A Custom Feature Rule Method Based on Function Signatures
Through a custom feature rule method based on function signature, a finite state automaton is designed and the access path of variables is monitored, which solves the defect that existing static analysis technology cannot detect resource release problems, realizes effective detection and reminding of resource release problems, and improves the security of the code.
Patent Information
- Application Number
- CN202210008854.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-01-06
- Publication Date
- 2025-06-24
- Estimated Expiration
- 2042-01-06
AI Technical Summary
Existing static analysis technologies cannot effectively detect resource release problems, resulting in possible security problems such as memory leakage.
Using a custom feature rule method based on function signature, we use the security vulnerabilities of statistical language, design programming security feature rules, define state transition processes and function signatures, and design finite state automata to monitor the functions called by variables and track their access and propagation paths to detect resource release problems.
Effectively detect and remind developers to release resources, avoid memory leaks and other security issues, and improve the security of the code compilation stage.
Smart Images

Figure CN114139167B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of source code analysis, and particularly relates to a custom feature rule method based on function signatures. Background Art
[0002] For some resources that need to be manually released (such as stream resources, database connections, socket connections that are not within the scope of GC memory management in the Java language, and pointers in the C / C++ language), if not released in time, it is easy to cause a series of security problems such as memory leaks, which are easily overlooked by developers. This requires detection through static analysis technology to remind developers to release resources and prevent such security vulnerabilities at the code compilation stage. However, most of the existing static analysis is based on pointer analysis technology, mainly constructing a relationship graph (referred to as a pointer flow graph, PFG) for the transfer relationship and mutual reference relationship between each pointer variable. This kind of analysis cannot detect resource release problems. Therefore, it is urgent to develop a custom feature rule method based on function signatures for program static analysis, which can detect resource release problems according to custom feature rules to avoid unnecessary security problems. Summary of the Invention
[0003] In view of the above technical problems, the present invention provides a custom feature rule method based on function signatures.
[0004] The technical solution adopted by the present invention to solve its technical problems is as follows:
[0005] A custom feature rule method based on function signatures, the method includes the following steps:
[0006] Step S100: Count the security vulnerabilities of the analyzed language, and design programming security feature rules for the security vulnerabilities;
[0007] Step S200: Define the corresponding state transition process according to the programming security feature rules, and record the function signatures that cause the state transition to obtain a set of function signatures;
[0008] Step S300: Design multiple finite state automata according to the state transition process, the set of function signatures, and the preset rule meanings;
[0009] Step S400: Obtain the set of function signatures that start each automaton. During static analysis, monitor the functions called by variables, and start the automaton according to the functions called by variables and the set of function signatures that start each automaton;
[0010] Step S500: After the automaton starts, track the access and propagation paths of variables, use the signatures of the functions called by the variables and their references as the input strings for the corresponding automata, and obtain the transformed state based on the current state of the automaton, the state transition function, and the input string until the automaton ends or an error occurs.
[0011] Preferably, the programming security feature rules include the language to which the rules belong, basic information, rule identification, rule classification, risk level, rule description, and specific rule content. Among them, the basic information includes the source, permission, accuracy level, and possibility level of the rules, and the specific rule content includes the state transition process and the state transition function.
[0012] Preferably, step S200 includes:
[0013] Define the corresponding state transition process according to the programming security feature rules. The state transition process includes the attributes of variables, the conversion relationships between attributes, and the conditions for attribute conversion. Among them, the condition for attribute conversion is the function signature that causes the attribute conversion, and store the programming security feature rules in the form of one-to-many for attributes and their conversion relationships, and one-to-many for conversion relationships and function signatures.
[0014] Preferably, the function signature in step S200 includes the identification name, namespace, class name, function name, exception cases, and application methods. Among them, the function signature is divided into the function signature that causes state transition and the function signature that starts the corresponding automaton, and the application methods include whether it can be inherited, implemented, or overloaded. The format of the exception cases is the same as that of the function signature.
[0015] Preferably, step S300 includes:
[0016] Set the attributes of variables as the various states of the automaton, set the conversion relationships between attributes as the state transitions of the automaton, set the set of function signatures as the state transition function of the automaton, and select the corresponding attributes as the start and end states of the automaton according to the preset rule meanings to complete the design of the finite state automaton.
[0017] Preferably, step S400 includes:
[0018] Traverse all statements in the program. When a statement calls a function, confirm that the signature of the called function is the function signature that causes the corresponding automaton to enter the start state, then store the signature of the called function in the set of function signatures that start the corresponding automaton, and store the automaton and the set of function signatures that start the corresponding automaton in a one-to-many form. During static analysis, obtain the signature of the function called by the variable, and match it with the set of function signatures that start the corresponding automaton. If the match is successful, start the corresponding automaton.
[0019] Preferably, step S500 includes:
[0020] Track the access and propagation paths of variables, and match the signatures of the functions called by the variables and their references with the set of function signatures that cause state transitions to perform state transitions on the automaton until the automaton ends or an error occurs.
[0021] Preferably, after step S500, the following is further included:
[0022] Step S600: When the state of the automaton is an error, report an error for the propagation paths of the variables that cause the error and their references.
[0023] The above method for custom feature rules based on function signatures first analyzes common security vulnerabilities in the analyzed language and summarizes programming security feature rules for preventing vulnerabilities; secondly, formats the feature rules, including the state transition process and state transition functions, and defines the function signatures of the state transition functions at the same time; then, through the formatted feature rule definition, studies the variable attribute conversion relationship, collects the function signatures that cause each attribute conversion, and designs a finite state automaton. The states of this automaton represent the attributes concerned during program analysis, and the state transition functions are the set of recorded function signatures; finally, during program static analysis, match the signatures of the functions called by the program, start the automaton according to the initial function signature, and track the variables involved. When a state transition function is encountered, perform the corresponding state change until the automaton ends or an error occurs. Extract these general state transition processes and abstract them into a series of feature rules based on function signatures. During static analysis, through the formatted feature rule definition document and simple automaton construction method, the custom feature rule technology based on function signatures has customizability and scalability. Users do not need to master the core technology of static analysis, and only need to understand the definition file format of the feature rules and the state changes of the automaton to expand the feature rule set and construct new feature rules. Brief Description of the Drawings
[0024] Figure 1 It is a flowchart of a method for custom feature rules based on function signatures provided by an embodiment of the present invention. Detailed Embodiment
[0025] In order to enable those skilled in the art to better understand the technical solutions of the present invention, the present invention will be further described in detail below with reference to the accompanying drawings.
[0026] In one embodiment, as Figure 1 shown, a method for custom feature rules based on function signatures includes the following steps:
[0027] Step S100: Count the security vulnerabilities of the analyzed language and design programming security feature rules for the security vulnerabilities.
[0028] Specifically, first, common security vulnerabilities in the analyzed language (such as Java) are collected through websites such as CWE and OWASP, and combined with the experience of rule designers to summarize the characteristic rules for preventing vulnerabilities.
[0029] In one embodiment, the programming security characteristic rules include the language to which the rule belongs, basic information, rule identifier, rule classification, risk level, rule description, and specific rule content. Among them, the basic information includes the source, permission, accuracy level, and likelihood level of the rule, and the specific rule content includes the state transition process and the state transition function.
[0030] Specifically, each rule consists of seven parts: the language to which the rule belongs, basic information, rule identifier, rule classification, risk level, rule description, and specific rule content. Among them, the basic information includes the source, permission, accuracy level, and likelihood level of the rule, and the specific rule content includes the state transition process and the state transition function.
[0031] Step S200: Define the corresponding state transition process according to the programming security characteristic rules, and record the function signatures that cause the state transition to obtain a set of function signatures.
[0032] Specifically, the state transition process needs to be defined according to the rule meaning and recorded in the formatted characteristic rule set as a condition for judging whether the program conforms to the rule. Among them, the state represents the attributes concerned during program analysis, such as the opening / closing of resources. The state transition is caused by a certain type of function signature. For example, if the rule is that the stream resource must be closed, then the initialization, closing, and error of the stream resource are states. The initialization can enter the closed state through functions such as close. At this time, if functions such as read are called again, it will be converted to the error state. The state transition process is defined in the specific rule content. start, end_of_scope, etc. represent states, and the single arrow represents the pointing relationship between states. The {} contains the state transition functions, that is, the set of function signatures that cause this state transition.
[0033] In one embodiment, step S200 includes:
[0034] Define the corresponding state transition process according to the programming security characteristic rules. The state transition process includes the attributes of variables, the conversion relationships between attributes, and the conditions for attribute conversion. Among them, the condition for attribute conversion is the function signature that causes the attribute conversion, and the programming security characteristic rules are stored in the form of one-to-many for attributes and their conversion relationships, and one-to-many for conversion relationships and function signatures.
[0035] In one embodiment, the function signature in step S200 includes an identification name, a namespace, a class name, a function name, exceptions, and an application method. Among them, the function signature is divided into a function signature that causes a state transition and a function signature that starts the corresponding automaton. The application method includes whether it can be inherited, implemented, or overloaded. The format of the exceptions is the same as that of the function signature. Specifically, the specific content of the rule is represented by a set of function signatures. The function signature consists of an identification name, a namespace, a class name, a function name, exceptions, and an application method. During program analysis, the function signature of the type that starts the corresponding automaton is preferentially matched, and then the rule is further matched based on this.
[0036] Step S300: Design a finite state automaton according to the state transition process, the set of function signatures, and the preset rule meaning.
[0037] Further, step S300 includes:
[0038] Set the attributes of the variable to each state of the automaton, set the conversion relationship between the attributes to the state transition of the automaton, set the set of function signatures to the state transition function of the automaton, and select the corresponding attributes as the start and end states of the automaton according to the preset rule meaning to complete the design of the finite state automaton.
[0039] Specifically, the automaton in step S300 is designed according to the state transition process. The state corresponds one-to-one with the attribute, and the state transition function it relies on is the set of function signatures. In addition, if the rule wants to determine whether a resource is closed, the resource is initialized as the start state and the resource being closed is the end state. The states in the state transition process have commonly used start and end_of_scope. Depending on the different rules being analyzed, their meanings are different. For example, for InputStream, they represent the opening and closing of the input stream resource respectively, and for Cookie, they represent being generated and being added respectively. However, in the automaton, it is always related to the start and end states of the automaton, and the remaining intermediate states are specific and are defined differently by different rules. Specific examples will be given below.
[0040] Step S400: Obtain the set of function signatures for starting each automaton. During static analysis, monitor the functions called by the variable, and start the automaton according to the functions called by the variable and the set of function signatures for starting each automaton.
[0041] Further, step S400 includes:
[0042] Traverse all statements in the program. When a statement calls a function, if the signature of the called function is the function signature that makes the corresponding automaton enter the starting state, then store the signature of the called function into the set of function signatures that start the corresponding automaton, and store the automaton and the set of function signatures that start the corresponding automaton in a one-to-many form. During static analysis, obtain the signature of the function called by the variable, and match it with the set of function signatures that start the corresponding automaton. If the match is successful, start the corresponding automaton.
[0043] In this embodiment, in order to analyze the program, for each defined rule, a corresponding automaton is designed. But when to start which automaton? In the feature rule document, the set of function signatures that start the corresponding automaton usually represents the set of initialization function signatures, which clearly exists in the specific content of each feature rule. When the program starts to be analyzed, when a variable calls a function, match the signature of this function with the above set of function signatures. If the match is successful, start the automaton corresponding to its rule.
[0044] Step S500: After the automaton is started, trace the access and propagation paths of the variables, use the signatures of the functions called by the variables and their references as the input string of the corresponding automaton, and obtain the converted state according to the current state, state transition function, and input string of the automaton until the automaton ends or an error occurs.
[0045] Further, step S500 includes:
[0046] Trace the access and propagation paths of the variables, and match the signatures of the functions called by the variables and their references with the set of function signatures that cause state transitions to convert the state of the automaton until the automaton ends or an error occurs.
[0047] In one embodiment, after step S500, it further includes:
[0048] Step S600: When the state of the automaton is an error, report an error for the propagation paths of the variables that cause the error and their references.
[0049] Specifically, the conversion of the automaton state is determined by the state transition function, and the state transition function is the set of function signatures that cause this state transition. These function signatures have already been recorded in the document when the feature rules are defined. After starting the automaton, continuously trace the variables. When the function called by this variable matches the state transition function, trigger the corresponding state transition, and report an error when entering the error state. In addition, when it is detected that the variable range is exceeded and the automaton has not entered the end state, detect its state and determine whether it is a state that does not conform to the rules. If so, report an error.
[0050] To better understand the working principle and technical effects of the present invention, the following takes the example that a file input stream resource must be released for detailed description.
[0051] public static void main(String[] args) throws IOException {
[0052] File file = new File("d:" + File.separator + "test.txt");
[0053] InputStream input = new FileInputStream(file);
[0054] InputStream alias = input;
[0055] byte b[] = new byte[(int) file.length()];
[0056] alias.read(b);
[0057] alias.close();
[0058] }
[0059] (1) Use the File class to find a file file. At this time, the signature of the called function is <java.io.File: void <init>(java.lang.String)>, has no impact on the automaton;
[0060] (2) Instantiate the superclass InputStream using the subclass FileInputStream to prepare an input object. At this time, the signature of the called function is <java.io.InputStream: void <init>()> The initialization function is recognized, the automaton is started, and the state changes from None to INIT;
[0061] (3) Assign to alias. At this time, the function is not called. According to the tracking of input, record its alias pointing relationship.
[0062] (4) Define the array b for read operation;
[0063] (5) Read the file input stream by the alias alias. At this time, the function signature is <java.io.InputStream:int read(byte[])>, and the automaton state changes from INIT to OPENED;
[0064] (6) Close the file input stream by the alias alias. At this time, the function signature is <java.io.InputStream:void close()>, and the automaton state changes from OPENED to CLOSED;
[0065] (7) When the detection reaches end_of_scope, that is, when the main function ends, and the automaton is in the CLOSED state at this time, the automaton is normally closed, and the file input stream resource is normally released.
[0066] In this example, if the automaton is in the INIT or OPENED state at end_of_scope, an error needs to be reported for the variable propagation path.
[0067] The above-mentioned custom feature rule method based on function signatures first analyzes the common security vulnerabilities in the analyzed language and summarizes the programming security feature rules for preventing vulnerabilities; secondly, formats the feature rules, including the state transition process and state transition functions, and defines the function signatures of the state transition functions at the same time; then, through the formatted feature rule definition, studies the variable attribute conversion relationship, collects the function signatures that cause each attribute conversion, and designs a finite state automaton. The state of this automaton represents the attributes concerned during program analysis, and the state transition function is the set of recorded function signatures; finally, during program static analysis, matches the signatures of the functions called by the program, starts the automaton according to the initial function signature, and tracks the variables involved. When encountering a state transition function, perform the corresponding state change until the automaton ends or an error occurs. Extract these general state transition processes and abstract them into a series of feature rules based on function signatures. In this way, when encountering problems such as stream resources that need to be closed during static analysis, they can be matched with these feature rules to effectively improve the processing efficiency.
[0068] The definition of documents through formatted feature rules and a simple automatic mechanism construction method enable the custom feature rule technology based on function signatures to have customizability and scalability. For some developers, due to different security issues involved, there is a corresponding set of feature rules, which can manually construct the required feature rules without understanding the core technology of static analysis, which is very important for technical personnel. By using the present invention, these developers only need to understand the feature rule format and the way of automaton state change, and they can expand the feature rule set to construct new feature rules.
[0069] Compared with the prior art, the present invention constructs an automaton by defining feature rules for various common security issues, tracks the changes of the attributes that variables need to be concerned about during program analysis, and solves the compliance / violation of variables with respect to each rule. The present invention supports custom feature rules. Users do not need to master the core technology of static analysis. They only need to understand the definition file format of feature rules and the automaton state change to manually construct, add, and modify rules.
[0070] The above has introduced in detail a method for custom feature rules based on function signatures provided by the present invention. Specific examples are used in this article to elaborate on the principle and implementation manner of the present invention. The description of the above embodiments is only used to help understand the core idea of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present invention, several improvements and modifications can be made to the present invention, and these improvements and modifications also fall within the protection scope of the claims of the present invention.< / init> < / init>
Claims
1. A custom feature rule method based on function signatures, characterized in that, The method includes the following steps: Step S100: Count the security vulnerabilities of the analyzed language, and design programming security feature rules for the security vulnerabilities; Step S200: Define a corresponding state transition process according to the programming security feature rules, and record the function signatures that cause the state transition to obtain a set of function signatures; Step S200 includes: Define a corresponding state transition process according to the programming security feature rules. The state transition process includes the attributes of variables, the conversion relationships between attributes, and the conditions for attribute conversion. Among them, the condition for attribute conversion is the function signature that causes the attribute conversion. Store the programming security feature rules in the form of one-to-many for attributes and their conversion relationships, and one-to-many for conversion relationships and function signatures; Step S300: Design multiple finite state automata according to the state transition process, the set of function signatures, and the preset rule meanings; Step S400: Obtain the set of function signatures for starting each automaton. During static analysis, monitor the functions called by variables, and start the automaton according to the functions called by variables and the set of function signatures for starting each automaton; Step S500: After the automaton is started, trace the access and propagation paths of variables, use the signatures of the functions called by the variables and their references as the input string of the corresponding automaton, and obtain the converted state according to the current state, state transition function, and input string of the automaton until the automaton ends or an error occurs.
2. The method according to claim 1, characterized in that The programming security feature rules include the language to which the rules belong, basic information, rule identification, rule classification, risk level, rule description, and specific rule content. Among them, the basic information includes the source, permission, accuracy level, and possibility level of the rules. The specific rule content includes the state transition process and the state transition function.
3. The method according to claim 2, characterized in that The function signatures described in Step S200 include identification name, namespace, class name, function name, exception situation, and application method. Among them, the function signatures are divided into function signatures that cause state transition and function signatures for starting the corresponding automaton. The application method includes whether it can be inherited, implemented, or overloaded. The format of the exception situation is the same as that of the function signature.
4. The method according to claim 3, wherein Step S300 includes: Set the attributes of the variables as the states of the automaton, set the conversion relationships between the attributes as the state transitions of the automaton, set the set of function signatures as the state transition functions of the automaton, and select the corresponding attributes as the start and end states of the automaton according to the preset rule meanings to complete the design of the finite state automaton.
5. The method according to claim 4, wherein Step S400 includes: Traverse all statements in the program. When a statement calls a function, confirm that the signature of the called function is the function signature that causes the corresponding automaton to enter the start state. Then store the signature of the called function into the set of function signatures for starting the corresponding automaton, and store the automaton and the set of function signatures for starting the corresponding automaton in a one-to-many form. During static analysis, obtain the signature of the function called by the variable, and match it with the set of function signatures for starting the corresponding automaton. If the match is successful, start the corresponding automaton.
6. The method according to claim 5, wherein Step S500 includes: Trace the variable access and propagation paths, and match the signatures of the functions called by the variable and its references with the set of function signatures that cause state transitions to perform state transitions on the automaton until the automaton ends or an error occurs.
7. The method according to claim 6, wherein After step S500, it further includes: Step S600: When the state of the automaton is an error, report an error for the propagation path of the variable that causes the error and its references.
Citation Information
Patent Citations
System and method for detecting and removing fault of software in operation
CN103257913A