A Compilation Check Method for C Language Declaration and Definition Security Guidelines

By compiling and checking the security criteria defined by C language declarations, the problem of insufficient declaration definition inspection in the existing technology is solved, and the security and accuracy improvement in multi-file scenarios is achieved.

CN115964047BActive Publication Date: 2025-07-11WUXI ADVANCED TECH RES INST
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202211547599.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-05
Publication Date
2025-07-11
Estimated Expiration
2042-12-05

AI Technical Summary

Technical Problem

Existing C compilers have insufficient inspections in declaration definitions, which cannot effectively prevent the introduction of vulnerabilities, and cannot detect inconsistent declaration definitions in multi-file compilation scenarios.

Method used

Provides a compilation inspection method for C declaration definition security criteria, including macro security check, data and function security check, and variable layout security check. By reading source files and storing macro information using containers, cross-file declaration definition inspection, combining hash value comparison algorithm and position relationship analysis, output alarm information that violates the declaration definition.

Benefits of technology

Effectively avoid semantic logic confusion and security issues in subsequent code caused by incorrect declaration definitions, and improves the security and accuracy of the compiler in multi-file scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115964047B_ABST
    Figure CN115964047B_ABST
Patent Text Reader

Abstract

The present invention discloses a compilation checking method for C language statement definition security criteria, including: reading a source file to be checked; performing macro security checking, data and function security checking, and variable layout security checking on the source file, and outputting an alarm message when code violating the statement definition criteria is detected; implementing security checking for macro definition-related criteria through processes such as macro definition capture, macro information storage, and macro information processing; performing data and function security checking through single-file or cross-file processing to implement security checking for statement definition-related criteria such as variables, structures, unions, enums, bit definitions, functions, etc.; performing variable layout security checking by constructing a complete function body structure diagram with the function body as the unit to implement security checking for statement definition position-related criteria; the present invention checks code with vulnerabilities to avoid semantic logic confusion and security problems in subsequent code caused by incorrect statement definitions.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of compilation detection, and particularly relates to a compilation checking method for C language statement definition security criteria. Background Art

[0002] Currently, mainstream C compilers mainly follow the relevant regulations in the ISO C language standard for checking statement definitions. Different C compilers perform checks according to different C language standards (such as C90, C99, C11, C18, etc.). The C compiler checks are mainly carried out in three stages: the first is the preprocessing and lexical analysis stage, which mainly checks the statement definition names, meanings, and formats; the second is the syntax analysis stage, which mainly checks elements such as structures and functions; and the last is the semantic analysis stage, which mainly checks the statement definition types.

[0003] Regarding the checks for C language statement definitions, most C compilers only implement the relevant descriptions in the ISO C language standard, and the ISO standard has relatively few constraints on statement definition security. For example, it allows the redefinition of C language keywords, which easily introduces some vulnerabilities that can be exploited. Therefore, the original C language standard often fails to meet the security requirements when used in some large projects.

[0004] In addition, most existing compilers cannot perform some cross-procedure code checks. For example, statement definition macros such as #define are already "deleted" by the compiler during the preprocessing stage. After the macro expansion in the preprocessing stage, it is impossible to determine whether it is a macro in the subsequent syntax analysis and semantic analysis processes. Therefore, it is also impossible to check the code with vulnerabilities, and incorrect statement definitions will cause the semantic logic of the subsequent code to be chaotic, thereby introducing code security problems.

[0005] On the other hand, the compiler takes a single source file as the compilation unit and automatically discards the source code information obtained from this file after completing the overall compilation process, and it is impossible to detect the hidden dangers caused by inconsistent statement definitions in different files in the multi-file compilation scenario. Summary of the Invention

[0006] The purpose of the present invention is to provide a compilation checking method for C language statement definition security criteria, which can check the code with vulnerabilities and avoid the semantic logic chaos and security problems of the subsequent code caused by incorrect statement definitions.

[0007] To achieve the above object, the technical solution adopted by the present invention is:

[0008] The first aspect of the present invention provides a compilation checking method for C language statement definition security criteria, including:

[0009] Read the source file to be checked; perform macro security checks, data and function security checks, and variable layout security checks on the source file, and output alarm information when code violating the declaration and definition criteria is detected;

[0010] The method for performing macro security checks on the source file includes:

[0011] Capture macro definitions in the source file to obtain complete macro information, encapsulate each piece of macro information into a class, and use a container to store the macro information; the container provides basic information access interfaces, and the information access interfaces are called by the compiler;

[0012] Perform security checks on the macro information obtained through the information access interface during the compilation stage.

[0013] Preferably, the method for capturing macro definitions in the source file to obtain complete macro information includes:

[0014] Detect the "#" mark through character matching in the source file, and then obtain the macro information after "#" through string cutting; the macro information includes the macro name, definition content, location information, and length information.

[0015] Preferably, the method for performing security checks on the macro information obtained through the information access interface during the compilation stage includes:

[0016] Obtain the macro name, definition content, location information, and length information through the information access interface during the compilation stage;

[0017] Complete the corresponding security checks according to the macro security rules using keyword matching methods, string recognition methods, or length judgment methods.

[0018] Preferably, the method for performing data and function security checks on the source file includes:

[0019] When performing declaration and definition checks within a single source file, directly obtain the necessary syntax and semantic information through relevant interfaces in the compiler, and perform checks in combination with the corresponding security criteria;

[0020] When performing cross-file compilation checks on multiple source files, traverse all source files, record the declaration and definition of data and functions in each source file one by one, and store them in a local data structure; when a keyword involving cross-files is detected, add a special mark to the recorded information;

[0021] During formal compilation, for declarations with special marks, search for corresponding definitions in the locally stored data structure based on the hash value comparison algorithm to complete the corresponding security checks.

[0022] Preferably, the method for performing variable layout security checks on the source file includes:

[0023] Construct a complete function body structure diagram based on the function bodies in the source file, calculate the relative positions of each declaration and definition within the function body, and through the analysis of the positional relationship, detect the declarations and definitions that violate the security criteria.

[0024] Preferably, the method for outputting an alarm message when detecting code that violates the declaration and definition criteria includes:

[0025] The declaration and definition criteria include mandatory criteria and recommended criteria; when detecting code that violates the mandatory criteria, output "Error" as the alarm message; when detecting code that violates the recommended criteria, output "Warning" as the alarm message.

[0026] The second aspect of the present invention provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that when the processor executes the program, it implements the steps of the compilation inspection method described in Embodiment 1.

[0027] Compared with the prior art, the beneficial effects of the present invention are:

[0028] The present invention conducts macro security inspection, data and function security inspection, and variable layout security inspection on the source file, and outputs an alarm message when detecting code that violates the declaration and definition criteria; it inspects the code with vulnerabilities to avoid semantic logic confusion and security problems in subsequent code caused by incorrect declarations and definitions. Description of the Drawings

[0029] Figure 1 is a structure diagram of a compilation inspection method for C language declaration and definition security criteria provided in Embodiment 1 of the present invention.

[0030] Figure 2 is a flowchart of macro security inspection provided in Embodiment 1 of the present invention;

[0031] Figure 3 is a flowchart of data and function security inspection provided in Embodiment 1 of the present invention;

[0032] Figure 4 is a flowchart of variable layout security inspection provided in Embodiment 1 of the present invention. Detailed Embodiments

[0033] The present invention will be further described below with reference to the drawings. The following embodiments are only used to more clearly illustrate the technical solutions of the present invention and should not be used to limit the protection scope of the present invention.

[0034] Embodiment 1

[0035] This embodiment designs a compilation check technology for the declaration and definition class security criteria in GJB 8114-2013 "Secure Subset of C / C++ Language Programming" (hereinafter referred to as the "Secure Subset"). The "Secure Subset" stipulates a programming secure subset that is stricter than the language standard for C and C++ languages respectively. This standard applies to military safety-critical software written in C / C++ language. Among them, the security criteria for the C language are divided into 13 categories, and declaration and definition is one of them, involving inspections of aspects such as macros, variables, structures, unions, enums, bit definitions, functions, etc. There are a total of 29 criteria, including 23 mandatory criteria and 6 recommended criteria. For the details of the criteria, please refer to the "Secure Subset".

[0036] As Figures 1 to 4 shown, the present invention provides a compilation check method for the declaration and definition security criteria of the C language, including:

[0037] Reading the source file to be checked; performing macro security check, data and function security check, and variable layout security check on the source file;

[0038] As Figure 2 shown, the method for performing macro security check on the source file includes:

[0039] The method for capturing complete macro information by performing macro definition capture on the source file includes:

[0040] Performing character matching on the source file to detect the "#" mark, and then obtaining the macro information after "#" through string cutting; the macro information includes macro name, definition content, location information, and length information. For different macro types, users can customize different keywords or lexical rules, and all the macros that users need to check can be intelligently captured according to the keywords and rules.

[0041] Encapsulating each item of macro information into a class and storing the macro information using a container; the container provides basic information access interfaces, and the information access interfaces are called by the compiler; users can add attributes and methods through subclass inheritance to achieve function expansion; the encapsulated macros can be obtained and checked during the security check phase, realizing some security check functions that the compiler cannot perform due to "deleting" macros in the preprocessing phase.

[0042] The method for performing security check on the macro information obtained through the information access interface during the compilation phase includes:

[0043] Obtaining the macro name, definition content, location information, and length information through the information access interface during the compilation phase; completing the corresponding security check according to the macro security rules using keyword matching method, string recognition method, or length judgment method.

[0044] As Figure 3As shown, the data and function security check function implements security checks for the relevant criteria of declarations and definitions such as variables, structures, unions, enums, bit definitions, and functions.

[0045] For the declaration and definition check within a single source file, directly obtain the necessary syntax and semantic information through the relevant information access interfaces in the compiler, and perform checks in combination with the corresponding security criteria, including using the type analysis interface to judge whether the variable types are consistent, using the variable length analysis interface to judge whether the bit length of signed integer variables in bit definitions is greater than 1, and using the string conversion interface to judge whether char variables are clearly defined as signed or unsigned.

[0046] When performing cross-file compilation checks on multiple source files, the methods for data and function security checks on source files include:

[0047] Traverse all source files, record the declarations and definitions of data and functions in each source file one by one, and store them in the local data structure; when detecting keywords related to cross-files (such as "extern"), add a special mark to the recorded information.

[0048] During formal compilation, for declarations with special marks, based on the hash value comparison algorithm, search for the corresponding definitions in the local stored data structure to complete the security check of cross-source file declarations and definitions. At the same time, it can be further extended according to requirements, such as storing the location information of declarations and definitions to complete more in-depth cross-source file security checks.

[0049] Such as Figure 4 As shown, the methods for variable layout security checks on source files include:

[0050] Construct a complete function body structure diagram with the function body in the source file as the unit, calculate the relative positions of each declaration and definition within the function body in the function body, and check the declarations and definitions that violate the security criteria through position relationship analysis. Users can customize different declaration and definition check rules according to different requirements, and can be implemented at each stage of the compiler, improving the flexibility and comprehensiveness of security checks.

[0051] The methods for outputting alarm information when detecting code that violates the declaration and definition criteria include:

[0052] The said declaration and definition criteria are determined in the "Security Subset"; the said declaration and definition criteria include mandatory criteria and recommended criteria; when detecting code that violates the mandatory criteria, output "Error" as the alarm information; when detecting code that violates the recommended criteria, output "Warning" as the alarm information;

[0053] The C compiler can identify all the security guidelines for C language declarations and definitions in the "Security Subset" and issue error or warning messages according to the corresponding requirements. At the same time, this embodiment can control the enabling of single or all declaration and definition security checks through compilation options. When a single security check is enabled, the loss to the compiler performance is relatively small. In addition, this embodiment adopts a modular design. All the code for security checks is located in newly added independent files. Only the call entry is added to the compiler source code, and the object data in the context is read-only and not written. Therefore, it will not affect the source code structure and original functions of the compiler.

[0054] Embodiment 2

[0055] An electronic device includes a memory, a processor, and a computer program stored on the memory and executable on the processor. It is characterized in that when the processor executes the program, the steps of the compilation check method described in Embodiment 1 are implemented.

[0056] Those skilled in the art should understand that the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memories, CD-ROMs, optical memories, etc.) containing computer-usable program code.

[0057] The present application is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each flow and / or block in the flowchart and / or block diagram can be implemented by computer program instructions, and the combination of the flows and / or blocks in the flowchart and / or block diagram can also be implemented. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate means for implementing the functions specified in Figure 1 one or more flows and / or blocks Figure 1 one or more blocks.

[0058] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured product including instruction means, and the instruction means implements the functions specified in Figure 1 one or more flows and / or blocks Figure 1 one or more blocks.

[0059] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus, so that a series of operation steps are executed on the computer or other programmable apparatus to produce a computer-implemented process, thereby providing instructions for implementing the processes Figure 1 one process or a plurality of processes and / or blocks Figure 1 steps for the functions specified in one block or a plurality of blocks.

[0060] The above are only the preferred embodiments of the present invention. It should be pointed out that for those of ordinary skill in the art, without departing from the technical principle of the present invention, several improvements and modifications can be made, and these improvements and modifications should also be regarded as the protection scope of the present invention.

Claims

1. A compilation check method for C language declaration and definition security guidelines, characterized in that, Including: Read the source file to be checked; Conduct macro security check, data and function security check, and variable layout security check on the source file. When code violating the declaration and definition guidelines is detected, output an alarm message; The method for conducting macro security check on the source file includes: Capture macro definitions in the source file to obtain complete macro information, encapsulate each piece of macro information into a class, and use a container to store the macro information; the container provides basic information access interfaces, and the information access interfaces are called by the compiler; During the compilation stage, obtain macro information through the information access interface for security check.

2. The compilation check method for the security criteria of C language declaration definition according to claim 1, characterized in that The method for capturing macro definitions in the source file to obtain complete macro information includes: Conduct character matching on the source file to detect the "#" mark, and then obtain the macro information after "#" through string cutting; the macro information includes macro name, definition content, location information, and length information.

3. The compilation check method for the safety criteria defined by C language declarations according to claim 2, characterized in that The method for conducting security check by obtaining macro information through the information access interface during the compilation stage includes: During the compilation stage, obtain the macro name, definition content, location information, and length information through the information access interface; Complete the corresponding security check according to the macro security rules using keyword matching method, string recognition method, or length judgment method.

4. A compilation check method for the security criteria defined by C language declarations according to claim 1, characterized in that, The method for conducting data and function security check on the source file includes: When checking the declaration and definition within a single source file, directly obtain the necessary syntax and semantic information through relevant interfaces in the compiler, and conduct the check in combination with the corresponding security guidelines; When conducting cross-file compilation check on multiple source files, traverse all source files, record the declaration and definition of data and functions in each source file one by one, and store them in a local data structure; when a keyword involving cross-files is detected, add a special mark to the recorded information; During the formal compilation, for the declarations with special marks, search for the corresponding definitions in the local stored data structure based on the hash value comparison algorithm to complete the corresponding security check.

5. A compilation check method for a C language statement definition security criterion according to claim 1, characterized in that The method for conducting variable layout security check on the source file includes: Construct a complete function body structure diagram with the function body in the source file as the unit, calculate the relative positions of each declaration and definition inside the function body in the function body, and detect the declaration and definition violating the security guidelines through position relationship analysis.

6. A compilation check method for C language statement definition security criteria according to claim 1, characterized in that The method for outputting an alarm message when code violating the declaration and definition guidelines is detected includes: The declaration and definition guidelines include mandatory guidelines and recommended guidelines; when code violating the mandatory guidelines is detected, output "Error" as the alarm message; when code violating the recommended guidelines is detected, output "Warning" as the alarm message.

7. An electronic device, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the steps of the compilation check method described in any one of claims 1 to 6.

Citation Information

Patent Citations

  • Compilation checking method and system oriented to C language pointer security

    CN116661796A