A patch detection method and a terminal

By obtaining the vulnerable files and feature data of the patch files to be detected, and patching the compiled files to be detected is solved, which requires manual use of decompilation tools to be detected in the existing technology, and efficient patch detection is achieved, saving labor costs.

CN115422542BActive Publication Date: 2025-06-24QINGKE LINGJING (ANHUI) TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210938590.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-08-05
Publication Date
2025-06-24
Estimated Expiration
2042-08-05

AI Technical Summary

Technical Problem

When using vulnerability scanners to detect whether the system has been patched, the prior art requires manual decompilation tools, resulting in high labor costs.

Method used

By obtaining the feature data of the vulnerable file and the patch file of the file to be detected, and using the feature data to be patched to detect the compiled file to be detected, the patch detection results of the file to be detected are directly obtained without the need for decompilation tools.

Benefits of technology

It realizes patch detection of system files without developing decompilation tools, saving labor costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115422542B_ABST
    Figure CN115422542B_ABST
Patent Text Reader

Abstract

This application belongs to the field of computer technology and mainly provides a patch detection method, device, terminal, and readable storage medium. This application obtains a reference file corresponding to the file to be detected, analyzes the reference file corresponding to the file to be detected, processes the corresponding program segment in the reference file, calculates the feature data, and uses the feature data to perform patch detection on the file to be detected, directly obtaining the patch detection result of the file to be detected, without the need to rely on decompilation tools to implement patch detection of system files, which can save labor costs.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application belongs to the field of computer technology, and particularly relates to a patch detection method and a terminal. Background Art

[0002] Currently, some system open-source manufacturers will regularly announce the patch code details of system vulnerabilities, and other manufacturers can develop vulnerability scanners based on the patch code details to scan whether there are any discovered vulnerabilities on existing devices.

[0003] However, when using a vulnerability scanner to detect whether a system has been patched, generally, only by manually using a decompilation tool can it be determined whether the file is an unpatched file, which requires a large amount of labor cost. Summary of the Invention

[0004] This application provides a patch detection method and a terminal, which can realize patch detection of files without developing a decompilation tool and can save labor costs.

[0005] In the first aspect of the embodiments of this application, a patch detection method is provided, including:

[0006] Obtain a file to be detected, where the file to be detected is a compiled file;

[0007] Obtain the feature data between a first compiled file and a second compiled file, where the first compiled file is the vulnerability file corresponding to the file to be detected, and the second compiled file is the patch file corresponding to the file to be detected;

[0008] Match the target data of the file to be detected with the feature data to determine the patch detection result of the file to be detected.

[0009] In the second aspect of the embodiments of this application, a patch detection device is further provided, including:

[0010] A first acquisition unit, configured to obtain a file to be detected, where the file to be detected is a compiled file;

[0011] A second acquisition unit, configured to obtain the feature data between a first compiled file and a second compiled file, where the first compiled file is the vulnerability file corresponding to the file to be detected, and the second compiled file is the patch file corresponding to the file to be detected;

[0012] A patch detection unit, configured to match the target data of the file to be detected with the feature data to determine the patch detection result of the file to be detected.

[0013] In a third aspect of the embodiments of the present application, a terminal is provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the computer program is executed by the processor, the steps of the patch detection method described in the first aspect above are implemented.

[0014] In a fourth aspect of the embodiments of the present application, a computer-readable storage medium is provided. The computer-readable storage medium stores a computer program, and when the computer program is executed by the processor, the steps of the patch detection method described in the first aspect above are implemented.

[0015] In the embodiments of the present application, by obtaining the characteristic data of the vulnerability file and the patch file of the file to be detected, and using the characteristic data to perform patch detection on the file to be detected obtained through compilation, by matching the target data of the file to be detected with the characteristic data, the patch detection result of the file to be detected can be directly obtained, and there is no need to rely on decompilation tools to implement the patch detection of system files, which can save labor costs. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] Figure 1 It is a schematic flowchart of the implementation process of the patch detection method provided by the embodiments of the present application.

[0017] Figure 2 It is a schematic flowchart of the specific implementation process of step 102 of the patch detection method provided by the embodiments of the present application.

[0018] Figure 3 It is a schematic diagram of data comparison based on a compiled file provided by the embodiments of the present application.

[0019] Figure 4 It is a schematic flowchart of the calculation process of the target difference data summary eigenvalue provided by the embodiments of the present application.

[0020] Figure 5 It is a first schematic diagram of the method for obtaining characteristic data provided by the embodiments of the present application.

[0021] Figure 6 It is a second schematic diagram of the method for obtaining characteristic data provided by the embodiments of the present application.

[0022] Figure 7 It is a schematic structural diagram of the patch detection device provided by the embodiments of the present application.

[0023] Figure 8 It is a schematic diagram of the terminal provided by the embodiments of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0024] In order to make the objectives, technical solutions and advantages of the present application more clear and understandable, the present application will be further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.

[0025] For the convenience of understanding, the nouns involved in the embodiments of the present application will be described below.

[0026] System patch: System open-source manufacturers will regularly announce the patch code details of system vulnerabilities, which include the location of the vulnerability code and the detailed content of the vulnerability repair code. The vulnerability repair code is the patch, and the process of repair is called patching.

[0027] Compilation: It refers to the process of using a compiler to convert a source program written in a source language into a target program. That is, converting a high-level language into a binary language containing 1s and 0s that can be recognized by a computer.

[0028] ELF file: It was developed and released by the UNIX System Laboratories (USL) as the Application Binary Interface (ABI), and it is also the main executable file format of Linux.

[0029] ELF file without symbol table: An ELF file has a block of data specifically storing function names. Generally, this block of data is called the symbol table. Deleting the symbol table in the ELF file will reduce the file size and delete all function names, resulting in the vulnerability scanner being unable to find the location of the function code based on the function name, and thus unable to perform patch detection.

[0030] In practical applications, the patch detection for an ELF file without a symbol table generally can only determine whether the file is an unpatched file by manually using a decompilation tool, which requires a large amount of labor cost.

[0031] In view of the above problems, a patch detection method, device, terminal and readable storage medium provided by the embodiments of the present application obtain the characteristic data of the vulnerability file and the patch file of the file to be detected, and use the characteristic data to perform patch detection on the file to be detected obtained after compilation. By matching the target data of the file to be detected with the characteristic data, the patch detection result of the file to be detected can be directly obtained, and there is no need to use a decompilation tool to implement the patch detection of the system file, which can save labor costs.

[0032] In order to better illustrate the technical solution of the present application, it will be exemplified below by way of embodiments.

[0033] Such as Figure 1As shown in the figure, it is a schematic flowchart of the implementation of a patch detection method provided by an embodiment of the present application. This patch detection method can be executed by a patch detection device configured on a terminal. Moreover, this terminal can be an intelligent terminal such as a mobile phone, a tablet computer, a server, a new energy vehicle, etc. The present application does not limit the type of this terminal.

[0034] Specifically, the patch detection method provided by the embodiment of the present application can be implemented by the following steps 101 to 103:

[0035] Step 101: Obtain a file to be detected, where the file to be detected is a compiled file.

[0036] In the embodiment of the present application, the above file to be detected is a file that needs to be patch-detected.

[0037] For example, the above file to be detected can be a file obtained by compiling a certain system file of the above terminal or the source code of a certain application installed on the terminal. The present application does not limit this.

[0038] Optionally, when the above terminal is a new energy vehicle, the above file to be detected can be a file obtained by compiling the automatic driving system of the new energy vehicle, or a file obtained by compiling the simulation test code included in the simulation test platform corresponding to the new energy vehicle's automatic driving system.

[0039] In the embodiment of the present application, the above file to be detected can be a file in Executable and Linkable Format (ELF), or an executable file in other formats. The present application does not limit this.

[0040] Step 102: Obtain the feature data between the first compiled file and the second compiled file, where the first compiled file is the vulnerability file corresponding to the file to be detected, and the second compiled file is the patch file corresponding to the file to be detected.

[0041] In the embodiment of the present application, this vulnerability file is the file before the patching process corresponding to the file to be detected, that is, the file with vulnerabilities. This patch file is the file after the patching process corresponding to the file to be detected, that is, the file after patching the vulnerabilities. Among them, this patch file can be the patch code for vulnerabilities regularly announced by open-source manufacturers.

[0042] In the embodiment of the present application, the above feature data corresponding to the first compiled file and the second compiled file can be the feature data pre-obtained by the terminal for detecting whether the file to be detected is unpatched, and this feature data is data that can represent the difference between the first compiled file and the second compiled file.

[0043] Among them, the first compiled file is the file obtained by compiling the file to be detected before adding the patch code, and the second compiled file is the file obtained by compiling the file to be detected after adding the patch code.

[0044] Exemplarily, the terminal device can compare the data of the first compiled file and the data of the second compiled file, and obtain the characteristic data between the first compiled file and the second compiled file based on the comparison result; alternatively, other devices compare the data of the first compiled file and the data of the second compiled file, obtain and store the characteristic data between the first compiled file and the second compiled file, and the terminal device is communicatively connected to other devices by wire or wirelessly to obtain the characteristic data.

[0045] Optionally, as Figure 2 shown, when the terminal device compares the data of the first compiled file and the data of the second compiled file, and obtains the characteristic data between the first compiled file and the second compiled file based on the comparison result, in the above step 102, to obtain the characteristic data between the first compiled file and the second compiled file, the following manner of steps 201 to 202 can be adopted:

[0046] Step 201, compare the data of the first compiled file with the data of the second compiled file to determine the target difference data between the first compiled file and the second compiled file.

[0047] Since the file before the patch that has not been compiled (the first compiled file) and the file after the patch that has been compiled (the second compiled file) have different file contents, therefore, by comparing the differences in the data of each byte of the first compiled file and the second compiled file, the data in the first compiled file that is different from the second compiled file can be obtained to determine the target difference data.

[0048] Optionally, in the above step 201, to compare the data of the first compiled file with the data of the second compiled file to determine the target difference data between the first compiled file and the second compiled file, the following manner of steps 2011 to 2014 can be adopted:

[0049] Step 2011, obtain the first data segment of the first compiled file and the second data segment of the second compiled file according to the first preset byte.

[0050] Step 2012, compare the data at the same position in the first data segment and the second data segment to determine the first difference data that is different between the first compiled file and the second compiled file.

[0051] In the embodiments of the present application, the first preset byte may be one or more unit bytes. The data segments of the first compiled file and the second compiled file are sequentially obtained according to the first preset byte. The data in the corresponding data segments of the first compiled file and the second compiled file are compared byte by byte to obtain the data with differences in the data segments, and the first difference data is determined.

[0052] For example, as Figure 3 shown, it is assumed that the first data segment sequentially obtained from the first compiled file according to the first preset byte includes four data segments A1, B1, C1, and D1, and the second data segment sequentially obtained from the second compiled file according to the first preset byte includes four data segments A2, B2, C2, and D2. Among them, the data contents of A1, C1, and D1 are the same as those of A2, C2, and D2, and the data contents of B1 and B2 are not completely the same. The data at the same positions of A1 and A2, B1 and B2, C1 and C2, and D1 and D2 are sequentially compared byte by byte; when the data contents of A1 and A2 are the same, the comparison of B1 and B2 is continued, and the first difference data with differences in B1 and B2 is determined.

[0053] Step 2013, calculate the ratio of the number of bytes of the first difference data to the first preset byte to obtain the first differentiation rate corresponding to the first difference data.

[0054] Step 2014, if the first differentiation rate is greater than the preset threshold, the first difference data is used as the target difference data.

[0055] In the embodiments of the present application, after the first difference data is determined based on the first data segment and the second data segment for data comparison, calculate the proportion of the difference data in the first data segment or the second data segment, that is, the proportion to the first preset byte, to obtain the first differentiation rate corresponding to the first difference data.

[0056] Exemplarily, the first preset byte may be 0x200 bytes, or may also be a number of bytes greater than 0x200; the preset threshold may be 80% or 90%. When the proportion of the difference data in the first data segment and the second data segment for data comparison to the first preset byte exceeds 80% or 90%, the first difference data is used as the target difference data.

[0057] Correspondingly, when the data contents of data segments A1 and A2 are the same, continue to compare the data contents of data segments B1 and B2. When the data contents of data segments B1 and B2 are not completely the same, calculate the proportion of the differential data in the data segment to the data segment. If the proportion of the differential data in data segments B1 and B2 to the first preset byte does not exceed the preset threshold, continue to compare the data segments C1 and C2 of the next first preset byte; if there is differential data in data segments C1 and C2 and the proportion of the differential data exceeds the preset threshold, use the differential data in data segments C1 and C2 as the target differential data.

[0058] By sequentially traversing each data segment and comparing the data in the data segment byte by byte as described above, the differential data existing in the first compilation file and the second compilation file and the positions where the differential data is located can be determined. For example, the contents of the first byte of B1 and the first byte of B2 are not the same. Based on this, when comparing the first compilation file and the second compilation file, a can be obtained as the differential position where there are differences between the first compilation file and the second compilation file, that is, the position of the first byte of B1.

[0059] Exemplarily, based on the above implementation method, by sequentially traversing each data segment and comparing the data in the data segment byte by byte, it is also possible to determine all data segments in which there is differential data between the first compilation file and the second compilation file and the proportion of the differential data to the data segment exceeds the preset threshold; furthermore, it is possible to determine the starting differential position of the differential data in all data segments. The starting differential position of the differential data can be the position of the starting byte of the data segment, or it can be the position of other bytes in the data segment. It is determined based on the actual comparison process and is not limited here.

[0060] In a possible implementation method, when the above first preset byte is greater than 0x200, in the second compilation file, traverse the differential positions of the differential data existing in each data segment. Starting from the differential positions in each data segment, extract the differential data in the 0x200-byte data to obtain the differential data corresponding to the differential positions in each data segment, and then calculate whether the differential rate of each differential data is greater than the preset threshold to determine the data segments with a differential rate greater than the preset threshold.

[0061] Among them, when calculating whether the differential rate of the differential data in each data segment is greater than the preset threshold, the ratio of the number of bytes with differences in the differential data to the number of bytes of the extracted data (0x200) can also be used as the differential rate of the differential data in the data segment.

[0062] Optionally, after calculating the proportion of the number of bytes of the first differential data to the first preset byte to obtain the first differential rate corresponding to the first differential data in step 2013, the following steps 2015 to 2018 can also be used to implement:

[0063] Step 2015, if the first differentiation rate is less than or equal to the preset threshold, obtain the third data segment of the first compiled file and the fourth data segment of the second compiled file according to a second preset number of bytes.

[0064] Step 2016, compare the data at the same positions of the third data segment and the fourth data segment to determine second difference data with differences between the first compiled file and the second compiled file.

[0065] Step 2017, calculate the ratio of the number of bytes of the second difference data to the second preset number of bytes to obtain a second differentiation rate corresponding to the second difference data.

[0066] Step 2018, if the second differentiation rate is greater than the preset threshold, use the second difference data as the target difference data. The number of bytes of the second preset number of bytes is less than the number of bytes of the first byte.

[0067] In the embodiment of the present application, when the differentiation rate corresponding to the difference data is less than or equal to the above preset threshold, it indicates that the difference position corresponding to the difference data does not belong to the patch position. Therefore, the difference data cannot be used as feature data, and the abstract feature value corresponding to the difference data cannot be used as feature data for patch detection.

[0068] When all data segments have been compared using the first preset number of bytes and the differentiation rates corresponding to the data segments with differences are all less than the preset threshold, then further reduce the number of bytes of the first preset number of bytes to the number of bytes of the second preset number of bytes. Based on the same implementation principle as the above implementation method, traverse and compare the third data segment in the first compiled file and the fourth data segment in the second compiled file according to the second preset number of bytes. Until a data segment with a differentiation rate greater than the preset threshold is obtained, and determine the target difference data based on the difference data in the data segment.

[0069] As Figure 5 shown in the schematic diagram of Example 1, traverse and compare the data at the same positions in the form of data segments of the first preset number of bytes or the second preset number of bytes. When difference data C is obtained after traversing and comparing, the corresponding data segment can be directly obtained, and when the differentiation rate corresponding to the data segment exceeds the preset threshold, the difference data C of the data segment can be determined as the target difference data. Among them, difference data D is the difference data in the next data segment of the first preset number of bytes or the second preset number of bytes.

[0070] Among them, the first preset byte and the second preset byte can be determined based on the file sizes of the first compilation file and the second compilation file. When the data segment compared based on the first preset byte does not exceed the preset threshold, the adjustment method of updating the first preset byte to the second preset byte can also be determined based on the file size or the size of the differentiation rate. For example, if the first preset byte is set to 1000 bytes, when the differentiation rate of the differential data in the corresponding data segment does not meet the preset threshold, the first preset byte is reduced to the second preset byte of 800 bytes, or when the differentiation rate based on the first preset byte is small, it can also be adjusted to the second preset byte of 200 bytes.

[0071] Optionally, in step 201 above, comparing the data of the first compilation file with the data of the second compilation file to determine the target differential data between the first compilation file and the second compilation file can be implemented in the following manner of steps 2111 to 2115:

[0072] Step 2111, compare the data at the same position in the first compilation file and the second compilation file to determine the first position where the differential data first appears in the first compilation file and the second compilation file.

[0073] Step 2112, respectively obtain the fifth data segment and the sixth data segment of the third preset byte after the first position in the first compilation file and the second compilation file.

[0074] In the embodiments of the present application, the first compilation file and the second compilation file are traversed starting from the file header, and the data at the same position are compared one by one byte by byte to determine the position where the data are first different, that is, the first position where the differential data appears. Then, based on the differential data at this first position, the data segment of the third preset byte is taken backward to obtain the fifth data segment of the first compilation file and the sixth data segment of the second compilation file.

[0075] Among them, the number of bytes of the third preset byte can be 0x200, or other numbers of bytes, and can be specifically determined based on the size of the compilation file, which is not limited herein.

[0076] Step 2113, compare the data at the same position in the fifth data segment and the sixth data segment to determine the third differential data that exists in the first compilation file and the second compilation file.

[0077] Step 2114, calculate the ratio of the number of bytes of the third differential data to the third preset byte to obtain the third differentiation rate corresponding to the third differential data.

[0078] Step 2115, if the third differentiation rate is greater than the preset threshold, then use the third differential data as the target differential data.

[0079] In an embodiment of the present application, each byte in the fifth data segment and the sixth data segment is compared, and the number of different bytes in the data segment, that is, the number of the third difference data, is calculated. The number of bytes of the third difference data is divided by the number of bytes of the third preset byte to obtain the third differentiation rate corresponding to the third difference data. If the third differentiation rate is greater than a preset threshold, for example, greater than 80% or 90%, then the third difference data is used as the target difference data.

[0080] Optionally, after calculating the proportion of the number of bytes of the third difference data in the third preset byte to obtain the third differentiation rate corresponding to the third difference data in step 2114, the following steps 2116 to 2120 can also be used to implement:

[0081] Step 2116, if the third differentiation rate is less than or equal to the preset threshold, then obtain the data after the first position in the first compilation file and the second compilation file by unit byte;

[0082] Step 2117, if there is a difference in the data at the second position after the first position in the first compilation file and the second compilation file, then obtain the seventh data segment and the eighth data segment of the fourth preset byte after the second position in the first compilation file and the second compilation file;

[0083] In an embodiment of the present application, as Figure 6 shown in the schematic diagram of Example 2, when the first difference data appears at the first position A for the first time, then obtain the data segment of the third preset byte after the first position, that is, the fifth data segment and the sixth data segment of the first compilation file. At this time, the data segment may include a data B part and a data C part. When calculating the differentiation rate of the difference data, the differentiation rate of the third difference data in the fifth data segment and the sixth data segment does not meet the requirements of the preset threshold, that is, it does not exceed the preset threshold. Then continue to traverse and compare the subsequent data by unit byte from the first position A, for example, the data at the A + 1th byte. If the data at the A + 1th byte is the same, then continue to traverse and compare the bytes at the A + 2, A + 3, A + 4, etc. positions until the next byte with different data appears. For example, the data at the A + N (N is an integer greater than or equal to 1) byte is different. For example Figure 6 the position where the data B in Figure 6 is located, then obtain the data segment of the fourth preset byte after the data at the A + N byte, that is, the seventh data segment of the first compilation file and the eighth data segment of the second compilation file. As

[0084] It should be noted that Figure 5 and Figure 6In the example, it only schematically represents the positions or quantities of the corresponding differential data in the first compiled file and the second compiled file, and does not represent the real data content. The real data content is obtained based on the comparison between the first compiled file and the second compiled file.

[0085] Step 2118: Compare the data at the same positions in the seventh data segment and the eighth data segment to determine the fourth differential data with differences in the first compiled file and the second compiled file.

[0086] Step 2119: Calculate the ratio of the number of bytes of the fourth differential data to the fourth preset number of bytes to obtain the fourth differential rate corresponding to the fourth differential data.

[0087] Step 2120: If the fourth differential rate is greater than the preset threshold, then use the fourth differential data as the target differential data.

[0088] In the embodiment of the present application, each byte in the seventh data segment and the eighth data segment is compared to determine the number of different bytes, that is, the number of the fourth differential data. Divide the number of bytes of the fourth differential data by the number of bytes of the fourth preset number of bytes to obtain the fourth differential rate corresponding to the fourth differential data. If the fourth differential rate is greater than the preset threshold, for example, greater than 80% or 90%, then use the fourth differential data as the target differential data.

[0089] Among them, for the part of the differential data that has been calculated before, the result can be saved. When calculating the differential data later, based on the repeated byte part, the previous calculation result can be directly used, which can avoid repeated calculation, improve the operation efficiency and reduce the operation pressure; for example Figure 6 in, for the overlapping part between the data segment of the third preset number of bytes and the data segment of the fourth preset number of bytes, when calculating the fourth differential data, the bytes of this overlapping part can directly adopt the result of the previous calculation of the third differential data.

[0090] In a possible implementation manner, in the above step 201, when comparing the data of the first compiled file with the data of the second compiled file to determine the target differential data between the first compiled file and the second compiled file, it can also be implemented in the following manner of steps 2211 to 2214:

[0091] Step 2211: Divide the data of the first compiled file and the data of the second compiled file into corresponding multiple data segments respectively.

[0092] Step 2212: Compare the data at the same positions in the multiple data segments of the first compiled file and the multiple data segments of the second compiled file respectively to determine the differential data in the first compiled file and the second compiled file and the target data segment with differential data.

[0093] Step 2213, calculate the ratio of the number of bytes of the differential data in the target data segment to the number of bytes of the target data segment to obtain the differentiation rate corresponding to the target data segment.

[0094] Step 2214, use the differential data in the target data segment with the largest differentiation rate as the target differential data.

[0095] In the embodiments of the present application, as Figure 3 shown, the first compilation file and the second compilation file can be divided into multiple corresponding data segments. For example, data segments A1, B1, C1, and D1 of the first compilation file, and data segments A2, B2, C2, and D2 of the second compilation file corresponding to the first compilation file. Compare the data in the corresponding data segments byte by byte to determine the target data segments with differences. For example Figure 3 the data segments B1 and the corresponding data segment B2 shown in

[0096] Exemplarily, there may be multiple data segments with differential data in the first compilation file and the second compilation file. Then, use the differential data in the target data segment with the largest differentiation rate as the target differential data.

[0097] Step 202, use the target differential data as feature data, or use the digest feature value corresponding to the target differential data as feature data.

[0098] In the embodiments of the present application, use the target differential data as feature data, or calculate the digest feature value of the target differential data, and use this digest feature value as feature data. Among them, this digest feature value can be the hash value HASH of the target differential data.

[0099] When the differentiation rate in the differential data is less than or equal to the above preset threshold, it means that the differential position corresponding to this differential data does not belong to the patch position. Therefore, this differential data cannot be used as feature data, and the digest feature value corresponding to this differential data cannot be used as feature data for patch detection. On the contrary, this differential data can be used as the target differential data, and then the above feature data can be obtained.

[0100] For example, as Figure 3As shown, when the differentiation rate between the first 0x200 bytes of data in the B1 data segment and the first 0x200 bytes of data in the B2 data segment is greater than a preset threshold, the first 0x200 bytes of data in the B1 code segment (target difference data) can be used as the characteristic data between the first compiled file and the second compiled file corresponding to the file to be detected, or the digest characteristic value corresponding to the first 0x200 bytes of data in the B1 code segment (target difference data) can be used as the characteristic data between the first compiled file and the second compiled file corresponding to the file to be detected.

[0101] Optionally, as Figure 4 shown, in the embodiment of the present application, the digest characteristic value corresponding to the above target difference data can be implemented in the following manner of steps 401 to 402.

[0102] Step 401: Extract the differential sub-data of the target bytes in the target difference data.

[0103] Among them, the target bytes include one or more bytes, and the target bytes are less than the number of bytes included in the data segment corresponding to the target difference data.

[0104] Step 402: Perform a hash operation on each differential sub-data respectively to obtain the hash value corresponding to each differential sub-data, and use the hash value as the digest characteristic value corresponding to the target difference data.

[0105] As Figure 5 shown, the data with the number of sub-bytes being H1 in the target difference data can be extracted as the first differential sub-data, and the data with the number of sub-bytes being H2 in the target difference data can be extracted as the second differential sub-data. Then, perform a hash operation on the first differential sub-data and the second differential sub-data respectively to obtain the hash value corresponding to the first differential sub-data and the hash HASH value corresponding to the second differential sub-data. Furthermore, use the hash value corresponding to the first differential sub-data and the hash value corresponding to the second differential sub-data as the digest characteristic value corresponding to the above target difference data, that is, use the hash value corresponding to the first differential sub-data and the hash value corresponding to the second differential sub-data as the characteristic data of the reference file corresponding to the file to be detected. For example, extract 0x20 bytes of data from the head of the data segment C ( Figure 5 H1 in it) to calculate the first HASH value; then take 0x20 bytes of data at a position 0x50 bytes offset from the head of the data segment C backward ( Figure 5 H2 in it) to calculate the second HASH value.

[0106] Among them, the number of bytes corresponding to H1 can be equal to or unequal to the number of bytes corresponding to H2. For example, it can be data of 0x20 bytes. The positions of the first differential sub-data and the second differential sub-data in the target differential data do not overlap; the offset between H1 and H2 can be a variable offset. For example, when the length of the data segment of the preset bytes to be compared is 0x200 bytes, the value range of this offset can be between 0x20 and 0x180. For example, the value of this offset is 0x50 bytes; while ensuring that the data sources corresponding to the two HASH values do not overlap, data outside the data segment to be compared will not be obtained either.

[0107] It should be noted that the above is an example of the acquisition method of the characteristic data based on the first compiled file and the second compiled file corresponding to the file to be detected. In some embodiments of the present application, the above characteristic data can also be other types of data. For example, the above characteristic data can also be the above-mentioned respective differential sub-data, and the present application does not limit this.

[0108] Step 103, match the target data of the file to be detected with the characteristic data to determine the patch detection result of the file to be detected.

[0109] In the embodiments of the present application, match the target differential data between the first compiled file and the second compiled file or the target data in the file to be detected; according to the matching result of the target differential data and the target data in the file to be detected, determine the patch detection result of the file to be detected.

[0110] In the embodiments of the present application, the patch detection result of the file to be detected may include: the file to be detected is a file with a vulnerability, the file to be detected is a file in which the vulnerability has been repaired or partially repaired.

[0111] Exemplarily, the characteristic data between the first compiled file and the second compiled file determined based on the above method can be the characteristic value of the unpatched compiled file or the characteristic value of the patched compiled file.

[0112] Specifically, when the above characteristic data is the characteristic value of the unpatched compiled file, match the target differential data with the target data in the file to be detected; when there is target data in the file to be detected that matches the target differential data, it is determined that the file to be detected is a file with a vulnerability. When the above characteristic data is the characteristic value of the patched compiled file, match the target differential data with the target data in the file to be detected; when there is target data in the file to be detected that matches the target differential data, it is determined that the file to be detected is a patched file; otherwise, it is determined that the file to be detected is a file with a vulnerability.

[0113] Optionally, in the embodiments of the present application, if the above feature data is the summary feature value corresponding to the above target difference data, in step 103, matching the target data of the file to be detected with the feature data to determine the patch detection result of the file to be detected, specifically: matching the summary feature value corresponding to the target difference data with the summary feature value of the target data in the file to be detected; determining the patch detection result of the file to be detected according to whether there is target data in the file to be detected whose summary feature value matches the summary feature value corresponding to the target difference data.

[0114] Specifically, when the feature data between the first compiled file and the second compiled file can be the feature value of the unpatched compiled file, in step 103, matching the target data of the file to be detected with the feature data to determine the patch detection result of the file to be detected, specifically: matching the summary feature value corresponding to the target difference data with the summary feature value of the target data in the file to be detected; when there is target data in the file to be detected whose summary feature value matches the summary feature value corresponding to the target difference data, determining that the file to be detected is an unpatched file.

[0115] When there is target data in the file to be detected that matches the target difference data, matching the summary feature value corresponding to the target difference data with the summary feature value of the target data in the file to be detected; when there is target data in the file to be detected whose summary feature value matches the summary feature value corresponding to the target difference data, determining that the file to be detected is a file with the vulnerability repaired, otherwise, determining that the file to be detected is a file with a vulnerability.

[0116] Optionally, when the feature data is the target difference data, before matching the target data of the file to be detected with the feature data, it includes: using the data segment in the file to be detected whose byte count is the same as that of the target difference data as the target data of the file to be detected. When the feature data is the summary feature value corresponding to the target difference data, before matching the target data of the file to be detected with the feature data, it includes: using the summary feature value corresponding to the data segment in the file to be detected whose byte count is the same as that of the target difference data as the target data of the file to be detected.

[0117] Exemplarily, the target data of the file to be detected can be data corresponding to the same position and byte count as the target difference data between the first compiled file and the second compiled file.

[0118] Exemplarily, the feature data corresponding to the same target difference data may include one or more. And when there are multiple pieces of feature data, each piece of feature data can be used to perform patch detection on the file to be detected. When the detection results corresponding to each piece of feature data all indicate that the file to be detected is a patched file, it is finally determined that the file to be detected is a patched file. When the detection results corresponding to each piece of feature data all indicate that the file to be detected is an unpatched file, it is finally determined that the file to be detected is an unpatched file.

[0119] In the embodiments of the present application, using multiple pieces of feature data to perform patch detection on the file to be detected respectively can effectively improve the accuracy of patch detection and avoid detection errors.

[0120] It should also be noted that in some embodiments of the present application, in the process of comparing the data of the first compiled file with the data of the second compiled file and determining the target difference data, it is possible to obtain multiple groups of target difference data corresponding to multiple data segments with a differentiation rate greater than the preset threshold.

[0121] That is to say, the first compiled file may be a file with multiple vulnerabilities, the second compiled file may be a file patched for multiple vulnerabilities, and the file to be detected may be a file that has been patched for all multiple vulnerabilities or a file that has been patched for only some of the multiple vulnerabilities. Therefore, when performing step 103 above, using the feature data to perform patch detection on the file to be detected, in the process of obtaining the patch detection result of the file to be detected, each target difference data among the above multiple target difference data can be sequentially used as the above feature data, or the digest feature values corresponding to each target difference data among the above multiple target difference data can be sequentially used as the feature data for performing patch detection on the file to be detected. When the detection results corresponding to each piece of feature data all indicate that the file to be detected is a file with the vulnerabilities repaired, it is finally determined that the file to be detected is a file with the vulnerabilities repaired. When some or all of the detection results corresponding to each piece of feature data indicate that the file to be detected is a file with vulnerabilities, it is finally determined that the file to be detected is a file with vulnerabilities.

[0122] In addition, the first preset byte number, the second preset byte number, the third preset byte number, and the preset threshold in each of the above embodiments of the present application can all be values obtained based on practical experience. For example, the above first preset byte can be 0x200 bytes, the second preset byte can be a byte number less than the first preset byte, the third preset byte and the fourth preset byte can also be 0x200 bytes, and the above preset threshold can be 90% or 80%.

[0123] It should also be noted that, for the foregoing method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should know that the present application is not limited by the described action sequence. In some embodiments of the present application, certain steps can be performed in other sequences.

[0124] As Figure 7 shown, it is a schematic structural diagram of a patch detection device 700 provided by an embodiment of the present application. The patch detection device may include: a first acquisition unit 701, a second acquisition unit 702, and a patch detection unit 703.

[0125] The first acquisition unit 701 is configured to acquire a file to be detected, and the file to be detected is a compiled file;

[0126] The second acquisition unit 702 is configured to acquire feature data between a first compiled file and a second compiled file, where the first compiled file is a vulnerability file corresponding to the file to be detected, and the second compiled file is a patch file corresponding to the file to be detected;

[0127] The patch detection unit 703 is configured to match target data of the file to be detected with the feature data to determine a patch detection result of the file to be detected.

[0128] Optionally, in some embodiments of the present application, the foregoing second acquisition unit 702 further includes:

[0129] A processing module, configured to compare data of the first compiled file with data of the second compiled file to determine target difference data between the first compiled file and the second compiled file;

[0130] An output module, configured to use the target difference data as the feature data, or use a summary feature value corresponding to the target difference data as the feature data.

[0131] Optionally, in some embodiments of the present application, the foregoing processing module is further configured to:

[0132] Acquire a first data segment of the first compiled file and a second data segment of the second compiled file according to a first preset number of bytes;

[0133] Compare data at the same position in the first data segment and the second data segment to determine first difference data where there are differences between the first compiled file and the second compiled file;

[0134] Calculate a ratio of the number of bytes of the first difference data to the first preset number of bytes to obtain a first differentiation rate corresponding to the first difference data;

[0135] If the first differentiation rate is greater than a preset threshold, the first difference data is used as the target difference data.

[0136] Optionally, in some embodiments of the present application, after calculating the ratio of the number of bytes of the first difference data to the first preset number of bytes to obtain the differentiation rate corresponding to the first difference data, the above processing module is further configured to:

[0137] If the first differentiation rate is less than or equal to the preset threshold, the third data segment of the first compiled file and the fourth data segment of the second compiled file are obtained according to a second preset number of bytes;

[0138] Compare the data at the same positions of the third data segment and the fourth data segment to determine the second difference data where there are differences between the first compiled file and the second compiled file;

[0139] Calculate the ratio of the number of bytes of the second difference data to the second preset number of bytes to obtain the second differentiation rate corresponding to the second difference data;

[0140] If the second differentiation rate is greater than the preset threshold, the second difference data is used as the target difference data;

[0141] Wherein, the second preset number of bytes is less than the first preset number of bytes.

[0142] Optionally, in some embodiments of the present application, the above processing module is further configured to:

[0143] Compare the data at the same positions of the first compiled file and the second compiled file to determine the first position where the difference data first appears between the first compiled file and the second compiled file;

[0144] Respectively obtain a fifth data segment and a sixth data segment of the third preset number of bytes after the first position in the first compiled file and the second compiled file;

[0145] Compare the data at the same positions of the fifth data segment and the sixth data segment to determine the third difference data where there are differences between the first compiled file and the second compiled file;

[0146] Calculate the ratio of the number of bytes of the third difference data to the third preset number of bytes to obtain the third differentiation rate corresponding to the third difference data;

[0147] If the third differentiation rate is greater than the preset threshold, the third difference data is used as the target difference data.

[0148] Optionally, in some embodiments of the present application, after calculating the ratio of the number of bytes of the third difference data to the third preset number of bytes to obtain the third differentiation rate corresponding to the third difference data, the above processing module is further configured to:

[0149] If the third differentiation rate is less than or equal to the preset threshold, obtain the data after the first position in the first compiled file and the second compiled file in units of bytes;

[0150] If there is a difference in the data at the second position after the first position in the first compiled file and the second compiled file, obtain the seventh data segment and the eighth data segment of the fourth preset number of bytes after the second position in the first compiled file and the second compiled file;

[0151] Compare the data at the same positions in the seventh data segment and the eighth data segment to determine the fourth difference data with differences in the first compiled file and the second compiled file;

[0152] Calculate the ratio of the number of bytes of the fourth difference data to the fourth preset number of bytes to obtain the fourth differentiation rate corresponding to the fourth difference data;

[0153] If the fourth differentiation rate is greater than the preset threshold, use the four difference data as the target difference data.

[0154] Optionally, in some embodiments of the present application, the above processing module is further configured to:

[0155] Divide the data of the first compiled file and the data of the second compiled file into corresponding multiple data segments respectively;

[0156] Compare the data at the same positions in the multiple data segments of the first compiled file and the multiple data segments of the second compiled file respectively to determine the difference data in the first compiled file and the second compiled file and the target data segment with difference data;

[0157] Calculate the ratio of the number of bytes of the difference data in the target data segment to the number of bytes of the target data segment to obtain the differentiation rate corresponding to the target data segment;

[0158] Use the difference data in the target data segment with the largest differentiation rate as the target difference data.

[0159] Optionally, in some embodiments of the present application, the above second obtaining unit is further configured to:

[0160] Extract the differential sub-data of the target byte in the target differential data; the target byte includes one or more bytes, and the target byte is less than the number of bytes included in the data segment corresponding to the target differential data;

[0161] Perform a hashing operation on each of the differential sub-data respectively to obtain the hash value corresponding to each of the differential sub-data, and use the hash value as the digest feature value corresponding to the target differential data.

[0162] Optionally, in some embodiments of the present application, when the feature data is the target differential data, before matching the target data of the file to be detected with the feature data, it includes: using the data segment in the file to be detected with the same number of bytes as the target differential data as the target data of the file to be detected;

[0163] When the feature data is the digest feature value corresponding to the target differential data, before matching the target data of the file to be detected with the feature data, it includes: using the digest feature value corresponding to the data segment in the file to be detected with the same number of bytes as the target differential data as the target data of the file to be detected.

[0164] It should be noted that for the convenience and conciseness of description, the specific working process of the patch detection device 700 described above can refer to the description of the patch detection method in the above various embodiments, and will not be elaborated here. And it should also be noted that the above various embodiments can be combined with each other to obtain a variety of different embodiments, all of which fall within the protection scope of the present application.

[0165] As Figure 8 shown, an embodiment of the present application further provides a terminal. The terminal can be configured with the patch detection device shown in the above various embodiments. As Figure 8 shown, the terminal 8 may include: a processor 80, a memory 81, and a computer program 82 stored in the memory 81 and executable on the processor 80. When the processor 80 executes the computer program 82, it implements the steps in the above various embodiments of the patch detection method, for example, Figure 1 the steps 101 to 103 shown.

[0166] The so-called processor 80 may be a Central Processing Unit (CPU), or may also be other general-purpose processors, Digital Signal Processors (DSPs), Application Specific Integrated Circuits (ASICs), Field-Programmable Gate Arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor, etc.

[0167] The memory 81 may be an internal storage unit of the terminal 8, for example, a hard disk or a memory. The memory 81 may also be an external storage device for the terminal 8, for example, a plug-in hard disk equipped on the terminal 8, a Smart Media Card (SMC), a Secure Digital (SD) card, a Flash Card, etc. Further, the memory 81 may also include both the internal storage unit of the terminal 8 and the external storage device. The memory 81 is used to store the above computer program and other programs and data required by the terminal.

[0168] The above computer program may be divided into one or more units. The above one or more units are stored in the above memory 81 and executed by the above processor 80 to complete this application. The above one or more units may be a series of computer program instruction segments capable of completing specific functions, and the instruction segments are used to describe the execution process of the above computer program in the terminal performing patch detection. For example, the above computer program may be divided into: a first acquisition unit, a second acquisition unit, and a patch detection unit, and the specific functions are as follows:

[0169] The first acquisition unit is used to acquire a file to be detected, and the file to be detected is a compiled file;

[0170] The second acquisition unit is used to acquire the feature data between the first compiled file and the second compiled file, where the first compiled file is a vulnerability file corresponding to the file to be detected, and the second compiled file is a patch file corresponding to the file to be detected;

[0171] The patch detection unit is used to match the target data of the file to be detected with the feature data to determine the patch detection result of the file to be detected.

[0172] Those skilled in the art can clearly understand that, for the convenience and conciseness of description, only the above division of each functional unit and module is used as an example. In actual applications, the above functions can be allocated to different functional units and modules according to needs, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above. Each functional unit and module in the embodiment can be integrated into a processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above integrated unit can be implemented in the form of hardware or in the form of a software functional unit. In addition, the specific names of each functional unit and module are only for the convenience of mutual distinction and do not limit the protection scope of this application. The specific working processes of the units and modules in the above system can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated here.

[0173] In the above embodiments, the descriptions of the respective embodiments have their own emphases. For parts not detailed or recorded in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.

[0174] Those of ordinary skill in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, or by a combination of computer software and electronic hardware. Whether these functions are executed in hardware or software depends on the specific application and design constraints of the technical solution. Skilled professionals can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of this application.

[0175] In the embodiments provided in this application, it should be understood that the disclosed terminals and methods can be implemented in other ways. For example, the terminal embodiments described above are only illustrative. For example, the division of modules or units is only a logical functional division. In actual implementation, there can be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection to each other can be an indirect coupling or communication connection through some interfaces, devices or units, and can be electrical, mechanical or other forms.

[0176] The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0177] In addition, in each embodiment of the present application, each functional unit may be integrated into one processing unit, or each unit may exist physically alone, or two or more units may be integrated into one unit. The above integrated unit may be implemented in the form of hardware or in the form of a software functional unit.

[0178] If the integrated module / unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, all or part of the processes in the above-described embodiment methods of the present application can also be completed by instructing relevant hardware through a computer program. The computer program can be stored in a computer-readable storage medium. When the computer program is executed by a processor, the steps of the above-described various method embodiments can be implemented. Among them, the computer program includes computer program code, and the computer program code can be in the form of source code, object code, executable file, or some intermediate form, etc. The computer-readable medium can include: any entity or device that can carry the computer program code, recording medium, USB flash drive, mobile hard disk, magnetic disk, optical disc, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signal, telecommunication signal, and software distribution medium, etc. It should be noted that the content included in the computer-readable medium can be appropriately increased or decreased according to the requirements of legislation and patent practice in the jurisdiction. For example, in some jurisdictions, according to legislation and patent practice, the computer-readable medium does not include electrical carrier signals and telecommunication signals.

[0179] The above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the various embodiments of the present application, and should all be included in the protection scope of the present application.

Claims

1. A patch detection method, characterized in that, Including: Obtain a file to be detected, where the file to be detected is a compiled file; Obtain feature data between a first compiled file and a second compiled file, where the first compiled file is a vulnerability file corresponding to the file to be detected, and the second compiled file is a patch file corresponding to the file to be detected; Match the target data of the file to be detected with the feature data to determine the patch detection result of the file to be detected; The obtaining of the feature data between the first compiled file and the second compiled file includes: Compare the data of the first compiled file with the data of the second compiled file to determine the target difference data between the first compiled file and the second compiled file; use the target difference data as the feature data, or use the digest feature value corresponding to the target difference data as the feature data; the comparing of the data of the first compiled file with the data of the second compiled file to determine the target difference data between the first compiled file and the second compiled file includes: Obtain a first data segment of the first compiled file and a second data segment of the second compiled file according to a first preset number of bytes; compare the data at the same positions in the first data segment and the second data segment to determine first difference data with differences in the first compiled file and the second compiled file; calculate the ratio of the number of bytes of the first difference data to the first preset number of bytes to obtain a first differentiation rate corresponding to the first difference data; if the first differentiation rate is greater than a preset threshold, use the first difference data as the target difference data; after calculating the ratio of the number of bytes of the first difference data to the first preset number of bytes to obtain the differentiation rate corresponding to the first difference data, the method further includes: If the first differentiation rate is less than or equal to the preset threshold, obtain a third data segment of the first compiled file and a fourth data segment of the second compiled file according to a second preset number of bytes; compare the data at the same positions in the third data segment and the fourth data segment to determine second difference data with differences in the first compiled file and the second compiled file; calculate the ratio of the number of bytes of the second difference data to the second preset number of bytes to obtain a second differentiation rate corresponding to the second difference data; if the second differentiation rate is greater than the preset threshold, use the second difference data as the target difference data; where the number of bytes of the second preset number of bytes is less than the number of bytes of the first preset number of bytes.

2. The patch detection method according to claim 1, characterized in that, The comparing of the data of the first compiled file with the data of the second compiled file to determine the target difference data between the first compiled file and the second compiled file further includes: Compare the data at the same positions in the first compiled file and the second compiled file to determine a first position where difference data first appears in the first compiled file and the second compiled file; Respectively obtain a fifth data segment and a sixth data segment of the third preset number of bytes after the first position in the first compiled file and the second compiled file; Compare the data at the same positions of the fifth data segment and the sixth data segment to determine the third difference data with differences between the first compiled file and the second compiled file; Calculate the ratio of the number of bytes of the third difference data to the third preset number of bytes to obtain the third differentiation rate corresponding to the third difference data; If the third differentiation rate is greater than the preset threshold, use the third difference data as the target difference data.

3. The patch detection method according to claim 2, wherein After calculating the ratio of the number of bytes of the third difference data to the third preset number of bytes to obtain the third differentiation rate corresponding to the third difference data, the method further includes: If the third differentiation rate is less than or equal to the preset threshold, obtain the data after the first position in the first compiled file and the second compiled file by unit byte; If the data at the second position after the first position in the first compiled file and the second compiled file is different, obtain the seventh data segment and the eighth data segment of the fourth preset number of bytes after the second position in the first compiled file and the second compiled file; Compare the data at the same positions of the seventh data segment and the eighth data segment to determine the fourth difference data with differences between the first compiled file and the second compiled file; Calculate the ratio of the number of bytes of the fourth difference data to the fourth preset number of bytes to obtain the fourth differentiation rate corresponding to the fourth difference data; If the fourth differentiation rate is greater than the preset threshold, use the fourth difference data as the target difference data.

4. The patch detection method according to claim 1, wherein The comparison of the data of the first compiled file with the data of the second compiled file to determine the target difference data between the first compiled file and the second compiled file further includes: Divide the data of the first compiled file and the data of the second compiled file into corresponding multiple data segments respectively; Compare the data at the same positions of the multiple data segments of the first compiled file and the multiple data segments of the second compiled file respectively to determine the difference data between the first compiled file and the second compiled file and the target data segments with difference data; Calculate the ratio of the number of bytes of the difference data in the target data segment to the number of bytes of the target data segment to obtain the differentiation rate corresponding to the target data segment; Use the difference data in the target data segment with the largest differentiation rate as the target difference data.

5. The patch detection method according to any one of claims 1 to 4, characterized in that, The obtaining of the summary feature value corresponding to the target difference data includes: Extract the difference sub-data of the target bytes in the target difference data; the target bytes include one or more bytes, and the target bytes are less than the number of bytes included in the data segment corresponding to the target difference data; Perform hash operations on each of the difference sub-data respectively to obtain the hash values corresponding to the respective difference sub-data, and use the hash values as the summary feature values corresponding to the target difference data.

6. The patch detection method according to any one of claims 1 to 4, characterized in that When the feature data is the target difference data, before matching the target data of the file to be detected with the feature data, it includes: taking a data segment in the file to be detected with the same number of bytes as the target difference data as the target data of the file to be detected; When the feature data is the digest feature value corresponding to the target difference data, before matching the target data of the file to be detected with the feature data, it includes: taking the digest feature value corresponding to the data segment in the file to be detected with the same number of bytes as the target difference data as the target data of the file to be detected.

7. A terminal, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the steps of the patch detection method according to any one of claims 1 to 6.

Citation Information

Patent Citations

  • A system and method for vulnerability locating and exploring for binary files

    CN109460641A

  • Vulnerability detection method and device based on patch comparison and taint analysis and medium

    CN114154152A