A Method for Classifying and Detecting Misuses of Cryptography in C / C++

By extracting the code attribute diagram and symbol execution of C/C++ code, combining OpenSSL document classification and prefix search tree, we identify C/C++ cryptography misuse, solving the problem of detecting environment dependence and API differences in the existing technology, and achieving efficient cryptography misuse detection.

CN116243970BActive Publication Date: 2025-07-22BEIJING UNIV OF POSTS & TELECOMM
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202310233257.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-03-06
Publication Date
2025-07-22
Estimated Expiration
2043-03-06

AI Technical Summary

Technical Problem

The existing C/C++ cryptography misuse detection technology relies on the compilation environment, resulting in detection failures, and lacks a common method to detect the differences in API misuse between different encryption libraries.

Method used

Code attribute graph (CPG) is extracted through fuzzy analysis, and based on the OpenSSL document classification function interface, combined with symbol execution and prefix search tree, cryptography elements and misuse rules sets are constructed to identify cryptography misuse.

Benefits of technology

It realizes comprehensive detection without compiling code, improves the ease of use and robustness of detection, covers 30 cryptographic misuse problems, and expands the detection range.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116243970B_ABST
    Figure CN116243970B_ABST
Patent Text Reader

Abstract

The present invention discloses a method for classifying and detecting cryptographic misuse in C / C++, belonging to the field of information security. Specifically, first, perform fuzzing analysis on the C / C++ source code to extract the Code Property Graph (CPG). Then, classify various function interfaces provided in the OpenSSL documentation. When the parameters required by the interface function involve cryptographic properties, classify the interface function into the key function set A. Next, start traversing from the root node of the CPG. When a function call node is encountered, determine whether the name of the called function at this node belongs to the key function set A. If so, add this node to the key function list; otherwise, continue to traverse the CPG downward until there are no successor nodes. Analyze and extract each item in the key function list to obtain the corresponding element table for each item, further construct the final cryptographic elements, and identify the misuse types therein. Compared with other detection technologies, the present invention reduces the conditions required for detection and improves the usability of the program.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of application security in information security, and specifically relates to a method for classifying and detecting C / C++ cryptographic misuses. Background Art

[0002] With the development of the Internet, more and more software development involves user data and privacy protection. During the software development process, while implementing the business logic of the software itself, it is also necessary to implement corresponding information security functions. When using software to communicate with the Internet, the three basic elements of information security need to be satisfied: availability, confidentiality, and integrity.

[0003] With the development of cryptographic applications, different languages have gradually begun to support various existing cryptographic primitives and secure communication frameworks. For example, JAVA provides JCA and JSSE as tools for secure communication in JAVA software; these cryptographic libraries provide interfaces for relevant cryptographic primitives in software development. However, understanding the correct usage of cryptographic primitives requires a certain learning threshold, and cryptographic primitives are necessary for information security in software development. Since most developers do not understand cryptography and its applications, when it comes to the development of cryptographic applications, they often habitually search for relevant example codes on the Internet without truly understanding the role of cryptographic primitives, resulting in the introduction of cryptographic misuses.

[0004] At the present stage, there are a large number of misuse problems in data encryption, message digest generation, and the use of SSL frameworks, mainly including the use of outdated cryptographic algorithms, incorrect algorithm configurations, and incorrect verification logics.

[0005] Most of the current tools are aimed at the cryptographic misuse in Android applications. For example, Zhiwu Xu et al. [1] proposed a method based on probability model to statically detect the use of cryptographic APIs in Android applications; Cong Sun et al. [2] developed the CryptoEval tool to determine the risk level caused by cryptographic misuse in Android applications; Larry Singleton et al. developed FireBugs [3] to detect the use of cryptographic APIs in Android applications; Sascha Fahl et al. [4] proposed MalloDroid to analyze the code related to secure communication in Android applications and judge whether the detected application will be attacked by MITM due to the abuse of SSL-related interfaces; Manuel Egele et al. [5] developed CryptoLint to statically detect common misuse cases; Ildar Muslukhov et al. [6] developed the BinSight tool to confirm the source of cryptographic abuse by statically detecting the third-party cryptographic libraries used in Android applications; Siqi Ma et al. [7] developed CDRep to automatically repair the cryptographic misuse in Android applications. Some general code detection tools also support the detection of cryptographic misuse, such as Sonarqube [8] and Xanitizer [9] supporting the detection of cryptographic misuse related to CWE327, CWE295, CWE330, CWE326 and CWE757.

[0006] There are relatively few techniques for detecting cryptographic misuse in C / C++ code. For example, reference

[10] proposed using taint analysis to extract the semantic information of cryptographic misuse in C / C++ code to complete the detection of cryptographic misuse.

[11] Lin Hao et al. identified cryptographic vulnerabilities under the Windows platform through dynamic analysis.

[0007] Currently, the detection of cryptographic misuse in C / C++ can be divided into two categories: static detection and dynamic detection. Among them, static detection uses the language checking ability of Clang to extract the AST graph of the code, and matches the cryptographic semantic information extracted from the AST graph with the existing cryptographic misuse rules. Dynamic detection compiles the C / C++ code into an executable file and then uses binary instrumentation to detect the cryptographic API call information during program runtime for capture and analysis to confirm whether there is cryptographic misuse. However, there are mainly two deficiencies in the current detection techniques for C / C++ cryptographic misuse:

[0008] 1) The code information extraction technology needs to compile the code. This type of method depends on the detection environment, and many codes may require a special development environment. When detecting such codes, the detection may fail due to problems such as compilation failure.

[0009] 2) Since there are many types of encryption libraries in C / C++, and the APIs between various encryption libraries are different, there is currently no general method to detect the misuses existing in various cryptographic libraries.

[0010] References:

[0011] [1] Xu Z, Hu X, Tao Y, et al. Analyzing Cryptographic API Usages for Android Applications Using HMM and N-Gram[C] / / 2020 International Symposium on Theoretical Aspects of Software Engineering(TASE). IEEE, 2020:153-160.

[0012] [2] Sun C, Xu X, Wu Y, et al. CryptoEval: Evaluating the Risk of Cryptographic Misuses in Android Apps with Data-Flow Analysis[J]. arXiv preprint arXiv:2112.06146, 2021.

[0013] [3] Singleton L, Zhao R, Siy H, et al. FireBugs: Finding and Repairing Cryptography API Misuses in Mobile Applications[C] / / 2021 IEEE 45th Annual Computers, Software, and Applications Conference(COMPSAC). IEEE, 2021:1194-1201.

[0014] [4] Fahl S, Harbach M, Muders T, et al. Why Eve and Mallory love Android: An analysis of Android SSL(in)security[C] / / Proceedings of the 2012 ACM conference on Computer and communications security. 2012:50-61.

[0015] [5] Egele M, Brumley D, Fratantonio Y, et al. An empirical study of cryptographic misuse in android applications[C] / / Proceedings of the 2013 ACM SIGSAC conference on Computer & communications security. 2013:73-84.

[0016] [6] Muslukhov I, Boshmaf Y, Beznosov K. Source attribution of cryptographic api misuse in android applications[C] / / Proceedings of the 2018 on Asia Conference on Computer and Communications Security. 2018:133-146.

[0017] [7] Ma S, Lo D, Li T, et al. Cdrep: Automatic repair of cryptographic misuses in android applications[C] / / Proceedings of the 11th ACM on Asia Conference on Computer and Communications Security. 2016:711-722.

[0018] [8] sonarqube https: / / www.sonarqube.org /

[0019] [9] xanitizer https: / / www.xanitizer.com /

[0020]

[10] Rahaman S, Cai H, Chowdhury O, et al. From Theory to Code: Identifying Logical Flaws in Cryptographic Implementations in C / C++[J]. IEEE Transactions on Dependable and Secure Computing, 2021, 19(6): 3790-3803.

[0021]

[11] Lin Hao. Research on the Detection Method of Password Misuse Vulnerabilities in Windows Encryption Application Programs[D]. Information Engineering University of Strategic Support Force, 2018. Summary of the Invention

[0022] In view of the above problems, the present invention proposes a method for classifying and detecting C / C++ cryptographic misuse. Through general cryptographic misuse classification techniques, it comprehensively covers cryptographic misuse problems and can eliminate differences in the use of different encryption library APIs. At the same time, based on the classification, a cryptographic misuse detection process is proposed, which can analyze the code, extract code information, and judge the cryptographic misuse existing in the code without compiling the code.

[0023] The specific steps of the C / C++ cryptographic misuse classification and detection method are as follows:

[0024] Step 1: Use the extraction tool joern-fuzzyc to perform fuzzy analysis on the C / C++ source code and extract the code property graph CPG;

[0025] The code property graph CPG contains nodes and edges;

[0026] Among them, the node types include AST-related nodes, control flow graph-related nodes, and data flow graph-related nodes;

[0027] All nodes are stored in nodes.csv; if a certain node is a statement, then the location attribute represents the offset of the statement in the file, otherwise it is a null value; if a certain node belongs to the control flow graph, the attribute value of isCFGNode is true. Each node has a code attribute, which is used to describe the value of the node.

[0028] Among the types of edges, there are edges related to REACH, IS_AST_PARENT, DEF, USE, etc., and those related to AST, control flow graph, and data flow graph; subgraphs belonging to the same file are connected to the File node by edges of the IS_FILE_OF type, and nodes related to AST are connected by edges of the IS_AST_PARENT type; nodes related to the same control flow graph are connected to the CFGEntryNode by edges of the CONTROLS type; if there is a data flow relationship between two nodes, then in the code property graph CPG, the two nodes are connected by an edge of the FLOWS_TO type.

[0029] The extraction tool Joern analyzes variables in the code and generates a symbol table. Each symbol is stored in a node symbol. Nodes related to variables are connected to the node symbol. If it is a statement node that defines the variable, it is connected by an edge DEF; if the variable is used in a statement, the node symbol and the statement node are connected by an edge USE, and at the same time, nodes using the same symbol are connected by an edge REACHES.

[0030] Step 2: Classify various function interfaces provided in the OpenSSL document. When the parameters required by the interface function F involve cryptographic properties, the interface function F is classified into the key function set A.

[0031] Step 3: Starting from the root node of the code property graph CPG, traverse the code property graph CPG. When encountering a function call node, determine whether the name of the called function of this node belongs to the key function set Α. If so, add this node to the key function list; otherwise, continue to traverse the code property graph CPG downward until there are no successor nodes.

[0032] Step 4: Analyze and extract each item in the key function list to obtain the corresponding element table for each item.

[0033] Specifically: For the i-th item α in the list i , for the called function in this item, extract the parameter list passed in when the function is called. For each parameter p i perform the following operations:

[0034] 1) If p i is a constant or a macro definition of a constant in the OpenSSL document, directly record it in the element table P i .

[0035] 2) If p iIf it is the variable v, traverse the Code Property Graph (CPG) starting from the root node to find the statements that modify the variable v, forming a statement sequence S. Perform symbolic execution operations on the variables and expressions involved in the statement sequence S, and calculate the value of the modified variable v after passing through these statements when α is passed in. i Store this value in the feature table P. i

[0036] The calculation process of the symbolic execution operation is as follows:

[0037] First, construct a symbol table T, add the variables involved in the sequence S to the symbol table T, search the Code Property Graph (CPG) to find the initialization statements of the variables in the symbol table T, and initialize the variables in the symbol table T.

[0038] Then, perform symbolic execution operations one by one in the order of the statements in the sequence S in the code, and calculate the modification results of the values of the variables in the symbol table T after each statement is executed.

[0039] The specific calculation method is: calculate the result of the expression on the right side of the assignment operator in the assignment statement, and modify the symbol value that appears on the left side of the assignment operator in the symbol table T.

[0040] Finally, after executing all the statements in the sequence S, obtain the final result of the variable v from the symbol table T and store it in the feature table P. i

[0041] 3) If p i is an expression, extract all the variables v in the expression, perform step 2) for the variable v to calculate the value when passing into this expression, and then calculate this expression to obtain the final value passed into α i and record this value in the feature table P. i

[0042] Finally, count all the elements in the table to form the feature table P of the i-th item of α i ={p1, p2,..., p i}; Similarly, perform the above operations for each item in the key function list to obtain the corresponding feature tables for each item. n}

[0043] Step Five: Use the corresponding feature tables for each item to construct the final cryptographic elements and identify the misusage types among them.

[0044] First, find each calling function in the set A of key functions and establish their respective corresponding prefix search trees.

[0045] Then, for each calling function, classify the cryptographic misuses in the code by checking the specific values of the parameters passed when calling the key function, forming a cryptographic misuse rule set Γ.​​​

[0046] Specifically, each parameter of the function corresponds to a cryptographic attribute respectively. The cryptographic library API is applied to map each parameter to various cryptographic attributes, that is, each parameter of the cryptographic library API is corresponded to the cryptographic attributes to form the set Β. For a pair {α,β}, where α∈Α and β∈Β, a misuse type γ is formed. All misuse types constitute the cryptographic misuse rule set Γ.

[0047] Next, a prefix search tree is used to construct a cryptographic misuse index and match it with the cryptographic misuse rule set Γ.

[0048] For the calling function fun, the root node of its prefix search tree is this key function, and the last leaf node is the misuse type m; the middle n layers correspond to the number of parameters of the function;

[0049] When the cryptographic element table of the calling function fun is obtained, each element in the element table, that is, each corresponding parameter, is matched with the nodes of the prefix search tree of the calling function fun one by one. When the current parameter in the element table meets the judgment condition of the node of the prefix search tree, it is considered that the cryptographic application implemented by the calling function fun contains the misuse type m;

[0050] A complete cryptographic element c and a cryptographic misuse type are formed: c = (fun, {p1, p2, …}, m).

[0051] The advantages of the present invention are as follows:

[0052] 1). The C / C++ cryptographic misuse classification and detection method of the present invention proposes the concept of cryptographic elements, and can construct a mapping between cryptographic misuse problems and the specific usage of the cryptographic library API, that is, by expanding the configuration file and adding database entries to expand the detection scope and increase the number of cryptographic libraries that can be detected.

[0053] 2). The C / C++ cryptographic misuse classification and detection method of the present invention proposes 30 cryptographic misuse rules, which comprehensively cover the currently proposed cryptographic misuse problems.

[0054] 3). The C / C++ cryptographic misuse classification and detection method of the present invention combines fuzzy detection and symbolic execution to detect the code without compiling the code. Compared with other detection technologies, it reduces the conditions required for detection and improves the usability of the program. BRIEF DESCRIPTION OF THE DRAWINGS

[0055] Figure 1 It is the schematic diagram of the C / C++ cryptographic misuse classification and detection method of the present invention;

[0056] Figure 2 This is a flowchart of a method for classifying and detecting cryptographic misuses in C / C++;

[0057] Figure 3 This is a schematic diagram of a cryptographic misuse type for matching called functions using a prefix search tree given in an embodiment of the present invention. Detailed implementation manners

[0058] Next, in conjunction with the accompanying drawings, the implementation manners of the present invention will be described in detail and clearly.

[0059] The present invention proposes a method for classifying and detecting cryptographic misuses in C / C++, aiming to use static code analysis to detect cryptographic misuse problems in OpenSSL applications. It is a comprehensive cryptographic misuse classification technology based on OpenSSL, which can detect misuses in OpenSSL cryptographic applications, solve the defect that existing detection tools require a complete compilation environment, and improve the robustness of the detection program.

[0060] The method for classifying and detecting cryptographic misuses in C / C++ is as Figure 1 shown. The overall detection process is as follows: input the C / C++ source code, first use an extraction tool to extract the code property graph (CPG) of the code; after obtaining the code property graph, extract the code semantics related to cryptography to obtain cryptographic elements. After obtaining the cryptographic elements, by analyzing the values of the cryptographic elements and matching them with the cryptographic misuse rule set, determine the values of cryptographic misuses existing in the code, and output them as cryptographic misuse types.

[0061] As Figure 2 shown, the specific steps are as follows:

[0062] Step 1: Use the extraction tool joern-fuzzyc to perform fuzzy analysis on the C / C++ source code and extract the code property graph CPG;

[0063] The code property graph CPG includes nodes and edges;

[0064] Among them, the node types are shown in Table 1, including nodes related to the AST (such as Identifier, CallExpression, ArgumentList, Callee, Argument, etc.), nodes related to the control flow graph (such as CFGEntryNode, etc.) and nodes related to the data flow graph (such as Symbol, etc.);

[0065] All nodes are stored in nodes.csv; if a node is a statement, the location attribute represents the offset of the statement in the file, otherwise it is a null value; if a node belongs to a control flow graph, the value of the isCFGNode attribute is true. Each node has a code attribute to describe the value of the node.

[0066] Table 1

[0067] Node Type Description Function Function Definition Node Symbol Symbol Node for Data Flow Analysis File File Node Indicating the Source Code File Name of the CPG CFGEntryNode Control Flow Entry CFGExitNode Control Flow Exit AssignmentExpr Assignment Expression PrimaryExpression Constants Such as Characters, Strings, Numbers, etc. Condition Condition Part of the Conditional Statement ReturnStatement Return Statement ArrayIndexing Array Identifier AST Node Are Connected to Each Other by Edges in the AST.

[0068] Among the types of edges, there are two types of edges, DEF and USE, as shown in Table 2;

[0069] Subgraphs belonging to the same file are connected to the File node by edges of the IS_FILE_OF type, nodes related to the AST are connected by edges of the IS_AST_PARENT type; nodes related to the same control flow graph are connected to the CFGEntryNode by edges of the CONTROLS type; if there is a data flow relationship between two nodes, edges of the FLOWS_TO type are used to connect the two nodes in the code property graph CPG;

[0070] The extraction tool Joern analyzes the variables in the code and generates a symbol table. Each symbol is stored in a node symbol. Nodes related to variables are connected to the node symbol. If it is a statement node that defines the variable, it is connected by an edge DEF; if the variable is used in a statement (such as passing the variable into a function or as an operand of an expression), the node symbol and the statement node are connected by an edge USE, and at the same time, nodes that use the same symbol are connected by an edge REACHES.

[0071] Table 2

[0072]

[0073]

[0074] Step 2: Classify various function interfaces provided in the OpenSSL document. When the parameters required by the interface function F involve cryptographic properties, the interface function F is classified into the key function set A;

[0075] Cryptographic properties include cryptographic algorithms, key lengths, etc.;

[0076] The type of the second parameter of the EVP_Encrypt_Init function is EVP_CIPHER*, and the cryptographic semantics of this parameter is the algorithm for symmetric encryption; similarly, the function of the AES_set_encrypt_key function is to generate a key according to the incoming password. The first parameter of this function receives the password, which may involve the problem of hard-coded keys, and the second parameter will determine the key length, which may involve the misusage type of insufficient key length. Both of these functions are placed in the set A of critical functions.

[0077] Step 3: Starting from the root node of the code property graph CPG, traverse the code property graph CPG. When a function call node is encountered, check this node to determine whether the name of the called function of this node belongs to the set Α of critical functions. If so, add this node to the critical function list; otherwise, continue to traverse the code property graph CPG downward until there are no successor nodes.

[0078] Step 4: Analyze and extract each item in the critical function list. One cryptographic element can be extracted from each item to obtain the corresponding element table for each item.

[0079] Specifically: for the i-th item α in the list i , for the called function in this item, extract the list of parameters passed in when this function is called. These parameters can be variable names, expressions, or constants. For each parameter p i , perform the following operations:

[0080] 1) If p i is a constant or a macro definition of a constant in the OpenSSL documentation, directly record it in the element table P i .

[0081] 2) If p i is a variable v, starting from the root node, search for the definition or declaration statement of this variable. After finding it, traverse the statements in the CPG that modify the value of v to form a statement sequence S. Perform symbolic execution operations on the variables and expressions involved in the statement sequence S, and calculate the value of the modified variable v after passing through these statements when passing into α i , and store this value in the element table P i .

[0082] The calculation process of the symbolic execution operation is as follows:

[0083] First, construct a symbol table T, add the variables involved in the sequence S to the symbol table T, search the code property graph CPG, find the initialization statements of the variables in the symbol table T, and initialize the variables in the symbol table T;

[0084] Then, perform symbolic execution operations one by one in the order of the statements in sequence S appearing in the code, and calculate the modification results of the values of the variables in symbol table T after each statement is executed;

[0085] The specific calculation method is as follows: calculate the result of the expression on the right side of the assignment operator of the assignment statement, and modify the symbol value that appears on the left side of the assignment operator in symbol table T.

[0086] Finally, after all the statements in sequence S are executed, obtain the final result of variable v from symbol table T and store it in element table P i .

[0087] 3) If p i is an expression, extract all variables v in the expression, execute step 2) for variable v to calculate the value when passing into the expression, and then calculate the expression to obtain the value finally passed into α i and record this value in element table P i .

[0088] Finally, count all elements in the table to form the element table P of the i-th item α i ={p1, p2, …, p i}; Similarly, perform the above operations on each item in the key function list to obtain the corresponding element tables for each item. n}

[0089] Step Five: Use the corresponding element table for each item to construct the final cryptographic elements and identify the misusage types among them.

[0090] First, find each calling function in the key function set A and establish their respective corresponding prefix search trees;

[0091] Then, for each calling function, classify the cryptographic misuses in the code by checking the specific values of the parameters passed when calling the key function to form the cryptographic misuse rule set Γ;

[0092] Generally speaking, parameter values are determined by developers when writing programs, such as which algorithm to use, the number of rounds for key generation, the set length of the key, and so on. Therefore, the specific behavior during the call of these key functions can be determined by checking the code semantics in the program. If behaviors such as using insecure algorithms, too short keys, or incorrect certificate verification logic occur, it is considered that there is a cryptographic misuse. These behaviors do not mean that the program execution goes wrong, but these behaviors cannot guarantee information security and are easily exploited by attackers to leak private data. Cryptographic misuse means that for a call of a key function, the program security may not be guaranteed due to incorrect parameter settings and can instead be exploited by attackers. Therefore, the present invention proposes a classification method that maps concepts in cryptography (such as cryptographic algorithms, keys, IVs, etc.) to the numbers of specific functions; and maps abstract cryptographic misuse behaviors to the specific values of parameters during function calls. The cryptographic misuse classification of the code is performed by checking the values in the parameters.

[0093] Specifically: for a certain called function, each parameter of this function respectively corresponds to a cryptographic attribute. The cryptographic library API is applied to map each parameter to various cryptographic attributes, that is, each parameter of the cryptographic library API is corresponded to the cryptographic attributes, forming a set Β. For a pair {α, β}, α ∈ Α, β ∈ Β, a misuse type γ is formed, and all misuse types form a cryptographic misuse rule set Γ.

[0094] Next, a prefix search tree is used to construct a cryptographic misuse index and match it with the cryptographic misuse rule set Γ; the number of indexes is reduced by merging prefixes to improve the search speed.

[0095] For the called function fun, the root node of its prefix search tree is the key function name, and the last leaf node is the misuse type m; the middle n layers correspond to the respective parameters of the function; each node in each layer stores a set, indicating the value range of this parameter in a certain misuse type.

[0096] After obtaining the cryptographic element table of the called function fun, each element in the element table, that is, each corresponding parameter, is matched one by one with the nodes of the prefix search tree of the called function fun. When the current parameter in the element table meets the judgment condition of the node of the prefix search tree, it is considered that the cryptographic application implemented by the called function fun contains the misuse type m;

[0097] For example, the key function misused due to a too short key is AES_set_encrypt_key. This function has three parameters, and the second parameter should be greater than 128. Then, the index tree for the misuse of a too short key has five layers: The root node of the first layer represents the key function. The second layer nodes store NAN, indicating that this misuse has nothing to do with the first parameter. The third layer nodes store <128, indicating that the set key length is too short. The fourth layer is still NAN, and finally, the leaf nodes have descriptions of the misuse of a too short key.

[0098] After obtaining the cryptographic element P of the AES_set_key function call in the code, the value of P is {"123456", 64, ptr}. Matching this index tree, since the first matching condition is NAN, it is considered a successful match. Then, continue to query downward. It is found that 64 belongs to the set <128, and then match downward. The condition of the next node is NAN, and it is considered that the cryptographic element P matches the misuse of a too short key.

[0099] Regarding the classification problem of cryptographic misuses in the present invention, a 3-tuple cryptographic element is defined: C = (α, β, γ); where α is the name of the cryptographic related function, β is the list of function parameters; γ is the possible cryptographic misuse problem.

[0100] Specifically, for a piece of code containing cryptographic misuses, the relevant function calls and statements can be represented by a quadruple: c1 = (fun1, {p1, p2, p3,...}, {m}).

[0101] Where fun1 is the key function name of this cryptographic misuse; {p1, p2,...} is the set of parameter values passed into the function, and m is the type of cryptographic misuse related to the function and the parameters. The semantics of cryptography are represented by these contents: such as cryptographic concepts like the used algorithm, key password, IV, salt value, etc. These information determine the type of cryptographic misuse of this piece of code.

[0102] Each type of cryptographic misuse corresponds to a cryptographic element. The type of cryptographic misuse is judged by checking the cryptographic elements extracted from the code. Specifically, for a type of cryptographic misuse, by extracting the key function in the code, then determining the parameters passed into the function and the relevant statements, and extracting the specific values corresponding to the cryptographic concepts from the parameters and the relevant statements, these values may violate the requirements of cryptographic use, that is, a cryptographic misuse problem occurs, such as selecting an insecure encryption algorithm, using a fixed salt value, using a too short key, etc. This embodiment defines 30 types of cryptographic misuses. For the specific types of cryptographic misuses, see Appendix A:

[0103]

[0104]

[0105] This embodiment proposes a cryptographic misuse classification technology based on OpenSSL. Specifically, it associates cryptographic elements with various API usages in OpenSSL. In OpenSSL, a CTX (context structure) is used to represent a series of cryptographic application processes.

[0106] In OpenSSL, the application of cryptographic algorithms is uniformly encapsulated in the EVP mode. At the same time, in lower versions of OpenSSL, some specific cryptographic applications are also encapsulated, and the cryptographic applications are directly implemented by calling interfaces. Therefore, α in the cryptographic elements belongs to a set of function names Α: the encapsulation functions for various cryptographic behaviors in the EVP mode, and the encapsulation functions for various cryptographic algorithm applications in lower versions of OpenSSL. See Appendix B for a list of some key functions:

[0107] EVP_PKEY_sign SHA1 AES_ecb_encrypt MD5 EVP_EncryptUpdate MD4 SHA512 MD2 EVP_DigestInit EVP_DigestUpdate SSL_CTX_new RSA_generate_key_ex DES_cbc_encrypt DES_ecb_encrypt EVP_BytesToKey RC4

[0108] For each key function, each parameter of the function corresponds to a cryptographic attribute. For example, a function for symmetric encryption requires parameters such as an encryption key, IV, plaintext input, and ciphertext output; the hash digest algorithm requires parameters such as message input and salt. For each cryptographic application API, map its parameters to various cryptographic attributes, that is, map each parameter of the API to the cryptographic attributes. This series of mappings constitutes a set Β. For a pair {α, β}, where α ∈ Α and β ∈ Β, it constitutes a misuse type γ, and various misuses form a set Γ of cryptographic misuse rules.

[0109] As Figure 3 shown, for the call to the function fun1, the prefix tree structure stores three misuse types, namely m1, m2, and m3;

[0110] In the misuse type m1, there are two judgment conditions p1 and p4 in the database. If the parameters passed into the function fun1 meet these two conditions p1 and p4, it is considered that the cryptographic application implemented by the call to the function fun1 contains the misuse type m1.

[0111] In the misuse type m2, there are two judgment conditions p1 and p3. If the parameters passed into the function fun1 meet these two conditions p1 and p3, it is considered that the cryptographic application implemented by the call to the function fun1 contains the misuse type m2

[0112] In misuse type m3, there are two judgment conditions p2 and p3. If the parameters passed into function fun1 meet these two conditions p2 and p3, it is considered that the cryptographic application implemented by calling function fun1 contains misuse type m3

[0113] For the remaining calling functions, there are their respective corresponding prefix search trees. For this section of source code, after all the search trees of all calling functions have been searched, the complete cryptographic element c can be obtained, and thus the type m of cryptographic misuse can be judged.

[0114] The present invention proposes a method for establishing a mapping between cryptographic misuse and a cryptographic algorithm library, namely a cryptographic element. This method abstracts and expresses the common characteristics between cryptographic misuse and cryptographic application code, can construct cryptographic elements based on the specific usage of the algorithm library, has universality, and can establish mappings between different algorithm libraries and cryptographic misuse.

[0115] The cryptographic element generation process proposed by the present invention can extract the cryptographic elements in the code without compiling the code, construct a cryptographic element index, retrieve the detected cryptographic misuse types, and detect the cryptographic misuse problems existing in the code. This method solves the problem of high requirements for the detection environment in the prior art.

Claims

1. A method for classifying and detecting C / C++ cryptographic misuse, characterized in that, The specific steps are as follows: First, use the extraction tool joern-fuzzyc to perform fuzzy analysis on the C / C++ source code and extract the Code Property Graph (CPG). The Code Property Graph (CPG) contains nodes and edges. Among them, the node types include nodes related to the Abstract Syntax Tree (AST), nodes related to the Control Flow Graph (CFG), and nodes related to the Data Flow Graph (DFG). Among the edge types, there are REACH, IS_AST_PARENT, DEF, and USE, as well as edges related to AST, CFG, and DFG. Then, classify various function interfaces provided in the OpenSSL documentation. When the parameters required by the interface function F involve cryptographic properties, classify the interface function F into the set A of key functions. Next, starting from the root node of the Code Property Graph (CPG), traverse the CPG. When a function call node is encountered, determine whether the name of the calling function of this node belongs to the set A of key functions. If so, add this node to the list of key functions; otherwise, continue to traverse the CPG downward until there are no successor nodes. Finally, analyze and extract each item in the list of key functions to obtain the corresponding element table for each item; use the element table corresponding to each item to construct the final cryptographic elements and identify the misusage types among them. Specifically: First, find each calling function in the set A of key functions and establish their respective corresponding prefix search trees. Then, for each calling function, classify the cryptographic misuses in the code by checking the specific values of the parameters passed when calling the key function, and form the cryptographic misuse rule set Γ. Specifically: Each parameter of the function corresponds to a cryptographic property. Apply the cryptographic library API to map each parameter to various cryptographic properties, that is, map the parameters of the cryptographic library API to the cryptographic properties to form the set Β. For a pair {α,β}, where α∈Α and β∈Β, a misusage type γ is formed, and all misusage types form the cryptographic misuse rule set Γ. Next, use the prefix search tree to construct a cryptographic misuse index and match it with the cryptographic misuse rule set Γ. For the calling function fun, the root node of its prefix search tree is this key function, and the last leaf node is the misusage type m; the middle n layers correspond to the number of parameters of the function. When the cryptographic element table of the calling function fun is obtained, use each element in the element table, that is, each corresponding parameter, to match the nodes of the prefix search tree of the calling function fun one by one. When the current parameter in the element table meets the judgment condition of the node of the prefix search tree, it is considered that the cryptographic application implemented by the calling function fun contains the misusage type m. Form a complete cryptographic element c and a type of cryptographic misuse: c = (fun, {p1, p2, ...}, m), where {p1, p2, ...} represents the element list of the i-th item α in the key function list i table.

2. The method for classifying and detecting C / C++ cryptographic misuse according to claim 1, characterized in that, All nodes of the Code Property Graph (CPG) are stored in nodes.csv. If a certain node is a statement, then the location attribute represents the offset of this statement in the file; otherwise, it is a null value. If a certain node belongs to the Control Flow Graph (CFG), the value of the isCFGNode attribute is true. Each node has a code attribute used to describe the value of this node.

3. A method for classifying and detecting misuses of C / C++ cryptography according to claim 1, characterized in that, In the Code Property Graph (CPG), subgraphs belonging to the same file are connected to the File node by edges of type IS_FILE_OF, and nodes related to the Abstract Syntax Tree (AST) are connected by edges of type IS_AST_PARENT; nodes belonging to the same Control Flow Graph (CFG) are connected to the CFGEntryNode by edges of type CONTROLS; if there is a data flow relationship between two nodes, they are connected by an edge of type FLOWS_TO in the CPG; the extraction tool Joern analyzes the variables in the code and generates a symbol table. Each symbol is stored in a node symbol, and nodes related to variables are connected to the node symbol. If it is a statement node that defines the variable, it is connected by an edge DEF; if the variable is used in a statement, the node symbol and the statement node are connected by an edge USE, and nodes that use the same symbol are connected by an edge REACHES.

4. A C / C++ cryptographic misuse classification and detection method according to claim 1, characterized in that The process of extracting the feature table for each item in the critical function list is as follows: Specifically: for the i-th item α in the list i , for the calling function in this item, extract the parameter list passed in when the function is called. For each parameter p i perform the following operations: 1) If p i is a constant or a macro definition of a constant in the OpenSSL documentation, it is directly recorded in the element table P i ; 2) If p i is the variable v, traverse the code property graph CPG starting from the root node to find the statements that modify the variable v, form a statement sequence S, perform symbolic execution operations on the variables and expressions involved in the statement sequence S, and calculate the value of the modified variable v after passing through these statements when α i is passed in, and store this value in the feature table P i ; 3) If p i is an expression, extract all variables v in the expression. For variable v, perform step 2) to calculate the value passed into the expression, and then calculate the expression to obtain the final value passed into α i and record this value in the feature table P i ; Finally, all the elements in the statistical table are combined to form the i-th item α i of the element table P i ={p1, p2, …, p n}; Similarly, the above operation is performed on each item in the key function list to obtain the corresponding element tables for each item.

5. A method for classifying and detecting misuse of C / C++ cryptography according to claim 4, characterized in that, The calculation process of the symbolic execution operation is as follows: First, construct a symbol table T, add the variables involved in the sequence S to the symbol table T, search the CPG to find the initialization statements of the variables in the symbol table T, and initialize the variables in the symbol table T; Then, perform symbolic execution operations one by one in the order of the statements in the sequence S in the code, and calculate the modification results of the values of the variables in the symbol table T after each statement is executed; The specific calculation method is: calculate the result of the expression on the right side of the assignment operator in the assignment statement, and modify the symbol value that appears on the left side of the assignment operator in the symbol table T; Finally, after executing all statements in sequence S, obtain the final result of variable v from symbol table T and store it in element table P i .