A method and system for detecting password constants in binary files

By establishing password constant matching rules in binary files, combining static semantic analysis and dynamic simulation execution, the problem of missing and false positives of password constants in binary files in the prior art is solved, and more efficient password constant recognition is achieved.

CN115544490BActive Publication Date: 2025-07-08SHANDONG UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211200715.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-09-29
Publication Date
2025-07-08
Estimated Expiration
2042-09-29

AI Technical Summary

Technical Problem

The prior art has problems with omissions and false positives when detecting password constants in binary files, especially for short constants and uninitialized array constants, which are difficult to accurately identify.

Method used

By establishing password constant matching rules, extracting the bytecode of the binary file and decompiling it, combining static semantic analysis and dynamic simulation execution, the compiler split and uninitialized constants are restored, and the control flow diagram and data flow diagram are used to locate constant initialization code blocks to identify the password algorithm.

Benefits of technology

The false alarm rate and missed alarm rate of detection are reduced, the detection range of the cryptographic algorithm is expanded, and the detection effect is improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115544490B_ABST
    Figure CN115544490B_ABST
Patent Text Reader

Abstract

The present invention provides a method and system for detecting password constants in binary files, including: establishing password constant matching rules; extracting bytecodes of binary files to obtain standard constants directly existing in binary files and directly recognizable; decompiling binary files and restoring constants split by the compiler through parsing assembly instructions; further analyzing functions in binary files, locating code blocks for constant initialization by analyzing the control flow graph and data flow graph of functions, and then restoring uninitialized constants by simulating the execution of target codes; summarizing standard constants, constants split by the compiler, and uninitialized constants, and identifying password algorithms by matching with the established password constant matching rules.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of cryptographic constant detection, and particularly relates to a method and a system for detecting cryptographic constants in a binary file. Background Art

[0002] The statements in this part merely provide background technical information related to the present invention and do not necessarily constitute prior art.

[0003] Currently, the method for detecting cryptographic constants in a binary file is to obtain the bytecode of the target binary file and directly perform matching and recognition of cryptographic constants in the bytecode through regular expressions and other methods. However, this method has serious problems of missed reports and false reports in actual applications. The specific problems are as follows:

[0004] 1. In the implementation process of cryptographic algorithms, some short constants are directly defined as basic data types such as integers in the source code. Therefore, during the compilation process, they may be affected by the compiler, which brings difficulties to the extraction and recognition process of constants. These constants are often not stored in the data segment of the binary file like an array after compilation, but are directly embedded in the instruction as an immediate number, mixed with assembly instructions, and loaded directly into register R1 for use in a form similar to "MOV R1,\#0x01234567".

[0005] However, on the one hand, certain instruction sets have restrictions on the length of instructions. For example, in a 32-bit instruction set, the maximum instruction length including the opcode is 32 bits, which cannot accommodate a 32-bit or even longer immediate number. Therefore, a 32-bit short constant can only be written into the lower 16 bits and the upper 16 bits of the register step by step in the form of "MOVWR1,\#0x4567; MOVT R1,\#0x0123", and a 64-bit short constant even needs to be stored using two registers together.

[0006] On the other hand, considering reasons such as instruction formats, within each instruction of instruction sets such as ARMv7, the immediate numbers are not necessarily stored continuously. Although the constant can function normally during runtime, in the static binary file, the complete constant is split into multiple parts and scattered into different instructions, and its features become incomplete. Therefore, it is necessary to first recover the constants scattered in different instructions before matching.

[0007] 2. Some complex array constants have a fixed generation algorithm. Therefore, when writing code, developers may not directly write password constants in the source code. Instead, they preset the algorithm and perform constant initialization operations during program execution. Writing code in this way is mainly to avoid defining overly large arrays in the source code, making the code concise and reducing the size of the generated binary file to a certain extent. These constants either do not have a fixed address allocated before a specific program runs, or have an address but no data initialization. Even if the corresponding address is found through decompilation tools during static analysis, the corresponding constants cannot be obtained and need to be restored first for identification. Summary of the Invention

[0008] To overcome the deficiencies of the above-mentioned prior art, the present invention provides a method for detecting password constants in binary files to identify the password algorithms therein.

[0009] To achieve the above object, one or more embodiments of the present invention provide the following technical solutions:

[0010] In a first aspect, a method for detecting password constants in binary files is disclosed, including:

[0011] Establishing password constant matching rules;

[0012] Extracting the bytecode of the binary file to obtain standard constants that directly exist in the binary file and can be directly recognized;

[0013] Decompiling the binary file and restoring the constants split by the compiler through parsing the assembly instructions;

[0014] Further analyzing the functions in the binary file, locating the code blocks for constant initialization by analyzing the control flow graph and data flow graph of the functions, and then restoring the uninitialized constants by simulating the execution of the target code;

[0015] Aggregating the standard constants, compiler-split constants, and uninitialized constants, and identifying the password algorithm by matching with the established password constant matching rules.

[0016] As a further technical solution, the constants in the password algorithm are divided into three types: short constants, long constants, and array constants, and their existence forms in the binary file are divided into three categories: standard constants, compiler-split constants, and uninitialized constants;

[0017] Among them, the compiler-split constants mainly include some short constants and long constants; and the uninitialized constants mainly include more complex array constants.

[0018] As a further technical solution, decompile the binary file, and perform cross-architecture semantic analysis by decompiling and converting the assembly code into intermediate language;

[0019] During the semantic analysis process, by parsing the register and memory read / write instructions, splice and extract the constants written to the same register and adjacent memory units;

[0020] After that, perform grouped recognition of constants in the same algorithm according to the logical relationship between instructions and the continuity of memory addresses.

[0021] As a further technical solution, further analyze the functions in the binary file. By parsing the control flow graph and data flow graph of the function, locate the independent algorithms for calculating constants and extract the relevant code paths.

[0022] As a further technical solution, splice and extract the constants written to the same register and adjacent memory units. The constant extraction process is divided into basic block extraction, semantic analysis and instruction screening, register restoration, memory unit restoration, and memory reorganization and constant extraction.

[0023] As a further technical solution, extraction of uninitialized constants:

[0024] First, filter the basic blocks in the function through data flow and control flow, exclude the code unrelated to constant generation, and then perform simulation execution through the extracted code paths to achieve the extraction of uninitialized constants.

[0025] As a further technical solution, the acquisition of the code path is: control flow graph screening, data flow graph screening, and code path extraction.

[0026] In the second aspect, a system for detecting password constants in a binary file is disclosed, including:

[0027] A matching rule establishment module, configured to: establish password constant matching rules;

[0028] A standard constant extraction module, configured to: extract the bytecode of the binary file to obtain the standard constants directly existing in the binary file and recognizable directly;

[0029] A compiler-split constant extraction module, configured to: decompile the binary file and restore the constants split by the compiler through parsing the assembly instructions;

[0030] An uninitialized constant extraction module, configured to: further analyze the functions in the binary file, locate the code blocks for constant initialization by analyzing the control flow graph and data flow graph of the function, and then restore the uninitialized constants through simulation execution of the target code;

[0031] The constant rule matching module is configured to summarize standard constants, constants split by the compiler, and uninitialized constants, and identify the cryptographic algorithm by matching with the established cryptographic constant matching rules.

[0032] The above one or more technical solutions have the following beneficial effects:

[0033] Compared with traditional constant detection tools, the present invention classifies cryptographic constants with a finer granularity, adds static semantic analysis and dynamic simulation execution methods, extracts cryptographic constants in a targeted manner, and greatly reduces the false positive rate and false negative rate of detection.

[0034] Traditional constant detection methods are prone to false positives when detecting short constants, so some relatively short constants cannot be used as judgment bases; while this method can eliminate false positives on short constants by adding semantic analysis, enabling many originally unusable constants to be used as judgment bases, expanding the detection range of cryptographic algorithms.

[0035] Compared with traditional static and dynamic analysis methods, this method combines dynamic and static methods, uses the method of selective dynamic execution, overcomes the problems of difficult full-file execution and low code coverage rate of dynamic methods and the problem of difficult handling of complex operation logic of static methods, and greatly improves the detection effect of cryptographic algorithms.

[0036] Advantages of additional aspects of the present invention will be partially given in the following description, partially become apparent from the following description, or be understood through the practice of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS

[0037] The specification drawings constituting a part of the present invention are used to provide a further understanding of the present invention. The schematic embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute an improper limitation to the present invention.

[0038] Figure 1 Schematic diagram of the overall concept of the present invention;

[0039] Figure 2 Recovery process diagram of constants split by the compiler;

[0040] Figure 3 Recovery process diagram of uninitialized constants. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0041] It should be noted that the following detailed description is exemplary and is intended to provide further illustration of the present invention. Unless otherwise specified, all technical and scientific terms used herein have the same meaning as commonly understood by those of ordinary skill in the technical field to which the present invention belongs.

[0042] It should be noted that the terms used herein are for describing specific embodiments only and are not intended to be limiting of exemplary embodiments according to the present invention.

[0043] In the absence of conflict, the embodiments of the present invention and the features of the embodiments may be combined with each other.

[0044] Embodiment 1

[0045] like Figure 1 As shown, this embodiment discloses a method for detecting cryptographic constants in a binary file, comprising the following steps:

[0046] (1) Establishment of a cryptographic constant matching rule library: By analyzing the official documents of standard cryptographic algorithms and common open source cryptographic libraries, we classified the constants after collecting them and established different matching rules for each constant to facilitate subsequent classification detection.

[0047] (2) Extraction of standard constants: Extract the bytecode of the binary file to obtain standard constants that exist directly in the binary file and can be directly identified;

[0048] (3) Extraction of constants split by the compiler: Decompile the binary file and restore the constants split by the compiler by parsing the assembly instructions;

[0049] (4) Extraction of uninitialized constants: Further analyze the functions in the binary file, locate the code block for constant initialization by analyzing the control flow graph and data flow graph of the function, and then restore the uninitialized constants by simulating the execution of the target code.

[0050] (5) Cryptographic algorithm identification: The constants extracted from steps (2), (3), and (4) are aggregated together and matched with the constant matching rules established in (1) to identify the cryptographic algorithm.

[0051] In step (1), the constants in the constant rule library are divided into three types: short constants, long constants and array constants. Subsequently, based on further analysis of the characteristics of each constant, the existence of cryptographic constants in binary files is divided into three categories: standard constants, compiler-split constants and uninitialized constants. The compiler-split constants mainly include some short constants and long constants; while the uninitialized constants mainly include more complex array constants. On the basis of completing the above classification, this method fully considers the big-endian and small-endian byte order and the redundant data introduced by different data structures, and formulates a complete matching rule for the subsequent matching and identification of cryptographic constants.

[0052] Regarding short constants: The password rules of the present invention classify constants with a single size less than 8 bytes in a cryptographic algorithm as short constants. Although sometimes multiple constants are combined to complete the same function, they are generally still stored as several independent integers during code writing and arrays are not used. For example, in MD5, an initial hash value of 16 consecutive bytes is required to initialize the algorithm result buffer. In the password standard, its little-endian byte order representation is "01 23 45 67 89ab cd ef fe dc ba 98 76 54 32 10", but developers often store it using four independent integers: 0x67452301, 0xefcdab89, 0x98badcfe, 0x10325476.

[0053] Therefore, when creating the rules, these constants are also regarded as a group of short constants. During the detection process, only when all the constants within a group of short constants are detected can it be considered a match to the cryptographic algorithm. It should be noted that if the length of the constant itself is greater than 1 byte, the byte order problem of big-endian and little-endian needs to be considered during matching.

[0054] Regarding long constants: Some constants with a size greater than 8 bytes are also used in cryptographic algorithms. These constants often represent fixed values or have specific meanings and are not allowed to be changed or split in the slightest during use, but the entire constant is used as a whole. For example, the parameters of the curve required in the elliptic curve algorithm, and the fields used to identify the algorithm type in some protocols or coding standards. They are directly defined in the form of consecutive byte codes in the rules: "0x3020300c06082a864886f70d020205000410".

[0055] Regarding array constants: Some array constants are also used in cryptographic algorithms. In addition to considering the byte order problem for constants with array elements greater than 1 byte, new problems also exist during the recognition of byte arrays. Some developers use int arrays to store byte arrays, which can achieve the same effect but introduces redundant data. Therefore, regular expressions need to be added during matching to be compatible with the redundant data between valid data to improve the matching effect: "0x63,[1-3],0x7c,[1-3],0x77,[1-3],0x7b……".

[0056] In step (2), since standard constants are directly hard-coded in the binary file, the present invention directly reads the file in the form of byte codes as the matching target without making any modifications to the binary file.

[0057] The specific method is as follows: directly obtain the bytecode of the target binary file in binary form through the file reading function read in Python, and use it as the target recognized by the standard constant.

[0058] In step (3), the present invention realizes cross-architecture semantic analysis by decompiling and converting the assembly code into an intermediate language. During the static semantic analysis process, first, the constants in the registers are restored, then the constants in the memory cells are restored, and finally, the memory reconstruction and the extraction of the constants split by the compiler are realized through the clustering analysis of the memory addresses. Specifically, in this embodiment, by parsing the register and memory read / write instructions such as "MOVW, MOVT, STORE, LOAD", the constants written to the same register and adjacent memory cells are spliced and extracted. Then, in this embodiment, the grouped recognition of the constants in the same algorithm is realized according to the logical relationship between the instructions and the continuity of the memory addresses.

[0059] After decompiling the binary file, it is promoted to the intermediate representation of the intermediate language of Binaryninja to be compatible with the instruction sets of different architectures, realizing cross-architecture analysis.

[0060] Specifically: First, the binary file is decompiled and converted into the middle layer representation (MLIL) of the Binaryninja intermediate language. This language can translate assembly languages such as "mov r5,r0" into forms such as "r5 = arg1". It not only has the cross-architecture characteristics of intermediate languages, but also can better represent the role of variables and the dependencies between variables compared with intermediate languages in the form of "r5 = r0", has higher readability, and can greatly facilitate the analysis work.

[0061] After decompilation, the constant extraction process is divided into several stages: basic block extraction, semantic analysis and instruction screening, register restoration, memory cell restoration, and memory reorganization and constant extraction, as Figure 2 shown:

[0062] Basic block extraction: During the analysis process, the basic block is used as the basic unit of analysis. Although the function is the basic unit of the function in the program, different algorithms may be used within the same function to achieve the same purpose. If it is considered that each function only contains one cryptographic algorithm, it is easy to cause false negatives. The analysis at the basic block granularity can include the entire set of short and long quantities without causing false negatives.

[0063] Semantic analysis and instruction screening: According to the semantics of the instructions, the instructions in the basic block are screened, and the instructions (SET_VAR, STORE_VAR) that write data to the registers and memory are screened out, and only this part of the instructions is further analyzed.

[0064] Register restoration: When restoring constants, the system first restores the constants in the registers. By parsing the "SET_VAR" instruction, the immediate values written to each register are obtained. The immediate values written to different positions in the same register are merged, and all the immediate values are recorded as short constants.

[0065] Memory cell restoration: The data written by each 'STORE_VAR' instruction is regarded as a memory cell, and the data of each memory cell is restored according to the semantics of the relevant instructions.

[0066] The source data of the "STORE_VAR" instruction can be 'VAR' and 'SPLIT_VAR', where "VAR" is a direct variable, and "SPLIT_VAR" is a variable formed by splicing multiple variables. During the parsing process, the system first traces the variables in the source data, obtains the values corresponding to each variable, and then splices and restores the source data according to the semantics of the instruction to restore the constant written by the instruction to the memory cell.

[0067] Memory reconstruction and constant extraction: After obtaining many short constants through the above analysis, the system identifies the constants in all registers as a group of short constants. For the constants loaded into memory, the constants are clustered according to the memory addresses where the constants are located, and the constants stored in consecutive memory addresses are preferentially regarded as a group of constants.

[0068] In step (4), to solve the problems of difficult full-file execution and low code coverage in the dynamic method, the code of the entire file is first statically analyzed and screened to locate the code related to constant calculation, and then the target code is simulated and executed to calculate and extract the relevant constants.

[0069] During the process of code screening, the characteristics of the constant generation algorithm are analyzed, and the control flow graph and data flow graph of the code are used for analysis to locate the loop structure that does not depend on external data as the target code.

[0070] Using unicorn to execute only the extracted code paths greatly improves the analysis efficiency and success rate.

[0071] Specifically, in step (4), the present invention analyzes all functions in the file. By parsing the control flow graph and data flow graph of the functions, the independent algorithms used to calculate constants are located, and the relevant code paths are extracted. The target code features for extraction by the present invention mainly have two:

[0072] To calculate complex constants such as arrays, complex code logics such as loops are required, which will be reflected in the control flow graph of the function.

[0073] To ensure that the calculation result is a constant and no external variables are used in the process, this will be reflected in the data flow graph of the function.

[0074] Finally, the present invention realizes the calculation and extraction of uninitialized constants by simulating the execution of the extracted code paths.

[0075] In this embodiment, first, the basic blocks in the function are filtered through data flow and control flow to exclude the code unrelated to constant generation, and then the uninitialized constants are extracted by simulating the execution through the extracted paths. The code path extraction process includes three parts: control flow graph screening, data flow graph screening, and code path extraction:

[0076] Control flow graph screening: Since the calculation of an array is a complex process and often involves loop logic, the function is first screened by detecting whether there is a loop structure in the function. The loop detection of this system is carried out on the control flow graph. After obtaining the control flow graph of the function, starting from the entry point of the function, the basic blocks in the control flow graph are traversed through depth-first search. While traversing, record the current path that has been walked. If the newly discovered basic block is already in the current path, then it is determined that there is a loop in the function, and the function is marked as the target function.

[0077] Data flow graph screening: In addition to the calculation process of constants, the target function often contains code for many other functions. These codes not only reduce the execution efficiency during the simulation execution but also cause many data dependency errors, resulting in execution failure. Fortunately, the initialization process of constants not only has relatively independent calculation logic. Since the values generated each time the program runs are constants, the data on which this part of the code logic depends is also often constants. All code blocks that generate constants can be accurately located through this feature. The screening method of this system is as follows: Starting from the parameters, perform data flow analysis on the function. That is, for a parameter, find and mark all instructions and variables affected by the parameter, and then starting from the marked instructions and variables, iterate continuously until no new marks are generated. Finally, this system excludes all the basic blocks with marks and takes the remaining basic blocks as the set of target basic blocks.

[0078] Code path extraction: This system first traverses the basic blocks in the set, performs topological sorting according to the predecessor and successor relationships of the basic blocks in the control flow graph, constructs the sequence relationship between the basic blocks, and takes the start address of the frontmost basic block and the end address of the last basic block as the start and end points of the path respectively to obtain the code path for calculating the constants.

[0079] After extracting the code path, the system uses Unicorn to simulate the execution of the target, records the addresses of the memory units affected during the execution, and extracts the data in the corresponding memory units after the execution ends as the extracted constants.

[0080] In step (5), the present invention realizes the identification of password constants among the constants extracted in steps (2), (3), and (4) by matching and comparison according to the rules established in (1). During the identification process, the system uses the maximum matching strategy to minimize false positives.

[0081] Specifically, the yara matching tool and the direct comparison method are used to match the constants extracted by the above three constant extraction modules with the password constant rule library to realize the identification of the password algorithm. During the identification process, for different password algorithms with overlapping constants, the system uses the maximum matching strategy to exclude false positives to the greatest extent. For example, the initial hash value in MD5 is "0x01234567,0x89abcdef,0xfedcba98,0x76543210"; while the initial hash value of SHA1 is "0x01234567,0x89abcdef,0xfedcba98,0x76543210,0xf0e1d2c3", so the constants of MD5 will also be recognized in the function of SHA1. The maximum matching strategy of the system will only recognize it as the SHA1 algorithm to avoid the influence caused by overlapping constants.

[0082] The method in this embodiment classifies constants into three types: standard constants, constants split by the compiler, and uninitialized constants, and designs different constant recovery and extraction methods for different constants, thereby realizing the extraction of password constants and the identification of password algorithms.

[0083] In this embodiment, by analyzing the official documents of standard cryptographic algorithms and common open-source cryptographic libraries, the constants are classified based on the collected constants, and different matching rules are established respectively for subsequent classification detection; the bytecode of the binary file is extracted to obtain the standard constants directly existing in the binary file and directly recognizable; the binary file is decompiled and converted into an intermediate language, and the constants split by the compiler are restored by parsing the semantics; the functions in the binary file are further analyzed, and the code block for constant initialization is located by analyzing the control flow graph and data flow graph of the function, and then the uninitialized constants are restored by simulating the execution of the target code; finally, the recognition of the cryptographic algorithm is achieved by matching the extracted constants with the constant rules. Compared with traditional constant detection tools, the present invention classifies cryptographic constants with a finer granularity, and adds static semantic analysis and dynamic simulation execution methods to extract cryptographic constants specifically, greatly reducing the false positive rate and false negative rate of detection.

[0084] Embodiment 2

[0085] The purpose of this embodiment is to provide a computer device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, the steps of the above method are implemented.

[0086] Embodiment 3

[0087] The purpose of this embodiment is to provide a computer-readable storage medium.

[0088] A computer-readable storage medium, on which a computer program is stored, and when the program is executed by a processor, the steps of the above method are executed.

[0089] Embodiment 4

[0090] The purpose of this embodiment is to provide a system for detecting cryptographic constants in a binary file, including:

[0091] A matching rule establishment module, configured to: establish a cryptographic constant matching rule library;

[0092] A standard constant extraction module, configured to: extract the bytecode of the binary file, extract the bytecode containing the corresponding constant, to obtain the standard constants directly existing in the binary file and directly recognizable; extract the bytecode containing the corresponding constant as one of the subsequent recognition targets;

[0093] A compiler-split constant extraction module, configured to: decompile the binary file and parse the semantics, splice, restore, and extract the split constants, and implement the restoration of the constants split by the compiler by parsing the assembly instructions;

[0094] An uninitialized constant extraction module is configured to: further analyze the functions in the binary file, locate the code blocks for constant initialization by analyzing the control flow graph and data flow graph of the functions, and then restore the uninitialized constants by simulating the execution of the target code;

[0095] A constant rule matching module is configured to: summarize the standard constants, the constants split by the compiler, and the uninitialized constants, and identify the cryptographic algorithms by matching with the established cryptographic constant matching rules.

[0096] When establishing the cryptographic constant matching rule library, the cryptographic constants are finely divided according to the uses of the cryptographic constants and the data structures adopted, which can better suit the constant matching process and improve the accuracy of matching.

[0097] In the devices of the above second, third, and fourth embodiments, the steps involved correspond to those of the first method embodiment. For the specific implementation manners, reference may be made to the relevant description parts of the first embodiment. The term "computer-readable storage medium" should be understood to include a single medium or multiple media containing one or more instruction sets; it should also be understood to include any medium that can store, encode, or carry an instruction set for execution by a processor and enable the processor to execute any method in the present invention.

[0098] Those skilled in the art should understand that the above modules or steps of the present invention can be implemented by a general computer device. Optionally, they can be implemented by program codes executable by a computing device, so that they can be stored in a storage device and executed by the computing device, or they can be separately fabricated into individual integrated circuit modules, or multiple modules or steps among them can be fabricated into a single integrated circuit module to implement. The present invention is not limited to any specific combination of hardware and software.

[0099] Although the specific implementation manners of the present invention have been described above in conjunction with the drawings, it is not a limitation to the protection scope of the present invention. Those skilled in the art should understand that based on the technical solutions of the present invention, various modifications or deformations that can be made without creative efforts by those skilled in the art are still within the protection scope of the present invention.

Claims

1. A method for detecting password constants in a binary file, characterized by comprising: Establishing a password constant matching rule; Extracting the bytecode of the binary file to obtain standard constants that directly exist in the binary file and can be directly recognized; Decompiling the binary file and restoring the constants split by the compiler therein through the analysis of assembly instructions; Further analyzing the functions in the binary file, locating the code blocks for constant initialization by analyzing the control flow graph and data flow graph of the functions, and then restoring the uninitialized constants through the simulated execution of the target code; Summarizing the standard constants, the constants split by the compiler, and the uninitialized constants, and realizing the identification of the password algorithm by matching with the established password constant matching rule; 2. The method for detecting password constants in a binary file according to claim 1, characterized in that, Dividing the constants in the password algorithm into three types: short constants, long constants, and array constants, and classifying their existence forms in the binary file into three categories: standard constants, constants split by the compiler, and uninitialized constants; Among them, the constants split by the compiler mainly include some short constants and long constants; while the uninitialized constants mainly include more complex array constants; 3. The method for detecting password constants in a binary file according to claim 1, characterized in that, Decompiling the binary file, and performing cross-architecture semantic analysis by decompiling and converting the assembly code into intermediate language; During the semantic analysis process, by analyzing the register and memory read / write instructions, splicing and extracting the constants written to the same register and adjacent memory units; After that, group identification of the constants in the same algorithm is performed according to the logical relationship between instructions and the continuity of memory addresses; 4. The method for detecting password constants in a binary file according to claim 1, characterized in that, Further analyzing the functions in the binary file, locating the independent algorithms for calculating constants by parsing the control flow graph and data flow graph of the functions, and extracting the relevant code paths; 5. The method for detecting password constants in a binary file according to claim 1, characterized in that, Splicing and extracting the constants written to the same register and adjacent memory units, and the constant extraction process is divided into basic block extraction, semantic analysis and instruction screening, register restoration, memory unit restoration, memory reorganization, and constant extraction; 6. The method for detecting password constants in a binary file according to claim 1, characterized in that, Extraction of uninitialized constants: First, filter the basic blocks in the function through data flow and control flow, exclude the code irrelevant to constant generation, and then perform simulated execution through the extracted code paths to realize the extraction of uninitialized constants; 7. The method for detecting password constants in a binary file according to claim 1, characterized in that, The acquisition of the code path is: control flow graph screening, data flow graph screening, and code path extraction; 8. A system for detecting password constants in binary files, characterized in that, Including: A matching rule establishment module, configured to: establish a password constant matching rule; A standard constant extraction module, configured to: extract the bytecode of the binary file to obtain standard constants that directly exist in the binary file and can be directly recognized; A compiler-split constant extraction module, configured to: decompile the binary file and restore the constants split by the compiler therein through the analysis of assembly instructions; An uninitialized constant extraction module, configured to: further analyze the functions in the binary file, locate the code blocks for constant initialization by analyzing the control flow graph and data flow graph of the functions, and then restore the uninitialized constants through the simulated execution of the target code; The constant rule matching module is configured to: summarize standard constants, constants split by the compiler, and uninitialized constants, and identify the cryptographic algorithm by matching with the established cryptographic constant matching rules.

9. A computer device, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the steps of the method according to any one of claims 1-7 above.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by the processor, it executes the steps of the method according to any one of claims 1-7 above.

Citation Information

Patent Citations

  • Hard coded data detection method and device, electronic equipment and medium

    CN111399848A

  • National cryptographic algorithm detection method in Android application

    CN113420310A