Binary Taint Vulnerability Detection Method and System Based on Static Taint Analysis

By constructing function atomic pool and path network diagram, optimizing path analysis, combining taint analysis and vulnerability characteristics, the problem of path explosion and complexity increase in static taint analysis is solved, and the accuracy and efficiency of vulnerability detection in binary files is improved.

CN114880672BActive Publication Date: 2025-07-08Chinese People's Liberation Army Cyberspace Force Information Engineering University
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210381604.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-04-13
Publication Date
2025-07-08
Estimated Expiration
2042-04-13

AI Technical Summary

Technical Problem

Existing static taint analysis has problems such as path explosion, data flow insensitive, model complexity and reduced accuracy in binary file vulnerability detection, especially when performing large-scale data flow analysis for low-level languages.

Method used

By constructing a function atomic pool, using the function as atoms with attributes, setting the starting point and end point, building a path network diagram, and using atomic properties to optimize the path diagram, combining stain analysis and vulnerability characteristics to determine whether the dangerous function call points meet the vulnerability characteristics.

Benefits of technology

It effectively avoids path explosion, reduces analysis complexity, improves detection accuracy and sensitivity, and reduces resource consumption.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114880672B_ABST
    Figure CN114880672B_ABST
Patent Text Reader

Abstract

The present invention discloses a binary taint vulnerability detection method and system based on static taint analysis. The method first takes a function as a whole, obtains its call relationship and variable pollution set; then uses the function call graph to assemble all path network graphs starting from user input or the main function and ending at the function with vulnerability points, and optimizes the path network graph using the data in the atomic pool to remove unusable paths; finally, analyzes the functions at the end of the path using pattern matching to screen out potential vulnerable points. The present invention reduces the function to atoms, eliminates the path increment in the function during the taint analysis process, and avoids the problem of static taint analysis path explosion; simplifies the analysis process by separating the internal and external connections of the function, reduces the complexity of the analysis; improves the accuracy of static taint analysis within the function through taint analysis within the function, makes the relationship between functions clearer, and improves the sensitivity of the data flow.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of network security, and particularly relates to a binary taint-type vulnerability detection method and system based on static taint analysis. Background Technique

[0002] With the popularization of embedded devices in people's daily lives, while bringing convenience to people, it also brings risks such as leakage of sensitive data, especially the security of router devices. As a network hub, a router can connect most intelligent devices in the same place, so it becomes a high-risk target for attacks. Most embedded devices are closed-source, which although increases the difficulty of attack, also makes their security mainly rely on a small number of people such as security testers, increasing the possibility of system vulnerabilities. Therefore, it is necessary to directly detect the firmware in binary form.

[0003] The static analysis technology of binary vulnerabilities is mainly divided into two types. One is to detect whether the target binary file has the same vulnerability by comparing it with a binary file with a vulnerability, and often uses machine learning to identify the characteristics of dangerous code; the other is static taint analysis, which detects the binary file by constructing a model of a certain type of vulnerability and using pattern matching, and the points that match the model are output as potential vulnerable points. Compared with dynamic testing, static detection has problems such as high false positive rate and path explosion, but because of its short use time and very small resource consumption, it is often used in the work of binary vulnerability mining. Moreover, static taint analysis can detect a certain type of vulnerability, expanding the detection scope. Therefore, this paper selects the method of static taint analysis for vulnerability detection.

[0004] The static taint analysis technology mainly depends on the potentially contaminated data flow in the target object, mainly for Web applications and Android applications, because both of these two types of target objects have a large number of user interactions, a large number of risk points brought by complex components, and the availability of partial or all source codes and other characteristics. The detection of Web applications is mainly to detect their scripting languages, such as PHP, JavaScript, etc.; the purpose of detecting Android applications is to protect whether sensitive information such as user privacy is stolen.

[0005] Currently, static taint analysis has problems such as path explosion, data flow insensitivity, and increased model complexity and reduced accuracy caused by large-scale data flow analysis of low-level languages. The objects of static detection are generally machine code, assembly code or intermediate language. Directly performing large-scale data flow detection on low-level languages will increase the model complexity, resulting in longer detection time and reduced accuracy. In addition, static detection technology also has problems such as path explosion and data flow insensitivity.

[0006] Existing methods for using static taint analysis to scan for vulnerabilities in binary files usually utilize constraints to track the input stream from the input point all the way to the output point. Since it is static analysis, all code needs to be analyzed, including many path forks and repeated analysis of certain functions, which leads to an exponential growth in the number of paths. In addition, the targets of static taint analysis are generally low-level languages such as machine code, assembly, and intermediate languages. When the data flow is very long, the constraints and limiting conditions in the paths will also explode, resulting in increased resource consumption and reduced detection accuracy, etc. Summary of the Invention

[0007] In view of the problems existing in the existing method of using static taint analysis to scan for vulnerabilities in binary files, such as the exponential growth in the number of paths, the explosion of constraints and limiting conditions in the paths when the data flow is very long, resulting in increased resource consumption and reduced detection accuracy, etc., the present invention proposes a binary taint-type vulnerability detection method and system based on static taint analysis. By constructing a function atom pool, functions are made into atoms with attributes; starting and ending points are set, a path network graph from the starting point to the ending point is constructed, and the path graph is optimized using atomic attributes; by combining taint analysis with vulnerability characteristics, it is determined whether the dangerous function call points meet the characteristics of existing vulnerabilities. The present invention reduces functions to atoms, eliminates the path increment in functions during the taint analysis process, avoids the problem of static taint analysis path explosion, simplifies the analysis process by separating the internal and external connections of functions, reduces the complexity of analysis, and furthermore, improves the accuracy of static taint analysis within functions through taint analysis within functions, making the relationships between functions clearer and improving the sensitivity of the data flow.

[0008] To achieve the above objectives, the present invention adopts the following technical solutions:

[0009] On the one hand, the present invention proposes a binary taint-type vulnerability detection method based on static taint analysis, including:

[0010] Step 1, construct a function atom pool: Use IDA Pro to disassemble the binary file to obtain C language code; take function parameters and external input points as pollution sources, traverse the entire function, obtain the polluted variables, the call relationships of the functions, and the pollution conditions of the parameters of the called functions, perform the above operations on all functions, and use the functions as atoms and the extracted data as the attributes of the atoms, and store them in the database;

[0011] Step 2, Construction and Optimization of Path Network Diagram: Set the external input function as the starting point, the function that calls the starting point as the beginning of the path, the dangerous function as the end point, and the function that calls the dangerous function as the end of the path. According to the call relationship between functions, use the breadth-first algorithm to traverse forward from the starting point to the end point to construct all path network diagrams from the starting point to the end point; and use the attributes of atoms to optimize the path network diagram and prune the unreachable paths.

[0012] Step 3, Vulnerability Establishment Judgment: Construct vulnerability models for injection and overflow vulnerabilities, and retrieve whether the dangerous function call points in the path-ending function conform to the vulnerability models. If they conform, it can be considered that the call point is a vulnerability point.

[0013] Further, the external input functions include nvram_bufget, get_var, and websGetVar; the dangerous functions include system, strcpy, and memcpy.

[0014] Further, Step 1 includes:

[0015] Step 1.1, Use the disassembler IDA Pro to disassemble the binary file to obtain C language code.

[0016] Step 1.2, Perform taint propagation analysis within the function: First, set up a pollution pool, with the initial pollution sources being function parameters and direct external inputs within the function. Traverse the internal code path of the function, classify variables, and add variables with direct and indirect pollution to the pollution pool, obtain the list of called functions, and record the pollution situation of the parameters of the called functions.

[0017] Step 1.3, Perform the operation of Step 1.2 on all functions in the C language code.

[0018] Step 1.4, Take functions as atoms and the extracted data as the attributes of the atoms, and store them in the mongoDB database to complete the construction of the function atom pool.

[0019] Further, Step 3 includes:

[0020] Construct vulnerability models for injection and overflow vulnerabilities; among them, the function parameters corresponding to overflow vulnerabilities must meet the conditions that the source variable is controllable and the memory space it points to is larger than the target variable; the function parameters corresponding to injection vulnerabilities need to meet the conditions of string type and controllability of the executed part of the string.

[0021] Retrieve whether the dangerous function call points in the path-ending function conform to the constructed vulnerability models. If they conform, it is considered that the call point is a vulnerability point; if they do not conform, delete the paths that have a call relationship with the dangerous function call point.

[0022] On the other hand, the present invention provides a binary taint - type vulnerability detection system based on static taint analysis, including:

[0023] A construction module, used to construct a function atom pool: Disassemble the binary file using IDA Pro to obtain C - language code; Taking function parameters and external input points as pollution sources, traverse the entire function to obtain polluted variables, the call relationship of functions, and the pollution situation of the parameters of called functions. Perform the above operations on all functions, and take functions as atoms and the extracted data as the attributes of atoms, and store them in the database;

[0024] A construction and optimization module, used to construct and optimize the path network graph: Set the external input function as the starting point, the function that calls the starting point as the beginning of the path, the dangerous function as the end point, and the function that calls the dangerous function as the end of the path. According to the call relationship between functions, use the breadth - first algorithm to perform a forward traversal from the starting point to the end point to construct all path network graphs from the starting point to the end point; And use the attributes of atoms to optimize the path network graph and prune the unreachable paths;

[0025] A vulnerability determination module, used to determine the establishment of vulnerability: Construct vulnerability models for injection - type and overflow - type vulnerabilities, and retrieve whether the dangerous function call points in the end - point function of the path conform to the vulnerability models. If they conform, it can be considered that the call point is a vulnerability point.

[0026] Further, the external input functions include nvram_bufget, get_var, websGetVar; the dangerous functions include system, strcpy, memcpy.

[0027] Further, the construction module is specifically used for:

[0028] Step 1.1, use the disassembly tool IDA Pro to disassemble the binary file to obtain C - language code;

[0029] Step 1.2, perform taint propagation analysis within the function: First, set up a pollution pool, with the initial pollution sources being function parameters and direct external inputs within the function. Traverse the internal code path of the function, classify variables, and add variables with direct and indirect pollution to the pollution pool, obtain the list of called functions, and record the pollution situation of the parameters of the called functions;

[0030] Step 1.3, perform the operation of Step 1.2 on all functions in the C - language code;

[0031] Step 1.4, take functions as atoms and the extracted data as the attributes of atoms, and store them in the mongoDB database to complete the construction of the function atom pool.

[0032] Further, the vulnerability determination module is specifically configured to:

[0033] Construct vulnerability models for injection and overflow vulnerabilities; among them, the function parameters corresponding to overflow vulnerabilities must meet the conditions that the source variables are controllable and the memory space they point to is larger than the target variables; the function parameters corresponding to injection vulnerabilities need to satisfy the string type and the strings in the execution part are controllable;

[0034] Retrieve whether the dangerous function call points in the path ending function conform to the constructed vulnerability model. If they conform, the call points are considered as vulnerability points; if not, the paths having a call relationship with the dangerous function call points are deleted.

[0035] Compared with the prior art, the beneficial effects of the present invention are:

[0036] The present invention first performs data flow analysis on a single function, uses parameters and external inputs as pollution sources, and analyzes the pollution conditions of variables in the function and the parameters of the called functions by using the method of static taint analysis to obtain relevant information of the function. After the acquisition is completed, the function can be regarded as an atom with attributes, and thus the focus of analysis can be placed on the path components between functions. The complexity of analyzing a single function is much lower than that of combined functions, and it also avoids the drawbacks brought by repeated function analysis. Moreover, the target detected by the present invention is the C language code after IDA disassembly, and combined with the method of atomic combination, the path length of the data flow will be greatly shortened and streamlined, which is beneficial to reducing the required resources and improving the detection accuracy.

[0037] The present invention first atomizes the function, which is a downgrade of the function analysis difficulty. By decoupling the entire program, the complexity of analyzing combined functions is reduced, and then the function is regarded as a whole and analyzed. Here, the difficulty of static taint analysis is reduced, and these operations will all reduce the resources consumed by static taint analysis. When constructing the path network diagram, the raw materials used are the function atoms that have been constructed. These atoms have attributes such as call information and called information, so the path network diagram can be quickly constructed in an assembled form, and the attributes such as the pollution conditions of the call parameters of the atoms are used to optimize the path, so that the reachability of the path from the input point to the dangerous function call point is greatly improved. BRIEF DESCRIPTION OF THE DRAWINGS

[0038] Figure 1 It is the basic flowchart of a binary taint vulnerability detection method based on static taint analysis according to an embodiment of the present invention;

[0039] Figure 2 It is the path network diagram constructed by a binary taint vulnerability detection method based on static taint analysis according to an embodiment of the present invention;

[0040] Figure 3 This is the taint analysis diagram of a binary taint - type vulnerability detection method based on static taint analysis according to an embodiment of the present invention;

[0041] Figure 4 This is the path network diagram after taint analysis optimization of a binary taint - type vulnerability detection method based on static taint analysis according to an embodiment of the present invention;

[0042] Figure 5 This is the determination diagram for the establishment of vulnerability points of a binary taint - type vulnerability detection method based on static taint analysis according to an embodiment of the present invention;

[0043] Figure 6 This is the schematic architecture diagram of a binary taint - type vulnerability detection system according to an embodiment of the present invention. Detailed implementation manners

[0044] The following further explains the present invention in conjunction with the accompanying drawings and specific embodiments:

[0045] As Figure 1 shown, a binary taint - type vulnerability detection method based on static taint analysis is provided. This method detects taint - type vulnerabilities such as injection - type and overflow - type vulnerabilities in router firmware through static taint analysis. First, taking functions as a whole, it obtains their call relationships and variable taint sets. Secondly, it assembles all path network diagrams starting from user input or the main function and ending at functions with vulnerability points using the function call graph, and optimizes the path network diagrams using the data in the atomic pool to remove unexploitable paths. Finally, it analyzes the functions at the ends of the paths using pattern matching to screen out potential vulnerability points. It mainly includes three key steps:

[0046] Step S101, constructing a function atomic pool. Use IDA Pro to disassemble the binary file to obtain C - language code. Taking function parameters and external input points as pollution sources, traverse the entire function to obtain polluted variables, the call relationships of functions, and the pollution situations of the parameters of called functions. Perform the above operations on all functions, and take functions as atoms and the extracted data as the attributes of the atoms, and store them in the database.

[0047] Step S102, construction and optimization of the path network graph. Set the external input function as the starting point, such as nvram_bufget, get_var, websGetVar, and use the function that calls the starting point as the beginning of the path. Use dangerous functions such as system, strcpy, memcpy as the end points, and use the function that calls the dangerous function as the end of the path. According to the call relationship between functions, use the breadth-first algorithm to traverse forward from the starting point to the end point to construct all path network graphs from the starting point to the end point, and use the attributes of atoms to optimize the path network graph and prune the unreachable paths.

[0048] Step S103, vulnerability establishment determination. Construct vulnerability models for injection and overflow vulnerabilities, and retrieve whether the dangerous function call points in the function at the end of the path conform to the vulnerability models. If they conform, it can be considered that the call points are vulnerability points.

[0049] Specifically, step S101, constructing the function atom pool includes:

[0050] Taking the function as the main body, obtain the call and called relationship of the function, the set of variables polluted within the function, and the pollution situation of the parameters of the called functions within the function. The main purpose of this step is to degrade the complexity of the function. After extracting the necessary information, the function can be regarded as an atomic node with attributes, simplifying the complexity of constructing the pollution path.

[0051] Use the disassembler IDA Pro to disassemble the collected binary files. For taint propagation analysis within the function, first set a pollution pool, and the initial pollution sources are function parameters and direct external inputs within the function, such as nvram_bufget, get_var, websGetVar. Traverse the internal code path of the function, classify the variables, and add the variables with direct and indirect pollution to the pollution pool, obtain the list of called functions, and record the pollution situation of these function parameters. Perform the above taint propagation analysis operation within the function for all functions in the C language code. Specifically, the atom pool construction algorithm is as follows:

[0052] Algorithm 1: Atom Pool Construction Algorithm

[0053]

[0054] Then, taking the function as an atom and the extracted data as the attributes of the atom, use the mongoDB database to store the extracted atom attributes, and the storage format is as follows:

[0055]

[0056] Specifically, step S102, construction and optimization of the path network graph includes:

[0057] This step requires constructing a path network graph and optimizing it so that external input data can reach the dangerous function call point. First, set the starting point and the ending point; then construct all paths from the starting point to the ending point; finally, use the atomic attributes in the atomic pool constructed in the previous step to optimize the constructed paths and delete the unavailable paths.

[0058] The starting point is a function that can directly accept external input, such as nvram_bufget, get_var, websGetVar, etc. Input functions generally come into play only when called by other functions. Therefore, the first section of the function path is generally the function that directly calls the input function. The ending point is the dangerous function where the vulnerability occurs, such as functions like system, strcpy, memcpy, etc. Similar to the input function, the ending point alone does not trigger the vulnerability. So, the last section of the path is generally the function that calls the ending function conforming to the vulnerability characteristics. To construct the path network graph, use the breadth-first algorithm to traverse forward from the starting point to the ending point. The traversal algorithm is as follows:

[0059] Algorithm 2: Breadth-First Traversal Algorithm for Path Network Graph

[0060]

[0061] The path network graph constructed according to Algorithm 2 is as Figure 2 shown.

[0062] Figure 2 All the nodes represented by circles in it are functions. Each node is connected by a directed arrow. The starting point of the arrow is the function that calls the function, and the ending point is the function being called; the blank circle on the left is the function that can accept external input, the solid black circle on the right is the dangerous function, and the gray circle in the middle is the taint propagation function.

[0063] Since the path network graph is all paths from the starting point to the ending point, there are many unavailable paths. For example, the parameters of the called function are not contaminated or are all contaminated, which makes the input data unable to pass through this node. Therefore, such nodes should be deleted. The basis for node deletion is the attributes of the function atoms obtained in the first step, which record the contamination situation of the parameters of the called function in the function. The optimization process is as Figure 3 shown in and Figure 4.

[0064] Specifically, in step S103, the determination of vulnerability establishment includes:

[0065] So far, the optimized taint transfer path has been obtained, and the external input can reach the dangerous function call function correctly. Therefore, the work of this step is to determine whether the parameters of the dangerous function are controllable and whether the parameter characteristics inject vulnerability characteristics of vulnerability types such as class injection and overflow. If so, it can be considered that this call point is a potential vulnerability point.

[0066] Whether the parameters of the dangerous function are controllable can be obtained based on the atomic attributes of the dangerous function call function. The characteristics of the overflow vulnerability type must meet the conditions that the source variable is controllable and the memory space it points to is larger than the target variable; the contact points of the injection vulnerability type are generally system command execution functions. Therefore, the contaminated parameters need to meet the string type and the executed part of the string needs to be controllable because some command execution functions will limit the length of the command during operation.

[0067] Algorithm 3 Vulnerability Establishment Judgment Algorithm

[0068]

[0069] For the vulnerability points (dangerous function call points) determined to be not established, the paths with call relationships with this vulnerability point are deleted. This set of call relationships generally exists at the end of the path, as Figure 5 shown. Then, the paths determined to be established are saved to the database.

[0070] As Figure 6 shown, based on the above embodiments, the present invention also proposes a binary taint vulnerability detection system based on static taint analysis, including:

[0071] A construction module for constructing a function atom pool: Using IDA Pro to disassemble the binary file to obtain C language code; taking function parameters and external input points as pollution sources, traversing the entire function to obtain the contaminated variables, the call relationships of the functions, and the pollution conditions of the parameters of the called functions. Perform the above operations on all functions, and use functions as atoms and the extracted data as the attributes of the atoms, and store them in the database;

[0072] A construction and optimization module for constructing and optimizing the path network graph: Setting the external input function as the starting point, taking the function that calls the starting point as the beginning of the path, taking the dangerous function as the end point, and taking the function that calls the dangerous function as the end of the path. According to the call relationships between functions, use the breadth-first algorithm to perform forward traversal from the starting point to the end point to construct all path network graphs from the starting point to the end point; and use the attributes of the atoms to optimize the path network graph and prune the unreachable paths;

[0073] The vulnerability determination module is used to determine the establishment of vulnerabilities: build vulnerability models for injection - type and overflow - type vulnerabilities, and retrieve whether the dangerous function call points in the path - ending functions conform to the vulnerability models. If they conform, the call points can be considered as vulnerability points.

[0074] Furthermore, the external input functions include nvram_bufget, get_var, websGetVar; the dangerous functions include system, strcpy, memcpy.

[0075] Furthermore, the building module is specifically used for:

[0076] Step 1.1: Use the disassembler IDA Pro to disassemble the binary file to obtain C - language code.

[0077] Step 1.2: Conduct taint - propagation analysis within the function. First, set a taint pool. The initial pollution sources are function parameters and direct external inputs within the function. Traverse the internal code path of the function, classify variables, and add variables with direct and indirect pollution to the taint pool. Obtain the list of called functions and record the pollution situation of the parameters of the called functions.

[0078] Step 1.3: Perform the operation of Step 1.2 on all functions in the C - language code.

[0079] Step 1.4: Take functions as atoms and the extracted data as the attributes of the atoms, and store them in the mongoDB database to complete the construction of the function atom pool.

[0080] Furthermore, the vulnerability determination module is specifically used for:

[0081] Build vulnerability models for injection - type and overflow - type vulnerabilities. Among them, the function parameters corresponding to overflow - type vulnerabilities must meet the conditions that the source variable is controllable and the memory space it points to is larger than the target variable; the function parameters corresponding to injection - type vulnerabilities need to meet the conditions of string type and the controllability of the executed part of the string.

[0082] Retrieve whether the dangerous function call points in the path - ending functions conform to the built vulnerability models. If they conform, the call points are considered as vulnerability points. If they do not conform, delete the paths that have a call relationship with the dangerous function call points.

[0083] In summary, the present invention first performs data flow analysis on a single function. Taking parameters and external inputs as pollution sources, it uses the method of static taint analysis to analyze the pollution conditions of variables within the function and the parameters of called functions, and obtains relevant information of the function. After the acquisition is completed, the function can be regarded as an atom with attributes, and thus the focus of analysis can be placed on the path components between functions. The complexity of analyzing a single function is much lower than that of analyzing combined functions, and it also avoids the drawbacks brought by repeated function analysis. Moreover, the object detected by the present invention is the C language code after IDA disassembly, and combined with the method of atomic combination, this greatly shortens and streamlines the path length of the data flow, which is beneficial to reducing the required resources and improving the detection accuracy.

[0084] The present invention first atomizes the function, which is a downgrade of the function analysis difficulty. By decoupling the entire program, the complexity of analyzing combined functions is reduced, and then the function is regarded as a whole for analysis. Here, the difficulty of static taint analysis is lowered. All these operations will reduce the resources consumed by static taint analysis. When constructing the path network diagram, the raw materials used are the function atoms that have already been constructed. These atoms all have attributes such as call information and called information. Therefore, the path network diagram can be quickly constructed in an assembled form, and the attributes such as the pollution conditions of the call parameters of the atoms are used to optimize the path, greatly improving the reachability of the path from the input point to the dangerous function call point.

[0085] The above are only the preferred embodiments of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present invention, several improvements and refinements can still be made, and these improvements and refinements should also be regarded as the protection scope of the present invention.

Claims

1. A binary taint vulnerability detection method based on static taint analysis, characterized in that including: Step 1, constructing a function atom pool: Disassembling the binary file using IDA Pro to obtain C language code; Taking function parameters and external input points as pollution sources, traversing the entire function to obtain the polluted variables, the call relationships of functions, and the pollution conditions of the parameters of the called functions. Performing the above operations on all functions, and taking functions as atoms and the extracted data as the attributes of the atoms, storing them in the database; Step 2, constructing and optimizing the path network graph: Setting the external input function as the starting point, taking the function that calls the starting point as the beginning of the path, taking the dangerous function as the end point, and taking the function that calls the dangerous function as the end of the path. According to the call relationships between functions, using the breadth-first algorithm to perform a forward traversal from the starting point to the end point to construct all path network graphs from the starting point to the end point; and optimizing the path network graph using the attributes of the atoms to prune the unreachable paths; Step 3, determining the establishment of vulnerability: Constructing vulnerability models for injection and overflow vulnerabilities, and retrieving whether the dangerous function call points in the path-ending function conform to the vulnerability models. If they conform, it can be considered that the call points are vulnerability points.

2. The binary taint vulnerability detection method based on static taint analysis according to claim 1, wherein The external input functions include nvram_bufget, get_var, and websGetVar; the dangerous functions include system, strcpy, and memcpy.

3. The binary taint vulnerability detection method based on static taint analysis according to claim 1, wherein The said Step 1 includes: Step 1.1, disassembling the binary file using the disassembling tool IDA Pro to obtain C language code; Step 1.2, performing taint propagation analysis within the function: First, setting up a pollution pool, with the initial pollution sources being function parameters and direct external inputs within the function. Traversing the internal code path of the function, classifying variables, and adding variables with direct and indirect pollution to the pollution pool, obtaining the list of called functions, and recording the pollution conditions of the parameters of the called functions; Step 1.3, performing the operation of Step 1.2 on all functions in the C language code; Step 1.4, taking functions as atoms and the extracted data as the attributes of the atoms, storing them in the mongoDB database to complete the construction of the function atom pool.

4. The binary taint-based vulnerability detection method based on static taint analysis according to claim 1 or 3, characterized in that The said Step 3 includes: Constructing vulnerability models for injection and overflow vulnerabilities; among them, the function parameters corresponding to overflow vulnerabilities must meet the conditions that the source variable is controllable and the memory space it points to is larger than the target variable; the function parameters corresponding to injection vulnerabilities need to meet the conditions of string type and the string part of the execution is controllable; Retrieving whether the dangerous function call points in the path-ending function conform to the constructed vulnerability models. If they conform, it is considered that the call points are vulnerability points. If they do not conform, deleting the paths that have call relationships with the dangerous function call points.

5. A binary taint-based vulnerability detection system based on static taint analysis, characterized in that, including: A construction module, used for constructing a function atom pool: Disassembling the binary file using IDA Pro to obtain C language code; Taking function parameters and external input points as pollution sources, traversing the entire function to obtain the polluted variables, the call relationships of functions, and the pollution conditions of the parameters of the called functions. Performing the above operations on all functions, and taking functions as atoms and the extracted data as the attributes of the atoms, storing them in the database; Build an optimization module for constructing and optimizing the path network diagram: Set the external input function as the starting point, the function that calls the starting point as the beginning of the path, the dangerous function as the end point, and the function that calls the dangerous function as the end of the path. According to the call relationship between functions, use the breadth-first algorithm to traverse forward from the starting point to the end point to construct all path network diagrams from the starting point to the end point; and use the attributes of atoms to optimize the path network diagram and prune the unreachable paths. A vulnerability determination module for determining the establishment of vulnerability: Construct vulnerability models for injection and overflow vulnerabilities, and retrieve whether the dangerous function call points in the path-ending function conform to the vulnerability models. If they conform, the call points can be considered as vulnerability points.

6. The binary taint type vulnerability detection system based on static taint analysis according to claim 5, characterized in that, The external input functions include nvram_bufget, get_var, and websGetVar; the dangerous functions include system, strcpy, and memcpy.

7. The binary taint vulnerability detection system based on static taint analysis according to claim 5, characterized in that, The construction module is specifically used for: Step 1.1, use the disassembler IDA Pro to disassemble the binary file to obtain C language code. Step 1.2, perform taint propagation analysis within the function: First, set a taint pool, with the initial pollution sources being function parameters and direct external inputs within the function. Traverse the internal code path of the function, classify variables, and add variables with direct and indirect pollution to the taint pool. Obtain the list of called functions and record the pollution situation of the parameters of the called functions. Step 1.3, perform the operation of Step 1.2 on all functions in the C language code. Step 1.4, take functions as atoms and the extracted data as the attributes of atoms, and store them in the mongoDB database to complete the construction of the function atom pool.

8. The binary taint-based vulnerability detection system based on static taint analysis according to claim 5 or 7, characterized in that The vulnerability determination module is specifically used for: Construct vulnerability models for injection and overflow vulnerabilities; among them, the function parameters corresponding to overflow vulnerabilities must meet the conditions that the source variable is controllable and the memory space it points to is larger than the target variable; the function parameters corresponding to injection vulnerabilities need to meet the conditions of string type and controllability of the executed part of the string. Retrieve whether the dangerous function call points in the path-ending function conform to the constructed vulnerability models. If they conform, the call points are considered as vulnerability points. If they do not conform, delete the paths that have a call relationship with the dangerous function call points.

Citation Information

Patent Citations

  • Method for discovering binary code vulnerability based on function model

    CN101814053A

  • Path-sensitive analysis framework for bug checking

    US20140344633A1