Instruction-level code reuse analysis method and instruction-level code reuse method

The instruction-level code reuse analysis method improves precision and efficiency in identifying and validating gadgets within binary code, addressing the limitations of existing non-control data-based methods by ensuring reachability and adherence to the original control flow graph.

CN115237405BActive Publication Date: 2025-07-15HUAZHONG UNIV OF SCI & TECH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210672521.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-06-14
Publication Date
2025-07-15
Estimated Expiration
2042-06-14

AI Technical Summary

Technical Problem

The existing code reuse methods based on non-control data have problems such as low analysis accuracy, low Gadgets accessibility and strong attack concealment, making it difficult to detect at the binary level.

Method used

The instruction-level code multiplexing analysis method is adopted to identify Gadgets by instrumenting the target binary code and combining dynamic taint analysis and symbol execution technology to identify and solve path constraint values to ensure the accessibility and accuracy of Gadgets.

Benefits of technology

Improves the accuracy and efficiency of code reuse, enables accurate identification of reusable Gadgets without changing the control flow, simplifies the analysis process, and supports hidden code poisoning analysis.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115237405B_ABST
    Figure CN115237405B_ABST
Patent Text Reader

Abstract

The present invention discloses an instruction-level code reuse analysis method and an instruction-level code reuse method, belonging to the field of code analysis and reuse, including: identifying Gadgets therein to obtain an initial Gadgets set by inserting a first callback function at each instruction of the target binary code; screening out the contaminated Gadgets from the initial Gadgets set through dynamic taint analysis technology as available Gadgets; for each available Gadget, using symbolic execution technology to obtain the execution path from the symbolic execution starting position to this available Gadget, constructing a path constraint expression and solving to obtain a path constraint value, if the execution path is successfully obtained and the path constraint value is successfully solved, then taking this available Gadget as a reusable Gadget; taking all reusable Gadgets and their path constraint values as the recognition result, and the recognition ends. The present invention can improve the accuracy of code reuse, ensure the reachability of the searched Gadgets, and is also conducive to code poisoning analysis.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of code analysis and reuse, and more specifically, relates to an instruction-level code reuse analysis method and an instruction-level code reuse method. Background Art

[0002] Code reuse is a technology that reuses existing code fragments (Gadgets) in target code. Gadgets are derived from legal code fragments of the target program, are naturally executable, and can naturally bypass or the DEP defense mechanism, greatly improving the code reuse ability, providing a new idea for code protection, and also opening up a new technical means for in-depth code poisoning analysis; currently, the research on code reuse mainly focuses on control-data-based code reuse. Typical control-data-based code reuse techniques include ROP (return-Oriented Programming) and JOP (Jump-Oriented Programming). The idea of ROP is mainly to extract instruction fragments ending with ret from existing libraries or executable files as Gadgets, use stack overflow vulnerabilities to fill the address sequence and values of the instruction fragments to be concatenated into the stack space in a set order, and concatenate the reusable Gadgets through the ret instruction to achieve Turing-complete functions. JOP constructs malicious code using code fragments ending with indirect call and indirect jmp instructions. An important feature of control-data-based code reuse is to change the program execution control flow. With the deployment of the Control-Flow Integrity (CFI) mechanism, control-data-based code reuse has become increasingly difficult.

[0003] Currently, some scholars have turned code reuse to the non-control data field. Code reuse based on non-control data can achieve code reuse without changing the program control flow. However, there are three problems with existing code reuse in the non-control data field: First, the granularity of code reuse analysis is limited to the intermediate code representation level, and the accuracy of reuse analysis is low; Second, code reuse uses static code analysis techniques, and the reachability of the searched Gadgets is low; Third, non-control data attacks can achieve code reuse attacks without changing the program control flow, with strong concealment and difficulty in detection. Moreover, attackers can cleverly use the complexity of code scale as a cover and bury the attacks in advance, further increasing the difficulty of detecting the attacks. This also makes it difficult for existing non-control data-based code reuse methods to detect code reuse attacks at the binary level. Summary of the Invention

[0004] In view of the defects and improvement requirements of the prior art, the present invention provides an instruction-level code reuse analysis method and an instruction-level code reuse method, aiming to realize instruction-level code reuse analysis, improve the code reuse accuracy, ensure the reachability of the searched Gadgets, and facilitate code poisoning analysis.

[0005] To achieve the above object, according to one aspect of the present invention, there is provided an instruction-level code reuse analysis method for identifying reusable Gadgets in a target binary code and solving corresponding path constraint values without changing the control flow; Gadgets are code segments for implementing target basic operations, and the target basic operations include arithmetic operations, assignment operations, and dereference operations; the method includes:

[0006] (S1) By inserting a first callback function at each instruction of the target binary code, identify the Gadgets in the target binary code to obtain an initial Gadgets set;

[0007] The first callback function is used to analyze the instructions and search for Gadgets in the target binary code based on the instruction analysis results;

[0008] (S2) Use dynamic taint analysis technology to screen out the tainted Gadgets from the initial Gadgets set as available Gadgets;

[0009] (S3) For each available Gadget, use symbolic execution technology to obtain the execution path from the symbolic execution start position to the available Gadget in the target binary code, construct a path constraint expression for the execution path and solve to obtain a path constraint value. If the execution path is successfully obtained and the path constraint value is successfully solved, then use the available Gadget as a reusable Gadget;

[0010] (S4) Take all the reusable Gadgets and their corresponding path constraint values as the identification results, and the identification ends.

[0011] Further, in step (S3), for any available Gadget, the following steps are performed:

[0012] (S31) Take the selected available Gadget as the target Gadget and determine the start position of symbolic execution;

[0013] (S32) Set the bytes of the memory units in the taint analysis space as symbolic variables and initialize these symbolic variables;

[0014] The taint analysis space is the contaminated memory space determined by the dynamic taint analysis technology in step (S2);

[0015] (S33) Obtain the static control flow graph of the target binary code, and use static analysis technology to exhaust all execution paths of the target binary code. Regard the execution paths that cannot reach the target Gadgets as blacklist paths and save them to the path search configuration file; determine the POC execution paths from the symbolic execution starting position to the target Gadgets obtained during the execution of the POC script as whitelist paths and write them into the path search configuration file;

[0016] (S34) Use the symbolic execution engine to execute the target binary code starting from the symbolic execution starting position, and import the path search configuration file into the symbolic execution engine, so that the symbolic execution engine can perform heuristic branch jumps according to the blacklist paths and whitelist paths during the execution process;

[0017] (S35) If the symbolic execution engine reaches the target Gadgets within the preset total number of jump thresholds and search depth thresholds, go to step (S36); otherwise, go to step (S37);

[0018] (S36) According to the symbolic variables defined in step (S32), symbolize the constraint conditions of the execution paths that reach the target Gadgets to obtain a path constraint expression, solve the path constraint expression, and obtain the path constraint value of the target Gadgets; if the solution is successful, determine that the target Gadgets are reusable Gadgets and go to step (S37); if the solution is unsuccessful and there are still unsearched paths in the path search configuration file, go to step (S34) to start searching for the next path; if the solution is unsuccessful and there are no unsearched paths in the path search configuration file, it means that the Gadgets are not reusable and go to step (S37);

[0019] (S37) The analysis of the target Gadgets ends.

[0020] Further, in step (S34), when the symbolic execution engine implements branch jumps, it preferentially jumps to the Gadgets located on the POC execution path.

[0021] Further, in step (S2), the pollution sources in dynamic taint analysis include: external input and vulnerable covered memory;

[0022] The taint propagation rules of dynamic taint analysis are as follows:

[0023] For the load meta-operation instruction, if the address or the value of the address in the instruction is a pollution source or is polluted, the register in the instruction is polluted;

[0024] For a storage element operation instruction, if the register in the instruction is contaminated, then the address and the value of the address in the instruction are contaminated;

[0025] For a binary operation element operation instruction, if at least one register in the instruction is contaminated, then the first register is contaminated; if only the first register is contaminated, then the second register is not contaminated;

[0026] The execution mode of dynamic taint analysis is: dynamically insert a second callback function at the API function where the user input is located in the target binary code; the second callback function is used to analyze the API function and determine the memory space that can be contaminated based on the defined pollution sources and taint propagation rules;

[0027] Wherein, the first register and the second register are respectively the two registers in the binary operation element operation instruction, and the first register is the register for storing the operation result.

[0028] According to another aspect of the present invention, an instruction-level code reuse method is provided for realizing the reuse of target binary code without changing the control flow; the method includes:

[0029] For the target binary code, execute the above-mentioned instruction-level code reuse analysis method provided by the present invention to obtain the reusable Gadgets and the corresponding path constraint values in the target binary code;

[0030] Establish a memory pollution dependency table for the target binary code; the memory pollution dependency table records the mapping relationship from the pollution source address to the pollution destination address;

[0031] According to the reuse function to be realized, execute the corresponding reuse strategy; the reuse strategy includes a single Gadgets single reuse strategy, and its execution mode includes:

[0032] (A1) Select a reusable Gadgets that can realize the reuse function and obtain its path constraint value;

[0033] (A2) Input the obtained path constraint value through the program input or the input of the vulnerability exploitation to reach the selected reusable Gadgets;

[0034] (A3) Determine the memory address to be operated by the reuse function as the pollution destination address, and determine the corresponding pollution source address through the memory pollution dependency table, and modify the memory value at the pollution source address so that different functions are realized after the selected Gadgets are executed.

[0035] Further, the reuse strategy also includes a single Gadgets multiple reuse strategy, and its execution mode includes:

[0036] (B1) Select a reusable Gadget that can achieve the reuse function and obtain its path constraint value;

[0037] (B2) Through program input or exploit input, input the obtained path constraint value to reach the selected reusable Gadget;

[0038] (B3) Determine the memory address to be operated on by the reuse function as the pollution target address, and determine the corresponding pollution source address through the memory pollution dependency table. Modify the memory value at the pollution source address so that different functions are realized after the selected Gadget is executed, and complete one reuse;

[0039] (B4) According to the number of reuse times required, execute steps (B2) to (B3) multiple times to achieve multiple reuse of a single Gadget.

[0040] Further, the reuse strategy also includes a single - reuse strategy for multiple Gadgets, and its execution method includes:

[0041] (C1) Select multiple reusable Gadgets that can achieve the reuse function and meet the reuse conditions, and obtain the path constraint values of each reusable Gadget;

[0042] The reuse condition is: the address of the storage meta - operation in the pre - Gadget is the same as the address of the load meta - operation in the post - Gadget; among the selected multiple reusable Gadgets, the pre - executed and post - executed reusable Gadgets are the pre - Gadget and the post - Gadget respectively;

[0043] (C2) Organize the selected reusable Gadgets together in an orderly manner according to the pre - and post - relationship;

[0044] (C3) Reach the selected reusable Gadgets in sequence. Each time after reaching a reusable Gadget, determine the memory address to be operated on by the reuse function as the pollution target address, and determine the corresponding pollution source address through the memory pollution dependency table. Modify the memory value at the pollution source address so that different functions are realized after the selected Gadget is executed; after all the selected reusable Gadgets are executed, achieve single - reuse of multiple Gadgets;

[0045] Among them, the way to reach the reusable Gadget is: through program input or exploit input, input the path constraint value of this reusable Gadget to reach this reusable Gadget.

[0046] Further, the reuse strategy also includes a multiple - reuse strategy for multiple Gadgets, and its execution method includes:

[0047] (D1) Select multiple reusable Gadgets that can achieve the reuse function and meet the reuse conditions, and obtain the path constraint values of each reusable Gadget;

[0048] (D2) Organize the selected reusable Gadgets together in an orderly manner according to the pre - and post - successor relationships;

[0049] (D3) Sequentially reach the selected reusable Gadgets. Each time a reusable Gadget is reached, determine the memory address to be operated on by the reuse function as the pollution target address, and determine the corresponding pollution source address through the memory pollution dependency table, and modify the memory value at the pollution source address so that different functions are achieved after the selected Gadgets are executed; after all the selected reusable Gadgets are executed, multiple Gadgets are reused at one time;

[0050] The way to reach the reusable Gadget is: through the program input or the input of vulnerability exploitation, input the path constraint value of the reusable Gadget to reach the reusable Gadget;

[0051] (D4) According to the number of reuse times required, execute step (D3) multiple times to achieve multiple reuses of multiple Gadgets.

[0052] Furthermore, steps (C1) and (D1) also include:

[0053] If among the selected multiple reusable Gadgets, there is a situation where the pre - Gadget and the post - Gadget do not meet the reuse conditions, then judge whether both the address of the store primitive operation in the pre - Gadget and the address of the load primitive operation in the post - Gadget are in the taint analysis space. If so, modify the address of the store primitive operation in the pre - Gadget and the address of the load primitive operation in the post - Gadget to be the same to ensure that the selected multiple reusable Gadgets meet the reuse conditions.

[0054] Furthermore, the way to establish the memory pollution dependency table includes:

[0055] Add a record of the address relationship in each instruction using the five - tuple <pollution source number, pollution source address, pollution target address, source coloring sequence, target coloring sequence> in the first callback function, where the pollution source number is used to uniquely identify the pollution source; the pollution source address and the pollution target address are the addresses of the pollution source in memory and the memory unit address to be polluted respectively; the source coloring sequence and the target coloring sequence are the sequence values after the pollution source address and the pollution target address are colored respectively;

[0056] For each executed instruction, the corresponding five-tuple is updated. After all instructions are executed, one round of coloring is completed. After executing at least rounds of coloring, the five-tuples with the same source coloring sequence and destination coloring sequence are filtered out, the source pollution address and the pollution destination address among them are extracted, and the mapping relationship is established and recorded in the memory pollution dependency table; N represents the total number of colors used for coloring, T represents the total number of bytes of the source pollution number, represents rounding up;

[0057] Each round of coloring includes the following steps:

[0058] (T0) Take the first instruction as the current instruction;

[0059] (T1) If the current instruction contains a source of pollution, update the source pollution number and the address of the source of pollution in the memory to the five-tuple, and transfer to step (T2); otherwise, transfer to step (T3);

[0060] (T2) Color the source pollution number to obtain the source coloring sequence and update it to the five-tuple; the method of coloring the source of pollution is:

[0061] Pre-define N different colors, and the corresponding color numbers are 1 to N in sequence;

[0062] Color the memory address of the source of pollution byte by byte as the 1st to Nth colors in sequence, and color the pollution destination address according to the pollution propagation rule to obtain the source coloring sequence and the destination coloring sequence, and update them to the five-tuple;

[0063] (T3) If there are still unexecuted instructions, take the next instruction of the current instruction and transfer to step (T1); otherwise, the current round of coloring ends.

[0064] Generally speaking, through the above technical solutions conceived by the present invention, the following beneficial effects can be achieved:

[0065] (1) The present invention takes binary code as the analysis object for code reuse, and uses the code snippets that implement arithmetic operations, assignment operations, and dereference operations as the units to be analyzed, namely Gadgets. By means of instruction-level dynamic instrumentation, each instruction in the code is analyzed, and combined with dynamic taint analysis technology and symbolic execution technology, reusable Gadgets are identified and the corresponding path constraint values are solved. This analysis method extends from non-control data to the instruction level, only needs to focus on the limited running logic at the binary code level, and does not need to consider the complex logical relationships of the source code and the differences brought by different source code language types, effectively improving the accuracy of code reuse. Moreover, since in the analysis process of the present invention, the defined Gadgets only involve load primitive operations, store primitive operations, and arithmetic primitive operations, and do not involve jump primitive operations, it can ensure that the instruction-level code reuse paths obtained by the analysis strictly follow the original CFG control flow of the binary code. Generally speaking, the present invention effectively improves the accuracy of code reuse without changing the original CFG control flow of the binary code.

[0066] (2) The present invention uses an instruction-level dynamic instrumentation method oriented to the binary level to analyze each instruction in the binary code, and further identifies the Gadgets therein. The Gadgets searched in this way are inherently reachable. Therefore, the present invention can ensure that the searched Gadgets are reachable, and in the process of code reuse analysis, there is no need to perform Gadget reachability analysis, which simplifies the code reuse analysis process and improves the analysis efficiency of code reuse.

[0067] (3) The present invention uses an instruction-level dynamic instrumentation method oriented to the binary level to analyze each instruction in the binary code, and further identifies the Gadgets therein. By combining dynamic taint analysis technology and symbolic execution technology, reusable Gadgets are identified and the corresponding path constraint values are solved. The finally determined reusable Gadgets and the path constraint values to reach these Gadgets are closer to the program origin. Based on these code reuse analysis results, code reuse behaviors can be accurately identified and located, which is beneficial to realizing more covert code poisoning analysis.

[0068] (4) In the analysis process of the present invention, the defined Gadgets are code snippets composed of load primitive operations, store primitive operations, and arithmetic primitive operations in a specific order. The instruction characteristics corresponding to the three types of primitive operations involved are simple, clear, and easy to identify. Correspondingly, the present invention effectively simplifies the extraction rules of Gadgets, so that the Gadgets that need to be further analyzed can be searched from the binary code efficiently and quickly.

[0069] (5) Based on the analysis results of instruction-level code reuse, the present invention formulates various instruction-level code reuse strategies, including the single reuse strategy of single Gadgets, the multiple reuse strategy of single Gadgets, the single reuse strategy of multiple Gadgets, and the multiple reuse strategy of multiple Gadgets, which can cover various different actual reuse requirements.

[0070] Generally speaking, the present invention can effectively solve the technical problems existing in the existing code reuse method based on non-control data, such as low accuracy of reuse analysis, low reachability of Gadgets, and high difficulty in detecting attacks. Brief Description of the Drawings

[0071] Figure 1 It is a flowchart of the instruction-level code reuse analysis method provided by an embodiment of the present invention;

[0072] Figure 2 It is a schematic diagram of the single reuse strategy of multiple Gadgets provided by an embodiment of the present invention;

[0073] Figure 3 It is a disassembly control flowchart of the target binary code provided by an embodiment of the present invention;

[0074] Figure 4 It is a stack space layout diagram when the target binary code executes a vulnerable function provided by an embodiment of the present invention;

[0075] Figure 5 It is a schematic diagram of the semantic memory and assembly code for the function of writing any value to any memory provided by an embodiment of the present invention. Detailed Description of the Embodiments

[0076] In order to make the objectives, technical solutions and advantages of the present invention clearer and more understandable, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention. In addition, the technical features involved in the various embodiments of the present invention described below can be combined with each other as long as they do not conflict with each other.

[0077] In the present invention, the terms "first", "second", etc. (if any) in the present invention and the accompanying drawings are used to distinguish similar objects and do not necessarily need to describe a specific order or sequence.

[0078] To solve the technical problems of the existing code reuse analysis methods for non-control data, such as low analysis accuracy, low reachability of the searched Gadgets, and difficulty in detecting code reuse attacks at the binary level, the present invention provides an instruction-level code reuse analysis method and an instruction-level code reuse method. The overall idea is as follows: Based on the execution mechanism of the program, that is, no matter how complex the source code is, it ultimately needs to be transformed into binary code that can be executed by the machine. Directly using the binary code as the analysis object for code reuse, and exploiting the vulnerabilities of the binary code while strictly following the original CFG execution flow of the binary code to identify reusable Gadgets in the binary code, that is, specified code segments, and determining the path constraint values to reach these reusable Gadgets; on this basis, according to the actual reuse requirements, select reusable Gadgets and combine the corresponding path constraint values to reuse the selected Gadgets to achieve instruction-level code reuse.

[0079] In the present invention, three types of meta-operation instructions need to be analyzed, namely, store meta-operation instructions, load meta-operation instructions, and arithmetic meta-operation instructions. The formal descriptions of the characteristics of these meta-operation instructions have a certain degree of generality; taking the binary code suitable for C / C++ code compilation in the Windows and Linux operating systems of the x86_64 architecture as an example, the definitions and formal descriptions of binary instructions of these three types of meta-operation instructions are as follows:

[0080] (1) Load instruction: Defined as the operation of reading data from a certain address into a certain register; the formal description of the binary instruction is:

[0081] mov register, address

[0082] (2) Store instruction: Defined as storing the value of a certain register back to a certain address, and the formal description of the binary instruction is:

[0083] mov address, register

[0084] (3) Arithmetic instruction, divided into binary arithmetic instructions and unary arithmetic instructions; binary arithmetic instructions are defined as the operation of taking the values of register 1 and register 2, performing the op operation, and saving the result to register 1. Among them, the binary op operators include two major categories: arithmetic operators and logical operators. Arithmetic operators include ADD, SUB, MUL, DIV, etc., and logical operators include AND, OR, XOR, etc.; the formal description of the binary instruction is:

[0085] op register1, register2

[0086] The unary operation instruction is defined as performing the op operation on the value in the register and saving the result back to the register; the unary op operators include NOT, etc.; the binary instruction is formally described as:

[0087] op register

[0088] Based on the above meta-operation instructions, basic operations with specific functions can be implemented. In the present invention, three basic operations need to be analyzed, namely arithmetic operation, assignment operation, and dereference operation. The formal descriptions of the characteristics of these meta-operation instructions also have a certain degree of generality; similarly, taking the binary code suitable for C / C++ code compilation in the Windows and Linux operating systems of the x86_64 architecture as an example, the basic definitions and formal descriptions of binary instructions for these three basic operations are as follows:

[0089] (1) Arithmetic operation: Taking the addition operation as an example, to implement a typical addition operation, two load operations, one addition operation, and one store operation are required; the formal definition of the binary instruction is as follows:

[0090] mov register1, address1

[0091] mov register2, address2

[0092] add register1, register2

[0093] mov address3, register1

[0094] (2) Assignment operation: To implement the assignment function, one load operation and one store operation are required. The formal definition of the binary instruction is as follows:

[0095] mov register1, address1

[0096] mov address2, register1

[0097] (3) Dereference operation: To implement the dereference operation, two load operations and one store operation are required. The formal definition of the binary instruction is as follows:

[0098] mov register1, address1

[0099] mov register2, [register1]

[0100] mov address2, register2

[0101] Among them, [register1] means taking the value in register1 as the address and fetching the value at that address; address1 can be the same as or different from address2.

[0102] In the present invention, instruction fragments that implement the above three basic operations, namely arithmetic operations, assignment operations, and dereference operations, are defined as Gadgets, which serve as the basic units for subsequent reuse analysis. It can be seen that the Gadgets defined in the present invention only include load primitive operation instructions, store primitive operation instructions, and arithmetic primitive operation instructions, and do not involve jump primitive operation instructions. Therefore, code reuse does not change the original CFG control flow of the binary code.

[0103] According to the address form in the code fragment, the Gadgets defined in the present invention can be divided into three categories: if the address form in the code fragment is "EBP - offset" (the address of a local variable), then this Gadget is a local Gadget; if the address form in the code fragment is "EBP + offset" (an address in the stack), then this Gadget is a parameter Gadget; if the address form in the code fragment is a definite address value (the address of a global variable), then this Gadget is a global Gadget; EBP represents the stack base address.

[0104] For the convenience of more clearly explaining the technical solution of the present invention, in the following embodiments, the primitive operation instructions and Gadgets are both defined using the above characteristics. It should be noted that under different architectures, the characteristics of the primitive operation instructions and Gadgets may vary. The above are only the characteristic definitions under a specific architecture, and are used as an exemplary illustration and should not be construed as the sole limitation of the present invention.

[0105] The following are the embodiments.

[0106] Embodiment 1:

[0107] An instruction - level code reuse analysis method is used to identify reusable Gadgets in the target binary code and solve the corresponding path constraint values without changing the control flow. In this embodiment, Gadgets are code fragments that implement the target basic operations, and the target basic operations include arithmetic operations, assignment operations, and dereference operations.

[0108] Refer to Figure 1 , the instruction - level code reuse analysis method provided in this embodiment includes:

[0109] (S1) By inserting the first callback function at each instruction of the target binary code, identify the Gadgets in the target binary code to obtain the initial Gadgets set.

[0110] The first callback function is used to analyze the instructions and search for Gadgets in the target binary code based on the instruction analysis results.

[0111] (S2) Screen out the contaminated Gadgets from the initial Gadgets set through dynamic taint analysis technology as available Gadgets;

[0112] (S3) For each available Gadget, use symbolic execution technology to obtain the execution path from the symbolic execution start position to this available Gadget in the target binary code, construct the path constraint expression of the execution path and solve to obtain the path constraint value. If the execution path is successfully obtained and the path constraint value is successfully solved, then regard this available Gadget as a reusable Gadget;

[0113] (S4) Take all reusable Gadgets and their corresponding path constraint values as the recognition result, and the recognition ends.

[0114] Based on the definition of Gadgets, in step (S1) of this embodiment, the first callback function analyzes the instructions, including: identifying whether the instruction is a record meta-operation instruction, a store meta-operation instruction, and an arithmetic meta-operation instruction;

[0115] The recognition process of the load meta-operation instruction is specifically as follows:

[0116] In the first step, judge the instruction operator. If it is the MOV operator, then make a second judgment; in the second step, judge the first operand. If it is a register, then make a third judgment; in the third step, judge the second operand. If it is an address, then identify it as a load meta-operation instruction;

[0117] The recognition process of the store meta-operation instruction is specifically as follows:

[0118] In the first step, judge the instruction operator. If it is the MOV operator, then make a second judgment; in the second step, judge the first operand. If it is an address, then make a third judgment; in the third step, judge the second operand. If it is a register, then identify it as a store meta-operation instruction;

[0119] The recognition of the arithmetic meta-operation instruction includes:

[0120] Judge the instruction operator. If it is a unary op operator, then perform the recognition of the unary arithmetic meta-operation instruction. If it is a binary op operator, then perform the recognition of the binary arithmetic meta-operation instruction; the recognition process of the unary arithmetic meta-operation instruction is specifically as follows:

[0121] In the first step, judge the first operand. If it is a register, then make a second judgment; in the second step, judge whether there is a second operand. If not, then identify it as a unary arithmetic meta-operation instruction;

[0122] The recognition process of binary operand operation instructions is as follows:

[0123] In the first step, judge the first operand. If it is a register, then proceed to the second judgment; in the second step, judge whether there is a second operand. If there is, then proceed to the third judgment; in the third step, judge the second operand. If it is a register, it is recognized as a binary operand operation instruction.

[0124] Based on the analysis result of the instruction, Gadgets can be further searched:

[0125] Typical arithmetic basic operations require two load operations, one addition operation, and one store operation; the recognition process of arithmetic basic operations includes: in the first step, take the first instruction and judge whether the instruction is a load instruction. If so, then execute the second step; in the second step, take the second instruction and judge whether the instruction is a load instruction. If so, then execute the third step; in the third step, take the third instruction and judge whether the instruction is a certain op operation instruction. If so, then execute the fourth step; in the fourth step, take the fourth instruction and judge whether the instruction is a store operation instruction; if all the above four steps are met, these four instructions are recognized as an arithmetic basic operation Gadget.

[0126] Typical assignment basic operations require one load operation and one store operation; the recognition process of assignment basic operations includes: in the first step, take the first instruction and judge whether the instruction is a load operation instruction. If so, then execute the second step; in the second step, take the second instruction and judge whether the instruction is a store operation instruction; if all the above two steps are met, these two instructions are recognized as an assignment basic operation Gadget.

[0127] Typical dereference basic operations include two load sub-operations and one store sub-operation; the recognition process of dereference basic operations includes: in the first step, take the first instruction and judge whether the instruction is a load operation instruction. If so, then execute the second step; in the second step, take the second instruction and judge whether the instruction is a load instruction, and at the same time, it is necessary to judge whether the second operand is the address in the register of the first operand of the first instruction; if all the above two steps are met, these two instructions are recognized as a dereference basic operation Gadget.

[0128] It should be noted that the above three basic operations are only typical basic operations. In actual applications, there may also be some variations. For example, in one variation, the first instruction remains unchanged, but the forms of the subsequent (second, third, fourth, etc.) instructions defined are not the direct subsequent instructions of the first instruction. Other forms of instructions are allowed in between, as long as the relevant context remains unchanged between the pre-instruction and the subsequent instruction; in actual applications, the search for Gadgets can be completed according to the specific forms of the basic operations.

[0129] In step (S2) of this embodiment, the pollution sources in dynamic taint analysis include: external input and vulnerability-covered memory; external input, that is, all data input externally to the program; vulnerability-covered memory, that is, all non-control data memory units that can be modified through the vulnerabilities of the program.

[0130] The taint propagation rules of dynamic taint analysis are as follows:

[0131] For the load primitive operation instruction, its binary instruction formal description is "mov register, address". If the address or the value of the address in the instruction is a pollution source or is tainted, the register in the instruction is tainted.

[0132] For the store primitive operation instruction, its binary instruction formal description is "mov address, register". If the register in the instruction is tainted, the address and the value of the address in the instruction are tainted.

[0133] For the binary operation primitive operation instruction, its binary instruction formal description is "op register1, register2". If at least one register in the instruction is tainted, the first register (i.e., register1) is tainted; if only the first register (i.e., register1) is tainted, the second register (i.e., register2) is not tainted.

[0134] Based on the defined pollution sources and pollution propagation rules, in this embodiment, the execution mode of dynamic taint analysis is as follows: perform dynamic instrumentation of the second callback function at the API function where the user input is located in the target binary code; the second callback function is used to analyze the API function and determine the memory space that can be polluted based on the defined pollution sources and pollution propagation rules; for example, instrument the system call read function, and the callback function analyzes the read function to obtain the address of buf and the function return value n in the read function, where buf is the starting address of the pollution range and n is the size of the pollution range, then the memory space [buf, buf + n) is the pollution source space, and by using the defined pollution propagation rules to perform data flow tracking, the taint analysis space can be obtained; the taint analysis space determined based on the pollution propagation rules defined in this embodiment can be either the local variable space of the stack frame where the vulnerability is located, or the local variables of other stack frames, or the global variable space of the Data segment of the target code.

[0135] After determining the taint analysis space, obtain the instruction memory and data memory addresses, and determine whether they are within the taint analysis space. If they are within the space, it is considered that the memory is polluted; if not, it is considered not polluted. If any of the instruction memory and data memory addresses is polluted, then determine that the instruction is polluted; if there is a polluted instruction in the code judgment corresponding to the Gadgets, then determine that the Gadgets is polluted.

[0136] The taint analysis space determined in this embodiment is the space in the memory that can be controlled by the reuser, and this space provides modifiable memory information for symbolic execution.

[0137] In step (S3) of this embodiment, screening out reusable Gadgets from all polluted Gadgets and calculating the path constraints to reach the reusable Gadgets includes: obtaining the taint memory area, obtaining the symbolic execution starting position, obtaining the symbolic execution input information, initializing symbolic variables, Gadgets path search strategy, Gadget path search, symbolic execution simulation, and path constraint solving.

[0138] Specifically, for any available Gadgets, perform the following steps:

[0139] (S31) Use the selected available Gadgets as the target Gadgets and determine the starting position of symbolic execution;

[0140] The starting position of symbolic execution can be any position in the target binary code. To improve the efficiency of symbolic execution, as a preferred implementation mode, in this embodiment, specifically use the program crash instruction address as the starting position of symbolic execution. The specific method for obtaining this starting position includes:

[0141] Run the vulnerability POC script of the target binary code, and use the Payload in the POC script as input to trigger the vulnerability of the target binary code, causing the program to crash. Use the crash instruction address at this time as the starting position of symbolic execution, and obtain the on-site context information of symbolic execution;

[0142] In this embodiment, a publicly available vulnerability POC script can be selected; the Payload in the POC script is a specific string of input, which can be used to trigger vulnerabilities in the target binary code or activate specific Gadgets;

[0143] The on-site context information of symbolic execution includes: data information such as dumping the memory, registers and their values at the crash site;

[0144] (S32) Set the bytes of the memory cells in the taint analysis space as symbolic variables, and initialize these symbolic variables;

[0145] The taint analysis space is the contaminated memory space determined by the dynamic taint analysis technique in step (S2);

[0146] If the constraint condition of a branch jump contains symbolic variables, then this branch is called a symbolic branch;

[0147] (S33) Obtain the static control flow graph of the target binary code, so as to use static analysis techniques to exhaust all execution paths of the target binary code, and use static analysis techniques to exhaust all execution paths of the target program. Save the execution paths that cannot reach the target Gadgets as blacklist paths into the path search configuration file; Determine the POC execution path from the symbolic execution starting position to the target Gadgets obtained during the execution of the POC script as the whitelist path and write it into the path search configuration file;

[0148] Optionally, in this embodiment, the specific way to obtain the static control flow graph of the target binary code is: disassemble the target binary code to obtain the target program, and extract the static control flow graph (Control Flow Graph, CFG) of the target program;

[0149] (S34) Use the symbolic execution engine to start executing the target binary code from the symbolic execution starting position, and import the path search configuration file into the symbolic execution engine, so that the symbolic execution engine can perform heuristic branch jumps according to the blacklist path and the whitelist path during the execution process;

[0150] Since the starting point of symbolic execution in this embodiment is the crash instruction address, before the target binary code is executed from the starting point using the symbolic engine, the context will be restored according to the context information of the symbolic execution site;

[0151] In step (S34) of this embodiment, the symbolic execution engine starts to execute the target binary code from the symbolic execution starting point, that is, the process of performing simulation is as follows:

[0152] Start the simulation execution of the instructions from the restored context, and modify the corresponding symbolic states and symbolic expressions according to the instruction semantics at the same time; when encountering a symbolic branch, select the jump direction according to the path exploration strategy and generate the corresponding path constraints; at the initial moment of the simulation, initialize the path constraints to a tautology, indicating that no branches have been executed yet, so there are no constraints; when the simulation execution reaches a branch jump instruction, check whether the branch jump constraint condition contains symbolic variables (that is, whether it is symbolized); if so, it means that this branch depends on symbolic variables and is a symbolic branch, then select whether to follow the direction of the jump of the current specific value according to the path exploration strategy, and add the branch constraint to the path constraints; after the jump, continue the simulation until there is no next path exploration strategy indication in the path indication when encountering a symbolic branch, or the total number of executed instructions exceeds the maximum limit, or a special instruction that cannot be processed by symbolic execution is encountered, or the total number of jumps exceeds the preset jump total threshold, or the search depth has exceeded the preset search depth threshold, or it has reached the position where the Gadget is located. During the simulation process, if external interactions such as system calls and library calls that may cause path explosion are encountered, the means of summary modeling are used to analyze the semantics of system calls or library calls to establish a symbolic model and simulate the effects of external interactions;

[0153] When the symbolic execution engine implements a branch jump, it preferentially jumps to the Gadgets located on the POC execution path, so that the path to the Gadgets can be the shortest and the time can be the fastest;

[0154] (S35) If the symbolic execution engine reaches the target Gadgets within the preset jump total threshold and search depth threshold, then go to step (S36); otherwise, it means that the Gadgets cannot be reused, and go to step (S37);

[0155] (S36) Symbolically represent the constraint conditions of the execution path reaching the target Gadgets according to the symbolic variables defined in step (S32) to obtain a path constraint expression, solve the path constraint expression, and obtain the path constraint value of the target Gadgets; if the solution is successful, determine that the target Gadgets are reusable Gadgets and proceed to step (S37); if the solution is unsuccessful and there are still un-searched paths in the path search configuration file, proceed to step (S34) to start searching for the next path; if the solution is unsuccessful and there are no un-searched paths in the path search configuration file, it means that the Gadgets are not reusable, and proceed to step (S37);

[0156] Optionally, in this embodiment, a publicly available path constraint solver is directly used to solve the established path constraint expression; if the solution is successful, the finally obtained path constraint value is a string of memory values or address values. By inputting this path constraint value through the program input or the input of the vulnerability exploitation, the program can reach the Gadgets without changing the original CFG execution flow of the target;

[0157] In this embodiment, by setting the total number of jumps threshold and the search depth threshold to limit the total number of jumps and the search depth, the complexity of the path constraint expression can be limited, effectively alleviating the path explosion problem and increasing the probability of successfully solving the path constraint value;

[0158] (S37) The analysis of the target Gadgets ends.

[0159] Embodiment 2:

[0160] An instruction-level code reuse method for realizing the reuse of target binary code without changing the control flow; the instruction-level code reuse method provided in this embodiment includes:

[0161] For the target binary code, execute the above-mentioned instruction-level code reuse analysis method provided by the present invention to obtain the reusable Gadgets and the corresponding path constraint values in the target binary code;

[0162] Establish a memory pollution dependency table for the target binary code; the memory pollution dependency table records the mapping relationship from the pollution source address to the pollution destination address;

[0163] According to the reuse function to be realized, execute the corresponding reuse strategy; the reuse strategy includes a single Gadgets single reuse strategy, a single Gadgets multiple reuse strategy, a multiple Gadgets single reuse strategy, and a multiple Gadgets multiple reuse strategy.

[0164] In this embodiment, the method for establishing the memory pollution dependency table includes:

[0165] In the first callback function, add the use of a five-tuple <pollution source number, pollution source address, pollution target address, source coloring sequence, target coloring sequence> to record the address relationships in each instruction. Among them, the pollution source number is used to uniquely identify the pollution source; the pollution source address and the pollution target address are respectively the address of the pollution source in memory and the address of the memory unit to be polluted; the source coloring sequence and the target coloring sequence are respectively the sequence values after coloring the pollution source address and the pollution target address;

[0166] For each executed instruction, update the corresponding five-tuple. After all instructions are executed, one round of coloring is completed. After executing at least rounds of coloring, filter out the five-tuples with the same source coloring sequence and target coloring sequence, extract the pollution source address and the pollution target address among them, establish a mapping relationship and record it in the memory pollution dependency table; N represents the total number of colors used for coloring, T represents the total number of bytes of the pollution source number, represents rounding up, and after executing rounds of coloring, a stable coloring state is reached;

[0167] Each round of coloring includes the following steps:

[0168] (T0) Take the first instruction as the current instruction;

[0169] (T1) If the current instruction contains a pollution source, update the pollution source number and the address of the pollution source in memory to the five-tuple, and transfer to step (T2); otherwise, transfer to step (T3);

[0170] (T2) Color the pollution source number to obtain the source coloring sequence and update it to the five-tuple; the way to color the pollution source is:

[0171] Pre-define N different colors, and the corresponding color numbers are 1 to N in sequence; optionally, in this embodiment, N = 8, and correspondingly, the color numbers are 1 to 8 in sequence;

[0172] Color the pollution source memory address byte by byte as the 1st to 8th colors in sequence, and color the pollution target address according to the stain propagation rule to obtain the source coloring sequence and the target coloring sequence, and update them to the five-tuple;

[0173] (T3) If there are still unexecuted instructions, take the next instruction of the current instruction and transfer to step (T1); otherwise, the current round of coloring ends.

[0174] Based on the above-mentioned memory pollution dependency table established in this embodiment, it can be clearly known which byte value in the target address can be correspondingly affected by modifying a certain byte value in the source address memory.

[0175] In this embodiment, the execution method of the single Gadgets single reuse strategy includes:

[0176] (A1) Select a reusable Gadgets that can implement the reuse function, and obtain its path constraint value;

[0177] (A2) Input the obtained path constraint value through program input or exploit input to reach the selected reusable Gadgets;

[0178] (A3) Determine the memory address to be operated on by the reuse function as the pollution target address, and determine the corresponding pollution source address through the memory pollution dependency table, and modify the memory value at the pollution source address so that different functions are realized after the selected Gadgets are executed.

[0179] In this embodiment, the execution method of the single Gadgets multiple reuse strategy includes:

[0180] (B1) Select a reusable Gadgets that can implement the reuse function, and obtain its path constraint value;

[0181] (B2) Input the obtained path constraint value through program input or exploit input to reach the selected reusable Gadgets;

[0182] (B3) Determine the memory address to be operated on by the reuse function as the pollution target address, and determine the corresponding pollution source address through the memory pollution dependency table, and modify the memory value at the pollution source address so that different functions are realized after the selected Gadgets are executed, completing one reuse;

[0183] (B4) According to the number of reuse times to be executed, execute steps (B2) to (B3) multiple times to achieve multiple reuse of a single Gadgets.

[0184] In this embodiment, the execution method of the multiple Gadgets single reuse strategy includes:

[0185] (C1) Select multiple reusable Gadgets that can implement the reuse function and meet the reuse conditions, and obtain the path constraint values of each reusable Gadgets;

[0186] The reuse condition is that the address of the storage meta-operation in the pre-Gadgets is the same as the address of the load meta-operation in the post-Gadgets; among the selected multiple reusable Gadgets, the pre-executed and post-executed reusable Gadgets are the pre-Gadgets and post-Gadgets respectively;

[0187] (C2) Organize the selected reusable Gadgets together in an orderly manner according to the pre-and post-relationship;

[0188] Figure 2 As shown, it is an example of the single reuse strategy for multiple Gadgets. Among them, Gadgets1, Gadgets3, Gadgets4, and Gadgets5 are 4 reusable Gadgets selected based on the single reuse strategy for multiple Gadgets. After determining the pre - and post - successor relationships between the Gadgets based on the reuse conditions and organizing them in an orderly manner, the execution order of each Gadget is as Figure 2 shown;

[0189] (C3) Arrive at the selected reusable Gadgets in sequence. Each time after arriving at a reusable Gadget, determine the memory address to be operated on by the reuse function as the contaminated destination address, and determine the corresponding pollution source address through the memory pollution dependency table, and modify the memory value at the pollution source address, so that different functions are realized after the selected Gadgets are executed; after all the selected reusable Gadgets are executed, the single reuse of multiple Gadgets is realized;

[0190] Among them, the way to arrive at a reusable Gadget is: through program input or exploit input, input the path constraint value of this reusable Gadget to arrive at this reusable Gadget.

[0191] In this embodiment, the execution method of the multiple reuse strategy for multiple Gadgets includes:

[0192] (D1) Select multiple reusable Gadgets that can realize the reuse function and meet the reuse conditions, and obtain the path constraint values of each reusable Gadget;

[0193] (D2) Organize the selected reusable Gadgets together in an orderly manner according to the pre - and post - successor relationships;

[0194] (D3) Arrive at the selected reusable Gadgets in sequence. Each time after arriving at a reusable Gadget, determine the memory address to be operated on by the reuse function as the contaminated destination address, and determine the corresponding pollution source address through the memory pollution dependency table, and modify the memory value at the pollution source address, so that different functions are realized after the selected Gadgets are executed; after all the selected reusable Gadgets are executed, the single reuse of multiple Gadgets is realized;

[0195] The way to arrive at a reusable Gadget is: through program input or exploit input, input the path constraint value of this reusable Gadget to arrive at this reusable Gadget;

[0196] (D4) Execute step (D3) multiple times according to the number of times of multiplexing required, to achieve multiple multiplexing of multiple Gadgets.

[0197] Steps (C1) and (D1) of this embodiment further include:

[0198] If among the selected multiple reusable Gadgets, there is a situation where the pre - Gadgets and post - Gadgets do not meet the multiplexing conditions, then determine whether the addresses of the store meta - operations in the pre - Gadgets and the addresses of the load meta - operations in the post - Gadgets are both in the taint analysis space. If so, modify the addresses of the store meta - operations in the pre - Gadgets and the addresses of the load meta - operations in the post - Gadgets to be the same, to ensure that the selected multiple reusable Gadgets meet the multiplexing conditions.

[0199] The above - mentioned instruction - level code multiplexing method provided by this embodiment, by exploiting the target code overflow vulnerability, only overwrites the values of the local variable memory units in the stack space and does not overwrite the return address value. The instruction - level code multiplexing paths discovered by this method strictly follow the original CFG execution flow of the target code.

[0200] The following further explains the execution process of the above - mentioned instruction - level code multiplexing method in combination with a specific code multiplexing example.

[0201] Figure 3 is the disassembly control flow chart of a certain target code. In the figure, nodes A - H are basic blocks. There are two types of code fragments in blocks G and H. The displayed code fragments, that is, some of the reusable Gadgets obtained through the instruction - level code multiplexing analysis method provided by Embodiment 1. For ease of description, the reusable Gadgets in block G are denoted as X, and the reusable Gadgets in block H are denoted as Y. Figure 4 shows the stack space layout diagram when the target code executes the vulnerable function. The memory space from EBP - 0x04 to EBP - 0x150 is the space that the vulnerability can overwrite, that is, the memory space that the attacker can modify.

[0202] The first step of multiplexing: When the vulnerable function is triggered for the first time, guide the program to execute the path A->B->E->G, see Figure 3 , to reach block G; by filling data into the buffer, causing a stack overflow to overwrite the positions of ebp - 0x20 and ebp - 0xc. By designing the overwritten data, specific values can be assigned to the corresponding memory units, as shown in Table 1.

[0203] Table 1 Semantic memory assignment table for the function of writing 55 to the memory at 0x80e1d60

[0204] Memory Address Value Remarks ebp - 0xc 0x00000037 This value is decimal 55 ebp - 0x20 0x80e1d60 This value is the memory address of the target code process data segment

[0205] When the program executes the first line of code on the right as Figure 5 shown, the CPU fetches the value 0x00000037 from the memory cell at ebp - 0xc and puts it into the eax register. When executing the second line of code, the value in the eax register is stored in the memory cell whose value in the memory cell at ebp - 0x20 is used as the memory address. This process realizes the function of assigning the value 55 to the memory cell at 0x80e1d60. Therefore, by reusing these Gadgets, the function of writing any value to any memory can be completed. This process is the execution process of the single Gadget single - reuse strategy.

[0206] Reuse step 2: The reuser triggers the vulnerability function for the second time. Similar to the first exploitation process, as shown in Table 2, it realizes the functional semantics of assigning the value 62 to the memory cell at 0x80e18ac.

[0207] Table 2 Reuse semantic memory assignment table for writing 62 to the memory at 0x80e18ac

[0208] Memory Address Value Remarks ebp - 0xc 0x0000003E This value is decimal 62 ebp - 0x20 0x80e18ac This value is the memory address of the target code process data segment

[0209] By reusing step 1 and step 2, through multiple reuses of X, the functional semantics of assigning values to the memory cells at 0x80e1d60 and 0x80e18ac are realized. These two steps realize the process of multiple reuses of a single Gadget.

[0210] Reuse step 3: When triggering the vulnerability function for the third time, guide the program to execute the path A -> B -> E -> H, as Figure 3 shown, reaching the H basic block. In a similar way, through the assignment rules in Table 3, the reuse semantics of the addition function of the values at the memory addresses 0x80e1d60 and 0x80e18ac are realized, and the result of the addition is stored in the memory at 0x80e1d60.

[0211] Table 3 Reuse semantic memory assignment table for the addition function

[0212] Memory Address Value Remarks ebp - 0x20 0x80e1d60 0x80e1d60 is the memory address and the value is equal to 55 ebp - 0x30 0x80e18ac 0x80e18ac is the memory address and the value is equal to 62 ebp - 0x50 0x80e1d60 0x80e1d60 is the memory address where the added result is stored

[0213] After the above three - step reuse process, by using the vulnerability to assign specific values (the values can be specific hexadecimal numbers or valid addresses) to specific memory cells, and reasonably organizing the target code Gadgets, the reuse semantics of the addition function of any two numbers are finally realized.

[0214] Example 3:

[0215] A computer-readable storage medium includes a stored computer program. When the computer program is executed by a processor, it controls the device where the computer-readable storage medium is located to execute the instruction-level code reuse analysis method provided in the above-mentioned Embodiment 1, or the instruction-level code reuse method provided in the above-mentioned Embodiment 2.

[0216] Those skilled in the art can easily understand that the above are only the preferred embodiments of the present invention, and are not intended to limit the present invention. Any modifications, equivalent replacements, and improvements made within the spirit and principles of the present invention should be included within the protection scope of the present invention.

Claims

1. An instruction-level code reuse analysis method, characterized in that Identify reusable Gadgets in the target binary code without changing the control flow and solve the corresponding path constraint values; the Gadgets are code segments that implement target basic operations, and the target basic operations include arithmetic operations, assignment operations, and dereference operations; the method includes: (S1) Identify the Gadgets in the target binary code by instrumenting the first callback function at each instruction of the target binary code, and obtain an initial Gadgets set; the first callback function is used to analyze the instruction and search for Gadgets in the target binary code based on the instruction analysis result; (S2) Screen out the contaminated Gadgets from the initial Gadgets set through dynamic taint analysis technology as available Gadgets; (S3) For each available Gadget, use symbolic execution technology to obtain the execution path from the symbolic execution start position to the available Gadget in the target binary code, construct a path constraint expression for the execution path and solve to obtain the path constraint value. If the execution path is successfully obtained and the path constraint value is successfully solved, then use the available Gadget as a reusable Gadget; (S4) Take all reusable Gadgets and their corresponding path constraint values as the identification result, and the identification ends; In the step (S3), for any available Gadget, perform the following steps: (S31) Take the selected available Gadget as the target Gadget and determine the symbolic execution start position; (S32) Set the bytes of the memory unit in the taint analysis space as symbolic variables and initialize these symbolic variables; the taint analysis space is the contaminated memory space determined by the dynamic taint analysis technology in the step (S2); (S33) Obtain the static control flow graph of the target binary code to exhaust all execution paths of the target binary code using static analysis technology, take the execution paths that cannot reach the target Gadget as blacklist paths and save them to the path search configuration file; determine the POC execution path from the symbolic execution start position to the target Gadget obtained during the execution of the POC script as the whitelist path and write it into the path search configuration file; (S34) Use the symbolic execution engine to execute the target binary code starting from the symbolic execution start position and import the path search configuration file into the symbolic execution engine, so that the symbolic execution engine can perform heuristic branch jumps according to the blacklist path and the whitelist path during the execution; (S35) If the symbolic execution engine reaches the target Gadget within the preset jump total threshold and search depth threshold, then go to step (S36); otherwise, go to step (S37); (S36)Symbolically represent the constraint conditions of the execution path reaching the target Gadgets according to the symbolic variables defined in step (S32) to obtain a path constraint expression, solve the path constraint expression to obtain the path constraint value of the target Gadgets; if the solution is successful, determine that the target Gadgets are reusable Gadgets and proceed to step (S37); if the solution is unsuccessful and there are still un-searched paths in the path search configuration file, proceed to step (S34) to start searching for the next path; if the solution is unsuccessful and there are no un-searched paths in the path search configuration file, it means that the Gadgets are not reusable, and proceed to step (S37); (S37)The analysis of the target Gadgets ends.

2. The instruction-level code reuse analysis method according to claim 1, wherein In step (S34), when the symbolic execution engine implements a branch jump, it preferentially jumps to the Gadgets on the POC execution path.

3. The instruction-level code reuse analysis method according to claim 1 or 2, characterized in that In step (S2), the pollution sources in dynamic taint analysis include: external input and vulnerability-covered memory; The taint propagation rules of dynamic taint analysis are as follows: For a load primitive operation instruction, if the address or the value of the address in the instruction is a pollution source or is tainted, the register in the instruction is tainted; For a store primitive operation instruction, if the register in the instruction is tainted, the address and the value of the address in the instruction are tainted; For a binary operation primitive operation instruction, if at least one register in the instruction is tainted, the first register is tainted; if only the first register is tainted, the second register is not tainted; The execution method of dynamic taint analysis is: dynamically instrument a second callback function at the API function where the user input is located in the target binary code; the second callback function is used to analyze the API function and determine the memory space that can be tainted based on the defined pollution sources and taint propagation rules; Among them, the first register and the second register are the two registers in the binary operation primitive operation instruction respectively, and the first register is the register for storing the operation result.

4. An instruction-level code reuse method, characterized in that, For realizing the reuse of the target binary code without changing the control flow; the method includes: For the target binary code, execute the instruction-level code reuse analysis method described in any one of claims 1 to 3 to obtain the reusable Gadgets and the corresponding path constraint values in the target binary code; Establish a memory pollution dependency table for the target binary code; the memory pollution dependency table records the mapping relationship from the pollution source address to the pollution destination address; According to the reuse function to be realized, execute the corresponding reuse strategy; the reuse strategy includes a single Gadgets single reuse strategy, and its execution method includes: (A1)Select a reusable Gadgets that can realize the reuse function and obtain its path constraint value; (A2)Input the obtained path constraint value through program input or exploit input to reach the selected reusable Gadgets; (A3) Determine the memory address to be operated by the multiplexing function as the contaminated destination address, and determine the corresponding source contaminated address through the memory contamination dependency table, and modify the memory value at the source contaminated address so that different functions are implemented after the selected Gadgets are executed.

5. The instruction-level code reuse method according to claim 4, wherein The multiplexing strategy further includes a strategy of multiplexing a single Gadget multiple times, and its execution method includes: (B1) Select a reusable Gadget that can implement the multiplexing function, and obtain its path constraint value; (B2) Input the obtained path constraint value through the program input or the input of the vulnerability exploitation to reach the selected reusable Gadget; (B3) Determine the memory address to be operated by the multiplexing function as the contaminated destination address, and determine the corresponding source contaminated address through the memory contamination dependency table, and modify the memory value at the source contaminated address so that different functions are implemented after the selected Gadget is executed, and complete one multiplexing; (B4) According to the number of multiplexing times required to be executed, execute steps (B2) to (B3) multiple times to implement multiplexing of a single Gadget multiple times.

6. The instruction-level code reuse method according to claim 5, wherein The multiplexing strategy further includes a strategy of multiplexing multiple Gadgets once, and its execution method includes: (C1) Select multiple reusable Gadgets that can implement the multiplexing function and meet the multiplexing conditions, and obtain the path constraint values of each reusable Gadget; The multiplexing condition is that the address of the storage primitive operation in the pre-Gadget is the same as the address of the load primitive operation in the post-Gadget; among the selected multiple reusable Gadgets, the pre-executed and post-executed reusable Gadgets are the pre-Gadget and the post-Gadget respectively; (C2) Organize the selected reusable Gadgets together in an orderly manner according to the pre and post relationships; (C3) Reach the selected reusable Gadgets in sequence. Each time after reaching a reusable Gadget, determine the memory address to be operated by the multiplexing function as the contaminated destination address, and determine the corresponding source contaminated address through the memory contamination dependency table, and modify the memory value at the source contaminated address so that different functions are implemented after the selected Gadget is executed; after all the selected reusable Gadgets are executed, multiplexing of multiple Gadgets once is achieved; Among them, the way to reach a reusable Gadget is: input the path constraint value of the reusable Gadget through the program input or the input of the vulnerability exploitation to reach the reusable Gadget.

7. The instruction-level code reuse method according to claim 6, wherein The multiplexing strategy further includes a strategy of multiplexing multiple Gadgets multiple times, and its execution method includes: (D1) Select multiple reusable Gadgets that can implement the multiplexing function and meet the multiplexing conditions, and obtain the path constraint values of each reusable Gadget; (D2) Organize the selected reusable Gadgets together in an orderly manner according to the pre and post relationships; (D3) Sequentially reach the selected reusable Gadgets in order. After reaching a reusable Gadget each time, determine the memory address to be operated on by the reuse function as the pollution target address, and determine the corresponding pollution source address through the memory pollution dependency table, and modify the memory value at the pollution source address so that different functions are achieved after the selected Gadgets are executed; after all the selected reusable Gadgets are executed, multiple Gadgets are reused at once; The way to reach the reusable Gadgets is: through program input or exploit input, input the path constraint value of the reusable Gadget to reach the reusable Gadget; (D4) According to the number of reuse times required, execute step (D3) multiple times to achieve multiple reuses of multiple Gadgets.

8. The instruction-level code reuse method according to claim 7, wherein The steps (C1) and (D1) further include: If among the selected multiple reusable Gadgets, there is a situation where the pre-Gadgets and post-Gadgets do not meet the reuse conditions, then determine whether the addresses of the store primitive operations in the pre-Gadgets and the addresses of the load primitive operations in the post-Gadgets are both in the taint analysis space. If so, modify the addresses of the store primitive operations in the pre-Gadgets and the addresses of the load primitive operations in the post-Gadgets to be the same to ensure that the selected multiple reusable Gadgets meet the reuse conditions.

9. The instruction-level code reuse method according to any one of claims 4 to 8, characterized in that The establishment method of the memory pollution dependency table includes: In the first callback function, add a record of the address relationship in each instruction using the five-tuple <pollution source number, pollution source address, pollution target address, source coloring sequence, target coloring sequence>, where the pollution source number is used to uniquely identify the pollution source; the pollution source address and the pollution target address are the addresses of the pollution source in memory and the address of the memory unit to be polluted respectively; the source coloring sequence and the target coloring sequence are the sequence values after coloring the pollution source address and the pollution target address respectively; For each executed instruction, update the corresponding five-tuple. After all instructions are executed, complete one round of coloring. After performing at least rounds of coloring, filter out the five-tuples with the same source coloring sequence and destination coloring sequence, extract the source pollution address and pollution destination address among them, establish a mapping relationship and record it in the memory pollution dependency table; N represents the total number of colors used for coloring, T represents the total number of bytes of the source pollution number, represents rounding up; Each round of coloring includes the following steps: (T0) Take the first instruction as the current instruction; (T1) If the current instruction contains a pollution source, update the pollution source number and the address of the pollution source in memory to the five-tuple, and transfer to step (T2); otherwise, transfer to step (T3); (T2) Color the pollution source number to obtain the source coloring sequence and update it to the five-tuple; the way to color the pollution source is: Predefined N different colors, and the corresponding color numbers are 1 to N ; For the memory addresses in the pollution source, dye them byte by byte into the 1st to N types of colors. Dye the polluted target addresses according to the merge taint propagation rules, obtain the source coloring sequence and the target coloring sequence, and update them into the five-tuple; (T3) If there are still unexecuted instructions, take the next instruction of the current instruction and transfer to step (T1); otherwise, the current round of coloring ends.

Citation Information

Patent Citations

  • Software protection method capable of resisting symbolic execution and taint analysis

    CN105787305A

  • Multi-level hybrid vulnerability automatic mining method

    CN111859388A