Memory vulnerability detection method, device, electronic device, storage medium and product

By preprocessing and statically analyzing the source code to be tested, identifying vulnerability-related data and their dependencies in memory read and write statements, and formulating vulnerability rules, the problems of poor memory vulnerability detection and high false positives in existing technologies are solved, and high-precision memory vulnerability detection is achieved.

CN114662118BActive Publication Date: 2025-10-03INSTITUTE OF INFORMATION ENGINEERING CHINESE ACADEMY OF SCIENCES
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202210255160.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-03-15
Publication Date
2025-10-03
Estimated Expiration
2042-03-15

AI Technical Summary

Technical Problem

Existing memory vulnerability detection methods have problems with poor detection effect and high false negatives, making it difficult to achieve accurate and efficient detection of memory vulnerabilities.

Method used

By preprocessing the source code to be tested, obtaining an abstract representation, and performing static analysis, we can identify vulnerability-related data and their data dependencies in memory read and write statements, formulate vulnerability rules, and determine whether memory read and write statements are memory vulnerabilities, including invalid pointers, modified data, and data dependencies of input data.

Benefits of technology

It achieves memory vulnerability detection with low false negative rate, improves the accuracy and efficiency of memory vulnerability detection, and reduces the false negative rate.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114662118B_ABST
    Figure CN114662118B_ABST
Patent Text Reader

Abstract

The present invention provides a memory vulnerability detection method, apparatus, electronic device, storage medium, and product. The method comprises: preprocessing the source code to be tested to obtain an abstract representation of the source code to be tested; statically analyzing the abstract representation of the source code to be tested to obtain memory read and write statements, vulnerability-related data, and data dependencies of the vulnerability-related data; and determining whether the memory read and write statements represent a memory vulnerability based on the vulnerability-related data and its data dependencies. Based on an analysis of the memory vulnerability mechanism, the present invention determines that the root cause of memory vulnerabilities is the dependency between certain data, thereby providing universal detection for memory vulnerabilities.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer security technology, and in particular to a memory vulnerability detection method, device, electronic device, storage medium and product. Background Art

[0002] Memory vulnerabilities, due to errors in software design or implementation, allow attackers to construct specific input data and illegally modify or read data in memory, thereby achieving their intended attack. These vulnerabilities are widely present in various software and operating systems. Universal detection of memory vulnerabilities is complex, difficult, and extremely challenging.

[0003] The methods for general memory vulnerability detection in the prior art include the following:

[0004] Memory vulnerability detection methods based on symbolic execution: This method traverses all possible execution paths and uses an external constraint solver or theorem prover to attempt to resolve all data and control the dependencies on each path. This method can generate path expressions that satisfy certain vulnerability-specific constraints. The method then determines whether a satisfyable constraint solution exists for the corresponding path expression, using methods such as Z3. If a satisfyable constraint solution exists, the vulnerability exists. However, this method suffers from the path explosion problem: as the path depth increases, the constraints become more complex, resulting in poor scalability. Therefore, it is difficult to detect all types of memory vulnerabilities and lacks general applicability.

[0005] Fuzzing-based vulnerability detection: This method discovers program vulnerabilities by constructing valid inputs. Its effectiveness relies on data structure and path coverage. It offers advantages such as high scalability, high efficiency in analyzing large programs, and high reliability. While it is a versatile vulnerability detection method, it suffers from incomplete path information and struggles to identify vulnerabilities with complex paths.

[0006] Vulnerability-type-agnostic machine learning-based memory vulnerability detection: This method can detect general memory vulnerabilities, but it relies on experts manually defining feature attributes and using a machine learning model to automatically classify vulnerable and non-vulnerable code. Due to the coarse-grained code input into the machine learning model, the exact location of the vulnerability cannot be determined. Vulnerability detection effectiveness depends on the completeness of the expert-defined feature attributes.

[0007] Deep learning-based vulnerability detection methods: This method eliminates the need for experts to manually define features and can automatically generate vulnerability patterns. However, based on current research, it cannot accurately locate all vulnerability types, and its detection effectiveness depends on the dataset, making it difficult to effectively detect memory vulnerabilities universally. Additionally, existing vulnerability detection tools also offer general memory vulnerability detection. These tools use simple parsers and vulnerability rules, resulting in high false negative rates.

[0008] In summary, existing general detection methods for memory vulnerabilities generally have problems such as poor detection effect and high false negatives. Summary of the Invention

[0009] The present invention provides a memory vulnerability detection method, device, electronic device, storage medium and product, which are used to solve the defects of poor memory vulnerability detection effect and high false negatives in the prior art, realize accurate and efficient detection of memory vulnerabilities, and reduce false negatives.

[0010] The present invention provides a memory vulnerability detection method, comprising:

[0011] Preprocessing the source code to be tested to obtain an abstract representation of the source code to be tested;

[0012] Performing static analysis on the abstract representation of the source code to be tested to obtain memory read and write statements, vulnerability-related data, and data dependency relationships of the vulnerability-related data;

[0013] Whether the memory read and write statement is a memory vulnerability is determined according to the vulnerability-related data and a data dependency relationship of the vulnerability-related data.

[0014] According to a memory vulnerability detection method provided by the present invention, determining whether the memory read / write statement is a memory vulnerability based on the vulnerability-related data and the data dependency relationship of the vulnerability-related data includes:

[0015] When the operand of the memory read / write statement is vulnerability-related data and the data dependency of the vulnerability-related data satisfies any vulnerability rule, the memory read / write statement is a memory vulnerability.

[0016] According to a memory vulnerability detection method provided by the present invention, the vulnerability-related data includes: invalid pointers, modified data and input data;

[0017] The vulnerability rules include: input data flows to modified data, invalid pointer flows to modified data, and input data flows to invalid pointer.

[0018] According to a memory vulnerability detection method provided by the present invention, the memory read and write statements include assignment statements, function call statements and mixed statements.

[0019] According to a memory vulnerability detection method provided by the present invention, the abstract representation of the source code to be tested includes: data dependency information, control dependency information, control flow, source operand, destination operand and statement type.

[0020] The present invention also provides a memory vulnerability detection device, comprising:

[0021] A preprocessing module, configured to preprocess the source code to be tested to obtain an abstract representation of the source code to be tested;

[0022] An information collection module is used to perform static analysis on the abstract representation of the source code to be tested, and obtain memory read and write statements, vulnerability-related data, and data dependencies of the vulnerability-related data;

[0023] The vulnerability detection module is used to determine whether the memory read and write statement is a memory vulnerability based on the vulnerability-related data and the data dependency relationship of the vulnerability-related data.

[0024] According to a memory vulnerability detection device provided by the present invention, the detection module is further used to determine that the memory read / write statement is a memory vulnerability when the operand of the memory read / write statement is vulnerability-related data and the data dependency of the vulnerability-related data satisfies any vulnerability rule.

[0025] The present invention also provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, any one of the above-described memory vulnerability detection methods is implemented.

[0026] The present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which implements any of the above-mentioned memory vulnerability detection methods when executed by a processor.

[0027] The present invention also provides a computer program product, comprising a computer program, wherein when the computer program is executed by a processor, the computer program implements any of the above-mentioned memory vulnerability detection methods.

[0028] The present invention provides a memory vulnerability detection method, device, electronic device, storage medium, and product. Starting from vulnerability type, this method conducts in-depth analysis of memory vulnerability mechanisms and explores the essence of memory vulnerabilities. The root cause of memory vulnerabilities is the dependency between certain data. Detection rules are then formulated to perform universal memory vulnerability detection. This method effectively solves the problem of universal memory vulnerability detection and achieves high-precision detection. BRIEF DESCRIPTION OF THE DRAWINGS

[0029] In order to more clearly illustrate the technical solutions in the present invention or the prior art, a brief introduction is given below to the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0030] Figure 1 This is one of the flow charts of the memory vulnerability detection method provided by the present invention;

[0031] Figure 2 This is the second flow chart of the memory vulnerability detection method provided by the present invention;

[0032] Figure 3 It is a structural diagram of the memory vulnerability detection device provided by the present invention;

[0033] Figure 4 It is a structural schematic diagram of the electronic device provided by the present invention. DETAILED DESCRIPTION

[0034] To make the objectives, technical solutions, and advantages of the present invention more clear, the technical solutions of the present invention will be clearly and completely described below in conjunction with the accompanying drawings. Obviously, the embodiments described are only some of the embodiments of the present invention, not all of them. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts shall fall within the scope of protection of the present invention.

[0035] Because the C language allows programmers to directly control memory addresses using pointers, this poses a serious and widespread security risk. Careless pointer manipulation can lead to memory errors and vulnerabilities easily exploited by attackers. Memory vulnerabilities are primarily caused by pointer out-of-bounds and dangling pointers, which are considered invalid. Dereferencing, reading, or writing invalid pointers can modify or leak memory data, triggering memory vulnerabilities. Memory vulnerabilities can modify memory data, including code pointers, data variables, and data pointers, while also leaking memory data. Attackers often trigger memory vulnerabilities by inputting data.

[0036] The present invention studies the above memory vulnerability mechanism, determines vulnerability-related data, formulates memory vulnerability rules, and solves the problems of existing methods and tools. Figure 1-Figure 2 The memory vulnerability detection method of the present invention is described as follows: Figure 1 As shown, this embodiment discloses a memory vulnerability detection method, including the following steps:

[0037] Step 101: pre-process the source code to be tested to obtain an abstract representation of the source code to be tested;

[0038] Step 102: statically analyze the abstract representation of the source code to be tested to obtain the memory read and write statements, vulnerability-related data, and data dependencies of the vulnerability-related data;

[0039] Step 103: Determine whether the memory read / write statement is a memory vulnerability based on the vulnerability-related data and its data dependency.

[0040] It should be noted that during the execution of a program, a large number of data read and write operations will occur, and data will flow from one variable to another. The data dependency relationship refers to the flow relationship between data in data read and write operations. The vulnerability-related data is all data that may logically affect the attacker's purpose of triggering a memory vulnerability.

[0041] By analyzing the memory vulnerability mechanism, the memory vulnerability detection method of the present invention can lock the data that needs to be identified in the source code to be tested, realize universal detection of software memory vulnerabilities, achieve the effect of low missed reports, and thus ensure the security of the software.

[0042] In at least one embodiment of the present invention, determining whether the memory read / write statement is a memory vulnerability based on the vulnerability-related data and its data dependency relationship includes:

[0043] When the operand of the memory read / write statement is vulnerability-related data and the data dependency of the vulnerability-related data satisfies any vulnerability rule, the memory read / write statement is a memory vulnerability.

[0044] In at least one embodiment of the present invention, the vulnerability-related data includes: invalid pointers, modified data, and input data;

[0045] The vulnerability rules include: input data flows to modified data, invalid pointer flows to modified data, and input data flows to invalid pointer.

[0046] It should be noted that the vulnerability-related data is obtained through abstract syntax tree analysis. Based on the analysis of the memory vulnerability mechanism, the vulnerability-related data identification strategy includes the following sub-steps:

[0047] Step 201: Get an invalid pointer;

[0048] Among them, a dangling pointer refers to a pointer that has been released; an out-of-bounds pointer refers to a pointer to which an offset and assignment of value are unsafe.

[0049] Specifically, in this embodiment, when static analysis is performed on the abstract representation of the memory read and write statements, if the vulnerability-related data is an invalid pointer, the identification strategy includes the following steps:

[0050] Pointer release; free(p)

[0051] An assignment is a value that contains a numeric value or a computed value (a value that is the result of applying an arithmetic or bitwise operator to one or more operands);

[0052] The variables assigned are from the stack;

[0053] Pointer plus offset, where offset is a variable.

[0054] For example: *(p+i)=q[j];

[0055] Among them, parameters i and j are int variables, and access to p and q may reference invalid memory, so *(p+i)} and q[j] are invalid writes and reads respectively, and p and q are invalid pointers.

[0056] Step 201: Obtain modification data;

[0057] Among them, modified data refers to the data modified by the memory vulnerability, including conditional branch parameters, loop judgment parameters, library function parameters, system call parameters and function pointers.

[0058] Step 203: Obtain input data;

[0059] The input data refers to data from the user, the system, the program, or the external functions, including user input, data passed as function parameters, and data returned by function calls.

[0060] It should be noted that the analysis strategy for the data dependency of the vulnerability-related data includes the following sub-steps:

[0061] Step a: Reversely analyze all data that flows to the modified data, that is, obtain the data dependency of the modified data.

[0062] Step b: Forward analyze the data flowing from the invalid pointer to obtain the data dependencies of the invalid pointer. Invalid pointers are the root cause of memory vulnerabilities and can be easily exploited by attackers to modify data, so it is necessary to pay attention to all data they may affect.

[0063] Step c: forwardly analyzing the data flowing out of the input data, that is, obtaining the data dependency of the input data.

[0064] It should be noted that attackers can manipulate invalid pointers through constructed input data to read or modify memory data, or they can directly modify data. Therefore, it is necessary to pay attention to all data that may be affected by the input data.

[0065] It should be noted that the vulnerability rules include:

[0066] 1) Input data flows to modified data: Modified data depends on input data, that is, input data flows to modified data;

[0067] 2) Invalid pointer flows to modified data: The modified data depends on the invalid pointer, that is, the invalid pointer flows to the modified data;

[0068] 3) Input data flows to an invalid pointer: The invalid pointer data depends on the input data, that is, the input data flows to an invalid pointer.

[0069] For a memory read / write statement, if its operand is vulnerability-related data and its data dependency satisfies one of the rules, then the statement is considered a memory vulnerability.

[0070] In at least one embodiment of the present invention, the memory read and write statements include assignment statements, function call statements, and mixed statements, as shown in Table 1:

[0071] Table 1

[0072]

[0073] It should be noted that for assignment statements, if the data dependency of the operands meets any vulnerability rule, it is considered a vulnerability; for function call statements, if the data dependency of the parameters meets any vulnerability rule, it is considered a vulnerability; for mixed statements, the judgment is made according to the detection of different statements, and if the data dependency of the operands meets any vulnerability rule, it is considered a vulnerability.

[0074] In at least one embodiment of the present invention, the abstract representation of the source code to be tested includes: data dependency information, control dependency information, control flow, source operands, destination operands, and statement types.

[0075] It should be noted that the static analysis described in this embodiment includes abstract interpretation-based methods such as abstract syntax tree analysis, control flow analysis, and DEF-USE analysis. Abstractly representing the source code of the program under test involves using the Joern tool to obtain data dependency information, control dependency information, control flow, source operands, destination operands, and statement types for each line of the source code. This information is stored in the Neo4j graph database as nodes and edges.

[0076] Since the nodes of the abstract syntax tree can store almost all the information in the corresponding program statements. In the abstract syntax tree, each tree node stores the corresponding node information, including variable information, operation information, operation type and other contents. At the same time, different types of tree nodes will also store some specific types of information, such as the Relational Expression Tree node will store related operator information, etc. Therefore, the present invention uses abstract syntax tree analysis to collect memory read and write statements and vulnerability-related data. For the collection of data dependencies, the present invention combines vulnerability-related data and uses control flow analysis and DEF-USE analysis to obtain them.

[0077] In at least one embodiment of the present invention, intra-line data dependency refers to the flow of data within each line of code. For example, if a = b, variable b flows to a. This means that variable a has a data dependency on variable b. We use abstract syntax tree analysis to obtain intra-line data dependencies. Inter-line data dependency refers to the dependency between data in different lines of code. We use DEF-USE analysis to obtain inter-line data dependencies.

[0078] This embodiment uses the CWEs of Juliet test suite v1.3 for C / C++ to test the method of the present invention. The test results are shown in Table 2. The overall false negative rate is approximately 1.41%, achieving a very low false negative rate.

[0079] Table 2

[0080]

[0081]

[0082] like Figure 2 As shown, the memory vulnerability detection of the present invention includes the following steps:

[0083] Step 201: collecting source code programs and preprocessing the source code programs;

[0084] Step 202: Using a static analysis method on the preprocessed source code program, obtain memory read and write statements, vulnerability-related data, and data dependency relationships of the vulnerability-related data;

[0085] Step 203: traverse the source code program. If it is a memory read / write statement, determine whether the parameter contains vulnerability-related data. If so, determine whether the vulnerability rule is met based on the data dependency relationship collected in step 202. If so, the statement is considered to be a memory vulnerability.

[0086] The memory vulnerability detection device provided by the present invention is described below. The memory vulnerability detection device described below and the memory vulnerability detection method described above can be referred to in correspondence with each other. Figure 3 As shown, a memory vulnerability detection device is disclosed, comprising:

[0087] A preprocessing module 301 is used to preprocess the source code to be tested to obtain an abstract representation of the source code to be tested;

[0088] An information collection module 302 is configured to perform static analysis on the abstract representation of the source code to be tested to obtain the memory statements, vulnerability-related data, and data dependencies of the vulnerability-related data;

[0089] The vulnerability detection module 303 is used to determine whether the memory read and write statement is a memory vulnerability based on the vulnerability-related data and its data dependency relationship.

[0090] In at least one embodiment of the present invention, the vulnerability detection module 303 is further configured to determine that the memory read / write statement is a memory vulnerability when the operand of the memory read / write statement is vulnerability-related data and the data dependency of the vulnerability-related data satisfies any vulnerability rule.

[0091] In at least one embodiment of the present invention, the vulnerability-related data includes: invalid pointers, modified data, and input data;

[0092] The vulnerability rules include: input data flows to modified data, invalid pointer flows to modified data, and input data flows to invalid pointer.

[0093] In at least one embodiment of the present invention, the memory read and write statements include assignment statements, function call statements, and mixed statements.

[0094] In at least one embodiment of the present invention, the abstract representation of the source code to be tested includes: data dependency information, control dependency information, control flow, source operands, destination operands, and statement types.

[0095] Figure 4 An example of a physical structure diagram of an electronic device is shown below. Figure 4 As shown, the electronic device may include: a processor 410, a communications interface 420, a memory 430, and a communication bus 440, wherein the processor 410, the communications interface 420, and the memory 430 communicate with each other via the communication bus 440. The processor 410 may call logic instructions in the memory 430 to execute a memory vulnerability detection method, which includes:

[0096] Preprocessing the source code to be tested to obtain an abstract representation of the source code to be tested;

[0097] Performing static analysis on the abstract representation of the source code to be tested to obtain memory read and write statements, vulnerability-related data, and data dependency relationships of the vulnerability-related data;

[0098] Whether the memory read and write statement is a memory vulnerability is determined according to the vulnerability-related data and a data dependency relationship of the vulnerability-related data.

[0099] In addition, the logic instructions in the above-mentioned memory 430 can be implemented in the form of a software functional unit and can be stored in a computer-readable storage medium when sold or used as an independent product. Based on this understanding, the technical solution of the present invention is essentially or the part that contributes to the prior art or the part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.

[0100] In another aspect, the present invention further provides a computer program product, comprising a computer program that can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can perform the memory vulnerability detection method provided by each of the above methods, which includes:

[0101] Preprocessing the source code to be tested to obtain an abstract representation of the source code to be tested;

[0102] Performing static analysis on the abstract representation of the source code to be tested to obtain memory read and write statements, vulnerability-related data, and data dependency relationships of the vulnerability-related data;

[0103] Whether the memory read and write statement is a memory vulnerability is determined according to the vulnerability-related data and a data dependency relationship of the vulnerability-related data.

[0104] In another aspect, the present invention further provides a non-transitory computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a processor, the memory vulnerability detection method provided by the above methods is implemented, and the method includes:

[0105] Preprocessing the source code to be tested to obtain an abstract representation of the source code to be tested;

[0106] Performing static analysis on the abstract representation of the source code to be tested to obtain memory read and write statements, vulnerability-related data, and data dependency relationships of the vulnerability-related data;

[0107] Whether the memory read and write statement is a memory vulnerability is determined according to the vulnerability-related data and a data dependency relationship of the vulnerability-related data.

[0108] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, i.e., they may be located in one location or distributed across multiple network units. Some or all of the modules may be selected based on actual needs to achieve the objectives of the present embodiment. Persons of ordinary skill in the art will be able to understand and implement the present invention without inventive effort.

[0109] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, or of course, by hardware. Based on this understanding, the essence of the above technical solution or the part that contributes to the existing technology can be embodied in the form of a software product. The computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, a magnetic disk, an optical disk, etc., and includes a number of instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or certain parts of the embodiments.

[0110] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the various embodiments of the present invention.

Claims

1. A memory vulnerability detection method, characterized in that: include: Preprocessing the source code to be tested to obtain an abstract representation of the source code to be tested; Performing static analysis on the abstract representation of the source code to be tested to obtain memory read and write statements, vulnerability-related data, and data dependency relationships of the vulnerability-related data, where the data dependency relationship refers to the flow relationship between data in data read and write operations; If the operand of the memory read / write statement is vulnerability-related data and the data dependency of the vulnerability-related data satisfies any vulnerability rule, the memory read / write statement is a memory vulnerability, the vulnerability-related data includes: invalid pointer, modified data, and input data; the vulnerability rule includes: input data flows to modified data, invalid pointer flows to modified data, and input data flows to invalid pointer, the invalid pointer includes an out-of-bounds pointer, and the out-of-bounds pointer refers to a pointer to which the source of the offset and assignment is unsafe; The analysis strategy for the data dependency of the vulnerability-related data includes: Reversely analyze all data flowing to the modified data to obtain data dependencies of the modified data; Forward analyzing the data flowing out of the invalid pointer to obtain the data dependency relationship of the invalid pointer; Analyze data flowing out of the input data in a forward direction to obtain data dependency relationships of the input data.

2. The memory vulnerability detection method according to claim 1, wherein: The memory read and write statements include assignment statements, function call statements and mixed statements.

3. The memory vulnerability detection method according to claim 1, wherein: The abstract representation of the source code to be tested includes: data dependency information, control dependency information, control flow, source operand, destination operand and statement type.

4. A memory vulnerability detection device, characterized in that: include: A preprocessing module, configured to preprocess the source code to be tested to obtain an abstract representation of the source code to be tested; An information collection module is used to perform static analysis on the abstract representation of the source code to be tested, and obtain memory read and write statements, vulnerability-related data, and data dependencies of the vulnerability-related data; a vulnerability detection module configured to determine that a memory read / write statement is a memory vulnerability if the operand of the memory read / write statement is vulnerability-related data and the data dependency of the vulnerability-related data satisfies any vulnerability rule, wherein the vulnerability-related data includes an invalid pointer, modified data, and input data; and wherein the vulnerability rules include: input data flows to modified data, an invalid pointer flows to modified data, and input data flows to an invalid pointer, wherein the invalid pointer includes an out-of-bounds pointer, which refers to a pointer to which an offset and assignment are made from an unsafe source. Among them, the analysis strategy of the data dependency relationship of the vulnerability-related data includes: reverse analysis of all data flowing to the modified data to obtain the data dependency relationship of the modified data; forward analysis of data flowing out from the invalid pointer to obtain the data dependency relationship of the invalid pointer; forward analysis of data flowing out from the input data to obtain the data dependency relationship of the input data.

5. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the program, the memory vulnerability detection method according to any one of claims 1 to 3 is implemented.

6. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the memory vulnerability detection method according to any one of claims 1 to 3 is implemented.

7. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the memory vulnerability detection method according to any one of claims 1 to 3 is implemented.

Citation Information

Patent Citations

  • Memory vulnerability detection method and device, equipment and storage medium

    CN113971278A