Semantic comparison method and device for binary function code

By constructing a binary function code semantic comparison model based on BERT and GraphSAGE, using binary control flow charts and directed graph neural networks, the problem of low accuracy of binary file alignment is solved, and efficient binary function similarity calculation is achieved.

CN115455382BActive Publication Date: 2025-07-11WUHAN UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210960065.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-08-11
Publication Date
2025-07-11
Estimated Expiration
2042-08-11

AI Technical Summary

Technical Problem

The prior art has low accuracy in binary file comparison, especially in large code bases to consume a lot of computing resources and lose the overall semantic information of the program.

Method used

A binary control flow chart is used to represent the binary function code, and a BERT model and a directed graph neural network GraphSAGE network is used to build a binary function code semantic comparison model. The instruction embedding and global embedding are extracted through the semantic perception module and the structure perception module, and the similarity calculation module is used for comparison.

Benefits of technology

It improves the accuracy and recall rate of binary function comparison, reduces time and space complexity, is suitable for rapid traceability analysis of massive code libraries, and supports software security and intellectual property protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115455382B_ABST
    Figure CN115455382B_ABST
Patent Text Reader

Abstract

The present invention discloses a semantic comparison method and device for binary function codes. The method first disassembles the binary function codes in a binary file and represents them with a binary control flow graph, constructs a semantic comparison model FUSION for binary function codes. Through the semantic perception module of this model, the semantic information of statements can be learned simultaneously, and the structure perception module can learn the structure of the binary control flow graph and the execution order information of nodes, so as to better represent various features of binary codes. The similarity of binary functions is obtained through the semantic comparison module, thereby improving the accuracy of binary function comparison. Moreover, this method has good time and space complexity and can meet the requirements of rapid traceability analysis of binary code files in a massive code library. It has a high accuracy rate and recall rate and can be applied to the traceability scenario of binary code files based on a massive code library.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular, to a semantic comparison method and device for binary function codes. Background Art

[0002] Analyzing binary files without source code can be widely applied in fields such as vulnerability mining and malicious code discovery. Due to the reuse and sharing of source code, while open source projects provide convenience, they pose great potential risks to software security. Comparing the local similarity of binary files and analyzing issues such as mutual inclusion and code reuse between software are of great significance in fields such as vulnerability discovery and software security analysis.

[0003] In the prior art, there are multiple different ideas and methods for software clone detection or similarity measurement, including detection methods based on string matching, token-based matching methods, tree-based methods, etc. Some methods consider from the perspective of source code and can only solve the similarity comparison of software with source code, but cannot handle the comparison of binary files, which is not practical in practice. Some researchers use symbolic execution and theorem provers to compare the semantic similarity of binary codes, such as binhunt and cop, but their methods have high time and space complexity, require a large amount of computing resources, and consume a large amount of time. Therefore, they are not applicable to large code libraries. Recently, research has proven the effectiveness of applying machine learning and deep learning technologies to code analysis, and proposed using word embeddings to represent instructions. However, they only used the word embedding model to understand assembly instructions, losing the overall semantic information of the program, resulting in low accuracy.

[0004] It can be seen that the methods in the prior art have the technical problem of low accuracy. Summary of the Invention

[0005] The present invention provides a semantic comparison method and device for binary function codes to solve or at least partially solve the technical problem of low accuracy existing in the prior art.

[0006] To solve the above technical problem, a first aspect of the present invention provides a semantic comparison method for binary function codes, including:

[0007] Obtain a binary file containing binary function codes;

[0008] Disassemble the binary function codes in the binary file to obtain disassembly codes, represent the disassembly codes using a binary control flow graph, and extract the data flow relationship in the binary control flow graph, where the nodes of the binary control flow graph represent basic blocks in the disassembly codes, the edges represent call instructions between basic blocks, and the basic blocks include binary function code segments;

[0009] Construct a semantic comparison model for binary function code. The model includes a semantic perception module, a structure perception module, and a similarity calculation module. Among them, the semantic perception module is used to generate instruction embeddings according to the input instructions using the BERT model. The structure perception module uses a directed graph neural network to obtain the global embedding of the entire binary function based on the instruction embeddings of basic blocks. The similarity calculation module uses a fully connected layer to calculate the similarity between the global embeddings of different binary functions.

[0010] Use the constructed semantic comparison model for binary function code to perform semantic comparison on binary function code.

[0011] In one implementation, the method further includes normalizing the call instructions in the binary control flow graph, specifically including:

[0012] Extract the call instructions for each binary control flow graph and retain the offset of the call instructions relative to the function start address.

[0013] In one implementation, the method further includes marking the separation of operands in the basic blocks of the binary control flow graph and normalizing each operand.

[0014] In one implementation, the semantic perception module is implemented based on a multi-level bidirectional Transformer encoder. The call instructions in the binary code segment are input into the semantic perception module in a concatenated manner. On the basis of the instruction embeddings, position embeddings and segment embeddings are added, and the mixed vector of the position embeddings and segment embeddings is used as the input of the bidirectional Transformer encoder. Then, the average pooling of the hidden states of the penultimate layer is used to obtain the high-dimensional vector representation of the call instructions, that is, the instruction embeddings. Among them, the position embeddings represent different positions in the input instruction sequence, and the segment embeddings are used to distinguish different instructions.

[0015] In one implementation, the structure perception module uses the directed graph neural network GraphSAGE network to capture the structure, order, and node information of the binary control flow graph and generate a global embedding for each binary control flow graph. One binary flow graph corresponds to one binary function.

[0016] In one implementation, the calculation formula of the GraphSAGE network is:

[0017]

[0018]

[0019] Represents the high-dimensional vector representation of node v during the node update in the t-th round. Is the high-dimensional vector representation of the neighbor nodes of node v, N v Represents the set of nodes adjacent to node v. σ represents the aggregation function in GraphSAGE, W t Represents the learnable weight in the t-th round. ∥ represents the concatenation operation. Represents the high-dimensional vector representation of node v during the node update in the (t - 1)-th round; α represents the non-linear activation function; Represents the set of out-degree nodes of node v. Represents the set of in-degree nodes of node v. p and q respectively belong to and The neighboring nodes in, Represents the high-dimensional vector representation of node p during the node update in the t-th round. Represents the high-dimensional vector table of node q during the node update in the t-th round, W o Represents the weight matrix of the out-degree, W i Represents the weight matrix of the in-degree. i and o respectively represent the in-degree and out-degree.

[0020] Based on the same inventive concept, the second aspect of the present invention provides a semantic comparison device for binary function codes, including:

[0021] A binary function code acquisition module for acquiring a binary file containing binary function codes;

[0022] A disassembly module for disassembling the binary function codes in the binary file to obtain disassembly codes, representing the disassembly codes using a binary control flow graph, and extracting the data flow relationship in the binary control flow graph. Among them, the nodes of the binary control flow graph represent the basic blocks in the disassembly codes, the edges represent the call instructions between the basic blocks, and the basic blocks include binary function code segments;

[0023] A model construction module for constructing a semantic comparison model for binary function codes. The model includes a semantic perception module, a structure perception module, and a similarity calculation module. Among them, the semantic perception module is used to generate instruction embeddings according to the input instructions using the BERT model, the structure perception module is used to obtain the global embedding of the entire binary function based on the instruction embeddings of the basic blocks using a directed graph neural network, and the similarity calculation module uses a fully connected layer to calculate the similarity between the global embeddings of different binary functions;

[0024] A semantic comparison module for semantically comparing binary function codes using the constructed semantic comparison model for binary function codes.

[0025] Based on the same inventive concept, a third aspect of the present invention provides a computer-readable storage medium, on which a computer program is stored, and when the program is executed, the method described in the first aspect is implemented.

[0026] Based on the same inventive concept, a fourth aspect of the present invention provides a computer device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, the method described in the first aspect is implemented.

[0027] Compared with the prior art, the advantages and beneficial technical effects of the present invention are as follows:

[0028] The semantic comparison method of the binary function code disclosed in the present invention first disassembles the binary function code in the binary file and represents it with a binary control flow graph, constructs a semantic comparison model FUSION of the binary function code. Through the semantic perception module of this model, the semantic information of the statements can be learned simultaneously, and the structure perception module can learn the structure of the binary control flow graph and the execution order information of the nodes, so as to better characterize various features of the binary code. The similarity of the binary function is obtained through the semantic comparison module, thereby improving the accuracy of the binary function comparison. Moreover, this method has good time and space complexity and can meet the requirements of rapid traceability analysis of binary code files in a large code library. It has a high accuracy rate and recall rate, thus providing technical support for software security and intellectual property autonomy; it can be based on the traceability application scenario of binary code files in a large code library. Description of the Drawings

[0029] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the following drawings are some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0030] Figure 1 It is a schematic flow chart of the semantic comparison method of the binary function code in the embodiment of the present invention;

[0031] Figure 2 It is a schematic diagram of the serial input composed of binary code segments in the embodiment of the present invention. Detailed Embodiments

[0032] To solve the technical problem of low comparison accuracy caused by less extracted information in binary function comparison, the present invention proposes a binary code embedding framework FUSION based on a directed graph neural network to process control flow graphs. FUSION can better represent the semantic and structural features of binary code embedding, and then more accurately measure the similarity of binary functions through similarity calculation.

[0033] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0034] Embodiment 1

[0035] The embodiment of the present invention provides a semantic comparison method for binary function codes, including:

[0036] Obtain a binary file containing binary function codes;

[0037] Disassemble the binary function codes in the binary file to obtain disassembly codes, represent the disassembly codes using a binary control flow graph, and extract the data flow relationship in the binary control flow graph. Among them, the nodes of the binary control flow graph represent the basic blocks in the disassembly codes, the edges represent the call instructions between the basic blocks, and the basic blocks include binary code segments;

[0038] Construct a semantic comparison model for binary function codes. The model includes a semantic perception module, a structural perception module, and a similarity calculation module. Among them, the semantic perception module is used to generate instruction embeddings according to the input instructions using the BERT model, the structural perception module uses a directed graph neural network to obtain the global embedding of the entire binary function based on the instruction embeddings of the basic blocks, and the similarity calculation module uses a fully connected layer to calculate the similarity between the global embeddings of different binary functions;

[0039] Use the constructed semantic comparison model for binary function codes to perform semantic comparison on the binary function codes.

[0040] Please refer to Figure 1 , which is a schematic flowchart of the semantic comparison method for binary function codes in the embodiment of the present invention.

[0041] Specifically, for a given binary code file, convert the code segment into assembly code. In a specific embodiment, angr is used for disassembly, and other disassembly programs can also be used to achieve this.

[0042] The semantic perception module of the binary function code semantic comparison model uses natural language technology to map binary files to a high-dimensional space, where each code snippet is mapped to a high-dimensional vector. Through the semantic perception module, the semantic information of the binary function code can be extracted. The structure perception module updates node information by using the control flow graph node order information, so as to effectively capture the structural order information, better represent various features of the binary code, extract richer features, and then obtain the similarity of the binary function code through the semantic comparison module, thereby improving the accuracy of binary function comparison.

[0043] In one implementation, the method further includes normalizing the call instructions in the binary control flow graph, specifically including:

[0044] Extract the call instructions for each binary control flow graph and retain the offset of the call instructions relative to the function start address.

[0045] In one implementation, the method further includes marking the separation of operands in the basic blocks of the binary control flow graph and normalizing each operand.

[0046] Specifically, first, disassemble the binary function code in the binary file to obtain a binary control flow graph, and each binary function corresponds to a binary control flow graph. The binary function code segment can be composed of multiple binary function control flow graphs (hereinafter simply referred to as control flow graphs). The nodes in the control flow graph are basic blocks in the binary file (including a segment of binary function code), and its edges are call instructions between basic blocks, such as jumps. Since the call instructions are directional, the obtained control flow graph is a directed graph, and the combination of multiple nodes and edges results in a binary code segment.

[0047] Next, data flow relationships are extracted from the control flow graph to discover hidden data flow features in the control flow graph. In addition, to solve the out-of-vocabulary (OOV) problem in natural language processing, in this embodiment, the instructions in the control flow graph are normalized. For each binary control flow graph, all call instructions are extracted, and their offsets relative to the function start address are retained. The call instructions contain call targets, i.e., the addresses called by the instructions. At the same time, since a natural language processing model is used, the OOV problem in natural language problems must also be considered. The OOV problem refers to the fact that in natural language processing, we usually have a word library for the initialization and vectorization of instructions in binary code. However, variables such as constants or strings that can be changed arbitrarily cannot be fully stored in the word list. To solve this problem, before sending the instruction sequence into the FUSION model, the operands and operators in the assembly instructions are separated and marked, and each operand is normalized.

[0048] Among them, the process of normalizing the operands includes:

[0049] If the operand belongs to the memory type, first determine whether the operand is based on a base address. If not, replace the operand with "MEM".

[0050] Secondly, replace the immediate data whose value is higher than the set threshold with the string "IMM". This is done because malware can misalign the stack pointer by a small value when the function returns, thus affecting the analysis efficiency. Therefore, some small constants cannot be ignored.

[0051] All opcodes and general registers maintain their original names because each of them has a specific purpose. Represent all strings with the special symbol "STR".

[0052] In one implementation, the semantic awareness module is implemented based on a multi-level bidirectional Transformer encoder. The call instructions in the binary code segment are input into the semantic awareness module in a concatenated manner. Based on the instruction embedding, position embedding and segment embedding are added, and the mixed vector of the position embedding and the segment embedding is used as the input of the bidirectional Transformer encoder. Then, the average pooling of the hidden states of the penultimate layer is used to obtain the high-dimensional vector representation of the call instruction, that is, the embedding of the instruction; among them, the position embedding represents different positions in the input instruction sequence, and the segment embedding is used to distinguish different instructions.

[0053] Specifically, the normalized binary function instructions are sent into the semantic awareness module (BERT model), and the instruction embedding will be obtained as the output.

[0054] The model proposed by BERT is a multi - level bidirectional Transformer encoder. Transformer is a neural network architecture based entirely on the multi - head attention mechanism. By modifying the BERT pre - trained model to capture the semantic features of basic blocks, in the model of the present invention, the Transformer units are bidirectionally connected and stacked into multiple layers.

[0055] In the specific implementation process, each call instruction is regarded as a sentence, and each instruction operation symbol (token) is regarded as a word. The instructions in the binary code segment are concatenated and then fed into the BERT model. As Figure 2 shown, the first token of this concatenated input is a special token [CLS], which is used to identify the start of a sequence. Secondly, the present invention uses another token [SEP] to separate the concatenated instructions. The position embedding and segment embedding will be trained together with the token embedding. These two embeddings can help to dynamically adjust the token embedding according to the position.

[0056] After feeding the normalized binary function instructions into the model, it is necessary to convert the hidden layer into instruction embeddings that can be used as inputs for downstream structural models. Since the Transformer encoder encodes all input information into the hidden state, the present invention uses the average pooling of the hidden state of the penultimate layer to represent the entire instruction.

[0057] In one implementation, the structure - aware module uses the GraphSAGE network of the directed graph neural network to capture the structure, sequence, and node information of the binary control flow graph, and generates a global embedding for each binary control flow graph. One binary flow graph corresponds to one binary function.

[0058] Specifically, after using BERT to obtain the instruction embeddings of all basic blocks in the binary control flow graph, the original binary control flow graph is converted into an enhanced control flow graph with more obvious semantic characteristics. The control flow graph of the instruction embeddings is input into the directed graph neural network (structure - aware module), and the embedding of the entire function control flow graph is output, and this graph embedding is used as the vector representation of the entire function.

[0059] The main objective of this step is to use the directed graph neural network to capture the structure, sequence, and node information of the function control flow graph, and then generate a global embedding for each control flow graph. This method includes steps such as graph node information sensing and graph attention mechanism acquisition.

[0060] In one implementation, the calculation formula of the GraphSAGE network is:

[0061]

[0062]

[0063] Represents the high-dimensional vector representation of node v during the node update in the t-th round. Is the high-dimensional vector representation of the neighbor nodes of node v, N v Represents the set of nodes adjacent to node v, σ represents the aggregation function in GraphSAGE, W t Represents the learnable weight in the t-th round, ∥ represents the concatenation operation. Represents the high-dimensional vector representation of node v during the node update in the (t - 1)-th round; α represents the non-linear activation function; Represents the set of out-degree nodes of node v. Represents the set of in-degree nodes of node v, p and q respectively belong to and The neighboring nodes in, Represents the high-dimensional vector representation of node p during the node update in the t-th round. Represents the high-dimensional vector table of node q during the node update in the t-th round, W o Represents the weight matrix of the out-degree, W i Represents the weight matrix of the in-degree, i and o respectively represent the in-degree and out-degree.

[0064] Specifically, in order to obtain the node information of each node in the graph structure, this embodiment adopts the GraphSAGE network based on the directed graph method. GraphSAGE is an inductive node embedding method, which can perform induction on unseen nodes. When learning how the information of a node is aggregated from the features of its neighbor nodes, and when such an "aggregation function" is learned, and through the binary control flow chart in the previous text, the features and neighbor relationships of each node can be known, so that a new node representation can be conveniently obtained to calculate the node embedding in the inductive enhanced control flow graph. Through the above method, the problem of fixed node embedding caused by the graph algorithm with fixed weights can be solved.

[0065] In the specific implementation process, the neighboring nodes of the node are divided into two types: out-degree and in-degree, and are calculated separately to represent the difference between the out-degree and in-degree information. And two different weight matrices are used to calculate the out-degree information and the in-degree information respectively. Finally, a binary function is represented by a high-dimensional vector. In order to effectively identify the direction of the edges in the CFG, the enhanced GraphSAGE in FUSION separately collects the out-degree and in-degree nodes of v as and

[0066] Finally, a similarity score is generated through a multi-layer fully connected neural network. The fully connected layer is a non-linear neural network that maps the input of dimension m to the desired output dimension n using multi-layer weighted neuron multiplications. Through the last layer of the fully connected neural network, a score representing the similarity of binary functions is calculated to represent the semantic similarity of binary function codes.

[0067] Embodiment 2

[0068] Based on the same inventive concept, this embodiment provides a semantic comparison device for binary function codes, including:

[0069] A binary function code acquisition module for acquiring binary files containing binary function codes;

[0070] A disassembly module for disassembling the binary function codes in the binary file to obtain disassembly codes, representing the disassembly codes using a binary control flow graph, and extracting the data flow relationship in the binary control flow graph. Among them, the nodes of the binary control flow graph represent the basic blocks in the disassembly codes, the edges represent the call instructions between the basic blocks, and the basic blocks include binary code segments;

[0071] A model construction module for constructing a semantic comparison model for binary function codes. The model includes a semantic perception module, a structure perception module, and a similarity calculation module. Among them, the semantic perception module is used to generate instruction embeddings according to the input instructions using the BERT model, the structure perception module is used to obtain the global embedding of the entire binary function based on the instruction embeddings of the basic blocks using a directed graph neural network, and the similarity calculation module uses a fully connected calculation to calculate the similarity between the global embeddings of different binary functions;

[0072] A semantic comparison module for semantically comparing binary function codes using the constructed semantic comparison model for binary function codes.

[0073] Since the device introduced in Embodiment 2 of the present invention is the device used to implement the semantic comparison method of binary function codes in Embodiment 1 of the present invention, based on the method introduced in Embodiment 1 of the present invention, those skilled in the art can understand the specific structure and variations of the device, so it will not be elaborated here. Any device used in the method of Embodiment 1 of the present invention belongs to the scope protected by the present invention.

[0074] Embodiment 3

[0075] Based on the same inventive concept, the present invention also provides a computer-readable storage medium, on which a computer program is stored, and when the program is executed, it implements the method described in Embodiment 1.

[0076] Since the computer-readable storage medium introduced in the third embodiment of the present invention is the computer-readable storage medium used in the semantic comparison method of the binary function code in the first embodiment of the present invention, based on the method introduced in the first embodiment of the present invention, those skilled in the art can understand the specific structure and variations of the computer-readable storage medium, so it will not be elaborated here. Any computer-readable storage medium used in the method of the first embodiment of the present invention falls within the scope of protection of the present invention.

[0077] Embodiment 4

[0078] Based on the same inventive concept, the present application also provides a computer device, including a storage, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the above program, the method in the first embodiment is implemented.

[0079] Since the computer device introduced in the fourth embodiment of the present invention is the computer device used in the semantic comparison method of the binary function code in the first embodiment of the present invention, based on the method introduced in the first embodiment of the present invention, those skilled in the art can understand the specific structure and variations of the computer device, so it will not be elaborated here. Any computer device used in the method of the first embodiment of the present invention falls within the scope of protection of the present invention.

[0080] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, a system, or a computer program product. Therefore, the present invention can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0081] The present invention is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the embodiments of the present invention. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and the combination of flows and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate means for implementing the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0082] Although the preferred embodiments of the present invention have been described, additional changes and modifications can be made by those skilled in the art once they learn the basic creative concept. Therefore, the appended claims are intended to be construed to include the preferred embodiments as well as all changes and modifications falling within the scope of the present invention.

[0083] Obviously, those skilled in the art can make various changes and modifications to the embodiments of the present invention without departing from the spirit and scope of the embodiments of the present invention. Thus, if these modifications and variations of the embodiments of the present invention fall within the scope of the claims of the present invention and their equivalent technologies, the present invention is also intended to include these modifications and variations.

Claims

1. A semantic comparison method for binary function codes, characterized in that, Comprising: Obtain a binary file containing binary function code; Disassemble the binary function code in the binary file to obtain disassembly code, represent the disassembly code using a binary control flow graph, and extract the data flow relationship in the binary control flow graph. Among them, the nodes of the binary control flow graph represent basic blocks in the disassembly code, the edges represent call instructions between basic blocks, and the basic blocks include binary function code segments; Construct a semantic comparison model for binary function code. The model includes a semantic perception module, a structure perception module, and a similarity calculation module. Among them, the semantic perception module is used to generate instruction embeddings according to the input instructions using the BERT model. The structure perception module uses a directed graph neural network to obtain the global embedding of the entire binary function based on the instruction embeddings of the basic blocks. The similarity calculation module uses a fully connected layer to calculate the similarity between the global embeddings of different binary functions. Among them, the semantic perception module is implemented based on a multi-level bidirectional Transformer encoder. The call instructions in the binary code segment are input into the semantic perception module in series. On the basis of the instruction embeddings, position embeddings and segment embeddings are added, and the mixed vector of the position embeddings and segment embeddings is used as the input of the bidirectional Transformer encoder. Then, the average pooling of the hidden states of the penultimate layer is used to obtain the high-dimensional vector representation of the call instruction, that is, the embedding of the instruction; among them, the position embedding represents different positions in the input instruction sequence, and the segment embedding is used to distinguish different instructions; Use the constructed semantic comparison model for binary function code to perform semantic comparison on the binary function code.

2. The semantic comparison method for binary function codes according to claim 1, wherein The method further includes normalizing the call instructions in the binary control flow graph, specifically including: For each binary control flow graph, extract the call instructions and retain the offset of the call instructions relative to the function start address.

3. The semantic comparison method for binary function codes according to claim 1, characterized in that, The method further includes marking the separation of operands in the basic blocks in the binary control flow graph and normalizing each operand.

4. The semantic comparison method for binary function codes according to claim 1, characterized in that, The structure perception module uses the directed graph neural network GraphSAGE network to capture the structure, order, and node information of the binary control flow graph and generate a global embedding for each binary control flow graph. One binary flow graph corresponds to one binary function.

5. The semantic comparison method for binary function codes according to claim 4, wherein The calculation formula of the GraphSAGE network is: Represents the high-dimensional vector representation of node v during the node update in the t-th round. Is the high-dimensional vector representation of the neighbor nodes of node v. Represents the set of nodes adjacent to node v. Represents the aggregation function in GraphSAGE. Represents the learnable weight in the t-th round. Represents the concatenation operation. Represents the high-dimensional vector representation of node v during the node update in the (t - 1)-th round; Represents the non-linear activation function; Represents the set of out-degree nodes of node v. Represents the set of in-degree nodes of node v. Respectively belong to and The neighboring nodes in. Represents the high-dimensional vector representation of node p during the node update in the t-th round. Represents the high-dimensional vector representation of node q during the node update in the t-th round. Represents the weight matrix of out-degree. Represents the weight matrix of in-degree. Respectively represent the in-degree and out-degree.

6. A semantic comparison device for binary function codes, characterized in that Comprising: A binary function code acquisition module for obtaining a binary file containing binary function code; A disassembly module for disassembling the binary function code in the binary file to obtain disassembly code, representing the disassembly code using a binary control flow graph, and extracting the data flow relationship in the binary control flow graph. Among them, the nodes of the binary control flow graph represent basic blocks in the disassembly code, the edges represent call instructions between basic blocks, and the basic blocks include binary function code segments; A model construction module for constructing a semantic comparison model of binary function codes. The model includes a semantic perception module, a structure perception module, and a similarity calculation module. Among them, the semantic perception module is used to generate instruction embeddings according to the input instructions by using the BERT model. The structure perception module uses a directed graph neural network to obtain the global embedding of the entire binary function based on the instruction embeddings of basic blocks. The similarity calculation module uses a fully connected layer to calculate the similarity between the global embeddings of different binary functions. Among them, the semantic perception module is implemented based on a multi-layer bidirectional Transformer encoder. The call instructions in the binary code segment are input into the semantic perception module in a concatenated manner. On the basis of the instruction embeddings, position embeddings and segment embeddings are added, and the mixed vector of the position embeddings and segment embeddings is used as the input of the bidirectional Transformer encoder. Then, the average pooling of the hidden states of the penultimate layer is used to obtain the high-dimensional vector representation of the call instruction, that is, the embedding of the instruction. Among them, the position embedding represents different positions in the input instruction sequence, and the segment embedding is used to distinguish different instructions. A semantic comparison module for semantically comparing binary function codes by using the constructed semantic comparison model of binary function codes.

7. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed, it implements the method described in any one of claims 1 to 5.

8. A computer device, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the method described in any one of claims 1 to 5.

Citation Information

Patent Citations

  • Cross-architecture binary function similarity detection method and system based on neural network

    CN112308210A

  • Cross-instruction architecture binary code similarity detection method based on semantics

    CN112596736A