Device and method for identifying encryption algorithms based on generating data flow graphs based on symbolic execution

Through the encryption algorithm identification method based on symbol execution, an architecture-independent data flow diagram is generated and the Ulman sub-graph isomorphic recognition encryption algorithm is solved, and the problems of compiler in the prior art are solved, and the accurate identification and positioning of SM3 and SM4 encryption algorithms are realized.

CN115659376BActive Publication Date: 2025-05-16XIDIAN UNIV
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202211403662.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-10
Publication Date
2025-05-16
Estimated Expiration
2042-11-10

AI Technical Summary

Technical Problem

The prior art has problems such as compiler incompatibility, source code incompatibility and one-to-many recognition results in encryption algorithm recognition, and it is difficult to implement.

Method used

The encryption algorithm recognition method is adopted to generate data flow graphs based on symbol execution. Through the binary abstract module, the signature construction module, the symbol execution module and the encryption algorithm recognition module, the architecture-independent data flow graph isomorphic and the encryption algorithm isomorphic recognition encryption algorithm is generated through the Ulman sub-graph.

Benefits of technology

It realizes encryption algorithm recognition of binary files under different instruction set architectures and different compilers, solves the problems of compiler inconsistency and source code inconsistency, accurately recognizes SM3 and SM4 encryption algorithms, and locates their locations in the binary files, simplifying the implementation process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115659376B_ABST
    Figure CN115659376B_ABST
Patent Text Reader

Abstract

A device and method for identifying an encryption algorithm based on symbolic execution to generate a data flow graph, wherein a binary abstraction module uses a disassembly tool and a processor model to convert binary instructions under an instruction set architecture into data flow graph nodes; a signature construction module uses a signature language specification and a signature language conversion method to convert the signature language corresponding to the encryption algorithm into a corresponding data flow graph; a symbolic execution module uses symbolic execution to construct a binary data flow graph; an encryption algorithm identification module identifies the encryption algorithm in binary through Ullmann subgraph isomorphism and outputs a binary data flow graph. The present invention solves the problem that the prior art does not have compiler and source code independence and one-to-many identification results. While improving the accuracy of identifying encryption algorithms, it can perform encryption algorithm identification and analysis on executable files or program function libraries containing encryption algorithms without source code.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of physical technology, and further relates to an encryption algorithm identification device and method based on symbolic execution to generate a data flow graph in the field of data processing technology. The present invention can be used in technical fields such as security analysis and software reverse engineering. The encryption algorithm identification analysis is performed on executable files or program function libraries containing encryption algorithms based on symbolic execution of binary file disassembly to generate corresponding data flow graphs. The analysis results can be used to evaluate the security of the software, which can guide software users to take targeted defense measures against encryption primitives with vulnerabilities, and can also guide software providers to take targeted repairs for encryption primitives with vulnerabilities. Background Art

[0002] Encryption algorithm identification involves analyzing whether the encryption primitives used in binary files used in cryptography are used correctly, so as to achieve the purpose of evaluating the security of binary files. In order to evaluate the security of binary files involving cryptography, it is first necessary to accurately identify and locate the encryption primitives in the binary files. However, with the popularization of commercial software, the evaluator is unable to obtain the source code. Therefore, the traditional encryption identification method based on data constants cannot meet the requirements of accurately identifying and locating the encryption primitives of binary programs under the premise of only static binary file analysis technology. The encryption identification method based on deep learning still requires the source code of the actual implementation of the encryption algorithm, which makes it not easy to implement in actual application.

[0003] Suzhou Inspur Intelligent Technology Co., Ltd. disclosed a method and device for identifying encryption algorithms based on identifying ciphertext length in its patent document "A method and device for identifying encryption algorithms in actual attack scenarios" (patent application number CN201911049540.8, application publication number CN111309987A). The method disclosed in the patent application identifies special characters in ciphertext in actual attack or penetration scenarios, identifies the encoding algorithm of the ciphertext for a limited number of times, and then decodes the ciphertext characters with the obtained encoding algorithm, identifies the length of the decoded string, and finally sorts out the ciphertext length rule table, matches the ciphertext string length with the ciphertext length rule table, and selects the matching algorithm to output to the result file. The result file will have one-to-one matching results and one-to-many matching results. The disadvantage of this method is that only the ciphertext length is used as the identification of the encryption algorithm, and other identification bases are not considered in the encryption algorithm identification process, resulting in multiple identification results of one algorithm in the identification result of this method, and the specific type of the encryption algorithm cannot be accurately identified, and only multiple possible results corresponding to the algorithm can be given. This method requires encoding and decoding of ciphertext, which is difficult for users who do not have relevant knowledge. The device disclosed in the patent is composed of a ciphertext encoding recognition module, a ciphertext length recognition module and an encryption algorithm recognition module, which correspond to the functions described in the implementation process of the method. Among them, the ciphertext encoding recognition module is responsible for identifying special characters in the ciphertext and performing a limited number of encoding algorithm recognition on the ciphertext. The ciphertext length recognition module is responsible for decoding the ciphertext characters with the obtained encoding algorithm and identifying the length of the decoded string. The encryption algorithm recognition module is responsible for arranging the ciphertext length rule table, matching the ciphertext string length with the ciphertext length rule table, and selecting the matching algorithm to output to the result file. The result file will have a one-to-one matching result and a one-to-many matching result. The shortcomings of this device are that the implementation of the ciphertext encoding recognition module and the ciphertext length recognition module requires professional knowledge of encoding and decoding, which is relatively difficult to implement; and the results of the encryption algorithm recognition module will have a one-to-many matching result, and the specific type of the encryption algorithm cannot be accurately identified, and only multiple possible results corresponding to the algorithm can be given.

[0004] Northwest University disclosed a method for identifying encryption algorithms based on deep learning graph networks and binary similarity detection in its patent application "A method for identifying encryption algorithms based on deep learning graph networks" (patent application number CN202010200633.2, application publication number CN111460472A). This method obtains information related to the source code of the encryption algorithm by crawling with a crawler tool to build a corresponding basic source code library. The basic source code library is cross-compiled and preprocessed to obtain a binary code library. During the cross-mutation preprocessing process, the method believes that the codes generated by different optimization levels and different compiler types are similar. Then, an encryption algorithm graph is generated based on the statistical and structural features of the binary encryption algorithm, and neural networks and vector comparisons are used to identify the encryption algorithm. The shortcomings of this method are that, in the information collection stage, relevant information of the encryption algorithm implementation source code is still needed, and the encryption algorithm cannot be identified completely independently of the encryption algorithm implementation source code; in the identification process, the method only considers that the codes generated by different optimization levels and different compiler types are similar, and no further processing is performed, resulting in that the method is essentially still limited by the compiler and its corresponding optimization level, and the compiler independence of the method cannot be achieved. Summary of the invention

[0005] The purpose of the present invention is to address the deficiencies in the above-mentioned prior art and to propose an encryption algorithm identification device and method based on symbolic execution to generate a data flow graph, so as to solve the problem that the prior art is not compiler-independent, the problem that the prior art is not source code-independent, the problem of one-to-many recognition results in the prior art, and the problem that the prior art is difficult to implement.

[0006] The specific idea for achieving the purpose of the present invention is that the device of the present invention is composed of a binary abstraction module, a signature construction module, a symbolic execution module, and an encryption algorithm identification module. The binary abstraction module uses a disassembly tool to obtain the disassembly form of each binary instruction under the instruction set architecture, and uses the processor model corresponding to the instruction set architecture to convert the operation code and operand of the relevant data in the disassembly form of each binary instruction into the corresponding graph node in the data flow graph. The signature construction module is used to translate the operation of the relevant data in the encryption algorithm into the corresponding signature language according to the signature language specification, and convert the signature language into a signature data flow graph according to the signature language conversion method. The symbolic execution module is used to form a path set according to the instruction address for all conditional jump instructions in the binary and all instructions located after the conditional jump instructions; judge whether the path corresponding to the selected element from the path set is a copy path, and if so, use the selected The execution path corresponding to the previous element of the element symbolizes the conditional jump instruction corresponding to the selected element, and the execution path corresponding to the selected element symbolizes the instruction corresponding to the selected element after the conditional jump instruction; otherwise, it is judged whether the path corresponding to the selected element is a tracking path or an ignored path; if it is a tracking path, the conditional jump instruction corresponding to the selected element is symbolized, otherwise, the instruction corresponding to the selected element after the conditional jump instruction is symbolized; the symbolic expressions corresponding to all elements are composed into a binary symbolic execution graph, and the binary symbolic execution graph is converted into a binary data flow graph according to the data flow graph conversion method. The encryption algorithm identification module is used to take the signed data flow graph and the binary data flow graph as inputs, and identify the encryption algorithm through the Ullman subgraph isomorphism. Since the device of the present invention has a binary abstract module, the device of the present invention can complete the identification of the encryption algorithm without being affected by the architecture and the compiler, which solves the problem that the prior art does not have compiler independence. Since the device of the present invention only uses binary, the device of the present invention can complete the identification of the encryption algorithm without relying on the source code implementation of the encryption algorithm, which solves the problem that the prior art does not have source code independence. Since the device of the present invention has a symbolic execution module, the device of the present invention can completely cover the code of the binary file, and the encryption algorithm identification process is more comprehensive. Since the device of the present invention has a signature construction module and an encryption algorithm identification module, the device of the present invention pays more attention to the transmission and flow process of data in files and encryption algorithms, and the data itself does not play a decisive factor. Therefore, the device of the present invention can more accurately identify the SM3 and SM4 encryption algorithms and locate their positions in binary files, thereby solving the problem of one-to-many recognition results in the prior art.Since the device of the present invention has a signature construction module, a symbolic execution module and an encryption algorithm identification module, the device of the present invention uses a signature data flow graph and a binary data flow graph subgraph isomorphic to identify the encryption algorithm in the binary, and the signature of the encryption algorithm only needs to be written according to the standard document, without additional professional knowledge. Compared with the invention that requires the use of ciphertext encoding and decoding knowledge, the device of the present invention is simpler and easier to implement, solving the problem that the prior art is difficult to implement. In the method of the present invention, the binary generated under different instruction set architectures and different compilers is disassembled, and the disassembled form of the instructions contained therein is converted into a data flow graph node that is independent of the architecture, and the signature language specification and the signature language conversion method are used to convert the signature into a data flow graph, and the binary data flow graph is generated by symbolic execution, and the Ullman subgraph isomorphism is used to identify the binary implementation of the SM3 and SM4 national secret algorithms in the GmSSL public cryptographic library, and determine whether a specific algorithm appears in a specific binary. If it appears, the position of the algorithm in the binary is located. Since the method of the present invention uses a disassembly tool to obtain the disassembly form of binary instructions for binaries generated under different instruction set architectures and different compilers, and uses the processor model corresponding to the instruction set architecture to convert the opcode and operand of the relevant data in the disassembly form of each binary instruction into the corresponding graph node in the data flow graph, the method of the present invention has architecture independence and compiler independence, which solves the problem that the prior art does not have compiler independence. Since the method of the present invention only uses binary files, the method of the present invention solves the problem that the prior art does not have source code independence. Since the method of the present invention uses symbolic execution, the method of the present invention covers the data flow direction of binary files and encryption algorithms more widely, and the correspondingly generated data flow graph is more accurate. Since the method of the present invention uses a data flow graph as the basis for identification, the importance of the data itself in the method of the present invention is not high, and the transmission and flow process of the overall data plays a decisive factor in the method of the present invention, so the method of the present invention can more accurately identify the SM3 and SM4 encryption algorithms, locate their positions in the binary, and solve the problem of one-to-many identification results in the prior art. Since the method of the present invention adopts the form of signature data flow graph and binary data flow graph subgraph isomorphic to identify the encryption algorithm in binary, and the signature of the encryption algorithm is simple to write and does not require additional professional knowledge, compared with the invention that requires the use of ciphertext encoding and decoding knowledge, the method of the present invention is simpler and easier to implement, which solves the problem that the existing technology is difficult to implement.

[0007] To achieve the above-mentioned purpose, the device of the present invention includes a binary abstraction module, a signature construction module, a symbol execution module, and an encryption algorithm identification module. Among them:

[0008] The binary abstraction module is used to obtain the disassembled form of each binary instruction under the instruction set architecture by using a disassembler tool; and to convert the operation code and operand of the relevant data in the disassembled form of each binary instruction into corresponding graph nodes in the data flow graph by using a processor model corresponding to the instruction set architecture;

[0009] The signature construction module is used to translate the operations on the data in the encryption algorithm into the corresponding signature language according to the signature language specification, and convert the signature language into a signature data flow graph according to the signature language conversion method;

[0010] The symbolic execution module is used to form a path set of all conditional jump instructions and all instructions after the conditional jump instructions in the binary according to the instruction addresses; determine whether the path corresponding to the selected element in the path set is a copy path, if so, use the execution path corresponding to the previous element of the selected element to symbolize the conditional jump instruction corresponding to the selected element, and use the execution path corresponding to the selected element to symbolize the instruction after the conditional jump instruction corresponding to the selected element; otherwise, determine whether the path corresponding to the selected element is a tracking path or an ignored path; if it is a tracking path, symbolize the conditional jump instruction corresponding to the selected element, otherwise, symbolize the instruction after the conditional jump instruction corresponding to the selected element; form a binary symbolic execution graph with the symbolic expressions corresponding to all elements, and convert the binary symbolic execution graph into a binary data flow graph according to the data flow graph conversion method;

[0011] The encryption algorithm identification module is used to take the signed data flow graph and the binary data flow graph as input, identify the encryption algorithm through the Ullmann subgraph isomorphism; determine whether any one of the encryption algorithms is implemented in the binary or both encryption algorithms exist in the binary, and if so, display the part of the data flow graph corresponding to the identified encryption algorithm in red in the binary data flow graph, otherwise, do not perform any operation on the binary data flow graph; and output the binary data flow graph.

[0012] The steps of the identification method of the present invention include the following:

[0013] Step 1: Convert binary instructions under the instruction set architecture into data flow graph nodes that are independent of the architecture:

[0014] The binary abstraction module uses a disassembly tool to obtain the disassembly form of each binary instruction under the instruction set architecture; using the processor model corresponding to the instruction set architecture, the operation code and operand of the relevant data in the disassembly form of each binary instruction are converted into corresponding graph nodes in the data flow graph;

[0015] Step 2: Convert the signature language corresponding to the encryption algorithm into the corresponding data flow graph:

[0016] The signature construction module translates the operations on the data in the encryption algorithm into the corresponding signature language according to the signature language specification, and converts the signature language into a signature data flow graph according to the signature language conversion method;

[0017] Step 3, construct a data flow graph that is independent of the instruction set architecture:

[0018] Step 3.1, the symbolic execution module forms a path set according to the instruction addresses of all conditional jump instructions and all instructions after the conditional jump instructions in the binary;

[0019] Step 3.2, select an unselected element from the path set;

[0020] Step 3.3, determine whether the path corresponding to the selected element is a copy path, if so, execute step 3.4, otherwise, execute step 3.5;

[0021] Step 3.4, symbolize the conditional jump instruction corresponding to the selected element with the execution path corresponding to the previous element of the selected element, symbolize the instruction corresponding to the selected element located after the conditional jump instruction with the execution path corresponding to the selected element, and then execute step 3.6;

[0022] Step 3.5, determine whether the path corresponding to the selected element is a tracking path or an ignored path; if it is a tracking path, symbolize the conditional jump instruction corresponding to the selected element, otherwise, symbolize the instruction corresponding to the selected element and located after the conditional jump instruction;

[0023] Step 3.6, determine whether all elements in the path set have been selected, if so, execute step 3.7, otherwise, execute step 3.2;

[0024] Step 3.7, the symbolic expressions corresponding to all elements are combined into a binary symbolic execution graph, and the binary symbolic execution graph is converted into a binary data flow graph according to the data flow graph conversion method;

[0025] Step 4: Using the data flow graph as the identification basis, the encryption algorithm is identified through the Ullmann subgraph isomorphism and the binary data flow graph is output:

[0026] Step 4.1, the encryption algorithm identification module takes the signature data flow graph obtained in step 2 and the binary data flow graph obtained in step 3 as input, and identifies the encryption algorithm of the binary through Ullmann subgraph isomorphism;

[0027] Step 4.2, determine whether any one of the encryption algorithms is implemented in the binary or both encryption algorithms exist in the binary. If so, the data flow graph portion corresponding to the identified encryption algorithm is marked in red in the binary data flow graph. Otherwise, no operation is performed on the binary data flow graph.

[0028] Step 4.3, output the binary data flow graph.

[0029] Compared with the prior art, the present invention has the following advantages:

[0030] First, due to the binary abstraction module in the device of the present invention, the device of the present invention can complete the recognition of the encryption algorithm without being affected by the architecture and compiler, solving the problem that the prior art cannot universally recognize it. Since the method of the present invention uses a disassembly tool to obtain the disassembled form of the binary instructions for the binaries generated under different instruction set architectures and different compilers, and uses the processor model corresponding to the instruction set architecture to convert the opcode and operand of the relevant data in the disassembled form of each binary instruction into the corresponding graph node in the data flow graph, the method of the present invention has architecture independence and compiler independence, solving the problem that the prior art does not have compiler independence.

[0031] Second, since the device and method of the present invention only use binary files, the present invention solves the problem that the prior art is not source code independent.

[0032] Third, due to the symbolic execution module in the device of the present invention, the device of the present invention can completely cover the binary code, and the encryption algorithm recognition and processing is more comprehensive; because the method of the present invention uses symbolic execution, the method of the present invention has a wider coverage of the data flow of binary files and encryption algorithms, and the corresponding generated data flow graph is more accurate.

[0033] Fourth, since the device of the present invention has a signature construction module and an encryption algorithm identification module, the device of the present invention pays more attention to the transmission and flow process of data in files and encryption algorithms, and the data itself does not play a decisive factor. Therefore, the device of the present invention can more accurately identify the SM3 and SM4 encryption algorithms, locate their positions in binary files, and solve the problem of one-to-many recognition results in the prior art; since the method of the present invention uses a data flow graph as the basis for recognition, the importance of the data itself in the method of the present invention is not high, and the transmission and flow process of the overall data plays a decisive factor in the method of the present invention. Therefore, the method of the present invention can more accurately identify the SM3 and SM4 encryption algorithms and locate their positions in the binary system.

[0034] Fifth, due to the signature construction module, symbolic execution module and encryption algorithm identification module in the device of the present invention, the device of the present invention adopts the form of signature data flow graph and binary data flow graph subgraph isomorphic to identify the encryption algorithm in binary, and the signature of the encryption algorithm only needs to be written according to the standard document, without the need for additional professional knowledge. Compared with inventions that require the use of ciphertext encoding and decoding knowledge, the device of the present invention is simpler and easier to implement. BRIEF DESCRIPTION OF THE DRAWINGS

[0035] Figure 1 is a schematic diagram of the device of the present invention;

[0036] Figure 2 is a flow chart of the method of the present invention;

[0037] Figure 3 is a signature data flow diagram generated by an embodiment of the present invention;

[0038] Figure 4 It is a partial binary data flow graph generated by an embodiment of the present invention. DETAILED DESCRIPTION

[0039] The present invention is further described below in conjunction with the accompanying drawings and embodiments.

[0040] Reference Figure 1 , the device of the present invention is further described.

[0041] The device of the present invention comprises a binary abstract module, a signature construction module, a symbolic execution module, and an encryption algorithm identification module. The binary abstract module performs the function described in step 1 of the method of the present invention, the signature construction module performs the function described in step 2 of the method of the present invention, the symbolic execution module performs the function described in step 3 of the method of the present invention, and the encryption algorithm identification module performs the function described in step 4 of the method of the present invention.

[0042] The binary abstract module obtains the disassembled form of each binary instruction under the instruction set architecture by using a disassembler tool, and converts the opcode and operand of the relevant data in the disassembled form of each binary instruction into corresponding graph nodes in the data flow graph through the processor model corresponding to the instruction set architecture.

[0043] In the embodiment of the present invention, the disassembled form of the binary instruction is obtained by using the IDAPro disassembler tool, and the opcode and operand of the relevant data in the disassembled form of the binary instruction are converted into corresponding graph nodes in the data flow graph by using the ARM processor model.

[0044] The signature construction module is used to formulate the signature language specification and convert it into a data flow graph, translate the operations related to data in the encryption algorithm into the corresponding signature language, and convert the signature language into the corresponding data flow graph.

[0045] The symbolic execution module is used to formulate a path replication strategy and its query times, and use the query results of the path replication strategy as the input of symbolic execution, construct a binary symbolic execution graph from the binary entry point, and finally convert the binary symbolic execution graph into a binary data flow graph.

[0046] The encryption algorithm identification module is used to take the signature data flow graph obtained by the signature construction module and the binary data flow graph obtained by the symbolic execution module as input, identify the SM3 and SM4 encryption algorithms in the binary through Ullmann subgraph isomorphism, and arrange and display the identification results in the order of identification. If any one of the SM3 and SM4 encryption algorithms exists in the binary or both implementations exist in the binary, the algorithm type is listed in detail; if not, the identification result is set to empty, and the binary data flow graph is output. If any one of the SM3 and SM4 encryption algorithms exists in the binary or both implementations exist in the binary, the data flow graph portion corresponding to the identified encryption algorithm will be marked in red in the data flow graph in the binary, otherwise the binary data flow graph is output normally.

[0047] Reference Figure 2 , the specific implementation steps of the method of the present invention are further described.

[0048] Step 1: Convert binary instructions under the instruction set architecture into data flow graph nodes that are independent of the architecture.

[0049] The binary abstract module uses a disassembly tool to obtain the disassembly form of each binary instruction under the instruction set architecture; using the processor model corresponding to the instruction set architecture, the opcode and operand of the relevant data in the disassembly form of each binary instruction are converted into corresponding graph nodes in the data flow graph.

[0050] The types of data flow graph nodes include: constant representation node, data addition node, data multiplication node, register representation node, circular shift node, left and right shift node, logical OR node, logical AND node, logical XOR node, memory write node, and memory read node, which respectively correspond to the constant representation operation, data addition operation, data multiplication operation, register representation operation, circular shift operation, left and right shift operation, logical OR operation, logical AND operation, logical XOR operation, memory write operation, and memory read operation in the disassembled form of binary instructions under the instruction set architecture.

[0051] In an embodiment of the present invention, for a data addition instruction in binary under the ARM instruction set architecture, the disassembly function of the IDAPro disassembly tool is used to obtain the disassembly representation form "ADDR4, R3, R2" of this instruction. The semantics of this instruction is to store the data after adding the registers R3 and R2 under the ARM instruction set architecture into R4. The ARM processor model is used to convert the operation code and operand of the relevant data in the disassembly form of this instruction into corresponding graph nodes in the data flow graph. The specific operation is to convert the registers R4, R3, and R2 under the ARM instruction set architecture into three register representation nodes, and convert the instruction semantics "addition" into a data addition node. After the ARM processor model conversion, there are four data flow graph nodes corresponding to this instruction, of which there are three register representation nodes corresponding to R4, R3 and R2 respectively, and there is one data addition node corresponding to the data addition in the instruction semantics R3 and R2.

[0052] Step 2: Convert the signature language corresponding to the encryption algorithm into a corresponding data flow graph.

[0053] The signature construction module translates the operations on the data in the encryption algorithm into the corresponding signature language according to the signature language specification; and converts the signature language into a signature data flow graph according to the signature language conversion method.

[0054] The signature used in the embodiment of the present invention is a self-defined signature of the present invention. The self-defined signature language specification of the present invention is to use the identifier (IDENTIFIER) keyword to specify the name of the signature, use the variant (VARIANT) keyword to specify the various implementation forms of the signature, use the wildcard (VARIANT) keyword to represent that the expression of the signature can be generally matched after being converted into a data flow graph node, use multiplication (MULT), circular shift (ROTATE), logical or (OR), logical and (AND), logical exclusive or (XOR), memory write (STORE) and memory read (LOAD) keywords to respectively represent the data multiplication operation, circular shift operation, logical or operation, logical and operation, logical exclusive or operation, memory write operation, and memory read operation of the encryption algorithm, and use "+" (ADD) and "<<" and ">>" (SHIFT) keywords to respectively represent the data addition operation and left and right shift operation of the encryption algorithm. The self-defined conversion mode of the present invention is that the IDENTIFIER keyword and the VARIANT keyword are not converted into graph nodes, the OPAQUE keyword can be converted into any one of a data addition node, a data multiplication node, a circular shift node, a left-right shift node, a logic OR node, a logic AND node, a logic XOR node, a memory write node, and a memory read node, and is used for general matching in the subsequent encryption algorithm identification process, the MULT, ROTATE, OR, AND, XOR, STORE and LOAD keywords are respectively converted into a data multiplication node, a circular shift node, a logic OR node, a logic AND node, a logic XOR node, a memory write node, and a memory read node; "+" (ADD) is converted into a data addition node, "<<" (SHIFT) is converted into a left shift node, and ">>" (SHIFT) is converted into a right shift node, and the edges of the signature data flow graph are implicitly represented by the signature expression.

[0055] In the embodiment of the present invention, the data operation "X⊕Y⊕Z" in the SM3 encryption algorithm specified in the Cryptography Industry Standard Technical Committee is translated into a signature language using a signature construction module to obtain a signature expression "XOR(XOR(X,Y),Z)". When the signature construction module converts the expression into a data flow graph, the graph nodes are two data XOR nodes, namely, the data XOR node corresponding to "XOR(X,Y)" and the data XOR node corresponding to "XOR(XOR(X,Y),Z)". The data flow direction should be "XOR(X,Y)"→"XOR(XOR(X,Y),Z)".

[0056] In the embodiment of the present invention, the data operation "X1⊕X2⊕X3⊕rk" in the SM4 encryption algorithm specified in the Cryptography Industry Standard Technical Committee is translated into a signature language using a signature construction module to obtain a signature expression "XOR(XOR(XOR(X1,X2),X3),rk)". When the signature construction module converts the expression into a data flow graph, the graph nodes are three data XOR nodes, namely, the data XOR node corresponding to "XOR(X1,X2)", the data XOR node corresponding to "XOR(XOR(X1,X2),X3)", and the data XOR node corresponding to "XOR(XOR(XOR(X1,X2),X3),rk)". The data flow direction is "XOR(X1,X2)"→"XOR(XOR(X1,X2),X3)"→"XOR(XOR(XOR(X1,X2),X3),rk)".

[0057] Step 3: construct a data flow graph that is independent of the instruction set architecture.

[0058] Step 3.1, the symbolic execution module forms a path set according to the instruction addresses for all conditional jump instructions in the binary and all instructions after the conditional jump instructions.

[0059] Step 3.2, select an unselected element from the path collection.

[0060] Step 3.3, determine whether the path corresponding to the selected element is a copy path, if so, execute step 3.4, otherwise, execute step 3.5;

[0061] Step 3.4, symbolize the conditional jump instruction corresponding to the selected element with the execution path corresponding to the previous element of the selected element, symbolize the instruction corresponding to the selected element located after the conditional jump instruction with the execution path corresponding to the selected element, and then execute step 3.6;

[0062] Step 3.5, determine whether the path corresponding to the selected element is a tracking path or an ignored path; if it is a tracking path, symbolize the conditional jump instruction corresponding to the selected element, otherwise, symbolize the instruction corresponding to the selected element and located after the conditional jump instruction;

[0063] Step 3.6, determine whether all elements in the path set have been selected, if so, execute step 3.7, otherwise, execute step 3.2;

[0064] Step 3.7, the symbolic expressions corresponding to all elements are combined into a binary symbolic execution graph, and the binary symbolic execution graph is converted into a binary data flow graph according to the data flow graph conversion method.

[0065] The path set in the embodiment of the present invention has an element and the conditional jump instruction corresponding to the element and the instruction disassembly form "CMPR3, R2; BNEloc_1B8D0; ADDR4, R3, R2", and an element before the element has the conditional jump instruction and the instruction disassembly form "CMPR3, R0; BNEloc_10435; ADDR7, R3, R1" after the conditional jump instruction. The data addition instruction disassembly form at loc_1B8D0 is: "ADDR3, #0x10", and the data addition instruction disassembly form at loc_10435 is "ADD R7, #0x16". The judgment result of the previous element is the tracking path, so the execution path corresponding to the previous element is "ADDR7, #0x16", and the element corresponding to the conditional jump instruction is judged, and the result is the copy path. The conditional jump instruction corresponding to the selected element should be symbolized by the execution path corresponding to the previous element, and the instruction following the conditional jump instruction corresponding to the selected element should be symbolized by the execution path corresponding to the selected element; these two execution paths are represented as two different graphs in the binary symbolic execution graph, corresponding to two different execution paths, which are "ADDR7, #0x16" → "ADDR3, #0x10" and "ADDR4, R3, R2" respectively. The symbol "→" indicates the flow of data during the symbolic execution process.

[0066] The data flow graph conversion method in the embodiment of the present invention is: the constants and registers represented by the symbolic expressions in the symbolic execution graph are regarded as data sources, and the constants and registers are converted into constant representation nodes and register representation nodes. The register representation node can also be used as an intermediate state of the data flow, indicating that the data is input into the register, and the symbolic expression in the symbolic execution graph is converted into corresponding constant representation nodes, data addition nodes, data multiplication nodes, register representation nodes, circular shift nodes, left and right shift nodes, logical OR nodes, logical AND nodes, logical XOR nodes, memory write nodes, and memory read nodes according to data addition operations, data multiplication operations, circular shift operations, left and right shift operations, logical OR operations, logical AND operations, logical XOR operations, memory write operations, and memory read operations. For repeated expressions, only one copy is retained in the binary data flow graph. The edges in the binary data flow graph are constructed with the assistance of symbolic expressions. The data operations in the symbolic expressions indicate the number of directed edges representing the data flow direction in the binary data flow graph and the directions of these directed edges. For repeated directed edges in the binary data flow graph, only one copy is retained and saved in the binary data flow graph. The data flow direction directed edge in the binary data flow graph is represented by a directed arrow. One end of the arrow is connected to the data source or the intermediate state of the data, and the other end is connected to the end point to which the data is to flow.

[0067] In the embodiment of the present invention, for the path "ADDR7, #0x16"→"ADDR3, #0x10" and the path "ADDR4, R3, R2" contained in the binary symbolic execution graph, the specific conversion operations are: converting R7, R4, R3, R2 into register representation nodes, converting 0x10 and 0x16 into constant representation nodes, and converting the data addition operation into a data addition node. After the conversion, there are four register representation nodes, two constant representation nodes, and three data addition nodes. The edges of the data flow graph are constructed under the guidance of the symbol "→". Finally, two binary data flow graphs are obtained, one data flow graph represents the path "ADDR7, #0x16"→"ADDR3, #0x10", and the other data flow graph represents the path "ADDR4, R3, R2".

[0068] Step 4: Using the data flow graph as the identification basis, the encryption algorithm is identified through the Ullmann subgraph isomorphism and the binary data flow graph is output.

[0069] Step 4.1, the encryption algorithm identification module takes the signature data flow graph obtained in step 2 and the binary data flow graph obtained in step 3 as input, and identifies the encryption algorithm of the binary through Ullmann subgraph isomorphism.

[0070] Step 4.2, determine whether any implementation of the encryption algorithm exists in the binary or both encryption algorithms exist in the binary. If so, the part of the data flow diagram corresponding to the identified encryption algorithm will be marked in red in the binary data flow diagram. Otherwise, no operation will be performed on the binary data flow diagram.

[0071] Step 4.3, output the binary data flow graph.

[0072] The above description and embodiments are only preferred examples of the present invention and do not constitute any limitation to the present invention. Obviously, for professionals in this field, after understanding the content and design principles of the present invention, they may make various modifications and changes in form and details based on the principles and structures of the present invention. However, these modifications and changes based on the present invention are still within the scope of protection of the claims of the present invention.

Claims

1. An encryption algorithm identification device for generating a data flow graph based on symbolic execution, characterized in that: The recognition device includes a binary abstraction module, a signature construction module, a symbol execution module, and an encryption algorithm recognition module, wherein: The binary abstraction module is used to obtain the disassembled form of each binary instruction under the instruction set architecture by using a disassembler tool; and to convert the operation code and operand of the relevant data in the disassembled form of each binary instruction into corresponding graph nodes in the data flow graph by using a processor model corresponding to the instruction set architecture; The signature construction module is used to translate the operations on the data in the encryption algorithm into the corresponding signature language according to the signature language specification, and convert the signature language into a signature data flow graph according to the signature language conversion method; The symbolic execution module is used to form a path set of all conditional jump instructions and all instructions after the conditional jump instructions in the binary system according to the instruction addresses; determine whether the path corresponding to the selected element in the set is a copy path, and if so, use the execution path corresponding to the previous element of the selected element to symbolize the conditional jump instruction corresponding to the selected element, and use the execution path corresponding to the selected element to symbolize the instruction after the conditional jump instruction corresponding to the selected element; otherwise, determine whether the path corresponding to the selected element is a tracking path or an ignored path; if it is a tracking path, symbolize the conditional jump instruction corresponding to the selected element, otherwise, symbolize the instruction after the conditional jump instruction corresponding to the selected element; form a binary symbolic execution graph with the symbolic expressions corresponding to all elements, and convert the binary symbolic execution graph into a binary data flow graph according to the data flow graph conversion method; The encryption algorithm identification module is used to take the signed data flow graph and the binary data flow graph as input, identify the encryption algorithm through the Ullmann subgraph isomorphism; determine whether any one of the encryption algorithms is implemented in the binary or both encryption algorithms exist in the binary, and if so, display the part of the data flow graph corresponding to the identified encryption algorithm in red in the binary data flow graph, otherwise, do not perform any operation on the binary data flow graph; and output the binary data flow graph.

2. According to claim 1, a method for identifying an encryption algorithm based on symbolic execution to generate a data flow graph, characterized in that: Symbolic execution is used to construct a data flow graph that is independent of the instruction set architecture. The data flow graph is used as the identification basis, and the encryption algorithm is identified through the Ullmann subgraph isomorphism. The steps of the identification method include the following: Step 1: Convert binary instructions under the instruction set architecture into data flow graph nodes: The binary abstraction module uses a disassembly tool to obtain the disassembly form of each binary instruction under the instruction set architecture; using the processor model corresponding to the instruction set architecture, the operation code and operand of the relevant data in the disassembly form of each binary instruction are converted into corresponding graph nodes in the data flow graph; Step 2: Convert the signature language corresponding to the encryption algorithm into the corresponding data flow graph: The signature construction module translates the operations on the data in the encryption algorithm into the corresponding signature language according to the signature language specification, and converts the signature language into a signature data flow graph according to the signature language conversion method; Step 3, construct a data flow graph that is independent of the instruction set architecture: Step 3.1, the symbolic execution module forms a path set according to the instruction addresses of all conditional jump instructions and all instructions after the conditional jump instructions in the binary; Step 3.2, select an unselected element from the path set; Step 3.3, determine whether the path corresponding to the selected element is a copy path, if so, execute step 3.4, otherwise, execute step 3.5; Step 3.4, symbolize the conditional jump instruction corresponding to the selected element with the execution path corresponding to the previous element of the selected element, symbolize the instruction corresponding to the selected element located after the conditional jump instruction with the execution path corresponding to the selected element, and then execute step 3.6; Step 3.5, determine whether the path corresponding to the selected element is a tracking path or an ignored path; If it is a tracing path, the conditional jump instruction corresponding to the selected element is symbolized, otherwise, the instruction following the conditional jump instruction corresponding to the selected element is symbolized; Step 3.6, determine whether all elements in the path set have been selected, if so, execute step 3.7, otherwise, execute step 3.2; Step 3.7, the symbolic expressions corresponding to all elements are combined into a binary symbolic execution graph, and the binary symbolic execution graph is converted into a binary data flow graph according to the data flow graph conversion method; Step 4: Using the data flow graph as the identification basis, the encryption algorithm is identified through the Ullmann subgraph isomorphism and the binary data flow graph is output: Step 4.1, the encryption algorithm identification module takes the signature data flow graph obtained in step 2 and the binary data flow graph obtained in step 3 as input, and identifies the encryption algorithm of the binary through Ullmann subgraph isomorphism; Step 4.2, determine whether any one of the encryption algorithms is implemented in the binary or both encryption algorithms exist in the binary. If so, the data flow graph portion corresponding to the identified encryption algorithm is marked in red in the binary data flow graph. Otherwise, no operation is performed on the binary data flow graph. Step 4.3, output the binary data flow graph.

3. The encryption algorithm identification method based on symbolic execution to generate data flow graph according to claim 2 is characterized in that: The graph nodes described in step 1 include: constant representation nodes, data addition nodes, data multiplication nodes, register representation nodes, circular shift nodes, left and right shift nodes, logical OR nodes, logical AND nodes, logical XOR nodes, memory write nodes, and memory read nodes, which respectively correspond to constant representation operations, data addition operations, data multiplication operations, register representation operations, circular shift operations, left and right shift operations, logical OR operations, logical AND operations, logical XOR operations, memory write operations, and memory read operations in the disassembled form of binary instructions under the instruction set architecture.

4. The encryption algorithm identification method based on symbolic execution to generate data flow graph according to claim 2, characterized in that: The signature language specification described in step 2 refers to using an identifier keyword to specify the name of the signature, using a variant keyword to specify the implementation form of the signature, using a wildcard keyword to represent that the expression of the signature can be universally matched after being converted into a data flow graph node, and using addition, multiplication, left and right shift, circular shift, logical OR, logical AND, logical XOR, memory write and memory read keywords to respectively represent the data addition operation, data multiplication operation, left and right shift operation, circular shift operation, logical OR operation, logical AND operation, logical XOR operation, memory write operation, and memory read operation of the encryption algorithm.

5. The encryption algorithm identification method based on symbolic execution to generate data flow graph according to claim 2, characterized in that: The signature language conversion method described in step 2 is as follows: identifier keywords and variant keywords are not converted into graph nodes, wildcard keywords can be converted into any data flow graph node, and the graph node after the keyword conversion is used for universal matching, addition, multiplication, left and right shift, circular shift, logical or, logical and, logical exclusive or, memory write and memory read keywords are respectively converted into graph nodes corresponding to the corresponding operations, and the edges of the signature data flow graph are implicitly represented by the signature expression.

6. The encryption algorithm identification method based on symbolic execution to generate data flow graph according to claim 2, characterized in that: The data flow graph conversion method described in step 3 is: the constants and registers represented by the symbolic expressions in the binary symbolic execution graph are regarded as data sources, and the constants and registers are converted into corresponding graph nodes respectively. The graph nodes corresponding to the registers are used as intermediate states of the data flow direction, indicating that the data is input into the registers. The data operations in the symbolic expressions in the symbolic execution graph are converted into corresponding graph nodes respectively. For repeated graph nodes, only one copy is retained in the binary data flow graph. The edges in the binary data flow graph are constructed with the assistance of symbolic expressions. The data operations in the symbolic expressions indicate how many directed edges representing the data flow direction are in the binary data flow graph and the directions of these directed edges. For repeated directed edges in the binary data flow graph, only one copy is retained and saved in the binary data flow graph. The directed edges of the data flow direction in the binary data flow graph are represented by directed arrows. One end of the arrow is connected to the data source or the intermediate state of the data, and the other end is connected to the end point to which the data is to flow.

Citation Information

Patent Citations

  • Encryption algorithm identification method and device in actual attack scene

    CN111309987A

  • A method and apparatus for identifying encryption algorithms in a real-world attack scenario

    CN111309987B

  • Encryption algorithm identification method based on deep learning graph network

    CN111460472A

  • Instruction-level password algorithm identification method and system

    CN105426707A

  • Distributed compiling process with instruction signature support

    US20130019231A1