Vulnerability Identification Method and System for Embedded Development Programs

By building a virtual machine in embedded development, conducting preliminary and secondary detection of embedded code, and generating boundary condition tables, the problem of low vulnerability detection efficiency in embedded development is solved, and efficient and comprehensive vulnerability detection is achieved.

CN114579972BActive Publication Date: 2025-05-27BEIJING ZHONGKE WEILAN TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210049942.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-01-17
Publication Date
2025-05-27
Estimated Expiration
2042-01-17

AI Technical Summary

Technical Problem

In embedded development, it is difficult for the existing technology to efficiently detect vulnerabilities in the code, resulting in cumbersome and time-consuming debugging process.

Method used

By building a virtual machine, receiving embedded code and test tables uploaded by users, performing preliminary and secondary detection, and generating boundary condition tables to achieve all-round and efficient detection of embedded code.

Benefits of technology

Improve debugging efficiency, simplify the code download process, enhance vulnerability discovery capabilities, and reduce detection costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114579972B_ABST
    Figure CN114579972B_ABST
Patent Text Reader

Abstract

The present invention relates to the technical field of vulnerability detection, and specifically discloses a method and system for identifying vulnerabilities in embedded development programs. The method includes receiving embedded code containing environmental parameters uploaded by a user, generating a virtual machine based on the environmental parameters; receiving a test table uploaded by the user, and preliminarily detecting the embedded code according to the test table; when the embedded code passes the preliminary detection, traversing the embedded code, identifying and extracting conditional code in the embedded code, and generating a boundary condition table according to the conditional code; performing secondary detection on the embedded code according to the boundary condition table, and generating a detection report according to the preliminary detection result and the secondary detection result. By building a virtual machine, the present invention simplifies the code download process. Through code detection, a boundary condition table is generated to perform all-round and high-efficiency detection on the code, with strong vulnerability discovery ability and high detection efficiency, which is convenient for popularization and use.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of vulnerability detection, and specifically to a method and system for identifying vulnerabilities in embedded development programs. Background Art

[0002] Embedded development refers to using discrete components or integrated devices for circuit design, structural design, then software programming (usually in a high-level language), experimentation, and after multiple rounds of design modification and production, finally completing the development of the entire system.

[0003] Embedded development is a development technology that combines software and hardware. It is necessary to continuously debug to discover vulnerabilities in the code; during the debugging process, each debugging requires downloading the code to the microprocessor and then observing the debugging results. These processes are highly repetitive and cumbersome. In addition, the energy of the staff is limited. If every condition is tested, the workload is extremely large.

[0004] Therefore, how to improve the debugging efficiency and detect vulnerabilities in embedded code faster is the technical problem that the technical solution of the present invention wants to solve. Summary of the Invention

[0005] The purpose of the present invention is to provide a method and system for identifying vulnerabilities in embedded development programs to solve the problems raised in the above background art.

[0006] To achieve the above purpose, the present invention provides the following technical solutions:

[0007] A method for identifying vulnerabilities in an embedded development program, the method comprising:

[0008] Receiving the embedded code containing environmental parameters uploaded by the user, and generating a virtual machine based on the environmental parameters;

[0009] Receiving the test table uploaded by the user, and preliminarily detecting the embedded code according to the test table; wherein, the test table includes input items and corresponding output items;

[0010] When the embedded code passes the preliminary detection, traversing the embedded code, identifying and extracting the conditional code in the embedded code, and generating a boundary condition table according to the conditional code;

[0011] Performing secondary detection on the embedded code according to the boundary condition table, and generating a detection report according to the preliminary detection result and the secondary detection result.

[0012] As a further limitation of the technical solution of the present invention: the step of receiving the embedded code containing environmental parameters uploaded by the user and generating a virtual machine based on the environmental parameters includes:

[0013] Receive the model number of the electronic component and the connection relationship uploaded by the user; the environmental parameters include the model number of the electronic component;

[0014] Read virtual components from a preset virtual component library according to the model number of the electronic component. When the reading result is empty, open the virtual component creation port;

[0015] Obtain the hardware architecture and data structure of the virtual component according to the virtual component creation port;

[0016] Receive the connection relationship to connect the virtual components, compile the embedded code uploaded by the user according to the connected virtual components. When the compilation result is successful, package the connected virtual components to obtain a virtual machine.

[0017] As a further limitation of the technical solution of the present invention: the step of traversing the embedded code, identifying and extracting the conditional code in the embedded code, and generating a boundary condition table according to the conditional code when the embedded code passes the preliminary detection includes:

[0018] When the embedded code passes the preliminary detection, traverse the embedded code and mark the delimiters in the embedded code;

[0019] Split the embedded code into sub-codes with position information according to the delimiters; the position information is the relative position relative to the starting point of the embedded code;

[0020] Extract the conditional statements in the sub-codes, read the boundary conditions in the conditional statements, and obtain a boundary condition sub-table with the position information of the sub-codes as the index items;

[0021] Connect the boundary condition sub-tables to obtain a boundary condition table.

[0022] As a further limitation of the technical solution of the present invention: the step of performing a secondary detection on the embedded code according to the boundary condition table and generating a detection report according to the preliminary detection result and the secondary detection result includes:

[0023] Read the boundary condition sub-tables and their position information in the boundary condition table;

[0024] Extract and combine all the boundary conditions in the boundary condition sub-tables to obtain a preset number of boundary condition groups;

[0025] Locate the sub-codes in the embedded code according to the position information;

[0026] Input the boundary condition groups into the sub-codes to obtain output information, and generate a detection report according to the output information.

[0027] As a further limitation of the technical solution of the present invention: The method further includes:

[0028] Dividing the virtual machines into several independent modules according to a preset classification rule, and obtaining the storage structure of each module; wherein, the storage structure includes a hardware structure and an operation rule;

[0029] Determining test data according to the storage structure, and sending the test data to the corresponding module to obtain the output data of each module; wherein, the test data includes random data and instruction data, and the length of the random data is determined by the hardware structure;

[0030] Performing regularity analysis and correlation analysis on the output data and the test data, and generating a risk value of the module according to the results of the regularity analysis and the correlation analysis;

[0031] When the risk value is greater than a preset risk threshold, marking the corresponding module, and generating a risk assessment report according to the marked module.

[0032] As a further limitation of the technical solution of the present invention: The step of performing regularity analysis on the output data and the test data includes:

[0033] Converting the output data and the test data into a first eigenvalue and a second eigenvalue respectively according to a preset conversion formula;

[0034] Generating coordinate points in a preset plane graph according to the first eigenvalue and the second eigenvalue; the plane graph contains coordinate axes, and the coordinate axes are adaptively adjusted in real time according to the magnitudes of the first eigenvalue and the second eigenvalue;

[0035] Performing discreteness analysis on the plane graph containing coordinate points, and generating a regularity level according to the results of the discreteness analysis.

[0036] As a further limitation of the technical solution of the present invention: The step of performing correlation analysis on the output data and the test data includes:

[0037] Extracting the instruction data in the test, and converting the instruction data and the test data into a third eigenvalue and a second eigenvalue respectively according to a preset conversion formula to obtain an eigenvalue group;

[0038] Generating a sampling table according to the eigenvalue group, randomly extracting a preset number of eigenvalue groups in the sampling table, and determining a fitting function;

[0039] Inputting the third eigenvalue in other eigenvalue groups into the fitting function to obtain a predicted value;

[0040] Calculate the offset rate between the predicted value and the corresponding second eigenvalue, and determine the association level according to the offset rate.

[0041] The technical solution of the present invention also provides a vulnerability identification system for an embedded development program, and the system includes:

[0042] A virtual machine generation module, configured to receive the embedded code containing environment parameters uploaded by a user, and generate a virtual machine based on the environment parameters;

[0043] A preliminary detection module, configured to receive a test form uploaded by a user, and perform preliminary detection on the embedded code according to the test form; wherein, the test form includes input items and corresponding output items;

[0044] A boundary condition extraction module, configured to traverse the embedded code to identify and extract conditional code in the embedded code when the embedded code passes the preliminary detection, and generate a boundary condition table according to the conditional code;

[0045] A secondary detection module, configured to perform secondary detection on the embedded code according to the boundary condition table, and generate a detection report according to the preliminary detection result and the secondary detection result.

[0046] As a further limitation of the technical solution of the present invention: the virtual machine generation module includes:

[0047] A component acquisition unit, configured to receive the electronic component model and connection relationship uploaded by a user; the environment parameters include the electronic component model;

[0048] A new creation unit, configured to read virtual components from a preset virtual component library according to the electronic component model, and open a virtual component new creation port when the reading result is empty;

[0049] A data reading unit, configured to obtain the hardware architecture and data structure of the virtual component according to the virtual component new creation port;

[0050] A compilation verification unit, configured to connect virtual components according to the connection relationship, compile the embedded code uploaded by a user according to the connected virtual components, and encapsulate the connected virtual components when the compilation result is successful to obtain a virtual machine.

[0051] As a further limitation of the technical solution of the present invention: the boundary condition extraction module includes:

[0052] A delimiter marking unit, configured to traverse the embedded code to mark delimiters in the embedded code when the embedded code passes the preliminary detection;

[0053] A code splitting unit for splitting the embedded code into sub-codes with position information according to the delimiter; the position information is the relative position relative to the starting point of the embedded code;

[0054] A sub-table generation unit for extracting conditional statements in the sub-codes, reading boundary conditions in the conditional statements, and obtaining a boundary condition sub-table with the position information of the sub-codes as index items;

[0055] A connection unit for connecting the boundary condition sub-tables to obtain a boundary condition table.

[0056] Compared with the prior art, the beneficial effects of the present invention are as follows: By building a virtual machine, the present invention simplifies the code download process. Through code detection, a boundary condition table is generated to detect the code comprehensively and efficiently, with strong vulnerability discovery ability and high detection efficiency, which is convenient for popularization and use. BRIEF DESCRIPTION OF THE DRAWINGS

[0057] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings in the following description are only some embodiments of the present invention.

[0058] Figure 1 Shows a flowchart of a method for identifying vulnerabilities in an embedded development program.

[0059] Figure 2 Shows a first sub-flowchart of a method for identifying vulnerabilities in an embedded development program.

[0060] Figure 3 Shows a second sub-flowchart of a method for identifying vulnerabilities in an embedded development program.

[0061] Figure 4 Shows a third sub-flowchart of a method for identifying vulnerabilities in an embedded development program.

[0062] Figure 5 Shows a block diagram of the composition structure of a vulnerability identification system for an embedded development program.

[0063] Figure 6 Shows a block diagram of the composition structure of a virtual machine generation module in a vulnerability identification system for an embedded development program.

[0064] Figure 7 Shows a block diagram of the composition structure of a boundary condition extraction module in a vulnerability identification system for an embedded development program. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0065] In order to make the technical problems, technical solutions and beneficial effects to be solved by the present invention more clearly understood, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.

[0066] Embodiment 1

[0067] Figure 1 The flowchart of the method for identifying vulnerabilities in an embedded development program is shown. In an embodiment of the present invention, a method for identifying vulnerabilities in an embedded development program includes:

[0068] Step S100: Receive the embedded code containing environmental parameters uploaded by the user, and generate a virtual machine based on the environmental parameters;

[0069] Embedded code will have its own application environment. For example, in the existing stm32 development board for learning, there are many basic modules. After the staff designs the code, they will input the code into the system, and then observe the outputs of each module, and debug the embedded code according to the outputs. The purpose of step S100 is to generate a virtual machine according to the actual situation. For example, generate a virtual stm32 development board and perform code testing in the virtual machine.

[0070] Step S200: Receive the test table uploaded by the user, and preliminarily detect the embedded code according to the test table; wherein, the test table includes input items and corresponding output items;

[0071] The process of preliminary detection is relatively simple. Its main body is actually the staff. The staff inputs the content to be tested into the test table. The test table contains input items and corresponding predicted output items. The input items are input into the virtual machine in turn to obtain the actual output items, and comparing the actual output items and the predicted output items can complete the preliminary detection step.

[0072] Step S300: When the embedded code passes the preliminary detection, traverse the embedded code, identify and extract the conditional code in the embedded code, and generate a boundary condition table according to the conditional code;

[0073] In embedded code, there are various judgment conditions. If the programming language is C language, then judgment conditions will exist in if statements or loop statements. The boundary points of these judgment conditions are the places where errors are most likely to occur. It can be imagined that in an embedded code with a large amount of code, there are many combination ways of boundary conditions. It is obviously impossible for the staff to test them one by one, but the detection of these boundary conditions is very important. Therefore, the purpose of step S300 is to automatically complete the detection of boundary conditions.

[0074] Step S400: Perform secondary detection on the embedded code according to the boundary condition table, and generate a detection report based on the preliminary detection result and the secondary detection result.

[0075] Step S400 is a data integration process, and a detection report is generated according to the results of the two detections.

[0076] Figure 2 The first sub - process block diagram of the vulnerability identification method for the embedded development program is shown. The steps of receiving the embedded code containing environmental parameters uploaded by the user and generating a virtual machine based on the environmental parameters include steps S101 to S104:

[0077] Step S101: Receive the electronic component model and connection relationship uploaded by the user; the environmental parameters include the electronic component model.

[0078] Step S102: Read virtual components in the preset virtual component library according to the electronic component model. When the reading result is empty, open the virtual component new - building port.

[0079] Step S103: Obtain the hardware architecture and data structure of the virtual component according to the virtual component new - building port.

[0080] Step S104: Receive the connection relationship to connect virtual components, compile the embedded code uploaded by the user according to the connected virtual components. When the compilation result is successful, package the connected virtual components to obtain a virtual machine.

[0081] Steps S101 to S104 further define the generation process of the virtual machine. The generation process of the virtual machine is actually the process of determining virtual components. Most virtual components are standard components. Of course, there are also a small number of components that are not included in the virtual component library for various reasons. Therefore, step S103 also provides the function of user input; after building the virtual machine, compile the embedded code based on the virtual machine. This step can not only detect the running situation of the virtual machine but also detect the syntax errors of the embedded code.

[0082] Figure 3 The second sub - process block diagram of the vulnerability identification method for the embedded development program is shown. The steps of traversing the embedded code, identifying and extracting conditional code in the embedded code, and generating a boundary condition table according to the conditional code when the embedded code passes the preliminary detection include steps S301 to S304:

[0083] Step S301: When the embedded code passes the preliminary detection, traverse the embedded code and mark the delimiters in the embedded code.

[0084] Step S302: Split the embedded code into sub-codes containing position information according to the delimiter; the position information is the relative position with respect to the starting point of the embedded code.

[0085] Step S303: Extract the conditional statements in the sub-codes, read the boundary conditions in the conditional statements, and obtain a boundary condition sub-table with the position information of the sub-codes as index items.

[0086] Step S304: Connect the boundary condition sub-tables to obtain a boundary condition table.

[0087] The key points of Steps S301 to S304 are the combination process of boundary conditions. When the amount of code in the embedded code is very large, there may also be a lot of judgment conditions. For the combination methods of these judgment conditions, it is based on the multiplication principle. Therefore, there are also many combination methods, and the calculation amount of the finally generated boundary condition table is extremely large. Therefore, if the embedded code is split and independent boundary condition combination operations are performed on each sub-code, the work efficiency can be greatly improved.

[0088] Figure 4 The third sub-flow block diagram of the vulnerability identification method for the embedded development program is shown. The steps of performing secondary detection on the embedded code according to the boundary condition table and generating a detection report based on the preliminary detection result and the secondary detection result include Steps S401 to S404:

[0089] Step S401: Read the boundary condition sub-table and its position information in the boundary condition table.

[0090] Step S402: Extract and combine all the boundary conditions in the boundary condition sub-table to obtain a preset number of boundary condition groups.

[0091] Step S403: Locate the sub-codes in the embedded code according to the position information.

[0092] Step S404: Input the boundary condition groups into the sub-codes to obtain output information, and generate a detection report according to the output information.

[0093] Steps S401 to S404 are result output steps. On the premise that the boundary condition table is determined, detecting the embedded code based on the boundary condition table is simply a database-based reading operation.

[0094] As a preferred embodiment of the technical solution of the present invention, the method further includes:

[0095] Classify the virtual machines into several independent modules according to preset classification rules, and obtain the storage structures of each module; wherein, the storage structure includes a hardware structure and an operation rule.

[0096] Determine test data according to the storage structure, send the test data to corresponding modules, and obtain the output data of each module; wherein, the test data includes random data and instruction data, and the length of the random data is determined by the hardware structure;

[0097] Conduct regularity analysis and correlation analysis on the output data and the test data, and generate a risk value for the module according to the results of the regularity analysis and the correlation analysis;

[0098] When the risk value is greater than a preset risk threshold, mark the corresponding module, and generate a risk assessment report according to the marked modules.

[0099] The above content is a further limitation based on the technical solution of the present invention and is also a special detection method. According to the input and output data, the entire embedded code is analyzed macroscopically to determine whether there are vulnerabilities.

[0100] For embedded development, it is a technology that combines software and hardware. The reasons for generating vulnerabilities include not only code but also memory aspects. There is such an attack method that by inputting a large amount of data, a certain memory overflows, and then attacks are carried out through these overflowed data. This is a type of vulnerability almost ignored by the existing technologies.

[0101] The core idea of the above content is to detect the embedded code through some overflowed data, that is, test data. The test data includes random data and instruction data. The random data is related to the storage capacity of the hardware structure and needs to reach the storage limit of the hardware structure, and then make the instruction data be the overflowed data; then, obtain the output data generated by the embedded code according to this test data. If these output data have their own rules or there is a certain correlation between them and the instruction data, it indicates that there may be vulnerabilities.

[0102] It is worth mentioning that in the existing embedded development hardware systems, there are rarely direct error reports, because if there are many error requirements for each module, then a little fluctuation will cause the entire embedded code to fail to run.

[0103] Further, the steps for conducting regularity analysis on the output data and the test data include:

[0104] Convert the output data and the test data into a first eigenvalue and a second eigenvalue respectively according to a preset conversion formula;

[0105] Generate coordinate points in a preset plane graph according to the first eigenvalue and the second eigenvalue; the plane graph contains coordinate axes, and the coordinate axes are adaptively adjusted in real time according to the magnitudes of the first eigenvalue and the second eigenvalue;

[0106] Perform a discreteness analysis on the plane graph containing the coordinate points, and generate a regularity level according to the discreteness analysis result.

[0107] The purpose of the regularity analysis is to determine whether there is a regularity in the test data. For example, for some similar test data, their output data is also similar. As long as there is such a regularity, it is very likely that through continuous testing, the final output data will have a certain meaning. The best way is that when the same test data is input, the output data is random.

[0108] The method for the regularity analysis is very simple. Convert the output data and the test data into a first eigenvalue and a second eigenvalue respectively. This can be done through a freely set conversion formula. The purpose is to simplify the data and convert long data into a single data. For these single data, coordinates can be generated in a plane graph to obtain a plane graph containing multiple coordinate points. The discrete analysis of this plane graph is the regularity analysis of the output data and the test data. Among them, the discrete analysis of the plane graph is a common existing technology. For those skilled in the art, an intelligent process for completing the discrete analysis can be designed by means of some simple statistical principles.

[0109] Specifically, the steps for performing a correlation analysis on the output data and the test data include:

[0110] Extract the instruction data in the test, and convert the instruction data and the test data into a third eigenvalue and a second eigenvalue respectively according to a preset conversion formula to obtain an eigenvalue group;

[0111] Generate a sampling table according to the eigenvalue group, randomly extract a preset number of eigenvalue groups from the sampling table, and determine a fitting function;

[0112] Input the third eigenvalue in other eigenvalue groups into the fitting function to obtain a predicted value;

[0113] Calculate the deviation rate between the predicted value and the corresponding second eigenvalue, and determine the correlation level according to the deviation rate.

[0114] The main body of the correlation analysis is the instruction data and the output data. It adopts a predictive method. According to some existing instruction data and output data, a fitting function is obtained. If the new data conforms to this fitting function, it can be considered that there is a certain correlation between them.

[0115] Embodiment 2

[0116] Figure 5 The block diagram of the composition structure of the vulnerability identification system for an embedded development program is shown. In an embodiment of the present invention, a vulnerability identification system for an embedded development program, the system 10 includes:

[0117] A virtual machine generation module 11, configured to receive the embedded code containing environment parameters uploaded by a user, and generate a virtual machine based on the environment parameters;

[0118] A preliminary detection module 12, configured to receive the test form uploaded by a user, and preliminarily detect the embedded code according to the test form; wherein, the test form includes input items and corresponding output items;

[0119] A boundary condition extraction module 13, configured to traverse the embedded code, identify and extract the conditional code in the embedded code, and generate a boundary condition table according to the conditional code when the embedded code passes the preliminary detection;

[0120] A secondary detection module 14, configured to perform secondary detection on the embedded code according to the boundary condition table, and generate a detection report according to the preliminary detection result and the secondary detection result.

[0121] Figure 6 The block diagram of the composition structure of the virtual machine generation module in the vulnerability identification system for an embedded development program is shown. The virtual machine generation module 11 includes:

[0122] A component acquisition unit 111, configured to receive the electronic component model and connection relationship uploaded by a user; the environment parameters include the electronic component model;

[0123] A new creation unit 112, configured to read virtual components from a preset virtual component library according to the electronic component model, and open a virtual component new creation port when the reading result is empty;

[0124] A data reading unit 113, configured to obtain the hardware architecture and data structure of the virtual component according to the virtual component new creation port;

[0125] A compilation verification unit 114, configured to connect virtual components according to the connection relationship, compile the embedded code uploaded by a user according to the connected virtual components, and encapsulate the connected virtual components to obtain a virtual machine when the compilation result is successful.

[0126] Figure 7 The block diagram of the composition structure of the boundary condition extraction module in the vulnerability identification system for an embedded development program is shown. The boundary condition extraction module 13 includes:

[0127] A delimiter marking unit 131 is configured to traverse the embedded code and mark the delimiters in the embedded code when the embedded code passes the preliminary detection;

[0128] A code splitting unit 132 is configured to split the embedded code into sub-codes with position information according to the delimiters; the position information is the relative position with respect to the starting point of the embedded code;

[0129] A sub-table generating unit 133 is configured to extract the conditional statements in the sub-codes, read the boundary conditions in the conditional statements, and obtain a boundary condition sub-table with the position information of the sub-codes as index items;

[0130] A connection unit 134 is configured to connect the boundary condition sub-tables to obtain a boundary condition table.

[0131] All functions that can be realized by the vulnerability identification method of the embedded development program are completed by a computer device, which includes one or more processors and one or more memories. At least one program code is stored in the one or more memories, and the program code is loaded and executed by the one or more processors to realize the functions of the vulnerability identification method of the embedded development program.

[0132] The processor fetches instructions from the memory one by one, analyzes the instructions, and then completes corresponding operations according to the requirements of the instructions, generating a series of control commands to make each part of the computer act automatically, continuously and coordinately, becoming an organic whole, realizing the input of the program, the input of data, and the operation and output of results. All arithmetic operations or logical operations generated in this process are completed by the arithmetic unit; the memory includes a read-only memory (ROM), and the read-only memory is used to store computer programs, and a protection device is provided outside the memory.

[0133] Exemplarily, a computer program can be divided into one or more modules, and one or more modules are stored in the memory and executed by the processor to complete the present invention. One or more modules can be a series of computer program instruction segments that can complete specific functions, and the instruction segments are used to describe the execution process of the computer program in the terminal device.

[0134] Those skilled in the art can understand that the description of the above service device is only an example and does not constitute a limitation on the terminal device. It may include more or fewer components than the above description, or combine some components, or different components. For example, it may include input and output devices, network access devices, buses, etc.

[0135] The so-called processor may be a Central Processing Unit (CPU), or it may also be other general-purpose processors, Digital Signal Processors (DSPs), Application Specific Integrated Circuits (ASICs), Field-Programmable Gate Arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc. The above-mentioned processor is the control center of the above-mentioned terminal device, and connects various parts of the entire user terminal through various interfaces and lines.

[0136] The above-mentioned memory can be used to store computer programs and / or modules. The above-mentioned processor realizes various functions of the above-mentioned terminal device by running or executing the computer programs and / or modules stored in the memory, and by calling the data stored in the memory. The memory mainly includes a program storage area and a data storage area. Among them, the program storage area can store an operating system, application programs required for at least one function (such as an information collection template display function, a product information release function, etc.); the data storage area can store data created according to the use of the berth status display system (such as product information collection templates corresponding to different product types, product information to be released by different product providers, etc.). In addition, the memory may include high-speed random access memory, and may also include non-volatile memory, such as a hard disk, memory, plug-in hard disk, Smart Media Card (SMC), Secure Digital (SD) card, Flash Card, at least one magnetic disk storage device, flash memory device, or other volatile solid-state storage devices.

[0137] If the modules / units integrated in the terminal device are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on such an understanding, to implement all or part of the modules / units in the above-described embodiment system of the present invention, it can also be completed by instructing relevant hardware through a computer program. The above computer program can be stored in a computer-readable storage medium. When the computer program is executed by a processor, it can realize the functions of the above various system embodiments. Among them, the computer program includes computer program code, and the computer program code can be in the form of source code, object code, executable file or some intermediate form, etc. The computer-readable medium can include: any entity or device capable of carrying the computer program code, recording medium, USB flash drive, mobile hard disk, magnetic disk, optical disk, computer memory, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), electrical carrier signal, telecommunication signal, and software distribution medium, etc.

[0138] It should be noted that in this article, the term "including", "comprising" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed, or further includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "including a..." does not exclude the existence of another identical element in the process, method, article or device including that element.

[0139] The above are only the preferred embodiments of the present invention, and do not limit the patent scope of the present invention accordingly. Any equivalent structure or equivalent process transformation made by using the content of the specification and drawings of the present invention, or directly or indirectly applied in other related technical fields, shall be equally included in the patent protection scope of the present invention.

Claims

1. A method for identifying vulnerabilities in an embedded development program, characterized in that, the method includes: Receiving the embedded code containing environmental parameters uploaded by the user, and generating a virtual machine based on the environmental parameters; Receiving the test table uploaded by the user, and preliminarily detecting the embedded code according to the test table; wherein, the test table includes input items and corresponding output items; When the embedded code passes the preliminary detection, traversing the embedded code, identifying and extracting the conditional code in the embedded code, and generating a boundary condition table according to the conditional code; Performing a secondary detection on the embedded code according to the boundary condition table, and generating a detection report according to the preliminary detection result and the secondary detection result; The method further includes: Dividing the virtual machine into several independent modules according to a preset classification rule, and obtaining the storage structure of each module; wherein, the storage structure includes a hardware structure and an operation rule; Determining test data according to the storage structure, and sending the test data to the corresponding module to obtain the output data of each module; wherein, the test data includes random data and instruction data, and the length of the random data is determined by the hardware structure; Performing a regularity analysis and a correlation analysis on the output data and the test data, and generating a risk value for the module according to the regularity analysis result and the correlation analysis result; When the risk value is greater than a preset risk threshold, marking the corresponding module, and generating a risk assessment report according to the marked module; Among them, the step of performing a regularity analysis on the output data and the test data includes: Converting the output data and the test data into a first eigenvalue and a second eigenvalue respectively according to a preset conversion formula; Generating coordinate points in a preset plane graph according to the first eigenvalue and the second eigenvalue; the plane graph contains coordinate axes, and the coordinate axes are adaptively adjusted in real time according to the magnitudes of the first eigenvalue and the second eigenvalue; Performing a discreteness analysis on the plane graph containing coordinate points, and generating a regularity level according to the discreteness analysis result.

2. The method for identifying vulnerabilities in an embedded development program according to claim 1, characterized in that, the step of receiving the embedded code containing environmental parameters uploaded by the user and generating a virtual machine based on the environmental parameters includes: Receiving the electronic component model and connection relationship uploaded by the user; the environmental parameters include the electronic component model; Reading virtual components in a preset virtual component library according to the electronic component model, and opening a virtual component new port when the reading result is empty; Obtaining the hardware architecture and data structure of the virtual component according to the virtual component new port; Receiving the connection relationship to connect the virtual components, compiling the embedded code uploaded by the user according to the connected virtual components, and when the compilation result is successful, encapsulating the connected virtual components to obtain a virtual machine.

3. The method for identifying vulnerabilities in an embedded development program according to claim 1, characterized in that, The steps of traversing the embedded code, identifying and extracting the conditional code in the embedded code, and generating a boundary condition table according to the conditional code when the embedded code passes the preliminary detection include: When the embedded code passes the preliminary detection, traverse the embedded code and mark the delimiters in the embedded code; Split the embedded code into sub-codes with position information according to the delimiters; the position information is the relative position relative to the starting point of the embedded code; Extract the conditional statements in the sub-codes, read the boundary conditions in the conditional statements, and obtain a boundary condition sub-table with the position information of the sub-codes as index items; Connect the boundary condition sub-tables to obtain a boundary condition table.

4. The vulnerability identification method for an embedded development program according to claim 1, wherein, The steps of performing a secondary detection on the embedded code according to the boundary condition table and generating a detection report according to the preliminary detection result and the secondary detection result include: Read the boundary condition sub-tables and their position information in the boundary condition table; Extract and combine all the boundary conditions in the boundary condition sub-tables to obtain a preset number of boundary condition groups; Locate the sub-codes in the embedded code according to the position information; Input the boundary condition groups into the sub-codes to obtain output information, and generate a detection report according to the output information.

5. The vulnerability identification method for an embedded development program according to claim 1, wherein, The steps of performing a correlation analysis on the output data and the test data include: Extract the instruction data in the test, and convert the instruction data and the test data into a third eigenvalue and a second eigenvalue respectively according to a preset conversion formula to obtain an eigenvalue group; Generate a sampling table according to the eigenvalue group, randomly extract a preset number of eigenvalue groups from the sampling table, and determine a fitting function; Input the third eigenvalue in other eigenvalue groups into the fitting function to obtain a predicted value; Calculate the offset rate between the predicted value and the corresponding second eigenvalue, and determine the correlation level according to the offset rate.

6. A vulnerability identification system for an embedded development program, wherein, The system includes: A virtual machine generation module, configured to receive the embedded code containing environment parameters uploaded by a user, and generate a virtual machine based on the environment parameters; A preliminary detection module, configured to receive a test table uploaded by a user, and perform a preliminary detection on the embedded code according to the test table; wherein, the test table includes input items and corresponding output items; A boundary condition extraction module, configured to traverse the embedded code, identify and extract the conditional code in the embedded code, and generate a boundary condition table according to the conditional code when the embedded code passes the preliminary detection; A secondary detection module, configured to perform a secondary detection on the embedded code according to the boundary condition table, and generate a detection report according to the preliminary detection result and the secondary detection result; The system is further configured to: Divide the virtual machine into several independent modules according to a preset classification rule, and obtain the storage structure of each module; wherein, the storage structure includes a hardware structure and an operation rule; Determine test data according to the storage structure, send the test data to the corresponding modules, and obtain the output data of each module; wherein, the test data includes random data and instruction data, and the length of the random data is determined by the hardware structure; Perform regularity analysis and correlation analysis on the output data and the test data, and generate a risk value for the module according to the results of the regularity analysis and the correlation analysis; When the risk value is greater than a preset risk threshold, mark the corresponding module, and generate a risk assessment report according to the marked module; Among them, the steps of performing regularity analysis on the output data and the test data include: Convert the output data and the test data into a first eigenvalue and a second eigenvalue respectively according to a preset conversion formula; Generate coordinate points in a preset plane graph according to the first eigenvalue and the second eigenvalue; the plane graph contains coordinate axes, and the coordinate axes are adaptively adjusted in real time according to the magnitudes of the first eigenvalue and the second eigenvalue; Perform discreteness analysis on the plane graph containing the coordinate points, and generate a regularity level according to the results of the discreteness analysis.

7. The vulnerability identification system for an embedded development program according to claim 6, characterized in that, The virtual machine generation module includes: A component acquisition unit, configured to receive the electronic component model and connection relationship uploaded by the user; the environmental parameters include the electronic component model; A new creation unit, configured to read virtual components in a preset virtual component library according to the electronic component model, and when the reading result is empty, open a virtual component new creation port; A data reading unit, configured to obtain the hardware architecture and data structure of the virtual component according to the virtual component new creation port; A compilation verification unit, configured to connect the virtual components according to the connection relationship, compile the embedded code uploaded by the user according to the connected virtual components, and when the compilation result is successful, encapsulate the connected virtual components to obtain a virtual machine.

8. The vulnerability identification system for an embedded development program according to claim 6, characterized in that, The boundary condition extraction module includes: A delimiter marking unit, configured to traverse the embedded code and mark the delimiters in the embedded code when the embedded code passes a preliminary detection; A code splitting unit, configured to split the embedded code into sub-codes with position information according to the delimiters; the position information is the relative position relative to the starting point of the embedded code; A sub-table generation unit, configured to extract conditional statements in the sub-codes, read boundary conditions in the conditional statements, and obtain a boundary condition sub-table with the position information of the sub-codes as index items; A connection unit, configured to connect the boundary condition sub-tables to obtain a boundary condition table.

Citation Information

Patent Citations

  • Testing method combining automatic tool and testing case

    CN102662846A

  • Embedded device SDK security analysis method

    CN113806715A