A Detection Method and System for Data Leakage in C Language Programs
By using information flow annotation and context security level analysis in C language programs, the problem of detecting hidden storage data leakage channels in C language programs is solved, and efficient data leakage detection and prevention is achieved.
Patent Information
- Application Number
- CN202111406827.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-11-24
- Publication Date
- 2025-06-24
- Estimated Expiration
- 2041-11-24
AI Technical Summary
There are hidden storage data leakage channels in C language programs, including implicit storage channels based on jumps and shared storage channels based on aliases. The prior art is difficult to effectively detect and prevent these leakages.
By using information flow annotations in C language programs, and determining the context security level of the program points based on preset rules, we can determine whether there is data leakage in the hidden storage channel.
It realizes effective detection of hidden storage channels based on jumps and alias in C language programs, improves the detection accuracy and efficiency of data leakage, and can be directly compiled using the existing C language compiler.
Smart Images

Figure CN114091018B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of program language data security, and particularly to a method and system for detecting data leakage of C language programs. Background Art
[0002] The development and progress of computer technology is a double-edged sword: on the one hand, it makes the processing and dissemination of data faster and more convenient; on the other hand, it also poses a more severe challenge to the protection of data confidentiality. The protection of data confidentiality means that a program does not allow a secret thief to obtain or infer confidential data (such as user passwords) in the program through information such as the output data that the thief can obtain. Traditional methods for solving security problems (such as access control, code detection, and encryption and decryption methods, etc.) cannot effectively handle the covert channel problem in the program. Language-based security technologies use technologies based on the theory and implementation of programming languages (including semantics, types, analysis, and verification, etc.) to solve security problems. Since the 1990s, the research on language-based information flow security analysis technology has always been a research hotspot in the world.
[0003] Most of these studies are aimed at simple model languages. Currently, the practical information flow security programming languages mainly include Jif in the United States and Flow Caml in France. These two languages are respectively based on Java and OCaml, and extend the traditional type system to describe information flow security attributes, and design an information flow type system independent of the ordinary type system to check information flow security.
[0004] Both Jif and Flow Caml check information flow security based on the information flow type system, that is, they extend the ordinary type system (add security level identifiers to ordinary types). Because these identifiers are part of the language, the Java language compiler or the Ocaml language compiler cannot be directly used, and a special compiler needs to be designed.
[0005] The object of Jif analysis is the Java language. The Java language has no pointer concept, so there will be no shared storage channel based on aliases in Java programs. The object of Flow Caml analysis is the Ocaml language. The Ocaml language has no complex jump statements, so there will be no implicit storage channel based on jumps in Ocaml programs. The pointers and jump statements in the C language are extremely flexible, which is convenient for programming but will also cause more serious data leakage than Java and Ocaml. There are the following covert storage data leakage channels in C language programs:
[0006] 1. Explicit storage channel of direct assignment; for example, assignment l = h. The secret thief can directly obtain data h through l.
[0007] 2. Implicit storage channels based on program control structures; for example, if (h > 0) l = 1 else l = 0. An eavesdropper can also infer information about h through l.
[0008] 3. Shared storage channels based on aliasing. For example
[0009]
[0010] An eavesdropper can infer information about h by determining whether the stored value of r1 has changed.
[0011] Based on the above-mentioned covert storage data leakage channels existing in C language programs, it is urgent to study a method for detecting data leakage in C language programs. Summary of the Invention
[0012] In view of the problems existing in the above-mentioned prior art, the present invention provides a method and system for detecting data leakage in C language programs, which can realize the detection of data leakage in implicit storage channels based on jumps and the detection of data leakage in shared storage channels based on aliasing. The technical solution is as follows:
[0013] On the one hand, a method for detecting data leakage in C language programs is provided. The method includes:
[0014] Receiving a C language program carrying information flow annotations;
[0015] Extracting and parsing the information flow annotations to obtain data access rule tags;
[0016] Based on preset rules, determining the context security levels of all program points, where the context security level of a program point represents the data access rule information reflected by the control structure where the program point is located;
[0017] Based on the data access rule tags at both ends of the covert storage channel and the context security levels of the program points, determining whether there is data leakage in the covert storage channel.
[0018] On the other hand, a system for detecting data leakage in C language programs is provided. The system includes:
[0019] A C language program receiving module for receiving a C language program carrying information flow annotations;
[0020] An information flow annotation parsing module for extracting and parsing the information flow annotations to obtain data access rule tags;
[0021] A program point context security level determining unit for determining the context security levels of all program points based on preset rules, where the context security level of a program point represents the data access rule information reflected by the control structure where the program point is located;
[0022] A data leakage analysis module, which is used to determine whether there is data leakage in the covert storage channel based on the data access rule tags at both ends of the covert storage channel and the context security level of the program point.
[0023] A method and system for detecting data leakage in a C language program according to the present invention have the following beneficial effects:
[0024] 1. The method for detecting data leakage in a C language program according to the present invention uses information flow annotation to describe the data access rules and exists in the program in the form of C language comments. After the information flow analysis is completed, the existing C language compiler can be directly used for compilation.
[0025] 2. By adding some constraints to the use of jump statements in the C program, the jump operations in the program are more regular, which makes the analysis of the influence of the program context at the program point where the jump statement is located on the subsequent statements simple and helps to detect the implicit storage channel based on jumps.
[0026] 3. By first determining the context security level of the program point where the jump statement is located and then analyzing the influence of the jump statement on the context security level of the subsequent program points, the context security levels of all program points within the function body are obtained, which is convenient for detecting the implicit storage channel based on the control structure.
[0027] 4. Considering that aliases in C programs are mainly caused by pointers, when performing related operations on C pointers, appropriate constraints are respectively imposed on the security levels of the pointer itself and the object it points to, and access rule tags are added to the object pointed to by the pointer and the pointer itself, which can effectively detect the shared storage channel based on aliases and more accurately analyze the alias data leakage caused by pointer-related operations.
[0028] 5. For the data access rule tags of local variables in the C program, they can be either manually annotated or automatically inferred by the local variable access rule tag automatic inference module, which improves the annotation efficiency of the access rule tags. Description of the Drawings
[0029] Figure 1 is a flowchart of a method for detecting data leakage in a C language program in an embodiment of the present application;
[0030] Figure 2 is a structural block diagram of a system for detecting data leakage in a C language program in an embodiment of the present application. Detailed Embodiments
[0031] To make the objectives, technical solutions and advantages of this application clearer, the following will further describe this application in detail with reference to the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of this application, rather than all of them. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in this application without creative efforts shall fall within the scope of protection of this application.
[0032] The following explains some terms in the embodiments of this application to facilitate the understanding of those skilled in the art.
[0033] (1) Confidentiality: The property that data is not leaked to unauthorized users, entities or processes, or used by them. It resists passive attacks by adversaries and ensures that information is not leaked to unauthorized persons.
[0034] (2) Integrity: The property that data cannot be changed without authorization. That is, the property that information remains unmodified, undamaged or not lost during storage or transmission. It resists active attacks by adversaries and prevents information from being tampered with without authorization.
[0035] (3) Program information flow security: The program can protect the confidentiality and integrity of important data.
[0036] (4) Covert channel: A mechanism that can send information from a high sensitivity level to a low sensitivity level.
[0037] The following further elaborates on this application in detail with reference to the accompanying drawings and specific embodiments.
[0038] Both Jif and Flow Caml perform information flow security checks based on information flow type systems, that is, they extend the ordinary type system (add security level identifiers to ordinary types). Since these identifiers are part of the language, it is not possible to directly use the Java language or Ocaml language compilers, and a specialized compiler needs to be designed.
[0039] The object of Jif analysis is the Java language. The Java language has no concept of pointers, so there will be no shared storage channels based on aliases in Java programs. The object of Flow Caml analysis is the Ocaml language. The Ocaml language has no complex jump statements, so there will be no implicit storage channels based on jumps in Ocaml programs. The use of pointers and jump statements in the C language is extremely flexible, which is convenient for programming but will also cause more serious data leakage than Java and Ocaml.
[0040] The present invention provides a method and system for detecting data leakage in a C language program. The access rules of data are described using information flow annotations and exist in the program in the form of C language comments. After the information flow analysis is completed, the existing C language compiler can be directly used for compilation, avoiding the problem in the prior art that when Jif and Flow Caml check information flow security, the Java language or Ocaml language compiler cannot be directly used.
[0041] By adding some constraints to the use of jump statements in the C program, the jump operations in the program become more regular, making the analysis of the influence of the program context at the program point where the jump statement is located on the subsequent statements simple, which helps to detect implicit storage channels based on jumps. Considering that aliases in the C program are mainly caused by pointers, when performing relevant operations on C pointers, appropriate constraints are respectively imposed on the security levels of the pointers themselves and the objects they point to, which can effectively detect shared storage channels based on aliases.
[0042] A method for detecting data leakage in a C language program provided by an embodiment of the present application includes:
[0043] S1: Receive a C language program carrying information flow annotations, where the information flow annotations are used to describe the data access rules of global variables, function formal parameters, return values, and local variables in the program;
[0044] S2: Extract and parse the information flow annotations to obtain data access rule tags;
[0045] S3: Based on preset rules, determine the context security levels of all program points, where the context security level of a program point represents the data access rule information reflected by the control structure where the program point is located;
[0046] S4: Based on the data access rule tags at both ends of the covert storage channel and the magnitude of the context security level of the program point, determine whether there is data leakage in the covert storage channel.
[0047] Wherein, before S1, it includes adding information flow annotations to the original C language program. In the present application, the access rules of data are described using information flow annotations and exist in the program in the form of C language comments. After the information flow analysis is completed, the existing C language compiler can be directly used for compilation, avoiding the problem in the prior art that when Jif and Flow Caml check information flow security, the Java language or Ocaml language compiler cannot be directly used.
[0048] Specifically, the positions of the information flow annotations include:
[0049] (1) For the computing entity and agency relationship: The definition of the computing entity is marked at the place where global declarations are allowed, and the agency relationship of the computing entity follows immediately after the definition of the computing entity;
[0050] (2) For label variables: Label variables are defined at the place where global declarations are allowed;
[0051] (3) For function information flow labels: Describing the data access rules for the formal parameters, return values and side effects of functions, the function information flow labels are inserted before the function declaration or definition;
[0052] (4) For local variable information flow labels, the local variable information flow labels are inserted at the local variable definition;
[0053] (5) For declassification labels: The declassification labels include function permission declarations and declassification statements;
[0054] Among them, when the data type is a pointer, the information flow annotation of the pointer includes the information flow label of the object pointed to by the pointer and the information flow label of the pointer itself.
[0055] Furthermore, considering that there is a hidden storage data leakage channel in C language programs - the shared storage channel based on aliasing, the use of C language pointers will cause aliasing in the program. Different from ordinary variables, the operations of pointers include dereferencing and assignment.
[0056] The security level of the object pointed to by the pointer variable p reflects the security level of the value stored at the address pointed to by p. The value of the pointer variable p can depend on the program control structure (for example, different addresses are assigned to p in the two branches of a conditional statement). In this way, the security level of the data leaked by the program control structure can only be reflected in the pointer p itself. These two security levels will ultimately be reflected in the value stored at the address pointed to by p (because there are two ways to assign values to this address: through variables or pointers). Therefore, in this embodiment, information flow annotations are added to both the object pointed to by the pointer and the pointer itself, and certain constraints are imposed on both to avoid alias leakage, which can more accurately analyze the alias data leakage caused by pointer-related operations.
[0057] For the information flow annotations in C language programs, the annotations on one line are embedded in comments in the style of / / @flowsec…, and the multi-line annotations are embedded in comments in the style of / *@flowsec…* / .
[0058] For example, the grammar definition of the computing entity and agency relationship is as follows:
[0059] <principal_def>:= / / @flowsec Principal id(,id)*;
[0060] <actsfor_def> := / / @flowsec Acts_for: id <id(, id <id)*;
[0061] In the <actsfor_def> production, the id must be a computing principal defined in <principal_def>.
[0062] For example,
[0063] / / @flowsec Principal A, B, M;
[0064] / / @flowsec Acts_for A < M, B < M;
[0065] The above annotation defines three computing principals A, B, and M. Among them, M can act for A and B (reflexivity is omitted).
[0066] In the embodiments of the present application, when adding information flow annotations to the original C language program, for the information flow labels of local variables, they are optional. They can either be added manually by the programmer or not added. For local variables without information flow annotations, the data access rule labels of these local variables can be automatically inferred through an automatic inference algorithm later.
[0067] In the above step S2, that is, when extracting and parsing the information flow annotation to obtain the data access rule label, it includes:
[0068] S21: For local variables without information flow annotations in the C language program with information flow annotations, obtain the data access rule labels of the local variables without information flow annotations through automatic inference.
[0069] Among them, the automatic inference method includes:
[0070] S211: Constraint equation extraction: Assign a new label variable to each local variable without a data access rule label in the function body, and obtain the constraint equation of the label variable according to the read-write usage restrictions of local variables in the function body. Among them, the form of the constraint equation is: L1 <: L2, where <: represents the partial order relationship, and L1 and L2 are the least upper bound operation expressions of access rule labels and label variables;
[0071] S212: Normalize the constraint equation. Specifically, the normalization of the constraint equation takes the above constraint equation as the object. Because the data access rule label can be decomposed into the least upper bound (set union operation) of zero or more basic access rules, that is According to the properties of the least upper bound operator, normalize the constraint equation to where is a basic access rule or a label variable;
[0072] Through the constraint equation normalization step, it is convenient to assign values to the label variables to be deduced during the iterative solution process.
[0073] S213: Solving the constraint equation: Using an iterative algorithm to calculate the values of the label variables of local variables, including the following steps:
[0074] (1) Initialize the label variable to be deduced to the maximum label value;
[0075] (2) Traverse the constraints in the constraint set one by one. When an unsatisfied constraint is encountered, if the left side of the constraint is the label variable to be deduced, then modify the value of the label variable to the current value and the maximum lower bound of the current value, and keep the values of other label variables unchanged, and enter step (3); if the left sides of all unsatisfied constraints in the constraint set are not the label variables to be deduced, then a contradiction is obtained and an error is reported;
[0076] (3) Repeat step (2) until all constraints are satisfied or a contradiction is obtained.
[0077] Before the above step S3, that is, before determining the context security levels of all program points based on preset rules, it also includes:
[0078] Perform constraint condition detection on the use of jump statements and judgment expressions in the program. When the use of jump statements and judgment expressions in the program meets the constraint conditions, enter step S3. The constraint conditions are used to make the jump operations in the program more regular, so as to simplify the analysis of the influence of the program context at the program point where the jump statement is located on the subsequent statements.
[0079] Specifically, the constraint conditions for the use of jump statements and judgment expressions include:
[0080] (1) If the judgment expression contains a short-circuit calculation logical operator, then the expression is not allowed to contain function calls and assignment statements;
[0081] (2) The jump statement shall not jump into selection and loop statements;
[0082] (3) The reverse jump statements form a loop, and no other jump statements are allowed to jump into this loop;
[0083] (4) There cannot be a reverse goto statement jumping out inside the loop statement;
[0084] (5) Each branch of the switch statement must end with a jump statement;
[0085] (6) Statement expressions are not allowed.
[0086] In step S3 above, based on preset rules, determine the context security levels of all program points, specifically including:
[0087] S30: Initialize the context security levels of all statement program points within the function body to the minimum value of the label.
[0088] S31: Determine the program context security level of the program point where the jump statement is located.
[0089] S32: Analyze the impact of the jump statement on the program context security levels of the subsequent program points of the program point where the jump statement is located, and adjust the program context security levels of the subsequent program points of the program point where the jump statement is located.
[0090] In the embodiments of the present application, by first determining the context security level of the program point where the jump statement is located, and then analyzing the impact of the jump statement on the context security levels of the subsequent program points, the context security levels of all program points within the function body are obtained, which is convenient for detecting implicit storage channels based on control structures.
[0091] Among them, step S31 includes:
[0092] (1) For conditional statements, determine the context security levels of the two branches of the conditional statement as: the minimum upper bound of the context security level of the conditional statement and the access rule label of the conditional expression.
[0093] (2) For loop statements, determine whether there is a jump statement in the loop body of the loop statement and the jump statement is not continue. If so, go to step (3), otherwise, go to step (4);
[0094] (3) Take the minimum upper bound of the context security levels of the jump statements included in the loop body as the new context security level of the loop statement, recalculate the context security levels of each program point in the loop body, and repeat this step until the context security levels of each program point in the loop body no longer change, to obtain the program context security level of the program point where the jump statement is located;
[0095] (4) Determine the context security level of the loop body of the loop statement as: the minimum upper bound of the context security level of the loop statement and the access rule label of the conditional expression.
[0096] Among them, step S32 includes:
[0097] (1) Determine the context security level of the label statement as: the minimum upper bound of the current context security level of the label statement and the context security levels of all jump statements that jump to the label statement.
[0098] (2) Denote the subsequent statements of all nested statements containing a return statement as the first subsequent statements, and determine the context security level of the first subsequent statements as: the least upper bound of the current context security level of the first subsequent statements and the context security level of the program point of the return statement;
[0099] (3) Denote the subsequent statements of all nested statements containing a break or continue statement within a loop body as the second subsequent statements, and determine the context security level of the second subsequent statements as: the least upper bound of the current context security level of the second subsequent statements and the context security level of the program point of the break or continue statement;
[0100] (4) Denote the subsequent statements of all nested statements from a goto statement to a Label statement as the third subsequent statements, and determine the context security level of the third subsequent statements as: the least upper bound of the current context security level of the third subsequent statements and the context security level of the program point of the goto statement
[0101] (5) If there is a jump statement in a conditional statement branch, denote the subsequent statement of the conditional statement as the fourth subsequent statement, and determine the context security level of the fourth subsequent statement as: the least upper bound of the program context of the conditional statement and the context of the program point of the jump statement;
[0102] (6) If there is a jump statement in the loop body of a loop statement and the jump statement is neither break nor continue, denote the subsequent statement of the loop statement as the fifth subsequent statement, and determine the context security level of the fifth subsequent statement as: the least upper bound of the program context of the loop statement and the context of the program point of the jump statement in the loop body that is neither break nor continue;
[0103] (7) If there is a jump statement in a switch statement branch and the jump statement is not break, denote the subsequent statement of the switch statement as the sixth subsequent statement, and determine the context security level of the sixth subsequent statement as: the least upper bound of the program context of the switch statement and the contexts of the program points of all non-break jump statements.
[0104] Considering that there are implicit storage channels based on program control structures in C language programs: for example, if (h > 0) l = 1 else l = 0, an eavesdropper can also infer information about h through l. Therefore, in the embodiments of the present application, for a C language program with program control structures, the context security levels of each program point are determined, and the program context security level is used to track the program control structures, which can effectively detect the hidden storage data leakage in the C language program.
[0105] Next, determine whether there is data leakage in the covert storage channel. Assume that the eavesdropper can only observe variables with a low confidentiality level. Therefore, assigning low-level data to a high-level variable will not cause leakage, and this action is allowed. However, assigning high-level data to a low-level variable will cause leakage, and this action is not allowed.
[0106] Step S4 in the embodiment of the present application: Determine whether there is data leakage in the covert storage channel based on the data access rule labels at both ends of the covert storage channel and the context security level of the program point, specifically including:
[0107] S41: For a covert storage channel that does not contain pointers at both ends, determine whether the minimum upper bound of the access rule label of the right value expression of the assignment statement and the context security level of the program point of the assignment statement is less than or equal to the access rule label of the left value expression. If not, report that there is data leakage in the program;
[0108] For example, for a simple variable assignment statement, it is required that the minimum upper bound of the access rule label of the right value expression and the context security level of the program point of this assignment statement is less than or equal to the access rule label of this simple variable. Otherwise, report that there is data leakage in the program.
[0109] Among them, when the above judgment result is "yes", that is, the minimum upper bound of the access rule label of the right value expression of the assignment statement and the context security level of the program point of the assignment statement is less than or equal to the access rule label of the left value expression, it means that low-level data is assigned to a high-level variable. When the above judgment result is "no", it means that high-level data is assigned to a high-level variable.
[0110] S42: For a covert storage channel that contains pointers at least at one end, determine whether the information flow labels of the objects pointed to by the pointers at both ends of the storage channel, the information flow label of the pointer itself, and the context security level of the program point of the storage channel satisfy the preset alias channel data security transmission rules. If not, report that there is data leakage in the program.
[0111] Among them, the preset alias channel data security transmission rules in S42 include:
[0112] (1) In the pointer variable assignment statement, the access rule labels of the objects pointed to by the left value and the right value have an equivalent relationship, and the access rule label of the right value itself is less than or equal to the access rule label of the left value itself;
[0113] (2) When the dereference expression of a pointer variable is used as the right value of an assignment statement, the access rule label of the dereference expression is equal to the minimum upper bound of the access rule label of the pointer variable itself, the access rule label of the data it points to, and the context security level of the program point where the expression is located. The access rule label of the dereference expression is less than or equal to the access rule label of the left value expression;
[0114] (3) When the dereference expression of a pointer variable is used as the left value of an assignment statement, the access rule label of the right value expression of the assignment statement is less than or equal to the access rule label of the object pointed to by the pointer, and the minimum upper bound of the access rule label of the pointer variable itself and the context security level of the program point where the assignment statement is located is less than or equal to the access rule label of the object pointed to by the pointer.
[0115] In addition, in the embodiments of the present application, for arrays in a language program, the data leakage detection method is similar to that of pointers. The array name is regarded as a pointer constant, and array elements are regarded as dereferences of pointers. The preset alias channel data security transmission rules are used to determine whether there is data leakage in the covert storage channel.
[0116] All array elements have the same access rule label, which is added by the user at the place where the array is defined. The access rule label of the array name is the default minimum label.
[0117] Based on the same inventive concept as the above-mentioned C language program data leakage detection method, an embodiment of the present application also provides a C language program data leakage detection system, which can be deployed in a server or a terminal device. Since the C language program data leakage detection system in this embodiment of the present application is the system corresponding to the C language program data leakage detection method in this embodiment, and the principle of solving problems by this C language program data leakage detection system is similar to that of the method, the implementation of this C language program data leakage detection system can refer to the implementation of the above-mentioned C language program data leakage detection method, and the repeated parts will not be described again.
[0118] A C language program data leakage detection system provided by an embodiment of the present application includes:
[0119] A C language program receiving module, configured to receive a C language program carrying information flow annotations;
[0120] An information flow annotation parsing module, configured to extract and parse the information flow annotations to obtain data access rule labels;
[0121] A program point context security level determination unit, configured to determine the context security levels of all program points based on preset rules, where the context security level of the program point represents the access rule information of the data reflected by the control structure where the program point is located;
[0122] A data leakage analysis module, configured to determine whether there is data leakage in the covert storage channel based on the data access rule tags at both ends of the covert storage channel and the context security level of the program point.
[0123] Furthermore, the above-mentioned C language program data leakage detection system further includes a local variable access rule tag automatic inference module, configured to automatically infer the data access rule tags of the local variables without information flow annotation in the C language program with information flow annotation.
[0124] It should be noted that when the C language program data leakage detection system provided in this embodiment performs data leakage detection, only the above-mentioned functional module division is used for illustration. In actual applications, the above functions can be allocated to different functional modules according to needs, that is, the internal structure of the C language program data leakage detection system is divided into different functional modules to complete all or part of the functions described above.
[0125] Those of ordinary skill in the art can understand that all or part of the steps to implement the above embodiments can be completed by hardware, or can be completed by a program instructing relevant hardware. The program can be stored in a computer-readable storage medium. The above-mentioned storage medium can be a read-only memory, a magnetic disk or an optical disc, etc.
[0126] The present invention is not limited to the above specific embodiments. Those of ordinary skill in the art starting from the above concepts and making various transformations without creative labor fall within the protection scope of the present invention.
Claims
1. A method for detecting data leakage in a C language program, characterized in that, Including: Receiving a C language program carrying information flow annotations; Extracting and parsing the information flow annotations to obtain data access rule tags; Based on preset rules, determining the context security level of all program points, where the context security level of a program point represents the data access rule information reflected by the control structure where the program point is located; Based on the data access rule tags at both ends of the covert storage channel and the size of the context security level of the program point, determining whether there is data leakage in the covert storage channel; The determining the context security level of all program points based on preset rules includes: Initializing the context security level of all statement program points within a function body to the minimum value of the tags; Determining the program context security level of the program point where the jump statement is located; Analyzing the impact of the jump statement on the program context security level of the subsequent program points of the program point where the jump statement is located, and adjusting the program context security level of the subsequent program points of the program point where the jump statement is located; The determining whether there is data leakage in the covert storage channel based on the data access rule tags at both ends of the covert storage channel and the size of the context security level of the program point includes: For a covert storage channel that does not contain pointers at both ends, determining whether the least upper bound of the access rule tag of the right - hand side expression of the assignment statement and the context security level of the program point of the assignment statement is less than or equal to the access rule tag of the left - hand side expression. If not, reporting that there is data leakage in the program; For a covert storage channel that contains pointers at least at one end, based on whether the information flow tags of the objects pointed to by the pointers at both ends of the storage channel, the information flow tags of the pointers themselves, and the context security level of the program point of the storage channel satisfy the preset data security transmission rules for alias channels. If not, reporting that there is data leakage in the program.
2. The detection method for C language program data leakage according to claim 1, characterized in that The C language program carrying information flow annotations, where the information flow annotations exist in the program in the form of C language comments, specifically including: (1) Computational entity and proxy relationship: The definition of the computational entity is annotated where global declarations are allowed, and the proxy relationship of the computational entity follows immediately after the definition of the computational entity; (2) Label variables: Label variables are defined where global declarations are allowed; (3) Function information flow tags: Describing the data access rules of the formal parameters, return values, and side effects of the function, and the function information flow tags are inserted before the function declaration or definition; (4) Local variable information flow tags, and the local variable information flow tags are inserted at the local variable definition; (5) Declassification tags: The declassification tags include function permission declarations and declassification statements; Among them, when the data type is a pointer, the information flow annotation of the pointer includes the information flow tag of the object pointed to by the pointer and the information flow tag of the pointer itself.
3. A method for detecting C language program data leakage according to claim 1, characterized in that, The extracting and parsing the information flow annotations to obtain data access rule tags further includes: For local variables in the C language program carrying information flow annotations that do not have information flow annotations added, automatically inferring the data access rule tags of the local variables without added information flow annotations; The automatically inferring the data access rule tags of the local variables without added information flow annotations includes: Constraint equation extraction: Assign a new labeled variable to each local variable without a data access rule label in the function body, and obtain the constraint equation of the labeled variable according to the read / write usage restrictions of the local variables in the function body. The constraint equation has the following form: L1 <: L2, where <: represents the partial order relation, and L1 and L2 are the least upper bound operation expressions of access rule labels and labeled variables; Steps for normalizing constraint equations, normalizing the constraint equation to where is a basic access rule or a label variable; Constraint equation solving: Use an iterative algorithm to calculate the values of the labeled variables of local variables, including the following steps: (1) Initialize the labeled variable to be deduced to the maximum label; (2) Traverse the constraints in the constraint set one by one. When encountering a non-satisfied constraint, if the left side of the constraint is the label variable to be deduced, then modify the value of the label variable to the maximum lower bound of the current value and the current value, and keep the values of other label variables unchanged, then enter step (3); if the left sides of all non-satisfied constraints in the constraint set are not the label variables to be deduced, then a contradiction is obtained and an error is reported; (3) Repeat step (2) until all constraints are satisfied or a contradiction is obtained.
4. A method for detecting C language program data leakage according to claim 1, characterized in that, Before determining the context security level of all program points based on the preset rules, it also includes: Perform constraint condition detection on the use of jump statements and judgment expressions in the program. When the use of jump statements and judgment expressions in the program satisfies the constraint conditions, proceed to the next step. The constraint conditions are used to make the jump operations in the program more regular. The constraint conditions include: (1) If the judgment expression contains a short-circuit calculation logical operator, the expression is not allowed to contain function calls and assignment statements; (2) Jump statements are not allowed to jump into selection and loop statements; (3) Reverse jump statements form a loop, and no other jump statements are allowed to jump into this loop; (4) There cannot be a reverse goto statement jumping out of a loop statement; (5) Each branch of the switch statement must end with a jump statement; (6) Statement expressions are not allowed.
5. The detection method for C language program data leakage according to claim 4, characterized in that, Determining the program context security level of the program point where the jump statement is located includes: (1) For conditional statements, determine the context security levels of the two branches of the conditional statement as: the least upper bound of the context security level of the conditional statement and the access rule label of the conditional expression; (2) For loop statements, determine whether there is a jump statement in the loop body of the loop statement and the jump statement is not continue. If so, proceed to step (3), otherwise, proceed to step (4); (3) Use the least upper bound of the context security levels of the jump statements included in the loop body as the new context security level of the loop statement, and recalculate the context security levels of each program point in the loop body. Repeat this step until the context security levels of each program point in the loop body no longer change, and obtain the program context security level of the program point where the jump statement is located; (4) Determine the context security level of the loop body of the loop statement as: the least upper bound of the context security level of the loop statement and the access rule label of the conditional expression.
6. The detection method for C language program data leakage according to claim 5, characterized in that, Analyzing the impact of the jump statement on the program context security level of the subsequent program points of the program point where the jump statement is located, and adjusting the program context security level of the subsequent program points of the program point where the jump statement is located, including: (1) Determine the context security level of the labeled statement as: the least upper bound of the current context security level of the labeled statement and the context security levels of all jump statements that jump to the labeled statement; (2) Denote the subsequent statements of all nested statements containing a return statement as the first subsequent statements, and the context security level of the first subsequent statements is determined as: the least upper bound of the current context security level of the first subsequent statements and the context security level of the program point of the return statement; (3) Denote the subsequent statements of all nested statements with a break or continue statement in the loop body as the second subsequent statements, and the context security level of the second subsequent statements is determined as: the least upper bound of the current context security level of the second subsequent statements and the context security level of the program point of the break or continue statement; (4) Denote the subsequent statements of all nested statements between a goto and a Label statement as the third subsequent statements, and the context security level of the third subsequent statements is determined as: the least upper bound of the current context security level of the third subsequent statements and the context security level of the program point of the goto statement; (5) If there is a jump statement in the conditional statement branch, denote the subsequent statement of the conditional statement as the fourth subsequent statement, and the context security level of the fourth subsequent statement is determined as: the least upper bound of the program context of the conditional statement and the context of the program point of the jump statement; (6) If there is a jump statement in the loop body of the loop statement and the jump statement is neither break nor continue, denote the subsequent statement of the loop statement as the fifth subsequent statement, and the context security level of the fifth subsequent statement is determined as: the least upper bound of the program context of the loop statement and the context of the program point of the jump statement that is neither break nor continue in the loop body; (7) If there is a jump statement in the switch statement branch and the jump statement is not break, denote the subsequent statement of the switch statement as the sixth subsequent statement, and the context security level of the sixth subsequent statement is determined as: the least upper bound of the program context of the switch statement and the contexts of the program points of all non-break jump statements; 7. A detection method for C language program data leakage according to claim 6, characterized in that Judging whether there is data leakage in the covert storage channel based on the data access rule labels at both ends of the covert storage channel and the size of the context security level of the program point further includes: For an array in a language program, regard the array name as a pointer constant, view the array elements as the dereference of the pointer, and use the preset data security transmission rules for the alias channel to judge whether there is data leakage in the covert storage channel.
8. The detection method for C language program data leakage according to claim 7, characterized in that, The preset data security transmission rules for the alias channel include: (1) In a pointer variable assignment statement, the access rule labels of the objects pointed to by the left value and the right value have an equivalent relationship, and the access rule label of the right value itself is less than or equal to the access rule label of the left value itself; (2) When a pointer variable dereference expression is used as the right value of an assignment statement, the access rule label of the dereference expression is equal to the least upper bound of the access rule label of the pointer variable itself, the access rule label of the data it points to, and the context security level of the program point where the expression is located, and the access rule label of the dereference expression is less than or equal to the access rule label of the left value expression; (3) When a dereferenced pointer variable expression is used as the left value of an assignment statement, the access rule label of the right value expression of the assignment statement is less than or equal to the access rule label of the object pointed to by the pointer, and the least upper bound of the access rule label of the pointer variable itself and the context security level of the program point where the assignment statement is located is less than or equal to the access rule label of the object pointed to by the pointer.
9. A detection system for C language program data leakage, characterized in that, Including: A C language program receiving module for receiving a C language program carrying information flow annotations; An information flow annotation parsing module for extracting and parsing the information flow annotations to obtain data access rule labels; A program point context security level determining unit for determining the context security levels of all program points based on preset rules, where the context security level of a program point represents the data access rule information reflected by the control structure where the program point is located; A data leakage analysis module for determining whether there is data leakage in the covert storage channel based on the data access rule labels at both ends of the covert storage channel and the size of the context security level of the program point; The steps executed by the program point context security level determining unit include: Determining the context security levels of all program points based on the preset rules includes: Initializing the context security levels of all statement program points within a function body to the minimum label value; Determining the program context security level of the program point where the jump statement is located; Analyzing the impact of the jump statement on the program context security levels of the subsequent program points of the program point where the jump statement is located and adjusting the program context security levels of the subsequent program points of the program point where the jump statement is located; The steps executed by the data leakage analysis module include: For a covert storage channel that does not contain a pointer at both ends, determining whether the least upper bound of the access rule label of the right value expression of the assignment statement and the context security level of the program point of the assignment statement is less than or equal to the access rule label of the left value expression. If not, it is reported that there is data leakage in the program; For a covert storage channel that contains a pointer at least at one end, determining whether it satisfies the preset alias channel data security transmission rules based on the information flow labels of the objects pointed to by the pointers at both ends of the storage channel, the information flow labels of the pointers themselves, and the context security level of the program point of the storage channel. If not, it is reported that there is data leakage in the program.
Citation Information
Patent Citations
Information flow analysis method based on system source code searching concealed channel
CN101377806A
System for detecting source code security flaws through analysis of code history
US10084819B1