Method and apparatus for identifying and protecting a function pointer and its data dependencies

Through a type and pointer-based analysis method, combined with inter-process data flow diagrams, taint propagation is carried out, function pointers and their dependent data are identified and protected, the problem of insufficient protection of function pointers in the prior art is solved, and higher program security and data integrity are achieved.

CN115510430BActive Publication Date: 2025-07-11WUHAN UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211121918.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-09-15
Publication Date
2025-07-11
Estimated Expiration
2042-09-15

AI Technical Summary

Technical Problem

In the prior art, the protection mechanism of function pointers and data dependencies has low security, especially when facing control flow hijacking attacks, traditional protection methods are easily bypassed and cannot effectively prevent attackers from modifying the program execution path.

Method used

A type and pointer-based analysis method is adopted, combining the inter-process data flow diagram for forward and backward taint propagation, identify function pointers and their dependencies, and allocate them to hardware-protected memory, protect using Intel MPK, and switch privileges through call gate to control the access of instructions.

Benefits of technology

Improves program security, ensures data integrity, prevents illegal modification of program execution paths, and enhances defense capabilities against control flow hijacking attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115510430B_ABST
    Figure CN115510430B_ABST
Patent Text Reader

Abstract

The present invention discloses a method and apparatus for identifying and protecting function pointers and their data dependencies. The method first identifies memory objects belonging to function pointers or containing at least one function pointer from a given program, then uses taint analysis to identify function pointers and their data dependencies, and then uses Intel MPK to protect this data. This ensures their integrity, thereby preventing the execution path of the program from being modified and improving the security of the program.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of software security, and in particular, to a method and device for identifying and protecting function pointers and their data dependencies. Background Art

[0002] Languages such as C / C++ give developers great freedom to control all resources at will. This enables developers to greatly improve the efficiency of the program. However, not everyone can perfectly manage memory manually and abide by type rules, which leads to security problems. Attackers take advantage of vulnerabilities such as buffer overflows and heap overflows to cause memory corruption to read and modify sensitive data or execute malicious code.

[0003] This has become a security problem that has persisted for decades, and the battle between attack and defense against it is constantly going on. In the early days, attackers generally adopted the method of code injection to achieve malicious behavior by jumping to execute the injected code. To prevent such attacks, researchers have proposed mechanisms such as DEP (Data Execution Prevention), Stack Canaries, and Address Space Layout Randomization. To break through these mechanisms, attackers have explored code reuse attacks. By modifying control data such as return addresses, they continuously redirect the control flow to selected addresses, usually code fragments in the attacked program, and connect them to achieve a powerful attack (Turing-complete). Currently popular code reuse attacks include Return-to-libc, ROP (Return Oriented Programming), JOP (Jump Oriented Programming), etc. Since no new code needs to be injected but existing code fragments are directly reused, DEP is ineffective; and attacks such as BROP dynamically search for gadgets at runtime, bypassing ordinary ASLR. In addition to targeting control-data, attackers also affect program behavior without violating control-flow integrity by modifying key data such as user identity data and decision-making data in non-control data, thereby achieving the purpose of leaking data or elevating privileges. Recent research has shown that non-control data attacks can achieve more diverse functions and are Turing complete.

[0004] Given the danger of control flow hijacking attacks, researchers have tried to defend against it from two aspects: control flow integrity and code pointer integrity. Control Flow Integrity (CFI) is a common solution to control flow hijacking attacks. It prevents control flow hijacking attacks by ensuring that the transfer targets of Indirect Control Transfer (ICT) instructions are not maliciously changed by attackers. Code Pointer Integrity (CPI) prevents control flow hijacking attacks by protecting the memory security of code pointers. Early CPI usually only realized the need to protect the code pointers themselves. The CPI that formally proposed the concept of code pointer integrity realized that in order to ensure the memory security of code pointers, it is also necessary to protect the data pointers used to access code pointers. Otherwise, by modifying these data pointers, attackers can make the program fetch what is considered a function pointer value from the wrong memory, thereby indirectly modifying the code pointer. PARTS goes further and extends code pointer integrity to pointer integrity, protecting all code pointers and data pointers, thus achieving higher security. However, the information hiding technology used by CPI to protect sensitive pointers has been proven to be insecure and can be broken by timing side-channel attacks and thread spraying; PARTS relies on pointer authentication (PA) of the ARM architecture for protection. Therefore, a new security mechanism against control flow hijacking attacks is necessary. Summary of the Invention

[0005] The present invention provides a method and device for identifying and protecting function pointers and their data dependencies, so as to solve or at least partially solve the technical problem of low security in the prior art.

[0006] To solve the above technical problems, a first aspect of the present invention provides a method for identifying and protecting function pointers and their data dependencies, including:

[0007] S1: Analyze the given program based on types and pointers, and identify memory objects that belong to function pointers or contain at least one function pointer;

[0008] S2: Concatenate the definition information and usage information of each function to construct an interprocedural data flow graph;

[0009] S3: Use the identified memory objects that belong to or contain function pointers as taint sources, and all indirect function call points as sinks, and perform depth-first search in the constructed interprocedural data flow graph to implement forward taint propagation. The paths from the taint sources to the sinks represent possible calculation processes of function pointers, and the instructions on the paths are used as sensitive instructions participating in the calculation of function pointers;

[0010] S4: Use the obtained sensitive instructions as taint sources, the identified memory objects that belong to or contain function pointers as sinks, and perform a depth-first search in the constructed interprocedural data flow graph to implement backward taint propagation. For the obtained paths from the taint sources to the sinks, regard the memory objects on the paths as the data relied on by the function pointers in the sensitive instructions;

[0011] S5: Allocate all the identified function pointers and the data they rely on to memory protected by hardware;

[0012] S6: Protect the memory protected by the hardware using Intel MPK, and use call gate to switch privileges to allow access to the instructions in the program that would originally write to the function pointers and the data they rely on.

[0013] In one implementation, step S1 includes:

[0014] Traverse the types in the given program in sequence. If a type is a function pointer type, it is a sensitive type. If a type is a composite type that contains one or more sensitive types, recursively judge all the elements in the composite type. If one of the elements is a sensitive type, then this type is a sensitive type. After identifying all sensitive types, traverse all the variables in the given program again. If the type of a variable is a sensitive type, then this variable is a sensitive variable;

[0015] Use a pointer-based analysis method for analysis. If there is a function in the target set of a pointer, regard this pointer as a function pointer and add it to the set of sensitive variables. At the same time, add the variables included in the pointer to the set of sensitive variables.

[0016] In one implementation, during the forward taint propagation in S3, start from the memory object containing the function pointer and end at the indirect function call point. After the forward taint propagation ends, all the taint paths from the taint source to the indirect call point are determined. Each taint path consists of a set of taint instructions, which are used to describe the life cycle of a function pointer from creation to call.

[0017] In one implementation, in the backward taint propagation of S4, start from the taint instructions identified in step S2 and end the propagation when encountering a memory object. After the backward taint propagation ends, all the taint paths from the taint source to the memory object are determined, and the memory objects on the taint paths are regarded as the data relied on by the function pointer.

[0018] In one implementation, step S5 includes:

[0019] If the function pointer and the data it relies on are local variables, allocate a corresponding stack frame for the function where the separated stack is located;

[0020] If the function pointer and the data it depends on are dynamically allocated variables, replace the original functions with memory allocation and release functions for a separate heap.

[0021] If the function pointer and the data it depends on are static variables in the BBS segment or DATA segment, create a new segment and corresponding global variables in the pass, and transfer the static variables to the global variables.

[0022] Based on the same inventive concept, a second aspect of the present invention provides an apparatus for identifying and protecting a function pointer and its data dependencies, including:

[0023] A function pointer identification module, configured to perform type-based and pointer-based analysis on a given program to identify memory objects belonging to function pointers or containing at least one function pointer;

[0024] An inter-procedural data flow graph construction module, configured to concatenate the definition information and usage information of each function to construct an inter-procedural data flow graph;

[0025] A sensitive instruction identification module, configured to use the identified memory objects belonging to or containing function pointers as taint sources, and all indirect function call points as convergence points, perform depth-first search in the constructed inter-procedural data flow graph to implement forward taint propagation, and the path from the taint source to the convergence point represents a possible calculation flow of the function pointer, and the instructions on the path are used as sensitive instructions participating in the calculation of the function pointer;

[0026] A data dependency identification module, configured to use the obtained sensitive instructions as taint sources, and the identified memory objects belonging to or containing function pointers as convergence points, perform depth-first search in the constructed inter-procedural data flow graph to implement backward taint propagation, and the path from the taint source to the convergence point, and the memory objects on the path are used as the data on which the function pointers in the sensitive instructions depend;

[0027] A memory allocation module, configured to allocate all the identified function pointers and the data they depend on to memory protected by hardware;

[0028] A protection module, configured to protect the memory protected by the hardware using Intel MPK, and use callgate to switch privileges to allow access to the instructions in the program that would originally write to the function pointers and the data they depend on.

[0029] Based on the same inventive concept, a third aspect of the present invention provides a computer-readable storage medium, on which a computer program is stored, and when the program is executed, the method described in the first aspect is implemented.

[0030] Based on the same inventive concept, a fourth aspect of the present invention provides a computer device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, the method described in the first aspect is implemented.

[0031] Compared with the prior art, the advantages and beneficial technical effects of the present invention are as follows:

[0032] The method for identifying and protecting function pointers and their data dependencies disclosed in the present invention first uses type-based and pointer-based analysis methods to identify memory objects belonging to function pointers or containing at least one function pointer, constructs an interprocedural data flow graph, and further uses forward taint propagation and backward taint propagation to analyze the identified memory objects to identify target function pointers (sensitive instructions) and the data they depend on, and then uses Intel MPK to protect these function pointers and the dependent data. This ensures the integrity of the data and prevents the execution path of the program from being modified, thereby improving the security of the program. BRIEF DESCRIPTION OF THE DRAWINGS

[0033] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the following drawings are some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0034] Figure 1 is a flowchart of the method for protecting the integrity of function pointers and their dependent data according to an embodiment of the present invention;

[0035] Figure 2 is a layout diagram of separated stack and separated heap according to an embodiment of the present invention;

[0036] Figure 3 is a schematic diagram of call gate assembly code according to an embodiment of the present invention;

[0037] Figure 4 is a structural block diagram of the device for the method for identifying and protecting function pointers and their data dependencies provided by an embodiment of the present invention;

[0038] Figure 5 is a structural schematic diagram of a computer-readable storage medium provided by an embodiment of the present invention;

[0039] Figure 6 is a structural schematic diagram of a computer device provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0040] The present invention mainly proposes a method and device for identifying and protecting function pointers and their data dependencies based on taint analysis and hardware-based isolation mechanisms, considering all the data used in the life cycle of function pointers. By fully considering the characteristics of function pointers and identifying the data to be protected through taint analysis (forward taint propagation and backward taint propagation), the integrity of the data is ensured. Further, the identified data is protected by hardware-protected memory, thereby providing higher security for software.

[0041] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Apparently, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the scope of protection of the present invention.

[0042] Embodiment 1

[0043] The embodiment of the present invention provides a method for identifying and protecting function pointers and their data dependencies, including:

[0044] S1: Analyze the given program based on type and pointer to identify memory objects that belong to function pointers or contain at least one function pointer;

[0045] S2: Concatenate the definition information and usage information of each function to construct an interprocedural data flow graph;

[0046] S3: Use the identified memory objects that belong to or contain function pointers as taint sources, and all indirect function call points as sink points. Perform a depth-first search in the constructed interprocedural data flow graph to implement forward taint propagation. The path from the taint source to the sink point represents a possible calculation process of the function pointer, and the instructions on the path are used as sensitive instructions participating in the function pointer calculation;

[0047] S4: Use the obtained sensitive instructions as taint sources, and the identified memory objects that belong to or contain function pointers as sink points. Perform a depth-first search in the constructed interprocedural data flow graph to implement backward taint propagation. The path from the taint source to the sink point is obtained, and the memory objects on the path are used as the data on which the function pointers in the sensitive instructions depend;

[0048] S5: Allocate all the identified function pointers and their dependent data to hardware-protected memory;

[0049] S6: Protect the memory protected by the hardware using Intel MPK, and use call gate to switch privileges to allow access to the instructions in the program that would originally write function pointers and the data they depend on.

[0050] Please refer to Figure 1 , which is the flowchart of the integrity protection method for function pointers and the data they depend on according to an embodiment of the present invention.

[0051] Specifically, most function pointers can be obtained through a type-based analysis method, and further combined with a pointer-based analysis method to obtain the function pointers that may be missed, thereby ensuring the accuracy of identification.

[0052] The interprocedural data flow graph is constructed by concatenating the def-use chain (definition information and use information chain) of each function. It contains the definition information and use information of the data, such as which instruction uses which data.

[0053] The taint analysis in steps S3 and S4 is implemented based on the interprocedural data flow graph. Among them, sources are the taint sources and sinks are the convergence points. Forward taint propagation starts from the taint source and performs a depth-first search. If a path reaches the convergence point, a taint path is found. Backward taint propagation is implemented by taking the sensitive instructions in step S3 as the taint source and the memory objects identified as belonging to or containing function pointers as the convergence points, and performing a depth-first search. The propagation ends when a memory object is encountered during the propagation process. All contaminated memory objects are the data that function pointers depend on.

[0054] In one embodiment, step S1 includes:

[0055] Traverse the types in the given program in sequence. If a type is a function pointer type, it is a sensitive type. If a type is a composite type containing one or more sensitive types, recursively judge all elements in the composite type. If one element is a sensitive type, then this type is a sensitive type. After identifying all sensitive types, traverse all variables in the given program again. If the type of a variable is a sensitive type, then this variable is a sensitive variable;

[0056] Perform analysis using a pointer-based analysis method. If there is a function in the target set of a pointer, then regard this pointer as a function pointer and add it to the set of sensitive variables. At the same time, add the variables contained in the pointer to the set of sensitive variables.

[0057] In the specific implementation process, first, type-based static analysis is used for identification. A variable is a sensitive variable if and only if its type is a sensitive type. Sensitive types include function pointer types and composite types that contain one or more sensitive types. When determining sensitive types, all types of the target program are traversed in sequence, and different types are processed separately: if a type is a basic type, such as an integer type, then it should be ignored; if it is a function pointer, then it is obviously a sensitive type; if it is other pointers, then it is ignored; if it is composite, then all its elements are recursively judged, and as long as one of them belongs to the sensitive type, then it is a sensitive type. After identifying all sensitive types, all variables of the program are traversed again. If the type of a variable is a sensitive type, then this variable is a sensitive variable.

[0058] It should be noted that sensitive types and sensitive variables refer to the types and variables analyzed in relation to program security.

[0059] The sensitive variables obtained by type-based static analysis are incomplete: general pointers may actually point to functions. Take char* as an example. In the C / C++ standard, although its type indicates that it should point to a string, it actually allows it to point to any type of object, including functions. However, since its type does not clearly specify a function type, the previous method missed this case.

[0060] Therefore, context-, flow- and field-sensitive pointer analysis is used to supplement the results obtained by type-based static analysis: if a function exists in the points-to set (the target set, which contains all memory objects that the pointer may point to) of a pointer, it is also regarded as a function pointer, added to the sensitive variable set, and the variable that contains it (recursively) is also added. This screening method is based on the fact that the result obtained by pointer analysis is the set of all memory objects that the pointer may point to in the entire program. If a function exists in this set, it means that it may be used for indirect calls during program execution.

[0061] In one embodiment, during the forward taint propagation of S3, it starts from a memory object containing a function pointer and ends at an indirect function call point. After the forward taint propagation ends, all taint paths from the taint source to the indirect call point are determined. Each taint path consists of a set of taint instructions, which are used to describe the life cycle of a function pointer from creation to invocation.

[0062] Specifically, take the memory object containing the function pointer obtained in step S1 as sources, and take all indirect function call points as sinks, and perform forward taint propagation. The forward taint propagation starts from the memory object containing the function pointer and ends at the indirect function call point. During this process, if any operand of an instruction is tainted, then the result of this instruction will also be tainted. After the forward taint propagation ends, all taint paths from the taint source to the indirect call point are determined. Each taint path consists of a set of taint instructions, which describes the life cycle of a function pointer from creation to invocation. Note that in LLVM IR, an instruction and its result value (if it exists) are semantically equivalent and can be substituted for each other.

[0063] In one embodiment, in the backward taint propagation of S4, it starts from the taint instructions identified in step S2 and ends when encountering a memory object. After the backward taint propagation ends, all taint paths from the taint source to the memory object are determined, and the memory objects on the taint paths are taken as the data relied on by the function pointer.

[0064] Specifically, take all the taint instructions obtained in step S2 as sources, perform backward taint propagation, and end the propagation when encountering a memory object. In the backward taint propagation, if an instruction is a taint instruction, then all its operands will be tainted. If a memory operation instruction is a taint instruction, then all the memory pointed to by the address operand of this instruction will be tainted. The result obtained from the backward taint propagation is the tainted memory object, which is the data relied on by the function pointer.

[0065] In the specific implementation process, the pointed memory usage instruction is analyzed to obtain, that is, the memory in the points-to set of the operand at this address. For example, if a phi instruction is a tainted instruction, then its corresponding condition (branch condition, that is, the conditional statement in the branch statement) will also be tainted. The phi instruction is used to implement the phi node in the Static Single Assignment (SSA) form. In the SSA form, each variable can only be assigned once. If a variable is assigned in different execution paths, SSA uses a phi node to represent it and selects its value according to the execution path at runtime. Therefore, the variable that determines which path to execute is also a dependency of the phi instruction. If the phi instruction is tainted, then the corresponding variable will also be tainted. This variable is located at the common starting point of these paths, that is, a branch instruction. To find this branch instruction, it is necessary to construct its dominance tree according to the control flow graph of the function. In the control flow graph, a node a dominates another node b if and only if all paths from the entry node to node b must pass through node a. Therefore, the immediately dominator of the tainted phi instruction (the immediately dominator refers to the nearest dominator of a certain node in the dominance tree) is the branch instruction to be found.

[0066] In one implementation, step S5 includes:

[0067] If the function pointer and its dependent data are local variables, allocate a corresponding stack frame for the function in the separated stack;

[0068] If the function pointer and its dependent data are dynamically allocated variables, replace the original function with the memory application and release functions of the separated heap;

[0069] If the function pointer and its dependent data are static variables in the BSS segment or DATA segment, create a new segment and corresponding global variables in the pass, and transfer the static variables to the global variables.

[0070] Specifically, separated stack, separated heap, and separated section respectively represent the separated stack, the separated heap, and the ELF segment. Section refers to the segment in the executable file, and safe section is a section created in the embodiment of the present invention specifically for storing global variables that need to be protected. Intel MPK is a hardware feature of Intel chips, and Call gate means call gate, which means giving the program high privileges for a period of time and immediately taking them back after the time ends.

[0071] The original functions are memory allocation and deallocation functions such as malloc and free.

[0072] Please refer to Figure 2 , which is a layout diagram of the separated stack and separated heap of the embodiments of the present invention;

[0073] In the specific implementation process, first, a separated stack needs to be maintained to store local variables that need to be protected. Specifically, a memory area is allocated in S, and the stack pointer of the separated stack is initialized to the high address of this memory area, as Figure 2 shown. Given a stack variable, first calculate its size according to the type and alignment; then, use the sub instruction to adjust the position of the stack pointer to allocate stack space. Finally, the result of the sub instruction is converted to the original type of the variable for referencing this variable. To recycle the stack frame, the position of the stack pointer is saved at the function entry and restored before all return instructions.

[0074] Then, a separated heap is maintained to store variables that require dynamically allocated memory. The separated heap divides the entire memory into 16-byte chunks and allocates dynamic memory starting from the low address. When there is a dynamic allocation request, a block composed of consecutive chunks that meets the requested size is found, and the base address of this block is returned. To find available chunks, COLLATE maintains a free_list that links the unallocated chunks into a single linked list, as Figure 2 shown. The free_list records the size of each block and the address of the subsequent block, which is beneficial to the implementation of allocation and deletion operations.

[0075] Finally, a separated section (separated ELF section) is provided, which stores statically allocated variables. Specifically, first, a special ELF section is created, and then two padding variables are inserted at the beginning and end of this section respectively. When the executable file is loaded into memory, these two padding variables can be used to determine the actual memory address range of the memory segment. Before the main function is executed, this memory segment is mapped to S for protection.

[0076] For each memory operation instruction that can write to memory, pointer analysis is used to obtain the points-to set of its pointer operands. If it contains protected memory objects, a call gate is used to allow access to it. In the case of an external call instruction, if the points-to set of its arguments contains any protected data, the same process is carried out.

[0077] To protect the memory in step 4, its permissions are modified using Intel MPK, which is read-only by default to prevent malicious modification. Only when executing the above-mentioned trusted instructions, a call gate is used to grant the instruction access to it.

[0078] Figure 3 The assembly code of the call gate is shown. Xor: Exclusive OR instruction, used to zero the ecx and edx registers so that they can be written to the PKRU register. Mov: Memory move instruction, which places the value to be written to the PKRU register into the eax register. WRPKRU: An instruction specifically used to write to the PKRU register, which will write the value in the eax register to the PKRU register. Each call gate first uses the WRPKRU instruction to write PKRU_ALLOW_D1 to the PKRU register (lines 1 - 5), allowing subsequent instructions to write to protected memory. PKRU\ALLOW_D1 is a macro representing the value of the PKRU register when all memory is readable and writable. Next, the trusted instruction is executed (line 7). After execution, the call gate writes PKRU_DISALLOW_D1 to the PKRU register (lines 9 - 13), prohibiting subsequent code from writing to protected memory. Regarding whether the WRPKRU instruction can be exploited by an attacker, since a control flow hijacking attack must first corrupt data that can affect the control flow, and the present invention prevents its occurrence at the source by protecting data related to control, therefore, the WRPKRU instruction cannot be exploited by an attacker. It should be noted that the WRPKRU instruction is a proprietary instruction of Intel MPK, used to write to the PKRU register to modify the CPU's access permissions to each memory protected by Intel MPK.

[0079] Embodiment 2

[0080] Based on the same inventive concept, this embodiment provides an apparatus for identifying and protecting function pointers and their data dependencies. Please refer to Figure 4 , the apparatus includes:

[0081] A function pointer identification module 201, configured to perform type-based and pointer-based analysis on a given program to identify memory objects that belong to function pointers or contain at least one function pointer;

[0082] The inter-procedural data flow graph construction module 202 is used to concatenate the definition information and usage information of each function to construct an inter-procedural data flow graph;

[0083] The sensitive instruction recognition module 203 is used to take the identified memory objects belonging to or containing function pointers as taint sources, and take all indirect function call points as convergence points, perform a depth-first search in the constructed inter-procedural data flow graph to implement forward taint propagation. The obtained path from the taint source to the convergence point represents a possible calculation process of the function pointer, and the instructions on the path are used as sensitive instructions participating in the calculation of the function pointer;

[0084] The data dependence recognition module 204 is used to take the obtained sensitive instructions as taint sources, take the identified memory objects belonging to or containing function pointers as convergence points, perform a depth-first search in the constructed inter-procedural data flow graph to implement backward taint propagation. The obtained path from the taint source to the convergence point, and the memory objects on the path are used as the data on which the function pointers in the sensitive instructions depend;

[0085] The memory allocation module 205 is used to allocate all the identified function pointers and their dependent data to the memory protected by the hardware;

[0086] The protection module 206 is used to protect the memory protected by the hardware using Intel MPK, and use callgate to switch privileges to allow access to the instructions that would originally write function pointers and their dependent data in the program.

[0087] Since the device introduced in the second embodiment of the present invention is the device adopted for the method of identifying and protecting function pointers and their data dependencies in the first embodiment of the present invention, based on the method introduced in the first embodiment of the present invention, those skilled in the art can understand the specific structure and variations of the device, so it will not be elaborated here. Any device adopted in the method of the first embodiment of the present invention belongs to the scope to be protected by the present invention.

[0088] Embodiment Three

[0089] Based on the same inventive concept, please refer to Figure 5 , the present invention also provides a computer-readable storage medium 300, on which a computer program 311 is stored, and when the program is executed, it implements the method described in Embodiment One.

[0090] Since the computer-readable storage medium introduced in the third embodiment of the present invention is the computer-readable storage medium used in the method for identifying and protecting function pointers and their data dependencies in the first embodiment of the present invention, based on the method introduced in the first embodiment of the present invention, those skilled in the art can understand the specific structure and variations of the computer-readable storage medium, so it will not be elaborated herein. Any computer-readable storage medium used in the method of the first embodiment of the present invention falls within the scope of protection of the present invention.

[0091] Embodiment Four

[0092] Based on the same inventive concept, please refer to Figure 6 , this application also provides a computer device, including a memory 401, a processor 402, and a computer program 403 stored in the memory and executable on the processor. When the processor executes the above program, it implements the method in the first embodiment.

[0093] Since the computer device introduced in the fourth embodiment of the present invention is the computer device used in the method for identifying and protecting function pointers and their data dependencies in the first embodiment of the present invention, based on the method introduced in the first embodiment of the present invention, those skilled in the art can understand the specific structure and variations of the computer device, so it will not be elaborated herein. Any computer device used in the method of the first embodiment of the present invention falls within the scope of protection of the present invention.

[0094] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, a system, or a computer program product. Therefore, the present invention can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memories, CD-ROMs, optical memories, etc.) containing computer-usable program code.

[0095] The present invention is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the embodiments of the present invention. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, as well as the combination of flows and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate means for implementing the specified functions in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0096] Although the preferred embodiments of the present invention have been described, additional changes and modifications can be made to these embodiments by those skilled in the art once they learn the basic inventive concept. Therefore, the appended claims are intended to be construed to include the preferred embodiments as well as all changes and modifications that fall within the scope of the present invention.

[0097] Obviously, those skilled in the art can make various changes and modifications to the embodiments of the present invention without departing from the spirit and scope of the embodiments of the present invention. Thus, if these modifications and variations of the embodiments of the present invention fall within the scope of the claims of the present invention and their equivalent technologies, the present invention is also intended to include these changes and modifications.

Claims

1. A method for identifying and protecting function pointers and their data dependencies, characterized in that Including: S1: Perform type-based and pointer-based analysis on a given program to identify memory objects that belong to function pointers or contain at least one function pointer; S2: Concatenate the definition information and usage information of each function to construct an inter-procedural data flow graph; S3: Use the identified memory objects that belong to or contain function pointers as taint sources, and all indirect function call points as sinks. Perform a depth-first search in the constructed inter-procedural data flow graph to implement forward taint propagation. The paths from the taint sources to the sinks represent possible calculation flows of function pointers, and the instructions on the paths are regarded as sensitive instructions involved in the function pointer calculation; S4: Use the obtained sensitive instructions as taint sources, and the identified memory objects that belong to or contain function pointers as sinks. Perform a depth-first search in the constructed inter-procedural data flow graph to implement backward taint propagation. The paths from the taint sources to the sinks are obtained, and the memory objects on the paths are regarded as the data on which the function pointers in the sensitive instructions depend; S5: Allocate all identified function pointers and the data they depend on to memory protected by hardware; S6: Protect the memory protected by hardware using Intel MPK, and use call gate to switch privileges to allow access to the instructions that would originally write function pointers and the data they depend on in the program.

2. The method for identifying and protecting a function pointer and its data dependencies according to claim 1, wherein Step S1 includes: Traverse the types in the given program in sequence. If a type is a function pointer type, it is a sensitive type. If a type is a composite type that contains one or more sensitive types, recursively judge all elements in the composite type. If one element is a sensitive type, then this type is a sensitive type. After identifying all sensitive types, traverse all variables in the given program again. If the type of a variable is a sensitive type, then this variable is a sensitive variable; Perform analysis using a pointer-based analysis method. If there is a function in the target set of a pointer, regard this pointer as a function pointer and add it to the set of sensitive variables. At the same time, add the variables contained in the pointer to the set of sensitive variables.

3. The method for identifying and protecting the function pointer and its data dependencies as claimed in claim 1, wherein During the forward taint propagation in S3, start from the memory object containing the function pointer and end at the indirect function call point. After the forward taint propagation ends, all taint paths from the taint sources to the indirect call points are determined. Each taint path consists of a set of taint instructions, which are used to describe the life cycle of a function pointer from creation to invocation.

4. The method for identifying and protecting a function pointer and its data dependencies according to claim 1, characterized in that, In the backward taint propagation of S4, start from the taint instructions identified in step S2 and end the propagation when encountering a memory object. After the backward taint propagation ends, all taint paths from the taint sources to the memory objects are determined, and the memory objects on the taint paths are regarded as the data on which the function pointers depend.

5. The method for identifying and protecting a function pointer and its data dependencies according to claim 1, characterized in that Step S5 includes: If the function pointer and the data it depends on are local variables, allocate a corresponding stack frame for the function in the separate stack; If the function pointer and the data it depends on are dynamically allocated variables, replace the original functions with the memory application and release functions of the separate heap. If the function pointer and the data it depends on are static variables in the BBS segment or the DATA segment, create a new segment and a corresponding global variable in the pass, and transfer the static variable to the global variable.

6. An apparatus for identifying and protecting a function pointer and its data dependencies, characterized in that, Including: A function pointer recognition module, which is used to perform type-based and pointer-based analysis on a given program to identify memory objects that belong to function pointers or contain at least one function pointer; An inter-procedural data flow graph construction module, which is used to concatenate the definition information and usage information of each function to construct an inter-procedural data flow graph; A sensitive instruction recognition module, which uses the identified memory objects that belong to or contain function pointers as taint sources, and all indirect function call points as sinks, performs a depth-first search in the constructed inter-procedural data flow graph to implement forward taint propagation, and the obtained path from the taint source to the sink represents a possible calculation process of the function pointer. The instructions on the path are used as sensitive instructions participating in the function pointer calculation; A data dependency recognition module, which uses the obtained sensitive instructions as taint sources, and the identified memory objects that belong to or contain function pointers as sinks, performs a depth-first search in the constructed inter-procedural data flow graph to implement backward taint propagation, and the obtained path from the taint source to the sink. The memory objects on the path are used as the data on which the function pointers in the sensitive instructions depend; A memory allocation module, which is used to allocate all the identified function pointers and the data they depend on to the memory protected by hardware; A protection module, which is used to protect the memory protected by hardware using Intel MPK, and uses call gate to switch privileges to allow access to the instructions in the program that would originally write to the function pointers and the data they depend on.

7. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed, the method described in any one of claims 1 to 5 is implemented.

8. A computer device, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, When the processor executes the program, the method described in any one of claims 1 to 5 is implemented.

Citation Information

Patent Citations

  • System and method for data propagation tracking of application system

    CN111966718A

  • Encoded pointer based data encryption

    US20210117342A1