A Method for Mining Vulnerabilities in Android System Service Memory Consumption
Through the method based on instruction recognition and directional fuzz testing, combined with static analysis and dynamic fuzz testing, the problems of low efficiency and insufficient accuracy of detecting memory consumption vulnerabilities in the existing technology are solved, and efficient and accurate memory consumption vulnerability detection is achieved.
Patent Information
- Application Number
- CN202111484888.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-07
- Publication Date
- 2025-07-04
- Estimated Expiration
- 2041-12-07
AI Technical Summary
Existing fuzz testing methods are difficult to efficiently and accurately detect memory consumption vulnerabilities in Android system services, especially due to the lack of systematic understanding of data storage instructions, seed selection that relies on expert knowledge, insensitive to memory changes, and high overhead of instrumentation methods.
Using a method based on instruction recognition and directional fuzz testing, combining static analysis to locate potential vulnerabilities, and design lightweight feedback collection, high-quality seed selection and staged seed generation mutation methods in dynamic fuzz testing, optimize seed selection and mutation strategies through simulated annealing algorithm to generate effective attack code.
It realizes efficient and accurate detection of memory consumption vulnerabilities in Android system services, reduces the time overhead of fuzzy testing, and improves detection efficiency and accuracy.
Smart Images

Figure CN114329478B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of software vulnerability mining, and particularly relates to a method for mining vulnerabilities in the memory consumption of Android system services. Background Art
[0002] Memory consumption vulnerabilities are a type of vulnerability that can occupy the memory resources of a process by triggering data storage instructions multiple times, affecting the normal operation of the process, and thus leading to a denial-of-service attack. There are a large number of unmonitored data storage processes in Android system services, and these data storage processes and their related data storage operations may lead to memory consumption vulnerabilities in Android system services. Many existing works detect memory leak problems by identifying data that is not needed but not released in the program, but this method is not applicable to detecting memory consumption vulnerabilities in Android system services because the memory data stored in Android system services may be used in the future and thus cannot be regarded as data that is not needed; in addition, some other works only focus on determining the boundary of program memory consumption.
[0003] Fuzz testing is an efficient vulnerability mining technology, but existing methods are difficult to meet the need for automated mining of memory consumption vulnerabilities in the Android system. Existing fuzz testing methods are difficult to meet the requirements for mining memory consumption vulnerabilities in Android system services. First, the design lacks a systematic understanding of data storage instructions, so they cannot effectively cover different types of data storage instructions in a large number of Android system service interfaces; second, most fuzz testing methods rely on domain knowledge provided by humans in input generation and seed selection. For example, AFLGO [1] uses a fixed time for stage division in seed selection, but different Android system service interfaces provide different functions, so a general solution that does not rely on expert knowledge is needed; in addition, although some works have proposed mitigation measures for this problem, they are still not efficient enough in mining memory consumption vulnerabilities. For example, Vuzzer [2] uses static analysis technology to aggressively extract data flow characteristics of conditional checks for input generation, but it is better to first understand the data storage process, then identify the data flow characteristics of conditional checks that have a data flow relationship with data storage instructions, and the conditional checks in the Android system usually depend on dynamic values determined by the system running state, so it is difficult to directly obtain them through static analysis; third, most existing tools are insensitive to changes in memory size and are difficult to use this feedback information to effectively improve the efficiency of directed fuzz testing; finally, the existing instrumentation methods of existing works have a large overhead and will seriously affect the efficiency of feedback collection. Summary of the Invention
[0004] The objective of the present invention is to provide a brand-new method for mining memory consumption vulnerabilities in Android system services based on instruction recognition and directed fuzz testing, which is applicable to the automated mining and verification of resource consumption vulnerabilities in Android system services.
[0005] The method for mining memory consumption vulnerabilities in Android system services based on instruction recognition and directed fuzz testing provided by the present invention combines static analysis to locate potential memory consumption vulnerabilities according to heuristic rules; and in the process of directed fuzz testing targeted at potential vulnerabilities, lightweight feedback collection, high-quality seed selection, and staged seed generation and mutation methods are designed for memory consumption vulnerabilities; the time overhead of the fuzz testing path exploration stage and the vulnerability attack stage is balanced during this process. The present invention can efficiently and accurately detect memory consumption vulnerabilities in Android system services. It is specifically divided into two stages: static analysis and dynamic fuzz testing.
[0006] (1) Static analysis stage; the task of static analysis is to locate potential vulnerabilities and generate initial inputs for fuzz testing; specifically, first locate data storage instructions and system service interfaces that can reach these instructions through heuristic rules; then collect the constraint conditions for reaching the data storage instructions and generate initial inputs for fuzz testing according to the constraint conditions.
[0007] (2) Dynamic fuzz testing stage, the purpose of dynamic fuzz testing is to determine whether the attack on the data storage instructions within the time window is sufficient to cause a security impact. The present invention proposes new methods in four aspects: feedback collection, seed selection, seed generation and mutation, and attack code generation during the dynamic fuzz testing process, so as to achieve efficient fuzz testing:
[0008] (1) Regarding feedback collection, the present invention designs a lightweight feedback collection method to guide fuzz testing; it includes efficiently collecting the execution paths and memory consumption status of the inputs during the fuzz testing process to evaluate the contribution of the seed inputs in terms of exploration and memory consumption; specifically, collect the distance of the execution path to the target instruction as the feedback information for fuzz testing exploration (exploration contribution), and collect the change in memory size as the feedback information for fuzz testing attack (memory consumption contribution);
[0009] (2) Regarding seed selection, fuzz testing needs to select high-quality seed inputs for mutation and execution; the present invention uses the simulated annealing algorithm and combines the collected feedback information to dynamically select and eliminate seed inputs;
[0010] (3) Regarding seed generation and mutation, the present invention adopts different mutation strategies to generate new inputs according to the stage of the seed in fuzz testing;
[0011] (4) Regarding attack code generation, the present invention reuses high-quality seeds in fuzz testing to generate effective attack codes.
[0012] For the process of the method of the present invention, please refer to Figure 1 as shown.
[0013] Further, in the static analysis stage:
[0014] For the potential vulnerability location, specifically, based on the observation of memory consumption vulnerabilities in Android system services, there are some constraints for the vulnerabilities - the system service needs to save references to the stored data, and the data structure used for storage has a variable size. Based on this observation, first identify all fields defined in the Android system service and all global static fields in the Android framework; then select container fields from them and mark their expansion operations as data storage instructions; finally, use backward control flow analysis to find system service interfaces that may reach the data storage instructions, and filter out interfaces whose parameters have data dependencies with the target instructions through data flow analysis.
[0015] The generation of the initial input for fuzz testing is to select the initial input from the branch conditions of the path constraints. Usually, the branch statement compares the input with specific constants or dynamic system state variables (such as UserHandler.getUserId()). Therefore, the present invention directly uses constants or the return values of such functions as the initial input.
[0016] During the static analysis process, the present invention also divides the interface parameters into control flow-related inputs, data flow-related inputs, and other types of inputs according to the results of control flow and data flow analysis. Then, fuzz testing can selectively mutate different types of inputs at different stages.
[0017] Further, in the fuzz testing stage:
[0018] (1) Regarding feedback collection
[0019] The calculation process of the distance from the execution path to the target instruction is as follows: Considering that whether the data storage instructions are called depends on the preconditions in the control flow structure of their callers, the present invention collects the execution paths at the function level and uses the control flow graph (CFG) information within the function to improve the accuracy of the distance calculation at the function level, thereby calculating the estimated probability of the function reaching the target, and then using this probability to calculate the "distance" of the directed fuzz testing. Specifically, first set the reachability probability of the target function on the call graph (CG) of the function to 1.0, and then traverse backward on the CG graph to calculate the estimated probability of each reachable function reaching the target. During the fuzz testing process, for the execution path of the seed input, take the maximum value c r of the function estimated probabilities as the exploration contribution score of the seed. During the backward traversal, estimate the probability of adjacent functions on the function call CG according to the CFG of the function, and then calculate the estimated probability of the function finally calling the target function through traversal. AsFigure 3 as shown
[0020] To observe the cumulative effects of multiple executions, the present invention designs a memory size monitor. Specifically, the monitor selects two indicators to observe the changes in memory size. They are: 1) JVM heap size. The JVM of Android limits the upper limit of the heap memory occupied by a process; 2) Customized memory size. Customized memory objects are distributed in Android system services. These objects can be identified through static analysis. The present invention further finds the conditional judgment statements for checking the sizes of these objects through control flow analysis, and extracts the constants representing the upper limit of the customized memory size from them. By observing the size m of the system service memory indicator before the execution of the observation interface i , and the size m after the execution e , combined with the memory indicator upper limit m t , the memory consumption contribution c of the seed can be calculated m :
[0021]
[0022] (2) Regarding seed selection
[0023] The specific process is as follows: Select seeds that are closer to the "distance" target or consume more memory resources, and use the simulated annealing algorithm to dynamically select exploratory or aggressive seeds, while preventing fuzz testing from wasting too much time on paths where it is difficult to succeed in the exploration stage or attack. The key of the simulated annealing algorithm is to gradually eliminate inefficient seeds. For seeds that are executed or mutated multiple times, the simulated annealing algorithm gradually reduces its "temperature", that is, reduces its priority of being selected and mutated
[0024] (3) Regarding seed generation and mutation
[0025] New inputs are generated by adopting different mutation strategies according to the stage where the seed is in the fuzz testing; the specific process is as follows
[0026] In the exploration stage, the goal of fuzz testing is to find seeds that can reach the fuzz testing target. Therefore, in this stage, the input parameters related to the control flow of the system service to be tested are mainly concerned. After selecting a seed in this stage, a series of new seeds will be generated based on the selected seed by compiling the input related to the control flow of the seed. The number of generated seeds depends on the energy of the seed
[0027] In the attack phase, to ensure that the objectives of fuzz testing can be stably executed, the present invention will not mutate the input parameters related to the input, but only mutate the parameters related to memory consumption. Because in some cases, repeatedly calling an interface with the same input parameters may not result in cumulative memory consumption, so mutating the parameters related to memory consumption in this phase is necessary. For example, when the data storage instruction is to insert data into a hash table, if the inserted data has the same key value as the existing data in the hash table, then this insertion operation will not increase the memory occupancy of the hash table. The purpose of this phase is to consume the memory resources of the Android system service. Therefore, the present invention will mutate the input related to memory consumption in the direction of increasing the memory size. Specifically, we observe that memory consumption inputs usually have two uses: 1) the size of memory allocation, such as the length of a container; 2) the content stored in memory, such as the elements stored in a container. For the first type of input, they are usually of a specific integer type. Therefore, the present invention tends to generate larger integer values for such inputs and generate inputs with a smaller difference during mutation. The memory occupied by the second type of input usually depends on the String objects stored in the input, and the length of String objects in Java is unlimited. Therefore, the present invention tends to generate different and longer String values for such inputs in this phase.
[0028] (4) Regarding the generation of attack code
[0029] Reuse the high-quality seeds in fuzz testing to generate effective attack code. The specific process is as follows: First, collect the high-quality seeds in fuzz testing, and then reuse the seeds in the attack phase to generate new seeds in the attack code; in the attack code, only mutate the input related to the input. Construct a third-party Android application according to the code template, which contains code for sending requests to the Android system service through Binder inter-process communication. The generated application can consume the memory resources of the Android system service. Description of the drawings
[0030] Figure 1 It is the overall system architecture diagram.
[0031] Figure 2 It is an example of extracting the initial input from Android.
[0032] Figure 3 It is an example of distance calculation in feedback collection. Calculate the probability that function e reaches the target data storage instruction s according to the information provided by the control flow graph in the function. Detailed implementation manners
[0033] The present invention designs and implements the above-mentioned method for mining memory consumption vulnerabilities in Android system services based on instruction recognition and targeted fuzz testing. This section details the specific implementation of this framework.
[0034] (1) Static Analysis
[0035] The present invention uses Smali / BakSmali and vDexExtractor tools to disassemble the Java bytecode of the Android system, and uses the Soot framework to implement static analysis of the Android system code. First, fields of various containers such as arrays, sets, maps, queues, lists, or databases and expansion operations such as add(), put(), and insert() in system services and global statics are screened as data storage instructions, and a total of 96 such instructions are obtained. Then, backward control flow analysis and data flow analysis are performed on these instructions to determine reachable interfaces and functions with data-dependent parameters existing with the data storage instructions. In this way, 609 fuzz testing targets and 1244 related public interfaces are screened out.
[0036] (2) Fuzz Testing
[0037] The present invention collects input feedback through dynamic instrumentation and uses it for seed selection. Specifically, the Xposed framework is used to perform function-level instrumentation on the Android system to collect the function paths passed by the inputs in dynamic fuzz testing, and combined with static calculation methods, the distance from the interface function to the fuzz testing target is estimated, so as to obtain the exploration contribution score c of the input execution. r In addition, instrumentation is performed before and after the execution of data storage instructions to collect the size change of customized memory during interface calls. In order to collect the overall memory change of the system JVM, the seeds and their multiple variants are executed, and the memory change during this period is collected to observe the overall memory change. Thus, the memory consumption contribution c can be estimated. m
[0038] When selecting seeds, the present invention gradually eliminates inefficient seeds in the way of simulated annealing. First, according to the number of times N that the seeds are mutated and executed, the "temperature" coefficient is calculated:
[0039]
[0040] Thus, the final contribution score c of the seeds is calculated as c = (c r +c m ) * T. Then, the energy of the seeds (the number of times of single-round mutation execution) is calculated according to this score where b is the initial energy and k is 100.
[0041] When generating seed mutations, the present invention dynamically generates inputs according to the stage at which the seeds are located. For example, the system service interface accountAuthenticated() has only one parameter, android.accounts.Account, which contains three fields, namely name, type, and accessId. The first of these fields is identified as an input related to memory consumption, and the remaining two are inputs related to control flow. Therefore, in the fuzz testing during the attack phase of the present invention, the name field will be mutated into a string with a longer length. This can increase the efficiency of mutation and cause memory consumption to occur more rapidly.
[0042] When generating and mutating seeds, the mutation strategy is dynamically selected. Compared with the fixed time allocation strategy, this strategy can more effectively find vulnerabilities. Specifically, the 5:1, 1:1, and dynamic time allocation strategies are used to conduct 5 rounds of targeted fuzz testing for 300 seconds each on the discovered vulnerabilities. It is found that the speed at which the dynamic strategy triggers vulnerability crashes is approximately four times that of the other two allocation strategies.
[0043] The analysis time of the present invention for the Android system is approximately 204 hours. Among them, static analysis takes about 4 hours to locate 435 potential dangerous data storage instructions and 963 public interfaces, and dynamic analysis takes about 148 hours for exploration and 52 hours for attacks. In the experiment, the fuzz testing timeout for each interface is 300 seconds, and the tool outputs a total of 673 crashes and 673 attack codes. After analysis, these crashes cover 40 vulnerabilities, 35 of which are memory consumption - type vulnerabilities, and there are no false positives. The detected vulnerabilities can be triggered by 474 different interfaces.
[0044] References
[0045] [1] Marcel,et al."Directed greybox fuzzing."Proceedings of the2017ACM SIGSAC Conference on Computer and Communications Security.2017.
[0046] [2]Rawat,Sanjay,et al."VUzzer:Application - aware EvolutionaryFuzzing."NDSS.Vol.17.2017。
Claims
1. A method for mining vulnerabilities in the memory consumption of Android system services, characterized in that It is divided into two stages: static analysis and dynamic fuzz testing; specifically: (1) Static analysis stage; the task of static analysis is to locate potential vulnerabilities and generate initial inputs for fuzz testing; specifically, first, locate data storage instructions and system service interfaces that can reach these instructions through heuristic rules; then collect the constraint conditions for reaching the data storage instructions, and generate initial inputs for fuzz testing according to the constraint conditions; The specific method for locating potential vulnerabilities is as follows: based on the observation of memory consumption vulnerabilities in Android system services, there are constraint conditions for vulnerabilities - the system service needs to save references to the stored data, and the data structure used for storage has a variable size; accordingly, first identify all fields defined in the Android system service and all global static fields in the Android framework; then select container fields from them and mark their expansion operations as data storage instructions; finally, use backward control flow analysis to find system service interfaces that may reach the data storage instructions, and filter out interfaces whose parameters have data dependencies with the target instructions through data flow analysis; The generation of initial inputs for fuzz testing selects initial inputs from the branch conditions of path constraints; branch statements compare the input with specific constants or dynamic system state variables; therefore, directly use constants or the return values of such functions as initial inputs; (2) Dynamic fuzz testing stage, the purpose of dynamic fuzz testing is to determine whether the attacks on data storage instructions within the time window are sufficient to cause security impacts; during the dynamic fuzz testing process, new methods are adopted in four aspects: feedback collection, seed selection, seed generation and mutation, and attack code generation, so as to achieve efficient fuzz testing: specifically: (1) Regarding feedback collection, design a lightweight feedback collection method to guide fuzz testing; including efficiently collecting the execution paths and memory consumption status of inputs during fuzz testing, so as to evaluate the contributions of seed inputs in terms of exploration and memory consumption; specifically, collect the distance from the execution path to the target instruction as the feedback information for fuzz testing exploration, called exploration contribution, and collect the change in memory size as the feedback information for fuzz testing attacks, called memory consumption contribution; (2) Regarding seed selection, fuzz testing needs to select high-quality seed inputs for mutation and execution; specifically, use the simulated annealing algorithm, combined with the collected feedback information, to dynamically select and eliminate seed inputs; (3) Regarding seed generation and mutation, different mutation strategies are adopted according to the stage of the seed in fuzz testing to generate new inputs; (4) Regarding attack code generation, reuse high-quality seeds in fuzz testing to generate effective attack codes.
2. The method for mining Android system service memory consumption - related vulnerabilities according to claim 1, wherein, During the static analysis process, interface parameters are also divided into control flow-related inputs, data flow-related inputs, and other types of inputs according to the results of control flow and data flow analysis, which is convenient for fuzz testing to selectively mutate different types of inputs in different stages.
3. The method for mining Android system service memory consumption vulnerabilities according to claim 2, characterized in that In the fuzz testing phase, the calculation process of the distance from the execution path to the target instruction described in the feedback collection is as follows: Based on the fact that data storage instructions are called depending on the preconditions in the control flow structure of their callers, collect the execution paths at the function level, and use the intra-function control flow (CFG) information to improve the accuracy of the function-level distance calculation, thereby calculating the estimated probability of the function reaching the target; then use this probability to calculate the "distance" of the directed fuzz testing; specifically, first set the reachability probability of the target function on the function call graph (CG) to 1.0, and then traverse backward on the function call graph to calculate the estimated probability of each reachable function reaching the target. During the fuzzing process, for the execution path of the seed input, the maximum value of the estimated probability of the function is used as the exploration contribution c of the seed. r During the backward traversal, according to the intra-function control flow of the function, the probability of adjacent functions on the function call graph is estimated, and then the estimated probability of the function finally calling the target function is calculated by traversing.
4. The method for mining Android system service memory consumption vulnerabilities according to claim 3, characterized in that To observe the cumulative consequences of multiple executions, design a memory size monitor; this monitor selects two indicators to observe the memory size changes, namely: (1) JVM heap size; (2) customized memory size; find the conditional judgment statements that check the sizes of these objects through control flow analysis, and extract the constants representing the upper limit of the customized memory size from them. The size m of the system service memory indicator before executing through the observation interface i , the size m after execution e , combined with the upper limit m of the memory indicator t , calculate the memory consumption contribution c of the seed m :
5. The method for mining Android system service memory consumption vulnerabilities according to claim 4, wherein In the fuzz testing phase, the specific process for seed selection is as follows: Select seeds that are "closer" to the target or consume more memory resources, and use the simulated annealing algorithm to dynamically select exploratory or aggressive seeds, while preventing fuzz testing from wasting too much time on paths where exploration or attack is difficult to succeed; through the simulated annealing algorithm, gradually eliminate inefficient seeds; for seeds that have been executed or mutated multiple times, gradually reduce their priority of being selected and mutated through the simulated annealing algorithm.
6. The method for mining Android system service memory consumption vulnerabilities according to claim 5, characterized in that, In the fuzz testing phase, for the seed generation and mutation described in the feedback collection, different mutation strategies are adopted according to the stage of the seed in the fuzz testing to generate new inputs, and the specific process is as follows: In the exploration phase, the goal of fuzz testing is to find seeds that can reach the fuzz testing target. Therefore, in this phase, mainly focus on the input parameters related to the service interface and control flow of the system under test; after selecting the seeds in this phase, based on the selected seeds, generate a series of new seeds by compiling the input related to the control flow of the seeds, and the number generated depends on the energy of the seeds. In the attack phase, to ensure that the goal of fuzz testing can be stably executed to, do not mutate the input parameters related to the input of the seeds, but only mutate the parameters related to memory consumption; specifically, considering that there are two uses for memory consumption inputs: (1) the size of memory allocation; (2) the content stored in memory; for the first type of input, which is usually a specific integer type, generate larger integer values for this type of input, and generate inputs with smaller differences during mutation; for the second type of input, the memory occupied depends on the String objects stored in the input, and the length of String objects in Java is unlimited; therefore, in this phase, generate different and longer String values for this type of input.
7. The method for mining Android system service memory consumption vulnerabilities according to claim 6, characterized in that In the fuzz testing phase, for generating attack code as described in the reuse of high-quality seeds in fuzz testing to produce effective attack code, the specific process is as follows: First, collect high-quality seeds in fuzz testing, and then reuse the seeds in the attack phase to generate new seeds in the attack code; in the attack code, only mutate the inputs related to the input; construct a third-party Android application according to the code template, where the code template contains code for sending requests to Android system services through Binder inter-process communication, and the generated application can consume the memory resources of the Android system services.
Citation Information
Patent Citations
Static and dynamic vulnerability analysis and mining method for power industrial control system
CN110519216A
Application vulnerability detection method and system
CN111291377A