memory operation function, the type of the target calling function is determined.

[0049] Specifically, if the function called by the target binary program is a dangerous memory operation function and function type, it is successfully matched with the dangerous function model, the type of the target calling function is determined, and the program is instrumented. The callback function and the analysis function executed after the instrumentation are set according to the function type.

[0050] Specifically, in the heap memory vulnerability detection method provided in the embodiment of the present application, the type of the target calling function is at least one of the following: the type of heap allocation function, the type of heap release function, the type of heap memory reading function, and the type of heap memory writing function.

[0051] Step S104, executing a heap memory vulnerability detection strategy corresponding to the target calling function according to the type of the target calling function.

[0052] For example, this application uses Func=[F1, F2, F3, ..., Fn], F(fname, ftype, fpara, foffset, flibc) to describe the dangerous function model, Fi represents the function, and the five parameters fname, ftype, fpara, foffset, and flibc jointly describe the function characteristics. Among them: fname represents the function name; ftype=[alloca, free, read, write] represents the function type, alloca represents the heap allocation function type (including malloc() / calloc() / realloc() function), free represents the heap release function type, read represents the memory read operation function type, and write represents the memory write operation function type; fpara=[p1, p2, p3, ..., pn] represents the function parameter set; flibc represents the link library to which the function belongs; foffset represents the function offset. The dangerous function model created by this application is easy to maintain and has universality for software using glibc. .

[0053] Optionally, in the heap memory vulnerability detection method provided in the embodiment of the present application, before executing the heap memory vulnerability detection strategy corresponding to the target calling function according to the type of the target calling function, the method also includes: if the type of the target calling function is the type of the heap allocation function, obtaining the function parameters of the heap allocation function through the target interface of the program; and calculating the heap memory space allocated by the target calling function according to the function parameters.

[0054] Specifically, the function name of the target calling function is matched with the dangerous function model. When the type of the target calling function is the type of the heap allocation function, before the target binary program calls the target calling function, an analysis routine (corresponding to the target interface in this application) is inserted into the program to obtain the function parameters, and the actual allocated heap memory size is calculated based on the function parameters (the heap memory allocated by the application).

[0055] Optionally, in the heap memory vulnerability detection method provided in the embodiment of the present application, according to the type of the target calling function, executing the heap memory vulnerability detection strategy corresponding to the target calling function includes: if the type of the target calling function is the type of the heap allocation function, obtaining the execution result of the heap allocation function according to the target interface of the program, wherein the execution result includes the content of the heap block metadata; judging whether the heap memory space of the target calling function is allocated successfully through the execution result, if the heap memory space of the target calling function is allocated successfully, judging the number of applications for the heap memory space; if the number of applications for the heap memory space is a first preset value, determining the heap memory usage log through the function parameters of the heap allocation function and the program execution result of the heap allocation function; if the number of applications for the heap memory space is greater than the first preset value, judging whether the heap memory space address is an idle heap memory address, if the heap memory space address is an idle heap memory address, judging whether the heap allocation function is the target function, and if the heap allocation function is the target function, updating the heap memory usage log.

[0056] Specifically, Figure 2 is a heap allocation operation detection flow chart of the heap memory vulnerability detection method provided in the embodiment of the present application, such as Figure 2As shown, before the heap allocation function is called, an analysis routine is inserted to obtain function parameters, and the actual allocated heap memory size is calculated based on the function parameters (the heap memory applied for allocation). After the heap allocation function is called, an analysis routine is inserted to obtain the return value, and the content of the heap block metadata (for example, the values ​​of the prev_size and size fields) is obtained based on the return value. It is determined whether the heap memory is successfully allocated based on the parsed function return value. If the allocation fails, an abnormal alarm is triggered and the program execution is terminated; if the heap memory is allocated successfully, it is determined whether it is the first time (corresponding to the first preset value in this application) to apply for heap memory. If it is the first time to apply for heap memory, a memory usage log is established based on the parameters and return value of the calling function; the memory usage log records the state of the heap block when the program is running. The heap block at run time is described by the starting address of the heap memory, the actual allocated heap memory size, the heap memory allocation state (allocated / released), the heap memory initialization state (initialized / uninitialized / unallocated), and the memory allocation state of the previous heap block (allocated / unallocated). The memory allocation state of the previous heap block is represented by the lowest bit of the size field in the chunk structure of the current allocated heap block; if it is not the first time to apply for heap memory, determine whether the allocated heap memory space is free and unallocated heap memory space based on the memory usage log. If it is not free and unallocated heap memory space, trigger an abnormal alarm to terminate program execution. If it is free heap memory space, update the memory usage log; and determine whether the heap allocation function is the calloc() function (corresponding to the target function in this application). If the current heap allocation function is the calloc() function, it will automatically initialize the heap memory space to zero after dynamically allocating memory. At this time, the initialization state of the corresponding record of the memory usage log is updated to be initialized. This application dynamically inserts heap memory allocation during software operation, achieving the effect of being able to effectively detect various illegal heap memory operations such as heap block metadata destruction, uninitialized heap memory access, and memory leaks without relying on complex semantic instruction set modeling. It can effectively protect the security of the software, avoid information leakage and execution of program control flow, and further improve the efficiency of heap memory vulnerability detection.

[0057] Optionally, in the heap memory vulnerability detection method provided in the embodiment of the present application, according to the type of the target calling function, executing the heap memory vulnerability detection strategy corresponding to the target calling function includes: if the type of the target calling function is the type of the heap release function, obtaining the function parameters of the heap release function through the target interface of the program; obtaining the heap memory address to be released according to the function parameters of the heap release function, and judging whether the heap memory address to be released has a matching record with the first address of the heap block already allocated in the heap memory usage log; if the heap memory address to be released has a matching record with the first address of the heap block already allocated in the heap memory usage log, releasing the heap memory address to be released, and updating the heap memory usage log.

[0058] Specifically, Figure 3 is a heap release operation detection flow chart of the heap memory vulnerability detection method provided in the embodiment of the present application, such as Figure 3 As shown, an analysis routine (corresponding to the target interface of the program in this application, the same below) is inserted before the heap release function is called, and the parameters of the heap release free() function are obtained to obtain the heap memory address to be released. It is determined whether the heap memory address to be released is the first address of the allocated heap block, that is, whether the released heap memory address has a matching record with the first address of the allocated heap block in the memory usage log. If there is a matching record, the heap block is released, the memory usage log is updated, and the initialization state of the corresponding record of the memory usage log is modified to be uninitialized; if there is no matching record, it means that the heap memory space is repeatedly released or the wrong memory address is released, triggering an abnormal alarm operation and terminating the program execution. This application dynamically inserts the heap memory release during the software operation process, and achieves the effect of being able to effectively detect various illegal heap memory operations such as heap block metadata destruction, uninitialized heap memory access, and memory leaks without relying on complex semantic instruction set modeling. It can effectively protect the security of the software, avoid information leakage and the execution of program control flow, and further improve the efficiency of heap memory vulnerability detection.

[0059] Optionally, in the heap memory vulnerability detection method provided in the embodiment of the present application, according to the type of the target calling function, executing the heap memory vulnerability detection strategy corresponding to the target calling function includes: if the type of the target calling function is the type of the heap memory read function, obtaining the function parameters of the heap memory read function and the program execution result of the heap memory read function through the target interface of the program; determining the target information of the heap memory read function according to the function parameters of the heap memory read function and the program execution result of the heap memory read function, wherein the target information includes at least: the address of the read memory and the length of the read content; judging whether the target binary program has a situation of reading heap memory data through the target information, and if the target information has a situation of reading heap memory data, judging whether the address of the read memory is a released heap memory address according to the heap memory allocation status in the memory usage log of the heap allocation function; if the address of the read memory is a released heap memory address, triggering an abnormal alarm and terminating the target binary program process.

[0060] Specifically, Figure 4 is a memory read operation detection flow chart of the heap memory vulnerability detection method provided in the embodiment of the present application, such as Figure 4As shown, an analysis routine is inserted before the memory read operation function call to obtain the parameters of the program calling function, and an analysis routine is inserted after the memory read operation function call to obtain the function return value (corresponding to the program execution result in this application), and the address of the read memory and the length of the read content are analyzed according to the dangerous function model; it is determined whether there is a heap memory read, that is, whether the address of the read memory is a heap memory address according to the heap memory start address and length in the memory usage log. If so, it is determined whether the read memory address is a released heap memory address according to the heap memory allocation status in the memory usage log. If so, there is a situation where memory is used after being released, triggering an abnormal alarm and terminating program execution; if not, it means that there is an allocated heap memory read, and according to the initialization status of the memory usage log, it is determined whether there is an uninitialized heap memory read behavior. If it exists, it means that an abnormal operation behavior of uninitialized heap memory access is detected, triggering an abnormal alarm and terminating program execution. This application dynamically inserts heap memory reading during software operation, and achieves the effect of effectively detecting various illegal heap memory operations such as heap block metadata destruction, uninitialized heap memory access, memory leakage, etc. without relying on complex semantic instruction set modeling. It can effectively protect the security of the software, avoid information leakage and execution of program control flow, and further improve the efficiency of heap memory vulnerability detection.

[0061] Optionally, in the heap memory vulnerability detection method provided in the embodiment of the present application, according to the type of the target calling function, executing the heap memory vulnerability detection strategy corresponding to the target calling function includes: if the type of the target calling function is the type of the heap memory write function, obtaining the function parameters of the heap memory write function and the program execution result of the heap memory write function through the target interface of the program; determining the target information of the heap memory write function according to the function parameters of the heap memory write function and the program execution result of the heap memory write function, wherein the target information at least includes: the address of the write memory and the length of the write content; judging whether the heap memory write function is a heap memory initialization function according to the address of the write memory, if the heap memory write function is a heap memory initialization function, updating the heap memory usage log, if the heap memory write function is not a heap memory initialization function, judging whether the target binary program has a heap memory write situation according to the address of the write memory and the heap memory usage log; when the target binary program has read heap memory data, judging whether the address of the write memory is in a released state or judging whether the heap memory of the address of the write memory is not allocated; if the address of the write memory is in a released state or the heap memory of the address of the write memory is not allocated, triggering an abnormal alarm and terminating the target binary program process.

[0062] Specifically, Figure 5 is a memory write operation detection flow chart of the heap memory vulnerability detection method provided in the embodiment of the present application, such as Figure 5As shown, analysis routines are inserted before and after the memory write operation function call to obtain the parameters of the program call function and the function return value. At the same time, based on the dangerous function model, the address of the memory write and the length of the successfully written data are analyzed; it is determined whether it is a memory initialization function such as memset. If it is a memory initialization function and the initialization heap memory operation is executed successfully, the initialization status of the corresponding heap memory in the memory usage log is updated to initialized; if it is not a memory initialization function, it is determined whether there is a heap memory write based on the address of the memory write in the memory usage log. If it exists, determine whether the write memory address is a released or unallocated heap memory based on the address of the write memory and the heap memory allocation status of the memory usage log; if it does, it means that there is a memory write operation of a released heap block or an unallocated heap block, triggering an exception alarm and terminating program execution; if not, there is a memory write operation of an allocated heap block, and determine whether there is heap block metadata tampering. The specific detection steps are: if there is a memory write operation of an allocated heap block, obtain the corresponding record of the heap block based on the memory usage log and the write memory address, including the start address of the heap memory and the actual allocated heap memory size; calculate the actual data area size of the heap block based on the actual allocated heap memory size, and determine whether the actual written data length is greater than the actual data area size of the heap block; if it is greater, it means that the memory write operation overwrites the metadata of the next physically adjacent heap block; if the written data overwrites the physically adjacent If the actual written data length is more than eight bytes longer than the size of the heap memory data area, it means that the written data covers the size field of the next heap block, and the heap block metadata is damaged, triggering an exception alarm and terminating the program execution. The present application dynamically inserts heap memory writes during software operation, and achieves the effect of effectively detecting various illegal heap memory operations such as heap block metadata damage, uninitialized heap memory access, and memory leaks without relying on complex semantic instruction set modeling. It can effectively protect the security of the software, avoid information leakage and execution of program control flow, and further improve the efficiency of heap memory vulnerability detection.

[0063] Optionally, in the heap memory vulnerability detection method provided in the embodiment of the present application, after executing the heap memory vulnerability detection strategy corresponding to the target calling function according to the type of the target calling function, the method also includes: traversing the heap memory allocation status records in the heap memory usage log to obtain the traversal results; and monitoring the target binary program based on the traversal results.

[0064] Specifically, before the program exits normally, the heap memory allocation status records in the memory usage log are traversed to detect whether there is still allocated heap memory that has not been released. If so, it means that there is a memory leak in the program, triggering an exception alarm and terminating the execution process of the target binary program. The present application uses binary dynamic instrumentation technology to monitor the functions called by the program in real time during runtime to detect heap memory vulnerability exploits such as heap block metadata destruction, uninitialized heap memory access, and memory leaks. This achieves the effect of not requiring static analysis of the program, not relying on source code, not requiring recompilation and linking of the program, and no intrusion into the binary program, thereby improving the efficiency of heap memory vulnerability detection.

[0065] Figure 6 is a schematic diagram of the system architecture of the heap memory vulnerability detection method provided in the embodiment of the present application, such as Figure 6 As shown, it mainly includes dangerous function model, function instrumentation module, heap memory vulnerability exploitation attack detection module, memory usage log, process alarm module, and response module. The dangerous function model is mainly used to help the detection module determine the memory operation type of the function called when the program is running and analyze the parameters of the calling function. The function instrumentation module mainly performs function-level instrumentation on the loaded target binary program, and determines the location to be instrumented and the analysis strategy to be executed in combination with the dangerous function model; the heap memory vulnerability exploitation attack detection module mainly detects illegal heap memory access operations based on the detection strategy and the maintained memory usage log. The detection module also includes heap allocation detection strategy, heap release detection strategy, heap memory read detection strategy, and heap memory write detection strategy; the response module is used to execute operations such as process termination and obfuscation of heap memory data after the process triggers an abnormal alarm.

[0066] In summary, the heap memory vulnerability detection method provided by the embodiment of the present application obtains the target call function in the target binary program through the binary plug-in module, wherein the target call function at least includes the function name of the target call function; matches the function name of the target call function with the risk function model to obtain a matching result, wherein the risk function model includes the function names of multiple functions, whether each function belongs to a risky memory operation function, and the type corresponding to each function name; if the matching result indicates that the target call function belongs to a risky memory operation function, the type of the target call function is determined; according to the type of the target call function, the heap memory vulnerability detection strategy corresponding to the target call function is executed, thereby solving the problem of low detection efficiency of heap memory corruption vulnerabilities in related technologies. The target call function in the target binary program is obtained through the binary plug-in module, the function name of the target call function is matched with the risk function model, the type of the target call function is determined based on the matching result, and according to the type of the target call function, the heap memory vulnerability detection strategy corresponding to the target call function is executed, thereby achieving the effect of improving the detection efficiency of heap memory corruption vulnerabilities.

[0067] It should be noted that the steps shown in the flowcharts of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and that, although a logical order is shown in the flowcharts, in some cases, the steps shown or described can be executed in an order different from that shown here.

[0068] The embodiment of the present application also provides a heap memory vulnerability detection device. It should be noted that the heap memory vulnerability detection device of the embodiment of the present application can be used to execute the heap memory vulnerability detection method provided by the embodiment of the present application. The heap memory vulnerability detection device provided by the embodiment of the present application is introduced below.

[0069] Figure 7 Schematic diagram of a heap memory vulnerability detection device according to an embodiment of the present application. Figure 7 As shown, the device includes: a first acquisition unit 701, a first matching unit 702, a first determination unit 703, and a first execution unit 704.

[0070] Specifically, the first acquisition unit 701 is used to acquire a target calling function in a target binary program through a binary instrumentation module, wherein the target calling function at least includes a function name of the target calling function;

[0071] The first matching unit 702 is used to match the function name of the target calling function with the risk function model to obtain a matching result, wherein the risk function model includes the function names of multiple functions, whether each function belongs to a risky memory operation function, and the type corresponding to each function name;

[0072] A first determining unit 703 is configured to determine the type of the target calling function if the matching result indicates that the target calling function belongs to a risky memory operation function;

[0073] The first execution unit 704 is used to execute the heap memory vulnerability detection strategy corresponding to the target calling function according to the type of the target calling function.

[0074] In summary, the heap memory vulnerability detection device provided by the embodiment of the present application obtains the target call function in the target binary program through the binary plug module through the first acquisition unit 701, wherein the target call function at least includes the function name of the target call function; the first matching unit 702 matches the function name of the target call function with the risk function model to obtain a matching result, wherein the risk function model includes the function names of multiple functions, whether each function belongs to a risky memory operation function, and the type corresponding to each function name; the first determination unit 703 determines the type of the target call function if the matching result indicates that the target call function belongs to a risky memory operation function; the first execution unit 704 executes the heap memory vulnerability detection strategy corresponding to the target call function according to the type of the target call function, thereby solving the problem of low detection efficiency of heap memory corruption vulnerabilities in the related art. The target call function in the target binary program is obtained through the binary plug module, the function name of the target call function is matched with the risk function model, the type of the target call function is determined based on the matching result, and the heap memory vulnerability detection strategy corresponding to the target call function is executed according to the type of the target call function, thereby achieving the effect of improving the detection efficiency of the heap memory corruption vulnerability.

[0075] Optionally, in the heap memory vulnerability detection device provided in an embodiment of the present application, the type of the target calling function is at least one of the following: the type of heap allocation function, the type of heap release function, the type of heap memory reading function, and the type of heap memory writing function.

[0076] Optionally, in the heap memory vulnerability detection device provided in the embodiment of the present application, the device also includes: a second acquisition unit, used to obtain function parameters of the heap allocation function through the target interface of the program before executing the heap memory vulnerability detection strategy corresponding to the target calling function according to the type of the target calling function, if the type of the target calling function is the type of the heap allocation function; and a first calculation unit, used to calculate the heap memory space allocated by the target calling function according to the function parameters.

[0077] Optionally, in the heap memory vulnerability detection device provided in the embodiment of the present application, the first execution unit includes: a first acquisition module, which is used to obtain the execution result of the heap allocation function according to the target interface of the program if the type of the target calling function is the type of the heap allocation function, wherein the execution result includes the content of the heap block metadata; a first judgment module, which is used to judge whether the heap memory space of the target calling function is allocated successfully through the execution result, and if the heap memory space of the target calling function is allocated successfully, judge the number of applications for the heap memory space; a first determination module, which is used to determine the heap memory usage log through the function parameters of the heap allocation function and the program execution result of the heap allocation function if the number of applications for the heap memory space is a first preset value; a first update module, which is used to judge whether the heap memory space address is a free heap memory address if the number of applications for the heap memory space is greater than the first preset value, and if the heap memory space address is a free heap memory address, judge whether the heap allocation function is the target function, and if the heap allocation function is the target function, update the heap memory usage log.

[0078] Optionally, in the heap memory vulnerability detection device provided in the embodiment of the present application, the first execution unit 704 includes: a second acquisition module, which is used to obtain the function parameters of the heap release function through the target interface of the program if the type of the target calling function is the type of the heap release function; a second judgment module, which is used to obtain the heap memory address to be released according to the function parameters of the heap release function, and judge whether the heap memory address to be released has a matching record with the first address of the heap block already allocated in the heap memory usage log; a second update module, which is used to release the heap memory address to be released and update the heap memory usage log if there is a matching record between the heap memory address to be released and the first address of the heap block already allocated in the heap memory usage log.

[0079] Optionally, in the heap memory vulnerability detection device provided in the embodiment of the present application, the first execution unit 704 includes: a third acquisition module, which is used to obtain the function parameters of the heap memory read function and the program execution result of the heap memory read function through the target interface of the program if the type of the target calling function is the type of the heap memory read function; a second determination module, which is used to determine the target information of the heap memory read function according to the function parameters of the heap memory read function and the program execution result of the heap memory read function, wherein the target information at least includes: the address of the read memory and the length of the read content; a third judgment module, which is used to judge whether the target binary program has a situation of reading heap memory data through the target information, and if the target information has a situation of reading heap memory data, judge whether the address of the read memory is a released heap memory address according to the heap memory allocation status in the memory usage log of the heap allocation function; a first trigger module, which is used to trigger an abnormal alarm and terminate the target binary program process if the address of the read memory is a released heap memory address.

[0080] Optionally, in the heap memory vulnerability detection device provided in the embodiment of the present application, the first execution unit 704 includes: a fourth acquisition module, which is used to obtain the function parameters of the heap memory write function and the program execution result of the heap memory write function through the target interface of the program if the type of the target calling function is the type of the heap memory write function; a third determination module, which is used to determine the target information of the heap memory write function according to the function parameters of the heap memory write function and the program execution result of the heap memory write function, wherein the target information includes at least: the address of the write memory and the length of the write content; a fourth judgment module, which is used to judge whether the heap memory write function is a heap memory write function according to the address of the write memory A memory initialization function, if the heap memory write function is a heap memory initialization function, updates the heap memory usage log; if the heap memory write function is not a heap memory initialization function, determines whether the target binary program has heap memory writes based on the write memory address and the heap memory usage log; a fifth judgment module, used to determine whether the write memory address is in a released state or whether the heap memory of the write memory address is not allocated when the target binary program has read heap memory data; a second trigger module, used to trigger an abnormal alarm and terminate the target binary program process if the write memory address is in a released state or the heap memory of the write memory address is not allocated.

[0081] Optionally, in the heap memory vulnerability detection device provided in the embodiment of the present application, the device also includes: a first traversal unit, which is used to traverse the heap memory allocation status records in the heap memory usage log after executing the heap memory vulnerability detection strategy corresponding to the target calling function according to the type of the target calling function to obtain a traversal result; and a first monitoring unit, which is used to monitor the target binary program based on the traversal result.

[0082] The heap memory vulnerability detection device includes a processor and a memory. The above-mentioned first acquisition unit 701, first matching unit 702, first determination unit 703, first execution unit 704, etc. are all stored in the memory as program units, and the processor executes the above-mentioned program units stored in the memory to implement corresponding functions.

[0083] The processor includes a kernel, which calls the corresponding program unit from the memory. The kernel can be set to one or more, and the heap memory vulnerability detection can be performed by adjusting the kernel parameters.

[0084] The memory may include non-permanent memory in a computer-readable medium, random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM, and the memory includes at least one memory chip.

[0085] An embodiment of the present invention provides a computer-readable storage medium on which a program is stored. When the program is executed by a processor, a heap memory vulnerability detection method is implemented.

[0086] An embodiment of the present invention provides a processor, which is used to run a program, wherein a heap memory vulnerability detection method is executed when the program is running.

[0087] An embodiment of the present invention provides an electronic device, the device includes a processor, a memory, and a program stored in the memory and executable on the processor, and the processor implements the following steps when executing the program: obtaining a target calling function in a target binary program through a binary plug-in module, wherein the target calling function at least includes a function name of the target calling function; matching the function name of the target calling function with a risk function model to obtain a matching result, wherein the risk function model includes function names of multiple functions, whether each function belongs to a risky memory operation function, and a type corresponding to each function name; if the matching result indicates that the target calling function belongs to a risky memory operation function, determining the type of the target calling function; and executing a heap memory vulnerability detection strategy corresponding to the target calling function according to the type of the target calling function.

[0088] When executing the program, the processor also implements the following steps: the type of the target calling function is at least one of the following: the type of the heap allocation function, the type of the heap release function, the type of the heap memory reading function, and the type of the heap memory writing function.

[0089] When the processor executes the program, the following steps are also implemented: before executing the heap memory vulnerability detection strategy corresponding to the target calling function according to the type of the target calling function, if the type of the target calling function is the type of the heap allocation function, the function parameters of the heap allocation function are obtained through the target interface of the program; the heap memory space allocated by the target calling function is calculated according to the function parameters.

[0090] When the processor executes the program, the following steps are also implemented: if the type of the target calling function is the type of the heap allocation function, the execution result of the heap allocation function is obtained according to the target interface of the program, wherein the execution result includes the content of the heap block metadata; whether the heap memory space of the target calling function is successfully allocated is judged through the execution result, and if the heap memory space of the target calling function is successfully allocated, the number of applications for the heap memory space is judged; if the number of applications for the heap memory space is a first preset value, the heap memory usage log is determined through the function parameters of the heap allocation function and the program execution result of the heap allocation function; if the number of applications for the heap memory space is greater than the first preset value, whether the heap memory space address is an idle heap memory address is judged, if the heap memory space address is an idle heap memory address, whether the heap allocation function is the target function is judged, and if the heap allocation function is the target function, the heap memory usage log is updated.

[0091] When the processor executes the program, the following steps are also implemented: if the type of the target calling function is the type of the heap release function, the function parameters of the heap release function are obtained through the target interface of the program; the heap memory address to be released is obtained according to the function parameters of the heap release function, and it is determined whether the heap memory address to be released has a matching record with the first address of the heap block already allocated in the heap memory usage log; if the heap memory address to be released has a matching record with the first address of the heap block already allocated in the heap memory usage log, the heap memory address to be released is released, and the heap memory usage log is updated.

[0092] When the processor executes the program, the following steps are also implemented: if the type of the target calling function is the type of the heap memory reading function, the function parameters of the heap memory reading function and the program execution result of the heap memory reading function are obtained through the target interface of the program; the target information of the heap memory reading function is determined according to the function parameters of the heap memory reading function and the program execution result of the heap memory reading function, wherein the target information at least includes: the address of the read memory and the length of the read content; it is judged through the target information whether the target binary program has a situation of reading heap memory data, and if the target information has a situation of reading heap memory data, it is judged whether the address of the read memory is a released heap memory address according to the heap memory allocation status in the memory usage log of the heap allocation function; if the address of the read memory is a released heap memory address, an abnormal alarm is triggered and the target binary program process is terminated.

[0093] When the processor executes the program, the following steps are also implemented: if the type of the target calling function is the type of the heap memory write function, the function parameters of the heap memory write function and the program execution result of the heap memory write function are obtained through the target interface of the program; the target information of the heap memory write function is determined according to the function parameters of the heap memory write function and the program execution result of the heap memory write function, wherein the target information at least includes: the address of the write memory and the length of the write content; according to the address of the write memory, whether the heap memory write function is a heap memory initialization function is judged; if the heap memory write function is a heap memory initialization function, the heap memory usage log is updated; if the heap memory write function is not a heap memory initialization function, whether the target binary program has a heap memory write situation according to the address of the write memory and the heap memory usage log; in the case that the target binary program has read heap memory data, whether the address of the write memory is in a released state or whether the heap memory of the address of the write memory is not allocated; if the address of the write memory is in a released state or the heap memory of the address of the write memory is not allocated, an abnormal alarm is triggered and the target binary program process is terminated.

[0094] When the processor executes the program, the following steps are also implemented: after executing the heap memory vulnerability detection strategy corresponding to the target calling function according to the type of the target calling function, the heap memory allocation status records in the heap memory usage log are traversed to obtain the traversal results; and the target binary program is monitored based on the traversal results.

[0095] The devices in this article can be servers, PCs, PADs, mobile phones, etc.

[0096] The present application also provides a computer program product, which, when executed on a data processing device, is suitable for executing an initialized program having the following method steps: obtaining a target calling function in a target binary program through a binary plug-in module, wherein the target calling function at least includes a function name of the target calling function; matching the function name of the target calling function with a risk function model to obtain a matching result, wherein the risk function model includes function names of multiple functions, whether each function belongs to a risky memory operation function, and the type corresponding to each function name; if the matching result indicates that the target calling function belongs to a risky memory operation function, determining the type of the target calling function; and executing a heap memory vulnerability detection strategy corresponding to the target calling function according to the type of the target calling function.

[0097] When executed on a data processing device, it is also suitable for executing an initialization program having the following method steps: the type of the target calling function is at least one of the following: the type of the heap allocation function, the type of the heap release function, the type of the heap memory reading function, and the type of the heap memory writing function.

[0098] When executed on a data processing device, it is also suitable for executing an initialization program having the following method steps: before executing the heap memory vulnerability detection strategy corresponding to the target calling function according to the type of the target calling function, if the type of the target calling function is the type of the heap allocation function, obtaining the function parameters of the heap allocation function through the target interface of the program; and calculating the heap memory space allocated by the target calling function according to the function parameters.

[0099] When executed on a data processing device, it is also suitable for executing an initialized program having the following method steps: if the type of the target calling function is the type of the heap allocation function, obtaining the execution result of the heap allocation function according to the target interface of the program, wherein the execution result includes the content of the heap block metadata; judging whether the heap memory space of the target calling function is successfully allocated through the execution result, and if the heap memory space of the target calling function is successfully allocated, judging the number of applications for the heap memory space; if the number of applications for the heap memory space is a first preset value, determining the heap memory usage log through the function parameters of the heap allocation function and the program execution result of the heap allocation function; if the number of applications for the heap memory space is greater than the first preset value, judging whether the heap memory space address is an idle heap memory address, and if the heap memory space address is an idle heap memory address, judging whether the heap allocation function is the target function, and if the heap allocation function is the target function, updating the heap memory usage log.

[0100] When executed on a data processing device, it is also suitable for executing an initialized program having the following method steps: if the type of the target calling function is the type of the heap release function, obtaining the function parameters of the heap release function through the target interface of the program; obtaining the heap memory address to be released according to the function parameters of the heap release function, and judging whether the heap memory address to be released has a matching record with the first address of the heap block already allocated in the heap memory usage log; if the heap memory address to be released has a matching record with the first address of the heap block already allocated in the heap memory usage log, releasing the heap memory address to be released, and updating the heap memory usage log.

[0101] When executed on a data processing device, it is also suitable for executing an initialized program having the following method steps: if the type of the target calling function is the type of the heap memory reading function, obtaining the function parameters of the heap memory reading function and the program execution result of the heap memory reading function through the target interface of the program; determining the target information of the heap memory reading function according to the function parameters of the heap memory reading function and the program execution result of the heap memory reading function, wherein the target information at least includes: the address of the read memory and the length of the read content; judging whether the target binary program has a situation of reading heap memory data through the target information, and if the target information has a situation of reading heap memory data, judging whether the address of the read memory is a released heap memory address according to the heap memory allocation status in the memory usage log of the heap allocation function; if the address of the read memory is a released heap memory address, triggering an abnormal alarm and terminating the target binary program process.

[0102] When executed on a data processing device, it is also suitable for executing an initialized program having the following method steps: if the type of the target calling function is the type of the heap memory write function, obtaining the function parameters of the heap memory write function and the program execution result of the heap memory write function through the target interface of the program; determining the target information of the heap memory write function according to the function parameters of the heap memory write function and the program execution result of the heap memory write function, wherein the target information at least includes: the address of the write memory and the length of the write content; judging whether the heap memory write function is a heap memory initialization function according to the address of the write memory, if the heap memory write function is a heap memory initialization function, updating the heap memory usage log, if the heap memory write function is not a heap memory initialization function, judging whether the target binary program has a heap memory write situation according to the address of the write memory and the heap memory usage log; in the case that the target binary program has read heap memory data, judging whether the address of the write memory is in a released state or judging whether the heap memory of the address of the write memory is not allocated; if the address of the write memory is in a released state or the heap memory of the address of the write memory is not allocated, triggering an abnormal alarm and terminating the target binary program process.

[0103] When executed on a data processing device, it is also suitable for executing an initialized program having the following method steps: after executing the heap memory vulnerability detection strategy corresponding to the target calling function according to the type of the target calling function, traversing the heap memory allocation status records in the heap memory usage log to obtain the traversal results; and monitoring the target binary program based on the traversal results.

[0104] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application may adopt the form of a computer program product implemented in one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that include computer-usable program code.

[0105] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1A device that provides the functions specified in a block or multiple blocks.

[0106] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.

[0107] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.

[0108] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.

[0109] The memory may include non-permanent memory in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. The memory is an example of a computer-readable medium.

[0110] Computer readable media include permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. Information can be computer readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic tape magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer readable media does not include temporary computer readable media (transitory media), such as modulated data signals and carrier waves.

[0111] It should also be noted that the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, commodity or device. In the absence of more restrictions, the elements defined by the sentence "comprises a ..." do not exclude the existence of other identical elements in the process, method, commodity or device including the elements.

[0112] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems or computer program products. Therefore, the present application may adopt the form of a complete hardware embodiment, a complete software embodiment or an embodiment in combination with software and hardware. Moreover, the present application may adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.

[0113] The above are only embodiments of the present application and are not intended to limit the present application. For those skilled in the art, the present application may have various changes and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application should be included within the scope of the claims of the present application.

Claims

1. A heap memory vulnerability detection method, characterized in that: include: Obtaining a target calling function in a target binary program through a binary stub module, wherein the target calling function at least includes a function name of the target calling function; the type of the target calling function is at least one of the following: a type of a heap allocation function, a type of a heap release function, a type of a heap memory read function, and a type of a heap memory write function; Matching the function name of the target calling function with the risk function model to obtain a matching result, wherein the risk function model includes the function names of multiple functions, whether each function belongs to a risky memory operation function, and the type corresponding to each function name; If the matching result indicates that the target calling function belongs to a risky memory operation function, determining the type of the target calling function; According to the type of the target calling function, executing the heap memory vulnerability detection strategy corresponding to the target calling function; Before executing the heap memory vulnerability detection strategy corresponding to the target calling function according to the type of the target calling function, the method further includes: If the type of the target calling function is the type of the heap allocation function, obtaining an execution result of the heap allocation function according to the target interface of the program, wherein the execution result includes the content of the heap block metadata; Determine whether the heap memory space of the target calling function is successfully allocated according to the execution result, and if the heap memory space of the target calling function is successfully allocated, determine the number of applications for the heap memory space; If the number of applications for the heap memory space is a first preset value, determining a heap memory usage log according to a function parameter of the heap allocation function and a program execution result of the heap allocation function; If the number of applications for the heap memory space is greater than a first preset value, determine whether the heap memory space address is an idle heap memory address; if the heap memory space address is an idle heap memory address, determine whether the heap allocation function is a target function; if the heap allocation function is the target function, update the heap memory usage log.

2. The method according to claim 1, characterized in that: Before executing the heap memory vulnerability detection strategy corresponding to the target calling function according to the type of the target calling function, the method further includes: If the type of the target calling function is the type of the heap allocation function, obtaining function parameters of the heap allocation function through the target interface of the program; The heap memory space allocated to the target calling function is calculated according to the function parameters.

3. The method according to claim 1, characterized in that According to the type of the target calling function, executing the heap memory vulnerability detection strategy corresponding to the target calling function includes: If the type of the target calling function is the type of the heap release function, obtaining function parameters of the heap release function through the target interface of the program; Obtaining a heap memory address to be released according to a function parameter of the heap release function, and determining whether a matching record exists between the heap memory address to be released and the first address of a heap block that has been allocated in the heap memory usage log; If there is a matching record between the heap memory address to be released and the first address of the heap block that has been allocated in the heap memory usage log, the heap memory address to be released is released, and the heap memory usage log is updated.

4. The method according to claim 1, characterized in that According to the type of the target calling function, executing the heap memory vulnerability detection strategy corresponding to the target calling function includes: If the type of the target calling function is the type of the heap memory reading function, obtaining function parameters of the heap memory reading function and a program execution result of the heap memory reading function through the target interface of the program; Determine target information of the heap memory reading function according to function parameters of the heap memory reading function and a program execution result of the heap memory reading function, wherein the target information at least includes: an address of a read memory and a length of a read content; Determine whether the target binary program has a situation of reading heap memory data by using the target information, and if the target information has a situation of reading heap memory data, determine whether the address of the read memory is a released heap memory address according to the heap memory allocation state in the memory usage log of the heap allocation function; If the address of the read memory is a released heap memory address, an abnormality alarm is triggered and the target binary program process is terminated.

5. The method according to claim 4, characterized in that According to the type of the target calling function, executing the heap memory vulnerability detection strategy corresponding to the target calling function includes: If the type of the target calling function is the type of the heap memory writing function, obtaining function parameters of the heap memory writing function and a program execution result of the heap memory writing function through the target interface of the program; Determining target information of the heap memory write function according to function parameters of the heap memory write function and a program execution result of the heap memory write function, wherein the target information at least includes: an address of a write memory and a length of a write content; Determine whether the heap memory write function is a heap memory initialization function according to the address of the write memory; if the heap memory write function is a heap memory initialization function, update the heap memory usage log; if the heap memory write function is not a heap memory initialization function, determine whether the target binary program has a heap memory write situation according to the address of the write memory and the heap memory usage log; In the case where the target binary program has read heap memory data, determining whether the address of the write memory is in a released state or determining whether the heap memory of the address of the write memory is not allocated; If the address of the write memory is in a released state or the heap memory of the address of the write memory is not allocated, an abnormal alarm is triggered and the target binary program process is terminated.

6. The method according to claim 1, characterized in that After executing the heap memory vulnerability detection strategy corresponding to the target calling function according to the type of the target calling function, the method further includes: Traversing the heap memory allocation state records in the heap memory usage log to obtain a traversal result; The target binary program is monitored based on the traversal result.

7. A heap memory vulnerability detection device, characterized in that: include: A first acquisition unit is used to acquire a target calling function in a target binary program through a binary plugging module, wherein the target calling function at least includes a function name of the target calling function; the type of the target calling function is at least one of the following: a type of a heap allocation function, a type of a heap release function, a type of a heap memory read function, and a type of a heap memory write function; a first matching unit, configured to match the function name of the target calling function with a risk function model to obtain a matching result, wherein the risk function model includes function names of multiple functions, whether each function belongs to a risky memory operation function, and a type corresponding to each function name; A first determining unit, configured to determine a type of the target calling function if the matching result indicates that the target calling function belongs to a risky memory operation function; A first execution unit, configured to execute a heap memory vulnerability detection strategy corresponding to the target calling function according to the type of the target calling function; Among them, the first execution unit includes: a first acquisition module, which is used to obtain the execution result of the heap allocation function according to the target interface of the program if the type of the target calling function is the type of the heap allocation function, wherein the execution result includes the content of the heap block metadata; a first judgment module, which is used to judge whether the heap memory space of the target calling function is successfully allocated through the execution result, and if the heap memory space of the target calling function is successfully allocated, judge the number of applications for the heap memory space; a first determination module, which is used to determine the heap memory usage log through the function parameters of the heap allocation function and the program execution result of the heap allocation function if the number of applications for the heap memory space is a first preset value; a first update module, which is used to judge whether the heap memory space address is an idle heap memory address if the number of applications for the heap memory space is greater than the first preset value, and if the heap memory space address is an idle heap memory address, judge whether the heap allocation function is the target function, and if the heap allocation function is the target function, update the heap memory usage log.

8. A computer-readable storage medium, characterized in that: The storage medium includes a stored program, wherein the program executes the method according to any one of claims 1 to 6.

9. An electronic device, characterized in that: The method comprises one or more processors and a memory, wherein the memory is used to store one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors implement the method described in any one of claims 1 to 6.

Citation Information

Patent Citations

  • Detection method and device for heap memory attack and electronic equipment

    CN111859372A