A counter-example guided sparse spatial flow model detection method and system
Through the sparse spatial flow model detection method guided by counterexample, the symbol level and address space level of C language programs are analyzed, which solves the problem of difficult to balance detection accuracy and efficiency in the existing technology, and realizes the security formal verification of the software.
Patent Information
- Application Number
- CN202111316310.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-11-08
- Publication Date
- 2025-06-06
- Estimated Expiration
- 2041-11-08
AI Technical Summary
The prior art is difficult to effectively analyze programming language programs with complex semantic characteristics at the symbol level and address space level, resulting in difficult to balance detection accuracy and efficiency, and the security formal verification of software cannot be guaranteed.
The sparse spatial flow model detection method is adopted with a counterexample-guided sparse spatial flow model. By compiling the C language program into LLVM intermediate code and converting it into a sparse spatial flow model, variable abstraction and explicit value analysis are performed, counterexample detection, and model abstraction refinement and strong update are guided through counterexample information to realize the analysis of the symbol level and address space level.
It realizes formal verification of security attributes of C language programs, provides security technical guarantees, can accurately analyze program status changes, and effectively balance detection accuracy and efficiency.
Smart Images

Figure CN114047913B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of software formal verification, and in particular relates to a counter-example guided sparse spatial flow model detection method and system. Background Art
[0002] Ensuring the correctness of software is the most critical but arduous task in today's software systems. It is one of the core factors to ensure the inherent security of software systems. Manually detecting software is error-prone and expensive. Therefore, many methods including software analysis and testing have been proposed to improve the correctness and security of software. These methods are widely used in a series of software engineering fields such as verifying application software, communication and security protocols, device drivers, system kernels, device firmware, etc., and have become the main methods to ensure software security. The design of a sparse spatial flow model detection method guided by counterexamples is of great significance to improving the correctness of software and strengthening the security of software.
[0003] Formal verification of software programs has always been a hot topic in the field of software security. It provides a core guarantee for software security by using mathematical methods to prove the semantic and logical correctness of software programs. Researchers have examined the problem of formal verification of software from different perspectives. Representative work includes the use of explicit state model detection, inductive proof, predicate abstraction, sparse value flow analysis, counterexample guidance and other technologies to achieve software correctness verification. Most of the existing methods focus on the research of program variable symbol level, and there are fewer formal works for programming languages with lower-level and more complex semantic characteristics (such as C language). If the actual program contains memory operations such as pointers or complex data structures, the existing methods will not be able to or will mistakenly perceive the state changes at the variable symbol level caused by the state changes on the memory space address, thereby generating false detection results, bringing unnecessary analysis overhead, and failing to ensure the effectiveness of verification. On the other hand, since there is a huge computational overhead in accurately calculating the object pointed to by the pointer, the existing insensitive pointer analysis sacrifices accuracy to improve analysis efficiency.
[0004] Therefore, in order to solve the problem of formal verification of software programs, it is necessary to design an accurate method that can comprehensively analyze the state changes of programming language programs with complex semantic characteristics (such as C language programs) at the symbolic level and address space level, and can effectively balance detection accuracy and efficiency to achieve its secure formal verification. Summary of the invention
[0005] The technical problem to be solved by the present invention is to provide a counter-example-guided sparse spatial flow model detection method and system in view of the deficiencies in the above-mentioned prior art. By implementing the counter-example-guided sparse spatial flow model detection method, the security attributes of C language program software can be formally verified accurately, providing security technical protection for C language program software.
[0006] The present invention adopts the following technical solutions:
[0007] A counterexample-guided sparse spatial flow model detection method, including
[0008] S1. Compile the C program code to be verified into LLVM intermediate code;
[0009] S2, converting the LLVM intermediate code into a sparse spatial flow model of the program to be verified;
[0010] S3, abstracting variables of the sparse spatial flow model, and executing a model detection algorithm of explicit value analysis to detect whether there are counterexamples in the abstracted sparse spatial flow model;
[0011] S4. Verify the feasibility of existing counterexamples to determine whether the counterexample path is valid in the original model. Use the counterexample information to guide the original model to perform model detection again based on interpolation-based abstract refinement and path, context, and field-sensitive strong update refinement models. Determine whether the program violates security properties by looking at counterexamples and whether there are weak updates on the counterexample paths.
[0012] Specifically, the sparse spatial flow model of converting the LLVM intermediate code into the program to be verified is as follows:
[0013] Extracting control flow automata from LLVM code The pointing information is obtained through the Andersen pointer analysis algorithm that is insensitive to both flow and context. The weak update function μ(a) and a=χ(a) are used to describe the uncertain pointing relationship. The def-use chain containing all top-level and address-taken pointer variables is described in the form of inter-procedural memory SSA. For the instruction loadp, μ(a) indicates that each variable a pointed to by pointer p may be indirectly accessed in the instruction; the function a=χ(a) indicates the definition and use of variable a; for store*p=&i, a=x(a) indicates that each variable a pointed to by pointer p is redefined and used, and a sparse value flow graph is obtained. By combining control flow automata and sparse value flow graph Constructing a sparse spatial flow model
[0014] Furthermore, control flow automata as follows:
[0015]
[0016] Sparse Value Flow Graph as follows:
[0017]
[0018] Sparse Spatial Flow Model as follows:
[0019]
[0020] Where L is the set of program locations; l 0 is the initial program position; E is the set of control flow edges; S is the set of all operation statements in the program; N represents the set of definition nodes or use nodes of pointer variables; ε represents the set of all possible def-use chains of pointer variables.
[0021] Specifically, the variable abstraction of the sparse spatial flow model is as follows:
[0022] Starting from the empty abstract precision, the precision π of the variable assignment statement in the sparse spatial flow model is calculated through the precision function Π, and the explicit value abstraction of the statement is calculated based on the variable v tracked by the precision π; the concrete state s is converted into an abstract state according to the precision Implements a variable abstraction for sparse spatial flow models.
[0023] Furthermore, the concrete state s is:
[0024] s∶=cs@l
[0025] Among them, cs: Indicates that an integer value is assigned to a program variable, l∈L is a program position; abstract state for:
[0026]
[0027] Specifically, the feasibility verification of the existing counterexamples is as follows:
[0028] Define a path as a sequence ρ consisting of a series of operation statements and program position pairs. When a path ρ is found to reach a violation of the detection property The wrong location When the constraint sequence is not satisfied, the accuracy is refined.
[0029] Furthermore, the precision is refined as follows:
[0030] Calculate the first node where ρ causes the constraint sequence to be unsatisfiable, and use the function SeqInterpolant to calculate the interpolation sequence Ι; after obtaining the interpolation sequence Ι, the corresponding program position l k Interpolation of ι k The program variables used are refined to l k As the starting point, the accuracy of all positions along the path ρ backward is ρ, and the function BackReachability is in the spatial flow model Find the interpolation value ι k The variables used are in program position l k The backward def-use chain will k The pointer variable pointed to by the used variable is added to the precision of the corresponding position, so as to iteratively refine the precision of the model from both the value space and the address space.
[0031] Specifically, the constraint rules of the strong update refinement model include ADDR rule, COPY rule, PHI rule, GEP rule, STORE rule, LOAD rule, SU / WU rule, CALL rule, RET rule and COMPO rule.
[0032] Specifically, the value flow information in the spatial flow model is traversed backward along the counterexample path to determine whether there is a weak update on the path. If there is a weak update on the counterexample path, the pointer pointing information in the model is updated through the path-sensitive strong update constraint rules guided by the counterexample, and the model is checked again to gradually achieve analysis at the program symbol level and address space level. If there is no weak update on the counterexample path, it indicates that the program has a counterexample that violates the security property, the model check is interrupted, and the found counterexample is reported.
[0033] Another technical solution of the present invention is a counterexample-guided sparse spatial flow model detection system, comprising:
[0034] Compilation module, compiles the C program code to be verified into LLVM intermediate code;
[0035] The conversion module converts the LLVM intermediate code into the sparse spatial flow model of the program to be verified;
[0036] The abstraction module performs variable abstraction on the sparse spatial flow model and executes a model detection algorithm of explicit value analysis to detect whether there are counterexamples in the abstracted sparse spatial flow model;
[0037] The detection module verifies the feasibility of existing counterexamples and determines whether the counterexample path is valid in the original model. It uses the counterexample information to guide the original model to perform model detection again based on interpolation-based abstract refinement and path, context and field-sensitive strong update refinement models, and determines whether the program violates security properties by determining whether there are weak updates on counterexamples and counterexample paths.
[0038] Compared with the prior art, the present invention has at least the following beneficial effects:
[0039] The present invention discloses a counter-example guided sparse spatial flow model detection method, which constructs a formalized model of a C language program to be verified, abstracts the model variables, detects whether there are counter-examples in the abstract model, and uses the counter-example information to guide the model abstraction refinement and strong update, thereby realizing the analysis of the program symbol level and the address space level, and verifying the security of the program.
[0040] Furthermore, the LLVM intermediate code is converted into a sparse spatial flow model of the program to be verified, providing a formal model for back-end model detection and extracting the control flow information of the LLVM code, namely the control flow automaton. Pointing information is obtained through the Andersen pointer analysis algorithm, which is insensitive to both flow and context, and two weak update functions are used to describe the uncertain pointing relationship. The def-use chain containing all top-level and address-taken pointer variables is described in the form of inter-procedural memory SSA. For the instruction load p, μ(a) indicates that each variable a (such as i and j) pointed to by pointer p may be indirectly accessed in this instruction. The function a=x(a) is used to indicate the definition and use (def&use) of variable a. For store*p=&i, a=χ(a) indicates that each variable a pointed to by pointer p may be redefined and used. Thus, a sparse value flow graph is obtained. By combining control flow automata and sparse value flow graph Constructing a sparse spatial flow model
[0041] Furthermore, we generate control flow automata Used to describe the state transition process expressed in code. Generate sparse value flow graph Used to describe the pointing relationship of the pointer. Generate sparse spatial flow model Used to provide formal verification of the model's security properties.
[0042] Furthermore, the precision-based abstraction refinement is achieved by performing variable abstraction on the sparse spatial flow model.
[0043] Furthermore, the concrete state and the abstract state Two state settings.
[0044] Furthermore, the feasibility of the existing counterexamples is verified to determine whether there is any erroneous pointing information and whether the accuracy needs to be refined.
[0045] Furthermore, the precision of symbolic variables and pointing information is refined to remove false pointing relationships. The first node where ρ causes the constraint sequence to be unsatisfiable is calculated, and the interpolation sequence Ι is calculated using the function SeqInterpolant; after obtaining the interpolation sequence Ι, the corresponding program position l is k Interpolation of ι k The program variables used are refined to l k As the starting point, the accuracy of all positions along the path ρ backward is ρ, and the function BackReachability is in the spatial flow model Find the interpolation value l k The variables used are in program position l k The backward def-use chain will k The pointer variable pointed to by the used variable is added to the precision of the corresponding position, so as to iteratively refine the precision of the model from both the value space and the address space.
[0046] Furthermore, constraint rules of the strong update refinement model are set to realize backward reachability analysis on the path.
[0047] Furthermore, the value flow information in the spatial flow model is traversed backward along the counterexample path to determine whether there is a weak update setting on the path to determine whether the program has a counterexample that violates the security property. If there is a weak update on the counterexample path, the pointer pointing information in the model is updated through the strong update constraint rules that are sensitive to the path guided by the counterexample, and the model is checked again, thereby gradually realizing the analysis of the program at the symbol level and address space level; if there is no weak update on the counterexample path, it indicates that the program has a counterexample that violates the security property, and the model check is interrupted and the counterexample found is reported.
[0048] In summary, the present invention can accurately perform formal verification of the security attributes of C language program software by implementing a counterexample-guided sparse spatial flow model detection method, thereby providing security technical protection for C language program software.
[0049] The technical solution of the present invention is further described in detail below through the accompanying drawings and embodiments. BRIEF DESCRIPTION OF THE DRAWINGS
[0050] Figure 1 This is a schematic diagram of a sparse spatial flow model detection method guided by a counterexample according to an embodiment of the present invention.
[0051] Figure 2 The figure is a schematic diagram of constructing a spatial flow graph of a C program in an embodiment of the present invention.
[0052] Figure 3 It is a pseudo code diagram of the precision refinement algorithm of the constraint difference sensitive to pointing information in an embodiment of the present invention.
[0053] Figure 4 Schematic diagram of the path, context and field-sensitive strong update constraint rules guided by counterexamples in an embodiment of the present invention.
[0054] Figure 5 Schematic diagram of pseudo code of the counter-example-guided abstract refinement and strong update model detection algorithm in an embodiment of the present invention.
[0055] Figure 6 Schematic diagram of counterexample detection results of the counterexample-guided sparse spatial flow model in an embodiment of the present invention.
[0056] Figure 7 Schematic diagram of the performance analysis of the sparse spatial flow model detection system guided by counterexamples in an embodiment of the present invention. DETAILED DESCRIPTION
[0057] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0058] In the description of the present invention, it should be understood that the terms “include” and “comprises” indicate the presence of described features, wholes, steps, operations, elements and / or components, but do not exclude the presence or addition of one or more other features, wholes, steps, operations, elements, components and / or collections thereof.
[0059] It should also be understood that the terms used in the present specification are only for the purpose of describing specific embodiments and are not intended to limit the present invention. As used in the present specification and the appended claims, the singular forms "a", "an" and "the" are intended to include plural forms unless the context clearly indicates otherwise.
[0060] It should be further understood that the term "and / or" used in the present description and the appended claims refers to and includes any and all possible combinations of one or more of the associated listed items.
[0061] Various structural schematic diagrams of the embodiments disclosed in the present invention are shown in the accompanying drawings. These figures are not drawn to scale, and some details are magnified and some details may be omitted for the purpose of clear expression. The shapes of various regions and layers shown in the figures and the relative sizes and positional relationships therebetween are only exemplary, and may deviate in practice due to manufacturing tolerances or technical limitations, and those skilled in the art may additionally design regions / layers with different shapes, sizes, and relative positions according to actual needs.
[0062] The present invention provides a counter-example-guided sparse spatial flow model detection method, which constructs a formalized model of a C language program to be verified and performs variable abstraction on the model; then, whether a counter-example exists in the abstract model is detected, and the counter-example information is used to guide the model abstraction refinement and strong update, thereby gradually realizing the analysis of the program symbol level and address space level, and verifying the security of the program; by realizing the counter-example-guided sparse spatial flow model detection method, the present invention can accurately and efficiently analyze the state changes of C language program software at the symbol level and address space level, and realize security formal verification.
[0063] See also Figure 1 The present invention provides a counter-example guided sparse spatial flow model detection method, which uses a C program benchmark library with a variety of complex grammatical and semantic characteristics as an implementation object to ensure the universality of the method of the present invention. The specific steps are as follows:
[0064] S1. Compile the C program code to be verified into LLVM intermediate code;
[0065] In order to generate LLVM intermediate code, the present invention example adopts LLVM (6.0.0) framework. Using this framework, C program code is compiled into LLVM intermediate code, namely LLVM IR, which is used in the construction process of sparse spatial flow model.
[0066] LLVM intermediate code is a partially static single assignment language, that is, a language in SSA form. It contains two types of variables: top-level and address-taken. Top-level variables are explicitly placed in the form of SSA using the standard SSA construction algorithm, that is, this type of variable will only be assigned once in its life cycle, and the top-level pointer variable has a definite pointing relationship; while address-taken variables are not in SSA form and need to be accessed indirectly through the top-level variables using the load and store instructions. The address-taken pointer variable usually has an uncertain pointing relationship.
[0067] S2, construct a sparse spatial flow model of the program to be verified;
[0068] According to the characteristics of the pointer analysis algorithm, the present invention divides pointer analysis into sensitive pointer analysis and insensitive pointer analysis. Sensitive pointer analysis includes path-sensitive, control flow-sensitive, context-sensitive and field-sensitive pointer analysis. This method can calculate the precise pointing relationship, but as the code scale increases, the computational complexity increases exponentially. It is used to strongly update and remove false pointing relationships. Insensitive pointer analysis includes pointer analysis based on implication constraints (also known as Anderson) or based on merge constraints (also known as Steensgaard). This method improves the calculation speed, but the accuracy of the analysis cannot be guaranteed. It is used to construct a sparse spatial flow model of the program in linear time.
[0069] The sparse spatial flow model of the program to be verified consists of a control flow automaton and a sparse value flow graph. The schematic diagram of the spatial flow graph construction of the C program is shown in Figure 2 The spatial flow model uses control flow automata to accurately describe the state transition process represented by codes, and uses sparse value flow graphs to describe the change process of memory address states.
[0070] The present invention constructs the sparse spatial flow model in the following form:
[0071]
[0072]
[0073]
[0074] in, Represents a spatial flow graph; represents a control flow automaton; represents a sparse value flow graph, L is a set of program locations, representing the program counter; l 0 ∈L is the initial program position, that is, the entry position of the program; is a set of control flow edges, representing the operations performed in migrating from one program location to another; S is the set of all operation statements in the program, where the set of all program variables is V; A collection of definition nodes or use nodes representing pointer variables; Represents the set of all possible def-use chains of pointer variables.
[0075] Based on the above spatial flow model construction form, the present invention converts the LLVM intermediate code into a sparse spatial flow model The specific method is as follows:
[0076] Extract the control flow information of LLVM code, that is, the control flow automaton
[0077] The pointing information is obtained through the Andersen pointer analysis algorithm which is not sensitive to flow and context, and two weak update functions μ(a) and a=x(a) are used to describe the uncertain pointing relationship and obtain the pointing information. The def-use chain containing all top-level and address-taken pointer variables is described in the form of inter-procedural memory SSA to obtain a sparse value flow graph. The μ(a) function is used to represent the use (use) of the variable a, and the function a=χ(a) is used to represent the definition and use (def&use) of the variable a.
[0078] Since the calling context may also lead to an uncertain pointing relationship at the function call, the present invention uses these two weak update functions to represent the pointer parameters in the function call, wherein a=χ(a) is used at the function call entry to indicate that each variable a pointed to by the pointer parameter variable p may be redefined and used by the function, and μ(a) indicates that a may be used when the function call returns;
[0079] By combining control flow automata and sparse value flow graph Constructing a sparse spatial flow model
[0080] S3, abstracting the variables of the sparse spatial flow model, and executing the model detection algorithm of explicit value analysis to detect whether there are counterexamples in the abstract model. If there are no counterexamples, it indicates that the program is safe for the attribute, and the detection stops;
[0081] Spatial flow model in the program When abstracting, it is divided into concrete state and abstract state There are two states, the description of the concrete state s is:
[0082] s∶=cs@l (4)
[0083] Among them, cs: It means assigning an integer value to a program variable, where l∈L is a program position.
[0084] Abstract State The description is:
[0085]
[0086] Among them, as: T represents an unknown value, such as that resulting from an assignment to an uninitialized variable or an external function call; ⊥ represents no value, i.e., a contradictory variable assignment.
[0087] The precision π defines a set of program variables that need to be analyzed and tracked. The precision function Π is expressed as:
[0088] Π:L→2 v (6)
[0089] Where L represents the program location, 2 v Represents a set of variable assignments.
[0090] Based on the above model abstract construction form, the specific method of the present invention for abstracting and detecting variables based on explicit values for the sparse spatial flow model is as follows:
[0091] At the beginning of the test, the precision is initialized to empty ( ), that is, for each l∈L, all variables are not tracked;
[0092] Computing sparse spatial flow model through precision function Π The precision π of the variable assignment statement in , and then the explicit value abstraction of the statement is calculated based on the variable v tracked by the precision π;
[0093] Convert the concrete state s into an abstract state according to the precision The abstraction of the model is realized; at the same time, the model detection algorithm that performs explicit value analysis detects whether there are counterexamples that violate security properties in the abstract model.
[0094] S4. Verify the feasibility of the counterexample to determine whether the counterexample path is valid in the original model.
[0095] S401, if the counterexample path is valid in the original model, guide the model to refine abstraction based on interpolation through the counterexample information, and perform model detection again, so as to gradually realize the analysis at the program symbol level and address space level;
[0096] A path is defined as a sequence ρ consisting of a series of operation statements and program position pairs as follows:
[0097] ρ:<(op 1 @l 1 ),…,(op n @l n )>
[0098] Among them, γ ρ = <op 1 ,…,op n >The constraint sequence of the path, op usually contains multiple operation statements.
[0099] The specific method of verifying the feasibility of the counterexample is as follows:
[0100] When a path ρ is found that can reach the violation of the detection property The wrong location When, that is, a counterexample CEX, the feasibility is verified first on the full precision ( ), use SMT technology to analyze the effectiveness of the counterexample ρ in the original model and determine whether the constraint sequence is satisfyable;
[0101] If it is not satisfied, it may be because the precision is not fine enough or there is wrong pointing information caused by weak update, and the precision needs to be refined.
[0102] Given formula and formula and is unsatisfiable, the formula and formula The description of the Craig interpolation is a formula that satisfies the following constraints:
[0103] 1) Effective, that is Unsatisfiable;
[0104] 2) Right now Unsatisfiable;
[0105] 3) ι only contains the formula and Public symbols, and symbols of the theory itself.
[0106] The above definition extends to the ordered sequence of formulas and Using the above interpolation method, we can obtain a series of interpolation values. 0 ,…,ι n :
[0107] 1) efficient;
[0108] 2)
[0109] 3)
[0110] 4) ι i Contains only formulas and Public symbols, and symbols of the theory itself.
[0111] The pseudo code diagram of the precision refinement algorithm of the constraint difference sensitive to the pointing information adopted in the counter-example guided model refinement in the embodiment of the present invention is as follows: Figure 3 shown.
[0112] Based on the above Craig interpolation, the specific manner in which the present invention performs the precision refinement algorithm of the information-sensitive constraint difference is as follows:
[0113] When an infeasible error path ρ is given, first calculate the first node where ρ causes the constraint sequence to be unsatisfiable, and then use the function SeqInterpolant to calculate the interpolation sequence Ι;
[0114] After obtaining the interpolation sequence I, the corresponding program position l k Interpolation of ι k The program variables used are refined to l k As the starting point, the accuracy of all positions along the path ρ backward is ρ, and the function BackReachability is in the spatial flow model Find the interpolation value ι k The variables used are in program position l k The def-use chain goes backwards, and then k The pointer variable pointed to by the used variable is added to the precision of the corresponding position, which can iteratively refine the precision of the model abstraction from both the value space and the address space.
[0115] S402: If the counterexample path is invalid in the original model, detect whether there is a weak update on the counterexample path;
[0116] See also Figure 4 , the embodiment of the present invention proposes ten strong update constraint rules, specifically:
[0117] ADDR rule, COPY rule, PHI rule, GEP rule, STORE rule, LOAD rule, SU / WU rule, CALL rule, RET rule and COMPO rule.
[0118] The ten strong update constraint rules are formally described as the following ten constraint expressions:
[0119] 1) ADDR rules:
[0120] Through the def-use chain of o, reversely obtain the memory address of o[ρ,c,n′] declared at node n′ to define the pointing relationship of p:
[0121]
[0122] 2) COPY rules:
[0123] For instructions on top-level variables, you can use a certain def-use chain to get the pointing set:
[0124]
[0125] 3) PHI Rules:
[0126] For the instructions of top-level variables, the def-use chain can be used to obtain the pointing set. Since PHI is related to the path condition, it is necessary to determine whether n′ and n″ belong to ρ. When n′ belongs to ρ (expressed by n′∈ρ=true), then This makes path-sensitivity possible:
[0127]
[0128] 4) GEP rules:
[0129] Implement field sensitivity analysis in field access, which builds an object for the field according to the index of GetElementPtr as the object pointed to by the field pointer:
[0130]
[0131] 5) STORE rule:
[0132] Introduce multiple indirect def-use chains to the address-taken variable. It is necessary to calculate and remove the current false def-use chain during the update process to ensure the correctness of the pointing relationship:
[0133]
[0134] 6) LOAD rules:
[0135] Indirectly from the address-taken variable and its pointing relationship set, assign it to the top-level variable for use. Due to the existence of multiple STORE operations, the pointing relationship obtained by the top-level variable will have a false def-use chain:
[0136]
[0137] 7)SU / WU Rules:
[0138] Used to represent strong and weak update operations in STOREρ,c,n:*p=_. The strong update operation kill(p[ρ,c,n]) is executed in three cases: when the pointer p points to an object with path and context related singletons (pcSingletons) When And remove the original content at position n′ in o, and update the new content at position n; when the set pointed to by p is empty, remove To avoid null pointers; in other cases, weak updates are performed. The SU / WU rule can be used to obtain the pointer information for processing the address-taken variable in the LOAD and STORE rules:
[0139]
[0140] 8)CALL rules:
[0141] Used to analyze function calls between procedures, using the same constraints as COPY. CALL means that when a function is called, the variable v' is passed directly or indirectly from the caller to the callee through parameter passing as variable v:
[0142]
[0143] 9) RET rules:
[0144] Used to analyze function calls between procedures, using constraints consistent with COPY. RET means that when the function returns, the variable v′ is returned directly or indirectly from the callee to the caller, and the original variable v is updated:
[0145]
[0146] 10) COMPO rules:
[0147] Used to express transitivity of def-use chains:
[0148]
[0149] Based on the above strong update constraint rules, if the counterexample path is valid in the original model, a strong update guided by the counterexample is performed.
[0150] S4021. If there is a weak update on the counterexample path, the counterexample information is used to guide the path, context, and field-sensitive strong updates, and the refined model is updated and the model is checked again, so as to gradually realize the analysis at the program symbol level and address space level.
[0151] The specific method of the present invention for performing counter-example guided strong updating is as follows:
[0152] First, we traverse the value flow information in the spatial flow model backward along the counterexample path to determine whether there is a weak update on the path;
[0153] If there is a weak update, it indicates that there is an ambiguous relationship in the current pointing information. By utilizing the strong update constraint rules, path, context and field sensitive strong update operations are performed to overwrite the previous content in the pointer variable and remove the false pointing relationship.
[0154] Among them, path-sensitive strong update is implemented by recording and analyzing counterexample paths; field-sensitive strong update is implemented by using the multi-level index information in the GetElementPtr instruction in LLVM IR as the index of the field; context-sensitive strong update is implemented by using the context stack.
[0155] S4022. If there is no weak update on the counterexample path, it indicates that the program has a counterexample that violates the safety property. The model check is interrupted and the counterexample found is reported.
[0156] S5. Counterexample-guided model checking.
[0157] The abstract reachability graph is used to record the analyzed states and their reachability relationships in a tree form. Two intermediate variables are used to record the information during the analysis process: the set Used to record all abstract states that can be reached under the current precision; collection It is used to record all the abstract states that are analyzed under the current precision. The pseudo code of the model detection algorithm guided by the counterexample designed in the embodiment of the present invention is as follows: Figure 5 The specific steps include:
[0158] S501, set the current precision π to the empty precision π 0 (i.e., do not record any variables), and initialize reached and waitlist (lines 1-2);
[0159] S502, execute the explicit value analysis model detection algorithm, extract the unanalyzed state b from the waitlist, find the reachable successor of b under precision π (that is, the branch condition is satisfyable after π abstraction), and abstract the successor: if the new state has not been analyzed, merge it into reached and waitlist; if the new state violates the property Indicates that a counterexample path is found and the current loop is exited (lines 4-12);
[0160] S503, determine whether there are any unanalyzed states remaining in the waitlist, if not, it indicates that the program is correct for the attribute. Therefore, stop the detection (line 22);
[0161] S504. If the waitlist is not empty, construct an abstract counterexample path ρ from the abstract reachable graph. a , and according to ρ a Information, use the function isFeasible to determine the path ρ a Whether the original model is valid (lines 13-15);
[0162] S505, if a If it is invalid, it means that the current path is not feasible. The algorithm uses the precision refinement algorithm (Refine) pointing to the information-sensitive constraint difference to update the precision π (line 16);
[0163] S506, ifa Valid, traverse the model in reverse along this path Judgment a Is there a weak update on the . If there is a weak update, use the constraint rules shown in Table 1 to Perform path-sensitive strong update to remove the pointing information brought by weak update, and then update the tracking variables brought by the pointing relationship in the precision to remove the abstract state of variable assignment caused by wrong pointing information (lines 17-19);
[0164] S507, if a is effective, and a If there is no weak update on the value space, then the path is valid in both the value space and the address space, indicating that the program violates the property Counterexamples, interrupt model detection, and report the found counterexamples (20 lines);
[0165] S508. After updating the accuracy in steps S505 and S506, the refined π is updated in reached and waitlist, and the process jumps to step S502 to perform model detection again (line 21).
[0166] The present invention uses empty precision during the first model detection, mainly for two reasons:
[0167] On the one hand, the simplest abstract model can be used to quickly detect whether there may be a state that violates the property in the program, thereby avoiding invalid computational analysis, such as the absence of pointer operations on the counterexample path;
[0168] On the other hand, the initial spatial flow model uses insensitive pointer analysis, so there is a lot of false pointing information, which will introduce wrong judgments to model detection;
[0169] After that, if a weak update is found on the detected path, a strong update is performed to provide the model detection with correct path-sensitive directional information;
[0170] If there is no weak update, it means that the pointing information on the path is correct, and the detected path is considered to be valid.
[0171] In yet another embodiment of the present invention, a counter-example guided sparse spatial flow model detection system is provided, which can be used to implement the above counter-example guided sparse spatial flow model detection method. Specifically, the counter-example guided sparse spatial flow model detection system includes a compilation module, a conversion module, an abstraction module and a detection module.
[0172] Among them, the compilation module compiles the C program code to be verified into LLVM intermediate code;
[0173] The conversion module converts the LLVM intermediate code into the sparse spatial flow model of the program to be verified;
[0174] The abstraction module performs variable abstraction on the sparse spatial flow model and executes a model detection algorithm of explicit value analysis to detect whether there are counterexamples in the abstracted sparse spatial flow model;
[0175] The detection module verifies the feasibility of existing counterexamples and determines whether the counterexample path is valid in the original model. The counterexample information guides the original model to perform model detection again based on the abstract refinement of interpolation and the strong update refinement model that is sensitive to the path, context, and field. It determines whether the program violates the security property by whether there is a weak update on the counterexample and the counterexample path.
[0176] In another embodiment of the present invention, a terminal device is provided, the terminal device includes a processor and a memory, the memory is used to store a computer program, the computer program includes program instructions, and the processor is used to execute the program instructions stored in the computer storage medium. The processor may be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, etc. It is the computing core and control core of the terminal, which is suitable for implementing one or more instructions, and is specifically suitable for loading and executing one or more instructions to implement the corresponding method flow or corresponding function; the processor described in the embodiment of the present invention can be used for the operation of the counter-example-guided sparse spatial flow model detection method, including:
[0177] Compile the C program code to be verified into LLVM intermediate code; convert the LLVM intermediate code into a sparse spatial flow model of the program to be verified; abstract the variables of the sparse spatial flow model, and execute the model detection algorithm of explicit value analysis to detect whether there are counterexamples in the abstracted sparse spatial flow model; verify the feasibility of the existing counterexamples to determine whether the counterexample path is valid in the original model; use the counterexample information to guide the original model to perform model detection again based on interpolation-based abstract refinement and path, context and field-sensitive strong update refinement models, and determine whether the program violates the security properties by determining whether there are weak updates on counterexamples and counterexample paths.
[0178] In another embodiment of the present invention, the present invention further provides a storage medium, specifically a computer-readable storage medium (Memory), which is a memory device in a terminal device for storing programs and data. It can be understood that the computer-readable storage medium here can include both the built-in storage medium in the terminal device and the extended storage medium supported by the terminal device. The computer-readable storage medium provides a storage space, which stores the operating system of the terminal. In addition, one or more instructions suitable for being loaded and executed by the processor are also stored in the storage space, and these instructions can be one or more computer programs (including program codes). It should be noted that the computer-readable storage medium here can be a high-speed RAM memory, or a non-volatile memory (non-volatile memory), such as at least one disk storage.
[0179] The processor may load and execute one or more instructions stored in a computer-readable storage medium to implement the corresponding steps of the counterexample-guided sparse spatial flow model detection method in the above embodiment; the processor may load and execute the following steps:
[0180] Compile the C program code to be verified into LLVM intermediate code; convert the LLVM intermediate code into a sparse spatial flow model of the program to be verified; abstract the variables of the sparse spatial flow model, and execute the model detection algorithm of explicit value analysis to detect whether there are counterexamples in the abstracted sparse spatial flow model; verify the feasibility of the existing counterexamples to determine whether the counterexample path is valid in the original model; use the counterexample information to guide the original model to perform model detection again based on interpolation-based abstract refinement and path, context and field-sensitive strong update refinement models, and determine whether the program violates the security properties by determining whether there are weak updates on counterexamples and counterexample paths.
[0181] In order to make the purpose, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, rather than all of the embodiments. The components of the embodiments of the present invention described and shown in the drawings here can usually be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present invention provided in the drawings is not intended to limit the scope of the claimed invention, but merely represents selected embodiments of the present invention. Based on the embodiments in the present invention, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present invention.
[0182] Effect:
[0183] In the embodiment of the present invention, a counter-example-guided sparse spatial flow model detection is performed on a C program benchmark library having a variety of complex grammatical and semantic characteristics. Figure 6 This is a schematic diagram of the counterexample detection process of the sparse spatial flow model in the present invention. This process only tracks the variables necessary to refute the invalid counterexample path, thereby suppressing the state space explosion problem caused by too many program variables and their values, making the verification more concise and efficient. The counterexamples CEX1 and CEX2 are false counterexamples in the detection process. Where CEX1 is θ 1 ∧θ 2 ∧θ 3 ∧θ 5 , CEX2 is
[0184] See also Figure 7 The present invention also analyzes the performance of the sparse spatial flow model detection system guided by the counterexample; specifically as follows:
[0185] Figure 7 (a) is a schematic diagram comparing the verification efficiency of the present invention and six mainstream software detection tools (GT, CPA-V, CPA-VP, CPA-KVP, Gazer, and SMACK) for different C program benchmark libraries, which respectively tests the verification efficiency of the present invention and six mainstream software detection tools (GT, CPA-V, CPA-VP, CPA-KVP, Gazer, and SMACK) for different C program benchmark libraries.
[0186] Figure 7 (b) is a schematic diagram for comparing the CDFs of the present invention and six mainstream software detection tools, and the CDFs of the present invention and six mainstream software detection tools are tested respectively.
[0187] Figure 7 (c) is a schematic diagram for comparing the accuracy of the present invention and six mainstream software detection tools in six aspects: array, function call (callsite), global variable (global), loop (loop), path (path), and structure (struct). The accuracy of the present invention and six mainstream software detection tools in six aspects: array, function call (callsite), global variable (global), loop (loop), path (path), and structure (struct) are tested respectively.
[0188] It can be seen that under the counterexample-guided sparse spatial flow model detection method, the present invention can more accurately analyze the state changes of C language program software at the symbol level and address space level than the existing method, and can effectively balance the detection accuracy and efficiency, with more accurate verification capabilities and faster verification efficiency, to achieve security formal verification.
[0189] In summary, the present invention provides a counter-example-guided sparse spatial flow model detection method and system, which can characterize program behavior at the symbol level and address space level, and provide accurate and comprehensive information for formal verification of the program; it can suppress the state space explosion problem caused by too many program variables and their values, making verification more concise and efficient; it can achieve efficient counter-example feasibility verification; it can iteratively refine the model accuracy from both the value space and the address space to ensure the integrity of the accuracy refinement; it can accurately and efficiently clarify the pointing relationship of pointers, remove false pointing relationships, and provide security.
[0190] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application may adopt the form of a computer program product implemented in one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that include computer-usable program code.
[0191] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0192] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture including an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.
[0193] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process in the computer or other programmable device. Figure 1A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.
[0194] The above contents are only for explaining the technical idea of the present invention and cannot be used to limit the protection scope of the present invention. Any changes made on the basis of the technical solution in accordance with the technical idea proposed by the present invention shall fall within the protection scope of the claims of the present invention.
Claims
1. A counter-example guided sparse spatial flow model detection method, It is characterized in that include S1. Compile the C program code to be verified into LLVM intermediate code; S2. Convert the LLVM intermediate code into a sparse spatial flow model of the program to be verified, and control flow automaton as follows: Sparse Value Flow Graph as follows: Sparse Spatial Flow Model as follows: in, L is the set of program locations; is the initial program position; is the set of control flow edges; S It is the collection of all operation statements in the program; A collection of definition nodes or use nodes representing pointer variables; Represents the set of all possible def-use chains of pointer variables; S3. Variable abstraction is performed on the sparse spatial flow model, and a model detection algorithm of explicit value analysis is executed to detect whether there is a counterexample in the abstracted sparse spatial flow model. Variable abstraction of the sparse spatial flow model is specifically as follows: Starting from the empty abstract precision, the precision of variable assignment statements in the sparse spatial flow model is calculated through the precision function Π π , according to the accuracy π Tracked variables v The explicit value abstraction of the computation statement; the concrete state s Transformed into abstract state according to precision , realize variable abstraction of sparse spatial flow model; S4. Verify the feasibility of existing counterexamples to determine whether the counterexample path is valid in the original model. Use the counterexample information to guide the original model to perform model detection again based on interpolation-based abstract refinement and path, context, and field-sensitive strong update refinement models. Determine whether the program violates security properties by looking at counterexamples and whether there are weak updates on the counterexample paths.
2. The counterexample-guided sparse spatial flow model detection method according to claim 1, It is characterized in that The sparse spatial flow model that converts LLVM intermediate code into the program to be verified is as follows: Extracting control flow automata from LLVM code , obtain the pointing information through the Andersen pointer analysis algorithm that is not sensitive to flow and context, and use the weak update function and Describe the uncertain pointing relationship and describe the def-use chain containing all top-level and address-taken pointer variables in the form of inter-procedural memory SSA. For the instruction loadp, Represents a pointer Each variable pointed to Instructions may be accessed indirectly; functions Representation variables Definition and use; for store*p=&i, Represents a pointer Each variable pointed to is redefined and used to obtain a sparse value flow graph ; By combining control flow automata and sparse value flow graph , construct a sparse spatial flow model .
3. The counter-example guided sparse spatial flow model detection method according to claim 1, It is characterized in that Representational State s for: in, It means to assign an integer value to a program variable. for a program position; Abstract State for: in, T, , T represents an unknown value; ⊥ represents no value.
4. The counterexample-guided sparse spatial flow model detection method according to claim 1, It is characterized in that The feasibility verification of the existing counterexamples is as follows: Define a path as a sequence of operation statements and program position pairs. , when a path is found Arrival violation detection nature The wrong location When the constraint sequence is not satisfied, the accuracy is refined.
5. The counter-example guided sparse spatial flow model detection method according to claim 4, It is characterized in that The precision is refined as follows: Calculate The first node that causes the constraint sequence to be unsatisfiable, using the function Calculate the interpolation sequence ; When getting the interpolation sequence After that, the corresponding program position Interpolation The program variables used are refined to Starting from In the accuracy of all positions in the backward direction, the function In the spatial flow model Find the interpolation value The variables used are in the program location The backward def-use chain will The pointer variable pointed to by the used variable is added to the precision of the corresponding position, so as to iteratively refine the precision of the model from both the value space and the address space.
6. The counter-example guided sparse spatial flow model detection method according to claim 1, It is characterized in that The constraint rules of the strong update refinement model include ADDR rule, COPY rule, PHI rule, GEP rule, STORE rule, LOAD rule, SU / WU rule, CALL rule, RET rule and COMPO rule.
7. The counter-example guided sparse spatial flow model detection method according to claim 1, It is characterized in that Traverse the value flow information in the spatial flow model backward along the counterexample path to determine whether there is a weak update on the path. If there is a weak update on the counterexample path, use the path-sensitive strong update constraint rules guided by the counterexample to update the pointer pointing information in the model, and perform model detection again to gradually achieve analysis at the program symbol level and address space level. If there is no weak update on the counterexample path, it indicates that the program has a counterexample that violates the security property, interrupt model detection, and report the found counterexample.
8. A counter-example guided sparse spatial flow model detection system, It is characterized in that include: Compilation module, compiles the C program code to be verified into LLVM intermediate code; The conversion module converts the LLVM intermediate code into the sparse spatial flow model of the program to be verified, the control flow automaton as follows: Sparse Value Flow Graph as follows: Sparse Spatial Flow Model as follows: in, L is the set of program locations; is the initial program position; is the set of control flow edges; S It is the collection of all operation statements in the program; A collection of definition nodes or use nodes representing pointer variables; Represents the set of all possible def-use chains of pointer variables; The abstraction module performs variable abstraction on the sparse spatial flow model and executes the model detection algorithm of explicit value analysis to detect whether there are counterexamples in the abstracted sparse spatial flow model. The variable abstraction of the sparse spatial flow model is specifically as follows: Starting from the empty abstract precision, the precision of variable assignment statements in the sparse spatial flow model is calculated through the precision function Π π , according to the accuracy π Tracked variables v The explicit value abstraction of the computation statement; the concrete state s Transformed into abstract state according to precision , realize variable abstraction of sparse spatial flow model; The detection module verifies the feasibility of existing counterexamples and determines whether the counterexample path is valid in the original model. It uses the counterexample information to guide the original model to perform model detection again based on interpolation-based abstract refinement and path, context and field-sensitive strong update refinement models, and determines whether the program violates security properties by determining whether there are weak updates on counterexamples and counterexample paths.
Citation Information
Patent Citations
Code defect static detection method and system oriented to Internet of Things operating system
CN113220302A
Method for verifying hardware / software co-designs
US20170031806A1