A Firmware Password Library Detection Method and Device Based on Similarity Analysis

By building a public password library dataset and using similarity analysis and clustering technology between functions, identifying the password library in the firmware of the Internet of Things device, the problem of not being able to automatically identify all password functions and APIs in the existing technology is solved, and efficient security analysis is achieved.

CN115878795BActive Publication Date: 2025-07-22ELECTRIC POWER RESEARCH INSTITUTE OF STATE GRID SHANDONG ELECTRIC POWER COMPANY +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211375766.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-04
Publication Date
2025-07-22
Estimated Expiration
2042-11-04

AI Technical Summary

Technical Problem

The existing password algorithm recognition methods cannot automatically identify all password functions in the firmware of IoT devices, and cannot identify API-related information of password functions, resulting in inefficient security analysis.

Method used

By building a public password library dataset, using inter-function similarity analysis and clustering technology, the password library in the firmware of IoT devices is identified and its API is restored.

Benefits of technology

It realizes automatic identification and API recovery of all password functions in the firmware of IoT devices, greatly improving the efficiency and accuracy of security analysis.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115878795B_ABST
    Figure CN115878795B_ABST
Patent Text Reader

Abstract

The present invention belongs to the field of Internet of Things security technology, and discloses a firmware password library detection method and device based on similarity analysis. The method includes: constructing a public password library data set, obtaining the binary file of the public password library data set as the data set binary file, and unpacking the firmware to be detected to obtain the binary file of the firmware as the binary file to be analyzed; performing file similarity analysis on the binary file to be analyzed and the data set binary file to identify the public password library; in the files where the public password library is not identified, clustering according to the file similarity to identify the private password library. In the process of performing similarity analysis, the method of the present invention not only utilizes the features inside the function, but also uses the sequence order between functions as the basis for similarity recognition, so as to be able to accurately identify the password library in the Internet of Things firmware and restore the APIs of all functions in the library, which greatly facilitates the subsequent security analysis work.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of Internet of Things security, and particularly relates to a firmware password library detection method and device based on similarity analysis. Background Art

[0002] There are various Internet of Things devices, and how to ensure the security of Internet of Things devices is a very difficult problem. To ensure the security of Internet of Things devices, security analysts often need to perform security analysis on the firmware of Internet of Things devices. In this process, it is necessary to unpack the firmware and perform reverse analysis on the binary files therein. During the reverse analysis process, security personnel need to analyze the legality of the network protocols therein, especially the usage of encryption algorithms to ensure the communication security of Internet of Things devices. During the compilation process, the password library may be mixed with various files in the form of static linking, making it difficult to identify and distinguish, and further identification is required.

[0003] Currently, the traditional password algorithm recognition method is to identify password functions by using features such as constants, control flow, and data flow in password functions, and it is unable to identify the password library and API therein. The above method has the following defects:

[0004] (1) The traditional password algorithm recognition method is carried out at the function granularity, identifying a single function each time, and the features used by these methods often only appear in one or several functions of a single password suite. Therefore, the function granularity recognition method can only identify one or several functions in a password suite, and the remaining parts that cannot be identified still need to be supplemented by manual analysis, and it is impossible to automatically identify all password functions in a firmware.

[0005] (2) The traditional password algorithm recognition method only uses the features of the password algorithm itself to perform recognition at the function granularity, so it can only identify the password algorithms that the password function may use, and the information that can be provided to analysts is very limited. Information related to APIs such as the function name and parameters of the password function is also very useful for the analysis of the password function, but there are significant differences in these information in different password libraries and there is not much correlation with the features of the function itself. Therefore, the traditional method cannot perform recognition. Summary of the Invention

[0006] An embodiment of the present invention provides a method and apparatus for detecting a firmware password library based on similarity analysis, which can identify the password library and corresponding APIs in the Internet of Things device firmware by using the similarity between functions and files. To provide a basic understanding of some aspects of the disclosed embodiments, a simple summary is given below. This summary part is not a general review, nor is it intended to identify key / important constituent elements or delineate the protection scope of these embodiments. Its sole purpose is to present some concepts in a simple form as a prelude to the detailed description that follows.

[0007] According to a first aspect of an embodiment of the present invention, there is provided a method for detecting a firmware password library based on similarity analysis, including:

[0008] Construct a public password library data set, obtain the binary file of the public password library data set as the data set binary file, and unpack the firmware to be detected to obtain the binary file of the firmware as the binary file to be analyzed;

[0009] Perform file similarity analysis on the binary file to be analyzed and the data set binary file to identify the public password library in the binary file of the firmware;

[0010] In the files where the public password library is not identified in the binary file to be analyzed, perform clustering according to the file similarity to identify the private password library in the binary file to be analyzed.

[0011] In one embodiment, after the step of identifying the private password library in the binary file to be analyzed, the method further includes:

[0012] Map the password functions of the public password library in the binary file to be analyzed to the APIs of the data set binary file, and extract the APIs of the password functions of the public password library in the binary file to be analyzed.

[0013] In one embodiment, after the step of identifying the private password library in the binary file to be analyzed, the method further includes:

[0014] Through static analysis, parse the number and type of parameters of each function in the private password library in the binary file to be analyzed, and extract the APIs of the password functions of the private password library in the binary file to be analyzed.

[0015] In one embodiment, the step of the method for constructing a public password library data set and obtaining the binary file of the public password library data set as the data set binary file further includes:

[0016] Perform similarity analysis between different binary files in the same public password library, and deduplicate all binary files in the public password library dataset according to the similarity analysis results to obtain dataset binary files.

[0017] In one embodiment, the step of unpacking the firmware to be detected to obtain the binary file of the firmware as the binary file to be analyzed further includes:

[0018] Unpack the firmware to be detected to obtain all binary files of the firmware, identify the cryptographic algorithms of all binary files of the firmware, and use the binary files of the firmware containing cryptographic algorithms as the binary files to be analyzed.

[0019] In one embodiment, the step of unpacking the firmware to be detected to obtain the binary file of the firmware as the binary file to be analyzed further includes:

[0020] Unpack the firmware to be detected to obtain all binary files of the firmware, identify the cryptographic algorithms of all binary files of the firmware, and use the binary files of the firmware containing more than the first threshold number of cryptographic algorithms as the binary files to be analyzed.

[0021] In one embodiment, the step of performing file similarity analysis on the binary file to be analyzed and the dataset binary files to identify the public password library in the binary files of the firmware further includes:

[0022] Perform file similarity analysis on the binary file to be analyzed and the dataset binary files by means of inter - function similarity.

[0023] In one embodiment, the inter - function similarity of the method includes the overall function similarity and the number of exactly - matching basic blocks.

[0024] In one embodiment, the step of performing file similarity analysis on the binary file to be analyzed and the dataset binary files to identify the public password library in the binary files of the firmware further includes:

[0025] Perform file similarity analysis on the binary file to be analyzed and the dataset binary files by means of inter - function - sequence similarity.

[0026] In one embodiment, the step of performing similarity analysis between different binary files in the same public password library, and deduplicating all binary files in the public password library dataset according to the similarity analysis results to obtain dataset binary files further includes:

[0027] If the function lists in two binary files of the same public password library are exactly the same and the similarity of the corresponding functions reaches above the second threshold, the two binary files are considered similar, and duplicate removal is performed on the two binary files.

[0028] In one embodiment, the step of performing password algorithm recognition on all binary files of the firmware by this method further includes:

[0029] Use IDAPro and its plugin findcrypt-yara to recognize password algorithms.

[0030] In one embodiment, the function similarity of this method is calculated by bindiff.

[0031] In one embodiment, the step of performing file similarity analysis on the binary file to be analyzed and the dataset binary file by this method in the manner of the similarity between function sequences further includes:

[0032] Calculate the similarity between function sequences according to at least one of the number of similar functions or the order between functions.

[0033] According to the second aspect of the embodiments of the present invention, a firmware password library detection device based on similarity analysis is provided.

[0034] In one embodiment, the device includes a dataset construction module, a public password library recognition module, a private password library recognition module, and an API extraction module; wherein,

[0035] The dataset construction module is used to construct a public password library dataset, obtain the binary files of the public password library dataset as dataset binary files, and unpack the firmware to be detected to obtain the binary files of the firmware as binary files to be analyzed;

[0036] The public password library recognition module is used to perform file similarity analysis on the binary file to be analyzed and the dataset binary file to identify the public password library in the binary file of the firmware;

[0037] The private password library recognition module is used to cluster according to the file similarity in the files where the public password library is not recognized in the binary file to be analyzed to identify the private password library in the binary file to be analyzed;

[0038] The API extraction module is used to map the password functions of the public password library in the binary file to be analyzed to the APIs of the dataset binary file, and extract the APIs of the password functions of the public password library in the binary file to be analyzed; parse the number and type of parameters of each function in the private password library in the binary file to be analyzed through static analysis, and extract the APIs of the password functions of the private password library in the binary file to be analyzed.

[0039] According to a third aspect of an embodiment of the present invention, a computer device is provided.

[0040] In some embodiments, the computer device includes a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the steps of the method described in the first aspect are implemented.

[0041] According to a fourth aspect of an embodiment of the present invention, a computer-readable storage medium is provided.

[0042] In some embodiments, a computer program is stored on the computer-readable storage medium; the computer program is executed by a processor to implement the steps of the method described in the first aspect.

[0043] The technical solutions provided by the embodiments of the present invention may include the following beneficial effects:

[0044] The present invention proposes a method for detecting a firmware password library based on similarity analysis. Compared with traditional detection methods, the password library recognition of the present invention can identify password algorithms that cannot be recognized by traditional password algorithm recognition methods by identifying all functions in the password library, greatly improving the effect of password algorithm recognition; during the process of identifying the password library, all APIs in the corresponding password library can be restored, thus greatly facilitating the subsequent security analysis process for security personnel.

[0045] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the present invention. BRIEF DESCRIPTION OF THE DRAWINGS

[0046] The accompanying drawings herein are incorporated into the specification and constitute a part of the specification, showing embodiments consistent with the present invention and used together with the specification to explain the principles of the present invention.

[0047] Figure 1 is a flowchart of the method for detecting a firmware password library based on similarity analysis provided by an embodiment of the present application;

[0048] Figure 2 is a structural diagram of the device for detecting a firmware password library based on similarity analysis provided by an embodiment of the present application;

[0049] Figure 3 is a schematic structural diagram of a computer device shown according to an exemplary embodiment. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0050] The following description and the accompanying drawings fully illustrate specific embodiments herein, enabling those skilled in the art to practice them. Parts and features of some embodiments may be included in or substituted for parts and features of other embodiments. The scope of the embodiments herein includes the entire scope of the claims and all available equivalents of the claims. In this document, the terms "first", "second", etc. are only used to distinguish one element from another, without requiring or implying any actual relationship or order between these elements. In fact, the first element can also be called the second element, and vice versa. Moreover, the terms "include", "comprise" or any other variant thereof are intended to cover non-exclusive inclusion, such that a structure, device or apparatus including a series of elements not only includes those elements, but also includes other elements not explicitly listed, or also includes elements inherent to such structure, device or apparatus. Without further limitation, an element defined by the statement "including one..." does not exclude the presence of additional identical elements in the structure, device or apparatus including the said element. The various embodiments herein are described in a progressive manner, with each embodiment highlighting the differences from other embodiments. The same or similar parts among the various embodiments can be referred to each other.

[0051] In this document, unless otherwise specified, the term "plurality" means two or more.

[0052] Figure 1 The flowchart of the firmware cryptographic library detection method based on similarity analysis of the present invention is shown as Figure 1 shown below:

[0053] S1: Construct a public cryptographic library dataset, obtain the binary file of the public cryptographic library dataset as the dataset binary file, and unpack the firmware to be detected to obtain the binary file of the firmware as the binary file to be analyzed.

[0054] Specifically, when constructing the public cryptographic library dataset, binary files of public cryptographic libraries of various versions are collected by directly downloading binary files or downloading source code for compilation and integrating them together as the dataset of the public cryptographic library. And through file similarity analysis, duplicate removal is performed on the cryptographic library files of versions with very small differences to reduce the scale of the dataset as much as possible.

[0055] In some embodiments of the present application, similarity analysis is performed between different binary files in the same public password library, and all binary files in the public password library dataset are deduplicated according to the similarity analysis result to obtain dataset binary files. Further, if the function lists in two binary files in the same public password library are exactly the same and the similarity of the corresponding functions reaches above the second threshold, the two binary files are considered similar, and the two binary files are deduplicated.

[0056] In an embodiment of the present application, when unpacking the firmware to be detected to obtain the binary file of the firmware, binwalk is used to analyze and unpack the Internet of Things firmware, the file system in different format firmwares is extracted, and the formats of all the extracted files are parsed respectively through the file command in linux, and the executable files and dynamic link library files are selected as the subsequent analysis targets.

[0057] In some embodiments of the present application, the firmware to be detected is unpacked to obtain all binary files of the firmware, the password algorithms in all binary files of the firmware are identified, and the binary file of the firmware containing the password algorithm is used as the binary file to be analyzed. Optionally, the binary file of the firmware that can contain more than the first threshold number of password algorithms can be used as the binary file to be analyzed. Further, IDAPro and its plugin findcrypt-yara are used to identify the password algorithms.

[0058] In a specific implementation, IDAPro and its plugin findcrypt-yara are used to identify the password algorithms, and the files are filtered according to the types and quantities of the identified password algorithms. Only when three or more (i.e., the first threshold is 3) password algorithms are identified in a binary file, it is considered that there may be a password library therein, and the binary file of the firmware that meets this condition is used as the binary file to be analyzed and further identification is performed in the next step. This filtering strategy can greatly reduce the scale of the files to be analyzed, thereby effectively improving the analysis efficiency.

[0059] S2: Perform file similarity analysis on the binary file to be analyzed and the dataset binary file to identify the public password library in the binary file of the firmware.

[0060] In some embodiments of the present application, file similarity analysis is performed on the binary file to be analyzed and the dataset binary file by means of the similarity between functions. Specifically, the similarity between functions includes the overall similarity of functions and the number of exactly matching basic blocks. Specifically, the similarity between functions is calculated by bindiff.

[0061] In a specific implementation, this embodiment performs a similarity analysis on the binary file that may contain the cryptographic library and the binary files in the cryptographic library dataset, so as to determine whether a target executable file contains a known public cryptographic library. The similarity between functions calculated using the IDApro plugin bindiff includes two aspects: the similarity of the overall function and the number of exactly matching basic blocks.

[0062] In some embodiments of the present application, file similarity analysis can also be performed on the binary file to be analyzed and the dataset binary file by means of the similarity between function sequences. Specifically, the similarity between function sequences is calculated according to at least one factor among the number of similar functions or the sequence order between functions.

[0063] In a specific implementation, considering that the distribution and sequence order of functions in different versions of the same cryptographic library also have significant similarities, this embodiment of the present application also calculates the similarity between the function sequences of the target file and the cryptographic library file as an identification criterion.

[0064] S3: Among the files in which no public cryptographic library is recognized in the binary file to be analyzed, clustering is performed according to the file similarity to identify the private cryptographic library in the binary file to be analyzed.

[0065] In a specific implementation, file similarity analysis is performed among binary files that do not contain known public cryptographic libraries. The purpose of this step is to find the unknown private cryptographic libraries hidden in the binary files by searching for the intersection of functions between different files.

[0066] S4: Map the cryptographic functions of the public cryptographic library in the binary file to be analyzed to the APIs of the dataset binary file, and extract the APIs of the cryptographic functions of the public cryptographic library in the binary file to be analyzed; by statically analyzing and parsing the number and types of parameters of each function in the private cryptographic library in the binary file to be analyzed, extract the APIs of the cryptographic functions of the private cryptographic library in the binary file to be analyzed.

[0067] In a specific implementation, the extraction of the cryptographic function API is achieved through the mapping between the identified cryptographic functions. For the identified public cryptographic library, directly identify the cryptographic algorithm according to the API of the identified cryptographic function; for the identified private cryptographic library, on the one hand, search for its function name in the same function as much as possible through the correspondence between functions, and on the other hand, analyze the data types of all parameters through static semantic analysis and extract its API.

[0068] The present application provides a specific embodiment to exemplarily illustrate the above steps:

[0069] First, a dataset of known public cryptographic libraries is established. In this process, binary files of public cryptographic libraries such as libcrypto, libmcrypt, and libgcrypt in various versions need to be collected. Their main sources are divided into two categories:

[0070] (1) Directly download the binary files of the officially compiled distribution;

[0071] (2) Download the source code from open source websites such as github and compile it by yourself.

[0072] After obtaining the binary files of these cryptographic libraries, in order to improve the matching efficiency, in this embodiment, bindiff is used to perform similarity analysis between different binary files of the same cryptographic library. If the function lists in the binary files of two versions are exactly the same and the similarity of the corresponding functions is all above 0.9 (i.e., the second threshold is 0.9), then the binary files of the two versions are considered duplicates, and only one of them is retained. This method can greatly reduce the scale of the public cryptographic library dataset and improve the analysis efficiency of the subsequent cryptographic library identification process.

[0073] When unpacking the firmware and extracting files in this embodiment, first, the "binwalk -Me{FILE}" command of binwalk is used to unpack the Internet of Things firmware to be identified. After unpacking, the file system contained in the firmware is obtained, which contains important directories for storing system files such as " / bin" and " / lib", and also contains some files of types such as html and png for providing other services. Therefore, this embodiment traverses the files in all directories, uses the file command of linux to identify the types of all files, and extracts the files whose file information contains keywords such as "executable" and "sharedobject". These two types of files represent executable files and dynamic link library files respectively, which are the targets of subsequent analysis.

[0074] When identifying the cryptographic algorithm in this embodiment, IDA Pro and its plugin findcrypt-yara are used to identify the cryptographic algorithms contained in the extracted binary file. Findcrypt-yara is a cryptographic algorithm identification tool based on cryptographic constants. It reads the binary file in bytecode form and searches for constants of common cryptographic algorithms in it in the form of regular expressions, such as the initial vector of the MD5 algorithm "0x01234567, 0x89abcdef, 0xefcdab89, 0x67452301" and the S-box of AES "0x63, 0x7c, 0x77, 0x7b...", etc., so as to achieve the identification of cryptographic algorithms. Since the plugin of findcrypt-yara only supports the graphical interface, those skilled in the art know that on the basis of the technical solution disclosed in this application, the plugin of findcrypt-yara can be modified during use to enable it to support silent analysis and batch analysis under the command line, and save its results in a json file.

[0075] After identifying the cryptographic algorithm of the binary file, this embodiment further filters the binary file according to the result of the cryptographic algorithm identification to further reduce the scale of the binary file: because the cryptographic library is often a dedicated library containing multiple cryptographic algorithms, and needs to contain multiple types of cryptographic algorithms such as hashing, symmetric encryption, asymmetric encryption, message authentication code, etc., so this embodiment only regards the binary file containing more than 3 (i.e., the first threshold is 3) cryptographic algorithms as a possible cryptographic library to exclude the scattered cryptographic functions used by developers.

[0076] When identifying the public cryptographic library in this embodiment, a similarity analysis is performed on the above-identified binary files that may contain the cryptographic library and the binary files in the public cryptographic library dataset, so as to achieve the identification of the cryptographic library. The similarity metrics in this part mainly include the characteristics of the function itself (similarity between functions) and the characteristics composed of function sequences ((similarity between function sequences)). The characteristics of the function itself are mainly calculated by bindiff, and mainly include two aspects of metrics:

[0077] (1) The number of basic blocks matched between functions. Since the function being too small will significantly increase the similarity analysis, only functions with the number of basic blocks in the function greater than or equal to 2 are used as the basis for similarity analysis;

[0078] (2) The similarity between functions. The similarity within the function calculated by bindiff based on characteristics such as the instruction sequence and call relationship within the function ranges from [0,1]. Only when the similarity is greater than 0.8 are two functions considered similar.

[0079] After obtaining similar functions through bindiff, in this embodiment, the similarity of the password library is identified based on the characteristics formed by the function sequences, and the characteristics used also include two parts:

[0080] (1) The number of similar functions. Generally speaking, the more similar functions there are, the higher the matching degree of the two binary files. In the implementation of this embodiment, files with more than 20 similar functions are considered to match each other;

[0081] (2) In addition to the number of matching files, the order of functions can also be an important basis for file similarity analysis. In this embodiment, the similar functions in the two binary files are extracted, arranged according to their addresses in the two binary files respectively, and the edit distance between the two function sequences is calculated. The smaller the edit distance, the more similar the two files are. Considering the different scales of the password library, in this embodiment, the quotient of the edit distance and the length of the function sequence is further calculated as the distance value to achieve the unification of similarity, and binary files with a value less than 0.2 are considered similar.

[0082] For a target file and a password library file, only when there are more than 20 similar functions between them and the function sequence spacing value is less than 0.2 are the files considered to match, that is, it is determined that the target file contains the corresponding public password library.

[0083] When identifying the private password library in this embodiment, mutual matching is performed between the binary files where the public password library is not identified, and the intersection between different binary files is identified, so as to identify the private password library contained in the binary files.

[0084] When performing API extraction in this embodiment, the API of the identified password library is restored by using the corresponding relationship between functions or through automated static analysis:

[0085] (1) For the functions in the identified public password library, the API in the corresponding password library is directly used as the API of the target function, which can achieve accurate extraction of the API.

[0086] (2) For the functions in the identified private password library, on the one hand, in this embodiment, the password functions located in different binary files are mapped, which can accurately depict the scope of the password library and parse the parameter types of each function; on the other hand, analysts can manually analyze and label the specific functions of each parameter for correction, so that the unknown password library becomes a known password library, and the automated extraction of the API can be achieved when the same password library is encountered next time.

[0087] In summary, during the similarity analysis process of the present application, not only the features inside the function are utilized, but also the sequence order between functions is used as the basis for similarity recognition, so as to be able to accurately identify the password library in the Internet of Things firmware and restore the APIs of all functions in the library, greatly facilitating subsequent security analysis work.

[0088] It should be understood that although the various steps in the flowchart are shown in sequence according to the indication of the arrows, these steps do not necessarily execute in the order indicated by the arrows. Unless there is a clear description in this article, the execution of these steps has no strict order limit, and these steps can be executed in other orders. Moreover, at least a part of the steps in the figure may include multiple sub-steps or multiple stages. These sub-steps or stages do not necessarily execute at the same moment, but can execute at different moments. The execution order of these sub-steps or stages is not necessarily sequential either, but can execute alternately or in turn with at least a part of other steps or sub-steps or stages of other steps.

[0089] Please refer to Figure 2 , an embodiment of the present application provides a firmware password library detection device based on similarity analysis, including a dataset construction module 10, a public password library recognition module 20, a private password library recognition module 30, and an API extraction module 40; wherein,

[0090] The dataset construction module 10 is used to construct a public password library dataset, obtain the binary file of the public password library dataset as the dataset binary file, and unpack the firmware to be detected to obtain the binary file of the firmware as the binary file to be analyzed;

[0091] The public password library recognition module 20 is used to perform file similarity analysis on the binary file to be analyzed and the dataset binary file to identify the public password library in the binary file of the firmware;

[0092] The private password library recognition module 30 is used to cluster according to the file similarity in the files where no public password library is identified in the binary file to be analyzed, so as to identify the private password library in the binary file to be analyzed;

[0093] The API extraction module 40 is used to map the password functions of the public password library in the binary file to be analyzed to the APIs of the dataset binary file, and extract the APIs of the password functions of the public password library in the binary file to be analyzed; by statically analyzing and parsing the number and type of parameters of each function in the private password library in the binary file to be analyzed, the APIs of the password functions of the private password library in the binary file to be analyzed are extracted.

[0094] For the specific limitations of the above firmware password library detection device based on similarity analysis, reference may be made to the limitations of the firmware password library detection method based on similarity analysis in the foregoing text, which will not be elaborated herein. Each module in the above firmware password library detection device based on similarity analysis can be implemented in whole or in part by software, hardware, and their combination. Each of the above modules can be embedded in the processor of the computer device in hardware form or be independent of it, or can be stored in the memory of the computer device in software form, so as to facilitate the processor to call and execute the operations corresponding to each of the above modules.

[0095] In another embodiment of the present application, a computer device is provided. The computer device can be a server, and its internal structure diagram can be as Figure 3 shown. The computer device includes a processor, a memory, and a network interface connected through a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store static information and dynamic information data. The network interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, it implements the steps in the above method embodiment.

[0096] Those skilled in the art can understand that Figure 3 the structure shown in

[0097] is only a block diagram of a part of the structure related to the solution of the present invention, and does not constitute a limitation on the computer device to which the solution of the present invention is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine certain components, or have a different component layout.

[0098] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, storage, database, or other medium used in the various embodiments provided by the present invention can include at least one of non-volatile and volatile memories. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, or optical memory, etc. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc.

[0099] The present invention is not limited to the structures already described and shown in the drawings, and various modifications and changes can be made without departing from its scope. The scope of the present invention is only limited by the appended claims.

Claims

1. A firmware password library detection method based on similarity analysis, characterized in that, Including: Construct a public cryptographic library dataset, obtain the binary file of the public cryptographic library dataset as the dataset binary file, and unpack the firmware to be detected to obtain the binary file of the firmware as the binary file to be analyzed; Perform file similarity analysis on the binary file to be analyzed and the dataset binary file to identify the public cryptographic library in the binary file of the firmware; In the files where the public cryptographic library is not identified in the binary file to be analyzed, perform clustering according to the similarity of the files to identify the private cryptographic library in the binary file to be analyzed.

2. The firmware password library detection method based on similarity analysis according to claim 1, wherein After performing the step of identifying the private cryptographic library in the binary file to be analyzed, the method further includes: Map the password functions of the public cryptographic library in the binary file to be analyzed to the APIs of the dataset binary file, and extract the APIs of the password functions of the public cryptographic library in the binary file to be analyzed.

3. The firmware password library detection method based on similarity analysis according to claim 2, wherein After performing the step of identifying the private cryptographic library in the binary file to be analyzed, the method further includes: Parse the number and type of parameters of each function in the private cryptographic library in the binary file to be analyzed through static analysis, and extract the APIs of the password functions of the private cryptographic library in the binary file to be analyzed.

4. The firmware password library detection method based on similarity analysis according to claim 3, characterized in that The step of constructing a public cryptographic library dataset and obtaining the binary file of the public cryptographic library dataset as the dataset binary file further includes: Perform similarity analysis among different binary files of the same public cryptographic library, and deduplicate all binary files of the public cryptographic library dataset according to the similarity analysis result to obtain the dataset binary file.

5. The firmware password library detection method based on similarity analysis according to claim 4, wherein, The step of unpacking the firmware to be detected to obtain the binary file of the firmware as the binary file to be analyzed further includes: Unpack the firmware to be detected to obtain all binary files of the firmware, identify the cryptographic algorithms of all binary files of the firmware, and use the binary file of the firmware containing the cryptographic algorithm as the binary file to be analyzed.

6. The firmware password library detection method based on similarity analysis according to claim 4, wherein The step of unpacking the firmware to be detected to obtain the binary file of the firmware as the binary file to be analyzed further includes: Unpack the firmware to be detected to obtain all binary files of the firmware, identify the cryptographic algorithms of all binary files of the firmware, and use the binary file of the firmware containing more than a first threshold number of cryptographic algorithms as the binary file to be analyzed.

7. The firmware password library detection method based on similarity analysis according to claim 5 or 6, characterized in that, The step of performing file similarity analysis on the binary file to be analyzed and the dataset binary file to identify the public cryptographic library in the binary file of the firmware further includes: Perform file similarity analysis on the binary file to be analyzed and the dataset binary file by means of function - to - function similarity.

8. The firmware password library detection method based on similarity analysis according to claim 7, characterized in that, The function - to - function similarity includes the overall function similarity and the number of exactly - matching basic blocks.

9. The firmware password library detection method based on similarity analysis according to claim 8, wherein, The step of performing file similarity analysis on the binary file to be analyzed and the dataset binary file to identify the public cryptographic library in the binary file of the firmware further includes: Perform file similarity analysis on the binary file to be analyzed and the dataset binary file by means of the similarity between function sequences.

10. The firmware password library detection method based on similarity analysis according to claim 4, characterized in that, The step of performing similarity analysis between different binary files in the same public password library and removing duplicates from all binary files in the public password library dataset according to the similarity analysis result to obtain the dataset binary file further includes: If the function lists in two binary files in the same public password library are exactly the same and the similarity of the corresponding functions reaches or exceeds the second threshold, then the two binary files are considered similar, and the two binary files are de-duplicated.

11. The firmware password library detection method based on similarity analysis according to claim 5 or 6, characterized in that, The step of identifying cryptographic algorithms for all binary files of the firmware further includes: Use IDA Pro and its plugin findcrypt-yara to identify the cryptographic algorithm.

12. The firmware password library detection method based on similarity analysis according to claim 8, wherein, The similarity between functions is calculated by bindiff.

13. The firmware password library detection method based on similarity analysis according to claim 9, characterized in that The step of performing file similarity analysis on the binary file to be analyzed and the dataset binary file by means of the similarity between function sequences further includes: Calculate the similarity between function sequences according to at least one of the number of similar functions or the order of functions.

14. A firmware password library detection device based on similarity analysis, characterized in that, Including a dataset construction module, a public password library identification module, a private password library identification module, and an API extraction module; wherein, The dataset construction module is used to construct a public password library dataset, obtain the binary files of the public password library dataset as dataset binary files, and unpack the firmware to be detected to obtain the binary files of the firmware as binary files to be analyzed; The public password library identification module is used to perform file similarity analysis on the binary file to be analyzed and the dataset binary file to identify the public password library in the binary file of the firmware; The private password library identification module is used to cluster according to the similarity of the files in the binary files of the firmware where the public password library is not identified, to identify the private password library in the binary file to be analyzed; The API extraction module is used to map the password functions of the public password library in the binary file to be analyzed to the APIs of the dataset binary files, and extract the APIs of the password functions of the public password library in the binary file to be analyzed; parse the number and type of parameters of each function in the private password library in the binary file to be analyzed through static analysis, and extract the APIs of the password functions of the private password library in the binary file to be analyzed.

15. A computer device, comprising a memory and a processor, the memory storing a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1-13.

16. A computer-readable storage medium, characterized in that, A computer program is stored thereon; the computer program is executed by a processor to implement the method according to any one of claims 1-13.

Citation Information

Patent Citations

  • Encryption method for network security

    CN113726752A

  • Software supply chain security detection method and device, electronic equipment, and storage medium

    CN114077741A