A Software Heterogeneous Security Evaluation Method and Device
The method addresses the limitations of existing software heterogeneity assessments by evaluating gadget quality, practicality, and distribution indicators to accurately measure security gains and guide effective deployment strategies.
Patent Information
- Application Number
- CN202211411417.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-11-11
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2042-11-11
AI Technical Summary
The existing software isomerization security evaluation methods have problems such as overestimating security, high evaluation overhead, and incomplete evaluation results, and fail to fully reflect the impact of software isomerization on code reuse attacks.
By measuring the impact of software isomerization on each stage of code reuse attack, a variety of software isomerization techniques of different granularity are used to process the original software, extract gadget feature information, including ROP, JOP, COP and microgadget information, calculate the difficulty of the gadget attack chain, the attacker's calculation ability and search cost differences, comprehensively integrate gadget quality, practicality and distribution indicators, and set weights to calculate security measurements.
It accurately and comprehensively reflects the security gains brought by software isomerization, and provides more effective deployment decision support.
Smart Images

Figure CN115730303B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of cyberspace security, and in particular, to a method and device for evaluating the security of software heterogeneity. Background Art
[0002] Currently, the methods for evaluating the security of software heterogeneity mainly evaluate from the perspectives of features such as similarity, elasticity, and the ability to defend against attacks:
[0003] Evaluating from the perspective of similarity features, mainly by calculating the differences in metrics such as McCabe cyclomatic complexity, entropy, and hash values before and after the deployment of software heterogeneity technology. However, in the case of pointer leaks in software, the security evaluation of software heterogeneity based on similarity will overestimate the security brought by software heterogeneity, and similarity has not been proven to be strongly correlated with security.
[0004] Evaluating from the perspective of elasticity features, mainly by measuring the differences in random factors or errors and symbolic execution time shown by the software during disassembly processing before and after the deployment of software heterogeneity technology. However, the security evaluation of software heterogeneity based on elasticity only considers the impact on reverse engineering, does not reflect the impact of software heterogeneity on attacks such as code reuse, and the time required for symbolic execution to cover all branches is relatively long, resulting in excessive evaluation overhead.
[0005] Evaluating from the perspective of the ability to defend against attack features, mainly through logical argumentation, specific attack tests, and defining indicators using the properties related to gadgets in code reuse attacks to evaluate the security of software heterogeneity. However, logical argumentation is one-sided and too idealistic. Specific attack tests require the actual deployment of various types of attacks, with high overhead, high thresholds, and poor universality. Moreover, the gadget indicators defined in existing work fail to comprehensively reflect the impact of software heterogeneity on each attack step in the entire code reuse attack process, and also have a certain degree of one-sidedness. Summary of the Invention
[0006] Existing methods for evaluating the security of software heterogeneity have problems such as overestimating the security gain brought by software heterogeneity, excessive evaluation overhead, and incomplete evaluation results due to differences in evaluation perspectives such as similarity, elasticity, and the ability to defend against attacks. The present invention provides a method and device for evaluating the security of software heterogeneity that comprehensively considers gadget quality, practicality, and distribution indicators. By measuring the impact of software heterogeneity on each stage of code reuse attacks, it can accurately and comprehensively reflect the security gain brought by software heterogeneity.
[0007] On the one hand, the present invention provides a method for evaluating the security of software heterogeneity, including:
[0008] Step 1: Perform heterogeneity processing on the original software using multiple software heterogeneity technologies with different granularities to obtain multiple different software variants correspondingly;
[0009] Step 2: Extract gadget feature information affected by software heterogenization technology from the original software and multiple software variants respectively. The gadget feature information includes at least one of ROP - type gadget information, JOP - type gadget information, COP - type gadget information, and micro - gadget information. Here, ROP represents return - oriented programming attack, JOP represents jump - oriented programming attack, and COP represents call - oriented programming attack.
[0010] Step 3: Measure the differences in the difficulty of constructing gadget attack chains, the potentially available computing power of the attacker, and the cost of the attacker searching for gadgets in the original software and software variants according to the gadget feature information.
[0011] Step 4: Obtain the security metric value of software heterogenization based on the differences in the difficulty of constructing gadget attack chains, the potentially available computing power of the attacker, and the cost of the attacker searching for gadgets.
[0012] Furthermore, step 3 specifically includes:
[0013] Pre - set a gadget quality scoring standard, which is used to indicate the gadget quality scores corresponding to each useless instruction. Among them, the greater the side - effect of the useless instruction on the entire gadget - based code reuse attack, the higher the gadget quality score corresponding to the useless instruction.
[0014] Count the useless instructions in each gadget in the gadget feature information in the original software and software variants respectively, and then query the gadget quality scores corresponding to the useless instructions in the gadget quality scoring standard.
[0015] Accumulate the gadget quality scores of all useless instructions in each gadget to obtain the quality score of each gadget. Accumulate the quality scores of all gadgets in the gadget feature information in the original software and software variants respectively to obtain the gadget quality score corresponding to the original software and the gadget quality score corresponding to the software variant.
[0016] Calculate the difference between the gadget quality scores corresponding to the original software and the software variant, and use it as the difference in the difficulty of constructing gadget attack chains in the original software and software variants.
[0017] Furthermore, step 3 specifically includes:
[0018] Pre-build a set of microgadgets with different computing capabilities, and custom microgadget category information is defined in each set of microgadgets with the same computing capability;
[0019] Match the microgadget information in the original software and software variants with all microgadget category information of all pre-built microgadget sets respectively, to obtain the corresponding number of microgadget types in the original software and software variants;
[0020] Calculate the difference between the corresponding number of microgadget types in the original software and software variants, and take it as the difference in the potentially available computing capabilities of the attacker in the original software and software variants.
[0021] Furthermore, pre-build three sets of microgadgets with different computing capabilities, which are the no-ASLR set, the ASLR-proof set, and the Turing-complete microgadget set in ascending order of computing capability.
[0022] Furthermore, step 3 specifically includes:
[0023] Pre-build a specific gadget set, and the most commonly used gadget classes in the ROP chains deployed in real scenarios in Metasploit are custom-defined in the specific gadget set;
[0024] Match the ROP-type gadget information in the original software and software variants with all gadget classes of the pre-built specific gadget set respectively, to obtain the corresponding commonly used gadget sets in the original software and software variants;
[0025] Use kernel density estimation to calculate the probability density functions of the distributions of the corresponding commonly used gadget sets in the original software and software variants respectively;
[0026] Calculate the difference between the probability density functions of the distributions in the original software and software variants, and take it as the difference in the cost of the attacker searching for gadgets in the original software and software variants.
[0027] Furthermore, the gadget classes included in the specific gadget set are: load register operations, arithmetic operations, load memory operations, unconditional jump operations, store memory operations, stack migration operations, logical operations, register assignment operations, function call operations, and system call operations.
[0028] Further, the probability density functions of the distributions of the corresponding common gadget sets in the original software and the software variant are calculated respectively using kernel density estimation based on the Gaussian kernel function.
[0029] Further, step 4 specifically includes:
[0030] Weights are set for the differences in the difficulty of constructing the gadget attack chain, the differences in the computing power potentially available to the attacker, and the differences in the cost for the attacker to search for gadgets, denoted as λ, ω, and θ in sequence;
[0031] The security metric value S of software heterogeneity is calculated according to the following formula:
[0032] S = λ(Q' - Q) + ω(C - C') + θ|D' - D|;
[0033] where Q and Q' are the difficulties of constructing the gadget attack chain in the original software and the software variant respectively, C and C' are the computing powers potentially available to the attacker in the original software and the software variant respectively, and D and D' are the costs for the attacker to search for gadgets in the original software and the software variant respectively.
[0034] On the other hand, the present invention provides a software heterogeneity security evaluation device, including:
[0035] A heterogeneity processing module, configured to perform heterogeneity processing on the original software using software heterogeneity technologies with multiple different granularities, and correspondingly obtain multiple different software variants;
[0036] A gadget feature information extraction module, configured to extract gadget feature information affected by the software heterogeneity technology from the original software and the multiple software variants respectively, where the gadget feature information includes at least one of ROP - type gadget information, JOP - type gadget information, COP - type gadget information, and micro - gadget information; wherein, ROP represents return - oriented programming attack, JOP represents jump - oriented programming attack, and COP represents call - oriented programming attack;
[0037] A difference calculation module, configured to measure the differences in the difficulty of constructing the gadget attack chain, the differences in the computing power potentially available to the attacker, and the differences in the cost for the attacker to search for gadgets in the original software and the software variant according to the gadget feature information;
[0038] A security evaluation module is used to obtain a security metric value of software heterogenization based on differences in the difficulty of constructing a gadget attack chain, differences in the potentially available computing power of an attacker, and differences in the cost for the attacker to search for gadgets.
[0039] Further, the gadget feature information extraction module employs the ROPgadget tool.
[0040] Advantages of the present invention:
[0041] A software heterogenization security evaluation method and apparatus provided by the present invention comprehensively consider multiple metric indicators such as gadget quality, practicality, and distribution. By calculating the corresponding gadget quality scores, the computing power of the microgadget set, and the distribution differences of specific gadget sets, it comprehensively measures the impact degree of software heterogenization on each step of code reuse attacks, can accurately and comprehensively reflect the security gain brought by software heterogenization, and can provide quantitative evaluation decision support for more effective deployment of software heterogenization. Description of the Drawings
[0042] Figure 1 It is a schematic flowchart of a software heterogenization security evaluation method provided by an embodiment of the present invention;
[0043] Figure 2 It is a schematic structural diagram of a software heterogenization security evaluation apparatus provided by an embodiment of the present invention. Detailed Embodiments
[0044] To make the objectives, technical solutions, and advantages of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly described below with reference to the accompanying drawings in the embodiments of the present invention. Apparently, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0045] Embodiment 1
[0046] As Figure 1 shown, an embodiment of the present invention provides a software heterogenization security evaluation method, including the following steps:
[0047] S101: Perform heterogenization processing on the original software using multiple software heterogenization techniques with different granularities, and correspondingly obtain multiple different software variants;
[0048] S102: Extract gadget feature information affected by software heterogenization technology from the original software and multiple software variants respectively. The gadget feature information includes at least one of ROP - class gadget information, JOP - class gadget information, COP - class gadget information, and micro - gadget information. Among them, ROP (Return - oriented Programming) represents return - oriented programming attack, JOP (Jump - oriented programming) represents jump - oriented programming attack, and COP (Call - oriented programming) represents call - oriented programming attack.
[0049] Specifically, inventors' code - reuse attacks generally search for required gadgets in the memory during the execution of an executable file or program to construct an attack chain. Therefore, the present invention extracts the gadget features affected by software heterogenization in software variants and sets corresponding metric indicators in the follow - up to quantitatively analyze the security gain brought by software heterogenization.
[0050] When extracting gadget feature information, the ROPgadget tool can be used to scan the original software and software variants to obtain it.
[0051] S103: Measure the differences in the difficulty of constructing gadget attack chains, the differences in the potential computing power that attackers can obtain, and the differences in the cost for attackers to search for gadgets in the original software and software variants based on the gadget feature information.
[0052] Specifically, the inventors believe that the impact of software heterogenization on code - reuse attacks mainly focuses on the following steps: the gadget search step and the step of constructing a gadget attack chain. Among them, in the gadget search step, software heterogenization affects the gadget search step by changing the memory - space layout, causing differences in gadget distribution among different software variants and increasing the search cost for attackers. At the same time, in this step, software heterogenization can also change the categories of gadgets that can be searched within the attack surface, that is, the potential computing power that attackers can obtain. In the step of constructing a gadget attack chain, the difficulty of successfully constructing an available attack chain for different gadgets is different, that is, each gadget execution needs to meet different specific conditions, and software heterogenization can cause differences in the difficulty of constructing an attack chain for gadgets by changing the internal structure of gadgets and other means. For the above reasons, the present invention quantitatively analyzes the security gain mainly from the three aspects mentioned in step S103 based on the extracted gadget feature information.
[0053] S104: Obtain the security metric value of software heterogenization based on the differences in the difficulty of constructing a gadget attack chain, the differences in the computing power potentially available to the attacker, and the differences in the cost for the attacker to search for gadgets.
[0054] As an implementable manner, this step specifically includes:
[0055] Set weights for the differences in the difficulty of constructing a gadget attack chain, the differences in the computing power potentially available to the attacker, and the differences in the cost for the attacker to search for gadgets, denoted as λ, ω, and θ in sequence;
[0056] Calculate the security metric value S of software heterogenization according to the following formula:
[0057] S = λ(Q' - Q) + ω(C - C') + θ|D' - D|;
[0058] Where Q and Q' are the difficulties of constructing a gadget attack chain in the original software and the software variant respectively, C and C' are the computing powers potentially available to the attacker in the original software and the software variant respectively, and D and D' are the costs for the attacker to search for gadgets in the original software and the software variant respectively
[0059] It can be understood that λ, ω, and θ are a set of adjustable weight values. By setting different magnitudes and calculating the differences before and after heterogenization of each feature according to the above formula, the security of software heterogenization can be evaluated from different focuses.
[0060] The software heterogenization security evaluation method provided by this application starts from the perspective of ROP attacks. By analyzing the impacts of software heterogenization on each stage in the code reuse attack process, it measures the impacts of software heterogenization on the difficulty of constructing a gadget attack chain, the computing power potentially available to the attacker, and the cost for the attacker to search for gadgets in different software variants to evaluate its security.
[0061] Example 2
[0062] Based on the above example, an embodiment of the present invention provides a calculation method for the difference in the difficulty of constructing a gadget attack chain in the original software and the software variant, including the following steps:
[0063] Step A1: Preset a gadget quality scoring criterion; the gadget quality scoring criterion is used to indicate the gadget quality scores corresponding to each useless instruction; among them, the greater the side effect of the useless instruction on the entire gadget-based code reuse attack, the higher the gadget quality score corresponding to the useless instruction;
[0064] Specifically, when an attacker constructs an attack payload using multiple gadgets, their main purpose is often to use the specific functional instructions in each gadget. However, in addition to the core functional instructions required by the attacker, most gadgets also contain multiple useless instructions, and they usually have side effects on the entire gadget-based code reuse attack, that is, adding additional restrictive conditions. Therefore, the embodiments of the present invention pre-construct a gadget quality scoring standard (as shown in Table 1) based on the differences of various code reuse attacks and the different side effects of useless instructions in gadgets. It should be noted that the principle of the gadget quality scoring standard is that the greater the side effect of the useless instruction, the higher the gadget quality score is set, and the more difficult it is for the attacker to use this gadget to construct an attack chain; as long as it is constructed according to this rule, the useless instructions and their scores can be extended or adaptively adjusted as needed.
[0065] Table 1 Gadget Quality Scoring Standard
[0066]
[0067] Step A2: Count the useless instructions in each gadget in the gadget feature information in the original software and the software variant respectively, and then query the gadget quality score corresponding to the useless instruction in the gadget quality scoring standard;
[0068] Step A3: Accumulate the gadget quality scores of all useless instructions in each gadget to obtain the quality score of each gadget; accumulate the quality scores of all gadgets in the gadget feature information in the original software and the software variant respectively to obtain the gadget quality score corresponding to the original software and the gadget quality score corresponding to the software variant;
[0069] Step A4: Calculate the difference between the gadget quality scores corresponding to the original software and the software variant, and use it as the difference in the difficulty of constructing a gadget attack chain in the original software and the software variant.
[0070] According to the calculation method of the embodiments of the present invention, the quantitative index for evaluating the difficulty of constructing a gadget attack chain is also referred to as the "gadget quality" index.
[0071] Embodiment 3
[0072] Code reuse attacks are mainly used in the initial stage of a complete vulnerability attack. By implementing the attack, system kernel functions (such as mmap) are called to allocate a memory space with writable and executable permissions, and a copy of the attack payload is copied to this memory space. The control flow is redirected to this memory space through indirect branch instructions to execute the attack payload.
[0073] Based on this, on the basis of the above embodiments, the embodiments of the present invention further provide a calculation method for the difference in the potentially available computing power of an attacker in the original software and software variants, including the following steps:
[0074] Step B1: Pre-build a set of microgadgets with different computing powers, and custom microgadget category information is defined in each set of microgadgets with different computing powers;
[0075] Specifically, a microgadget actually refers to a type of gadget with a specific length. As an implementable manner, from the perspective of the actual attack scenario, three sets of microgadgets with different computing powers can be pre-built, which are the no-ASLR set, the ASLR-proof set, and the Turing-complete microgadget set in ascending order of computing power. Among them, the no-ASLR set and the ASLR-proof set can realize the allocation of an executable memory space, copy and execute the attack payload in this memory space, and the ASLR-proof set can successfully implement the attack in a system with ASLR deployed. The quantity information of the types of microgadgets in each set is shown in Table 2.
[0076] Table 2 Quantity information of the types of microgadgets in the microgadget set
[0077] microgadget set number of microgadget types no-ASLR 11 ASLR-proof 35 Turing-complete microgadget set 17
[0078] Step B2: Match the microgadget information in the original software and software variants with all the microgadget category information of all the pre-built microgadget sets (for example, through corresponding regular expression matching) to obtain the corresponding number of microgadget types in the original software and software variants;
[0079] Step B3: Calculate the difference between the corresponding number of microgadget types in the original software and software variants, and use it as the difference in the potentially available computing power of the attacker in the original software and software variants.
[0080] Specifically, according to the calculation method of the embodiments of the present invention, calculating the difference in the potentially available computing power of the attacker in the original software and the software variant is to evaluate the change in the number of microgadget categories in the set of different computing power microgadgets existing in the software before and after the heterogeneous deployment of the software. In the embodiments of the present invention, the quantitative index for evaluating the potentially available computing power of the attacker is also referred to as the "gadget utility" index.
[0081] Embodiment 4
[0082] Based on the above embodiments, the embodiments of the present invention further provide a calculation method for the difference in the cost of the attacker searching for gadgets in the original software and the software variant, including the following steps:
[0083] Step C1: Pre-build a specific gadget set, in which the most commonly used gadget classes in the ROP chains deployed in real scenarios in Metasploit are customized.
[0084] In this embodiment, the specific gadget set is composed of 10 most commonly used gadget classes statistically deployed in the ROP chains in real scenarios in Metasploit. The gadget information of each category in this set is shown in Table 3. Except for the stack pivot operation, the remaining gadgets still belong to the Turing-complete gadget set.
[0085] Table 3 Commonly used gadget categories in the specific gadget set
[0086]
[0087] Step C2: Match the ROP-type gadget information in the original software and the software variant with all the gadget classes of the pre-built specific gadget set (for example, through corresponding regular expression matching) to obtain the corresponding commonly used gadget sets in the original software and the software variant.
[0088] Step C3: Use kernel density estimation (such as kernel density estimation based on the Gaussian kernel function) to calculate the probability density functions of the distributions of the corresponding commonly used gadget sets in the original software and the software variant respectively.
[0089] It should be noted that before performing kernel density estimation, it also includes: normalizing according to the address information corresponding to each category of gadgets obtained by matching.
[0090] Step C4: Calculate the difference between the probability density functions distributed in the original software and the software variant, and use it as the difference in terms of the cost for an attacker to search for gadgets in the original software and the software variant.
[0091] Specifically, based on kernel density estimation, obtain the probability density function of the spatial distribution of a specific gadget set in a file. By comparing the differences in the distribution of a specific gadget set in the file before and after software heterogeneous deployment, evaluate the security gain brought by software heterogeneity. That is, the greater the difference in spatial distribution, the lower the homogeneity between software variants, and the cost for an attacker to launch attacks on different software variants will increase significantly. In the embodiments of the present invention, the quantization index for evaluating the cost for an attacker to search for gadgets in the original software and the software variant is also referred to as the "gadget distribution" index.
[0092] A software heterogeneity security evaluation method provided by the present invention can set corresponding metrics for gadget quality, practicality, and distribution based on the extracted gadget features to quantify the security brought by software heterogeneity. By calculating the corresponding gadget quality scores, the computing capabilities of different micro-gadget sets, and the distribution differences of specific gadget sets based on kernel density estimation, the influence degree of software heterogeneity on each attack step of code reuse attacks can be comprehensively measured, thereby comprehensively and effectively evaluating the security gain brought by software heterogeneity.
[0093] Embodiment 5
[0094] Corresponding to the above-mentioned software heterogeneity security evaluation method, as Figure 2 shown, the embodiments of the present invention provide a software heterogeneity security evaluation device, including a heterogeneous processing module, a gadget feature information extraction module, a difference calculation module, and a security evaluation module;
[0095] Among them, the isomerization processing module is used to perform isomerization processing on the original software by using software isomerization technologies with multiple different granularities, and correspondingly obtain multiple different software variants; the gadget feature information extraction module is used to extract gadget feature information affected by the software isomerization technology from the original software and the multiple software variants respectively, and the gadget feature information includes at least one of ROP-type gadget information, JOP-type gadget information, COP-type gadget information, and micro-gadget information; among them, ROP represents return-oriented programming attack, JOP represents jump-oriented programming attack, and COP represents call-oriented programming attack; the difference calculation module is used to measure the differences in the difficulty of constructing a gadget attack chain, the potential computing power that the attacker can obtain, and the cost of the attacker searching for gadgets between the original software and the software variants according to the gadget feature information; the security evaluation module is used to obtain the security metric value of software isomerization according to the differences in the difficulty of constructing a gadget attack chain, the potential computing power that the attacker can obtain, and the cost of the attacker searching for gadgets.
[0096] Among them, the gadget feature information extraction module can use the ROPgadget tool.
[0097] It should be noted that a software isomerization security evaluation device provided in an embodiment of the present invention is for the above method embodiment, and its functions can be specifically referred to the above method embodiment, which will not be elaborated here.
[0098] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A software heterogeneous security assessment method, characterized in that Including: Step 1: Perform heterogeneous processing on the original software using multiple software heterogeneous technologies with different granularities, and correspondingly obtain multiple different software variants; Step 2: Extract gadget feature information affected by the software heterogeneous technology from the original software and multiple software variants respectively. The gadget feature information includes at least one of ROP - type gadget information, JOP - type gadget information, COP - type gadget information, and micro - gadget information; where ROP represents return - oriented programming attack, JOP represents jump - oriented programming attack, and COP represents call - oriented programming attack; Step 3: Measure the differences in the difficulty of constructing gadget attack chains, the differences in the computing power potentially available to attackers, and the differences in the cost for attackers to search for gadgets between the original software and software variants according to the gadget feature information; Step 4: Obtain a security metric value for software heterogeneity based on the differences in the difficulty of constructing gadget attack chains, the differences in the computing power potentially available to attackers, and the differences in the cost for attackers to search for gadgets; Step 4 specifically includes: setting weights for the differences in the difficulty of constructing gadget attack chains, the differences in the computing power potentially available to attackers, and the differences in the cost for attackers to search for gadgets, denoted as λ, ω, and θ in sequence; Calculate the security metric value S of software heterogeneity according to the following formula: S = λ(Q' - Q)+ω(C - C')+θ|D' - D|; where Q and Q' are the difficulties of constructing gadget attack chains in the original software and software variants respectively, C and C' are the computing powers potentially available to attackers in the original software and software variants respectively, and D and D' are the costs for attackers to search for gadgets in the original software and software variants respectively.
2. The software heterogeneous security evaluation method according to claim 1, wherein Step 3 specifically includes: Pre - set a gadget quality scoring criterion; the gadget quality scoring criterion is used to indicate the gadget quality scores corresponding to each useless instruction; among them, the greater the side - effect of the useless instruction on the entire gadget - based code reuse attack, the higher the gadget quality score corresponding to the useless instruction; Count the useless instructions in each gadget in the gadget feature information in the original software and software variants respectively, and then query the gadget quality scores corresponding to the useless instructions in the gadget quality scoring criterion; Accumulate the gadget quality scores of all useless instructions in each gadget to obtain the quality score of each gadget; accumulate the quality scores of all gadgets in the gadget feature information in the original software and software variants respectively to obtain the gadget quality score corresponding to the original software and the gadget quality score corresponding to the software variant; Calculate the difference between the gadget quality scores corresponding to the original software and the software variant, and use it as the difference in the difficulty of constructing a gadget attack chain in the original software and the software variant.
3. The software heterogeneous security evaluation method according to claim 1, wherein Step 3 specifically includes: Pre-construct a set of microgadgets with different computing capabilities, and custom microgadget category information is defined in each set of microgadgets with the same computing capability; Match the microgadget information in the original software and the software variant with all the microgadget category information of all the pre-constructed microgadget sets respectively, and obtain the corresponding number of microgadget types in the original software and the software variant; Calculate the difference between the corresponding number of microgadget types in the original software and the software variant, and use it as the difference in the potentially available computing capabilities of the attacker in the original software and the software variant.
4. The software heterogeneous security evaluation method according to claim 3, wherein, Pre-construct three sets of microgadgets with different computing capabilities, which are the no-ASLR set, the ASLR-proof set, and the Turing-complete microgadget set in ascending order of computing capability.
5. The software heterogeneous security evaluation method according to claim 1, characterized in that Step 3 specifically includes: Pre-construct a specific gadget set, and the most commonly used gadget classes in the ROP chains deployed in real scenarios in Metasploit are custom-defined in the specific gadget set; the gadget classes included in the specific gadget set are: load register operations, arithmetic operations, load memory operations, unconditional jump operations, store memory operations, stack migration operations, logical operations, register assignment operations, function call operations, and system call operations; Match the ROP-type gadget information in the original software and the software variant with all the gadget classes of the pre-constructed specific gadget set respectively, and obtain the corresponding commonly used gadget sets in the original software and the software variant; Use kernel density estimation to calculate the probability density functions of the distributions of the corresponding commonly used gadget sets in the original software and the software variant respectively; Calculate the difference between the probability density functions of the distributions in the original software and the software variant, and use it as the difference in the cost of the attacker searching for gadgets in the original software and the software variant.
6. The software heterogenization security evaluation method according to claim 5, wherein Use kernel density estimation based on the Gaussian kernel function to calculate the probability density functions of the distributions of the corresponding commonly used gadget sets in the original software and the software variant respectively.
7. A software heterogeneous security evaluation device, characterized in that Includes: A heterogeneous processing module for performing heterogeneous processing on the original software using various software heterogeneous technologies with different granularities, and correspondingly obtaining multiple different software variants; The gadget feature information extraction module is used to extract gadget feature information affected by software heterogenization technology from the original software and multiple software variants respectively. The gadget feature information includes at least one of ROP - type gadget information, JOP - type gadget information, COP - type gadget information, and micro - gadget information. Among them, ROP represents return - oriented programming attack, JOP represents jump - oriented programming attack, and COP represents call - oriented programming attack. The difference calculation module is used to measure the differences in the difficulty of constructing gadget attack chains, the potential computing power that an attacker can obtain, and the cost of an attacker searching for gadgets between the original software and software variants according to the gadget feature information. The security evaluation module is used to obtain the security metric value of software heterogenization based on the differences in the difficulty of constructing gadget attack chains, the potential computing power that an attacker can obtain, and the cost of an attacker searching for gadgets. Specifically, it is used for: Setting weights for the differences in the difficulty of constructing gadget attack chains, the potential computing power that an attacker can obtain, and the cost of an attacker searching for gadgets respectively, denoted as λ, ω, and θ in sequence. Calculating the security metric value S of software heterogenization according to the following formula: S = λ(Q' - Q)+ω(C - C')+θ|D' - D|; Where Q and Q' are the difficulties of constructing gadget attack chains in the original software and software variants respectively, C and C' are the potential computing powers that an attacker can obtain in the original software and software variants respectively, and D and D' are the costs of an attacker searching for gadgets in the original software and software variants respectively.
8. The software heterogeneous security evaluation device according to claim 7, characterized in that, The gadget feature information extraction module uses the ROPgadget tool.
Citation Information
Patent Citations
ROP (Return-Oriented Program) protection method based on attack tree
CN105825086A
Detecting software attacks on processes in computing devices
CN108027859A